Meta says Muse will sometimes make mistakes
In its own write-up on Muse's safety, Meta says prompt injection is still unsolved across the industry and that Muse will sometimes get it wrong. It's paying up to $300,000 to people who find ways to trick it.
Keep reading
Prompt injection means hiding instructions in something the agent reads, like an email or a web page, so the agent follows them instead of you. Meta has built several layers of defense against it. It's also telling users plainly that those layers won't catch everything.
This month a Mac security researcher, Patrick Wardle, found a separate problem. Malware already on a Mac could quietly redirect Muse's voice dictation and use whatever access the person had given Muse. Meta patched it quickly, but it shows how every connection you give an agent becomes available to whoever finds the next flaw.
None of this means you shouldn't use Muse. It does mean it matters which Gmail you connect and what else depends on that inbox.
Sources: Meta, The Register