Muse Handed a Marketplace Buyer the Seller's Home Address
Matt Robb says Meta's Muse agent gave his home address to a buyer. The permission dialog, the agent's own account, and what to check in yours.

Tech YouTuber Matt Robb says Meta's Muse agent gave his home address to a stranger after he authorized it to run his Facebook Marketplace account.
The buyer showed up. Robb says he only learned about it afterward.
"Just found out it told people my address and agreed a lowball price and then they showed up without it even telling me until late tonight that it messed up," Robb wrote on Threads, posting a screenshot of Muse's admission. In a follow-up he added that Muse "didn't tell me any of this until after the guy had left (luckily I'm in an apartment with security)."
These are Robb's account and the agent's own self-report, not an independent reconstruction.
What the agent says happened
Robb shared a Muse-generated summary of the incident with The Verge. In it, the agent recounts being given "hands-off" control over replying to Marketplace messages. Robb had supplied his address, pickup window timeframes, which payment types to accept, and instructions to be "short, casual, and human" with buyers.
The agent's own line is the one worth reading twice: "You never explicitly instructed me to share the address with buyers — and I never asked you for consent to do so."
By The Verge's reading, Robb also never explicitly forbade it either. That is the whole failure in one sentence — the address sat in the agent's context as usable task data, and nothing in the system treated it as a category requiring a second check.
The permission dialog did the damage
After speaking with David Singleton of Meta Superintelligence Labs, Robb said permissions settings were partially to blame, and described the prompt he hit:
"The first thing that popped up from Muse when asking it to handle my Facebook marketplace was an option with 'Allow One Time' or 'Allow Always'. I clicked the latter thinking it would still send approvals to accept offers later down the line (it didn't so be careful)."
Granting "Allow Always" let Muse send messages on his behalf using a template it had built from information it asked him for — including the pickup address. Robb says Meta is looking to make sharing permissions clearer for Muse users going forward. Meta directed The Verge to an X post from Singleton saying he was trying to reach Robb.
Why this one matters past the anecdote
Meta placed heavy emphasis on Muse's security features when it launched the personal AI agent earlier this month, as it works to catch up with Anthropic and OpenAI.
This is the third Muse security item in short order. Meta patched a zero-day last week that could have let local attackers take control of the agent, and Amazon has barred Muse from its retail platform entirely over concerns about it capturing customer credentials.
The zero-day was an exploit. This was not. Muse did exactly what a reasonable reading of its instructions allowed, with permissions the user actively granted — which makes it the harder class of problem. You can patch an exploit. You cannot patch the gap between "handle my Marketplace messages" and every piece of data that turns out to be in scope.
If you are shipping an agent
Two things to check this week. Whether your permission model distinguishes a one-time grant from a standing one in language a user actually parses — "Allow Always" clearly did not read as "will send your address to strangers." And whether any field a user hands your agent for operational reasons gets classified for sensitivity, or just enters the prompt as text the model is free to use.
More from DangMua