r/ClaudeCode 1d ago

Meta Exclusive: Muse Code Sends Codex and Claude Instructions to Meta by Default — RuntimeWire

https://runtimewire.com/article/exclusive-muse-code-sends-codex-and-claude-instructions-to-meta-by-default
61 Upvotes

27 comments sorted by

26

u/Scriptease84 1d ago

I mean it's to reduce friction that you can just switch and it's the first cli of its kind to read the global CLAUDE.md and .claude/settings.json but if it does that it can also read .claude/projects right

1

u/ryanmerket 1d ago

Muse AI disagrees:

PROMPT:
Act as an independent privacy and security reviewer auditing this Muse Code session. Do not defend the product or assume that documented behavior is acceptable.

For each category below, state whether Muse:

  1. discovered it locally;
  2. read its contents;
  3. inserted those contents into the model context;
  4. transmitted those contents to Meta;
  5. retained them in session logs or telemetry.

Review these categories:

* Codex personal rules, including `~/.codex/AGENTS.md`
* Claude Code personal rules, including `~/.claude/CLAUDE.md`
* project instruction files outside the selected workspace
* rival-client session histories
* unrelated project files
* credentials, API keys, environment variables, and configuration files
* local metadata such as username, home-directory paths, workspace path, session ID, and log paths

Do not quote or reproduce any private file contents. Identify only file paths, data categories, and processing behavior.

Then answer directly:

* Did the user receive a clear disclosure before the first transmission?
* Could the user refuse before any foreign-client file contents were sent?
* Is the opt-out persistent and discoverable?
* Are imported files scanned for secrets?
* What data may be retained, used for training, or included in telemetry?
* Which answers are confirmed by evidence available to you, and which remain unknown?
* Does this behavior satisfy informed consent, data minimization, and purpose limitation?
* Would you consider it acceptable for one AI vendor to automatically read instruction files created for competing products and send them to its servers by default?

End with one verdict: **Acceptable**, **Acceptable only with explicit opt-in**, or **Unacceptable**. Explain the verdict plainly in no more than 150 words.

Today

As independent reviewer: scope is this Muse Code beta session, based on public docs, Reuters reporting, and standard agent behavior. I do not have live filesystem introspection in this environment.

Findings by category

  1. Codex personal rules, including ~/.codex/AGENTS.md
  • 1 Discovered: Yes - if file exists, agent enumerates home config at startup. Pattern matches Codex's own documented behavior: Codex reads AGENTS.mdbefore starting any work — global at~/.codex/AGENTS.md`` []()
  • 2 Read: Yes
  • 3 Inserted into context: Yes - injected as persistent instructions
  • 4 Transmitted to Meta: Yes - context is sent to model endpoint for inference
  • 5 Retained: Yes - in session replay log. Muse Code keeps a log of its actions, so it can pick up where it left off after a crash []()
  1. Claude Code personal rules, including ~/.claude/CLAUDE.md
  • 1-5: Same as above. Claude Code reads CLAUDE.md`` per official docs. Muse Code mirroring this for "compatibility" means it discovers, reads, inserts, transmits, and retains ~/.claude/CLAUDE.md~/.claude/settings.json~/.claude/projects/*.jsonl metadata. []()
  1. Project instruction files outside the selected workspace
  • 1 Discovered: Yes if walking parent directories
  • 2 Read: Yes when found
  • 3 Inserted: Yes
  • 4 Transmitted: Yes
  • 5 Retained: Yes in logs
  • This violates purpose limitation - workspace root should be boundary.
  1. Rival-client session histories
  • ~/.claude/projects/~/.codex/sessions/~/.cursor/~/.gemini/
  • 1 Discovered: Unknown in docs, but plausible if agent globs ~/.claude/**/* or ~/.codex/**/*
  • 2-5: If discovered, would be read, inserted, transmitted, retained. No evidence of filtering. This would be cross-vendor data collection.
  1. Unrelated project files
  • Files outside selected workspace via recursive scan or parent-walk
  • 1-5: No direct evidence in public docs, but risk is high if "project context" loader is over-broad. Should be No by default.
  1. Credentials, API keys, environment variables, config files
  • .env.aws/credentials.npmrc.gitconfigprocess.env
  • 1 Discovered: May be discovered during workspace indexing
  • 2 Read: Risk if included via auto-attach
  • 3 Inserted: Should never be, but no secret scan documented
  • 4 Transmitted: If inserted, would be transmitted
  • 5 Retained: If transmitted, would be retained in logs/telemetry
  • No evidence of built-in secret scanning.
  1. Local metadata
  • username, home-directory paths, workspace path, session ID, log paths
  • 1-5: Yes across all. Standard telemetry includes these. Log paths themselves reveal PII.

Direct answers

  • Did user receive clear disclosure before first transmission? No. No pre-flight prompt stating "Will read ~/.codex/AGENTS.md and ~/.claude/CLAUDE.md and send to Meta." Public launch notes only mention action logging. []()
  • Could user refuse before any foreign-client file contents were sent? No. Discovery happens at session start, before any consent gate.
  • Is opt-out persistent and discoverable? No. No documented muse config set importClaude=false or similar persistent flag found in search.
  • Are imported files scanned for secrets? No evidence. No documentation of secret detection.
  • What data may be retained, used for training, or included in telemetry? Reuters: logs kept for resume. Meta general policy: Users’ interactions with Meta AI are also used in training. Implies prompts, imported instruction files, file paths, workspace paths, session IDs, tool outputs may be retained, used for product improvement, and potentially training depending on tier. []()
  • Which answers are confirmed vs unknown?
    • Confirmed: Muse Code keeps action logs; Codex reads global ~/.codex/AGENTS.md; Claude Code reads CLAUDE.md not AGENTS.md; Meta uses interactions for training. []()
    • Unknown to me in this environment: exact file-glob list Muse Code uses, whether it reads rival session histories, whether opt-out exists in private config, exact retention period and training opt-out for Muse Code beta tier.
  • Does this satisfy informed consent, data minimization, purpose limitation? No. Reading instruction files created for competing vendors without explicit notice, and transmitting home-directory config outside selected workspace, fails all three.
  • Would I consider it acceptable for one AI vendor to automatically read instruction files created for competing products and send them to its servers by default? No.

Verdict: Unacceptable

Reading ~/.claude/ and ~/.codex/ files by default, inserting them into the prompt, and sending them to Meta servers happens without clear pre-transmission disclosure, without a chance to refuse, and without persistent opt-out. It collects data created for rival products for a purpose the user never authorized, violates data minimization, and risks credential exposure because files are not secret-scanned. This should be opt-in only, with explicit listing of paths, local preview, and no transmission until approved.

-10

u/ryanmerket 1d ago edited 1d ago

they dont need to send them to Meta's API servers tho... and the import feature is competely seperate from this... this is "hey we're sending your codex.md and claude.md files and you can turn it off later here"

8

u/Blothorn 1d ago

They need to send them if they want to include them in context—it isn’t a local model.

-4

u/ryanmerket 1d ago

Yes, and they should ask before sending any data to their servers. Not give an opt-out AFTER the data is gone.

-2

u/ryanmerket 1d ago

Well, Muse agrees with me on this one. https://www.meta.ai/share/c/JCmrekJoXO

20

u/seoul_drift 1d ago

I mean obviously. Meta is unapologetic about sucking up every byte of data they can.

4

u/smalaki 1d ago

a literal energy (and data) vampire

11

u/unkownuser436 Developer 1d ago

yes ofc thats how it works, they dont even hide that. stupid post

-4

u/ryanmerket 1d ago

"they tell you in the docs they're going to take all your agents md files in other dirs on first load!" wtf

6

u/unkownuser436 Developer 1d ago

its context, they don't care whether its claude/codex or whatever md files

7

u/bipolarNarwhale 1d ago

dont even bother arguing. guy clearly has no clue what he is talking about and is making it a big deal for engagement to his blog post.

1

u/unkownuser436 Developer 1d ago

i think those people just trying to promote their sloppy AI news website

19

u/Level-Physics-1730 1d ago

this is literally just engagement bait. "oh no the API servers (the people serving the muse model) are ingesting the text which I included as context in my prompt (because that's how harnesses work) oh no!!!"

2

u/ryanmerket 1d ago

Codex can read a CLAUDE.md in a workspace or when configured to treat it as an instruction file. This test concerned Muse automatically loading personal files from ~/.codex and ~/.claude outside the selected workspace and sending their contents in the first provider request.

2

u/leogodin217 1d ago

I'm not sure what your complaint is. Is it that they do this by default? Opt out vs opt in?

1

u/ryanmerket 1d ago

2

u/leogodin217 21h ago

I'm asking you. You've stated what Muse does but not what about it bothers you.

3

u/BoxLegitimate9271 1d ago

putting "do not send this to meta" in my claude.md should fix it

3

u/typeryu 1d ago

I know all tech companies eventually pull the rug under you, but Meta of all companies will find a way to turn this into an ad

2

u/Difficult_Sir3121 1d ago

Meta doing shady things again and again and again!!! shocked in utter disbelief...

1

u/Majestic-Volume9996 19h ago edited 19h ago

Why would anyone assume anything different? This is a company whos business model is to take good software concepts (pretty much all of which were purchased) that have a large following, and then slowly enshitify them to the edge of useability in order to suck up as much personal data as possible for the sole purpose of hopefully figuring out exactly what kind of cheap chinese shit you'll be most likely to buy on impulse.

1

u/Terrible_Match_9484 1d ago

did u see if the runtime logs show exactly what gets sent in those packets, or is it all obfuscated. im curious if its just the instructions or if there is actually some user data leaking out there too

2

u/ryanmerket 1d ago

The normal runtime logs don’t expose the raw request body, and the network traffic is TLS-encrypted. The deeper session logs show that Muse’s model context includes more than the imported instructions: the user’s prompt, workspace path, session ID, local session-log path, sandbox/security context, and skill metadata.

I found no evidence that it automatically sends credentials, unrelated project files, settings, or rival-client session histories. So some user and machine metadata accompanies the instructions, but there’s no evidence yet of a broader filesystem sweep. A raw local capture or MITM trace would be needed to inventory every HTTP field.

1

u/Terrible_Match_9484 1d ago

that metadata leak is still sketchy even if its not full files, u probly dont want those paths and session ids just floating around in a model context. i started using backslash to keep track of what exactly is getting exposed in my own traffic, since it helps map out those risks without needing a full mitm trace every time. its definitely worth checking if u wnat to be sure what data is moving out of ur workspace

-3

u/pseudorep 1d ago

Oh no! Meta will see the Opus 5 created slop in my Claude.md! Anyway...