№ 0107Resource★ Pick
How Meta built safety into Muse
Meta's engineering write-up on Muse security: isolated VMs, a separate Sentinel permission authority, credential surrogation and layered prompt-injection defenses, with bug bounties up to $300,000.
The post details systemd-nspawn runtime cells mapped to unprivileged host users, Sentinel as sole gatekeeper for connector actions and network egress, and ensemble classifiers plus human approvals against prompt injection. It lists a $130,000 bounty for a successful single-user prompt injection and a planned confidential VM mode.








ChatForm
Tgmlabs