Muse Puts OpenClaw’s Agent Playbook Through Meta’s Security Test
Meta’s Muse and Instinct show how OpenClaw’s agent design is moving into mainstream apps, where easier access now has to answer data, malware and hijacking risks.

Meta's new Muse agent has turned OpenClaw's open-source influence into a commercial test of whether consumer AI assistants can become easier to use without carrying forward the same security worries, The Verge reported.
Muse has already broken through in a way few agent products have.
An Apptopia estimate cited by the source put the app at 600,000 daily active users in the US soon after release, while Instinct, another agent platform, has been circulating in the industry as its creator fundraises at a $2.5 billion valuation.
Both products are being compared with OpenClaw, the earlier open-source project that helped show how agents could work as everyday assistants instead of research demos.
The comparison is unusually specific for Muse.
Social media users pointed to shared names for core files, including SOUL.md, memory and tools, along with similar design choices and overlapping language in documents that govern personality and tone.
One Reddit user argued that Muse looked like a wrapper on top of OpenClaw and warned that it could inherit security risks from the older project.
Meta disputes the copying claim.
Nat Friedman, head of product for Meta's Superintelligence Labs, wrote on X that Muse was built “from scratch,” while acknowledging that the product was “heavily inspired” by OpenClaw.
He also wrote that he bought hundreds of Mac Minis for his team after first using OpenClaw in January, and that Meta wanted a similar platform that could be made safe, secure, easy to use and scalable to billions of people.
The technical tradeoff is that OpenClaw's most appealing feature was also one of its hazards.
The project let users converse with agents through WhatsApp, Telegram, Slack, Teams and Discord while running the software on personal computers.
In roughly a week, it drew two million visitors and 100,000 GitHub stars, encouraged some users to buy Mac Minis so agents could run constantly, and helped form meetups and side projects around the agent community.
That momentum pulled larger AI companies toward the same user pattern.
OpenAI hired OpenClaw creator Peter Steinberger in February to work on agents.
Google highlighted consumer agent plans in May, Apple moved further into agents in June, Instinct grew in private beta in August, and Meta introduced Muse in September.
The sequence made the design question less about whether OpenClaw created the entire category and more about how much of its interaction model would be absorbed by better-funded platforms.
Security remains the hardest part of that absorption.
OpenClaw had a widely discussed malware problem, including one top-downloaded skill that contained malware and a researcher finding that 15 percent of the skill repository included “malicious instructions” to access user data secretly or perform suspicious tasks.
Mark Zuckerberg wrote that Muse was built from the ground up for privacy and security, with user data and credentials stored inside the Muse Secure VM, an isolated Linux computer with browser, CPU, memory and storage.
Muse still leaves open questions for users who want stronger guarantees.
Although data is isolated from other users, Meta can access it for now.
The company plans to add a way later this year to cryptographically and verifiably prevent Meta from accessing data inside a user's VM.
Muse also defaults to allowing Meta to train and improve models with user data, though users may opt out, and a researcher flagged a zero-day vulnerability this week that could let an attacker hijack an agent.
Instinct's distinction is less about code similarity and more about access.
Its agents can communicate through Apple's default messaging product, broadening the group of people likely to try the service.
Muse benefits from one-tap downloading and integration with Meta systems, reducing the friction that made OpenClaw powerful but harder to adopt.
The commercial bet behind both products is that mainstream users will accept agents when setup becomes simple and the security model is convincing enough.
OpenClaw supplied the pattern; Muse and Instinct now have to show that scale, convenience and stronger controls can improve it rather than merely repackage it.




















