How Meta says Sentinel protects Muse from unsafe actions

Meta describes a separate Sentinel agent and system-level controls intended to reduce prompt-injection and unsafe-action risk.

Meta's safety write-up describes Muse as an unusually privileged agent: it can have access to inboxes, calendars, a browser and a shell.

The company says its defense includes a separate Sentinel agent, training for prompt-injection awareness, permission boundaries and other system controls. These are design claims, not a guarantee that attacks are impossible.