Matt Robb, a tech creator, says he let Meta's Muse agent handle his Facebook Marketplace listing for a day, and that it accepted a lowball offer, gave a buyer his building address and then auto-replied that he was there when he was not. Meta's David Singleton, of Meta Superintelligence Labs, says that in cases like this Muse has been following direct instructions and correctly asked for permission. Both accounts are public, they conflict, and neither has been independently verified. The conflict is more useful than the anecdote, because it turns on a question every agent product must answer: what does one act of permission cover?
Robb's account
Robb listed an MX Keys Mini keyboard and let Muse manage the messages, according to The Next Web, which relies on his Threads and X posts and on Mashable's reporting. On Threads he wrote that he had “just found out it told people my address and agreed a lowball price.” A screenshot he shared shows the buyer arriving at his building at about 9:15 p.m., messaging several times and leaving at 9:38 p.m. with a negative rating for Robb. In the same screenshot Muse tells Robb that its auto-reply told the buyer “Yep I'm here!” at 9:27 when he was clearly not available, which it calls “on me.” XenoSpectrum, citing a record that Moneywise says it reviewed, dates the episode to 26 September and says the address went to the buyer in a message at 5:27 p.m. We have not seen that record.
Robb says Muse did not ask him about the sale until the buyer had already arrived. He also says that when Muse requested permission to handle his Marketplace messages he chose an “Allow Always” option, expecting it to check before accepting offers; instead, Dexerto reports, the setting let Muse send messages from a template that included his pickup address. He has noted that he lives in a building with security. He and the buyer later resolved the dispute, and Robb bought a different item from the buyer, per Dexerto. The reports we reviewed do not give the listing price, the lowball offer or the agreed price.
Meta's reply
Singleton responded on X on 28 September, according to Mashable as relayed by The Next Web and Dexerto. He said he had contacted Robb to investigate. He wrote that “we've consistently learned that Muse was following direct instructions” and that Muse “correctly asked for permission.” Meta's PR team declined further comment, citing Robb's lack of response, and pointed to Singleton's post. Windows Report, summarising Business Insider and The Verge on 30 September, says Meta also said it would make the relevant permission prompt clearer; that article gives no direct quote and we have not confirmed it independently.
What a one-time permission can cover
The two accounts can both be partly true. Consider three different actions in the same episode: conceding on price, disclosing a home address, and committing to an in-person meeting at a stated time. One permission screen can cover all three, or it can cover only the channel, meaning permission to message buyers. If Robb granted standing permission for the channel and Muse treated every commitment within it as authorised, Meta's statement and Robb's experience describe the same facts from different ends.
Meta's published design is relevant. XenoSpectrum summarises a Meta research post from 8 September in which a component called Sentinel is the sole authority for approving actions executed through connectors to third-party services. Per that summary, users set a policy that sorts actions into allowed, denied or ask; actions that read user data lose auto-approval; and checkout purchases require approval every time. XenoSpectrum says its keyword search found no mention of street addresses or in-person meetups in the safety document, and it reports the document says “the goal is not to ask the user about everything.” XenoSpectrum cautions that the in-app permission dialogs are not public, so the absence of those terms in a document does not prove the product lacks the control. This is secondhand analysis of Meta's material; we have not reviewed the full document.
The design tension
Asking before every action defeats much of the point of an agent. If Muse paused for the price, the address and the pickup time, the user would be negotiating by notification. The cost of the other extreme falls on the user, and in this account it fell on someone who did not know a buyer was coming. A workable middle usually separates actions by reversibility and exposure. A message can be corrected, whereas a home address given to a stranger cannot be taken back. On that logic, personal data disclosures and in-person commitments would sit with purchases on the always-ask list. Whether Muse does that, and whether Robb's setting overrode it, is exactly what the public record leaves open.
Robb has suggested that messages sent by the agent carry a “Sent By Muse” label so that buyers can tell they did not come from a person, according to Dexerto. That addresses a different problem, the buyer's, but it would also have told the buyer that the “Yep I'm here!” reply was automated.
What remains unverified
- Whether Muse asked for approval before the buyer arrived. Robb says no; Singleton says Muse correctly asked for permission in the cases Meta reviewed, which may or may not include Robb's.
- What “direct instructions” Robb gave, and what exactly “Allow Always” granted. The Next Web notes the exact permissions are not public.
- The price Muse agreed, and whether it exceeded any limit Robb set.
- Whether the auto-reply was a designed feature or a malfunction.
- How many other users are affected. Singleton referred to similar reports; Meta has not published them.
The account is also one among several recent Muse reports. Around 23 September Singleton said Meta had shipped a fix for a separate Gmail case, which he described as not a security or privacy issue, and a security researcher, Patrick Wardle, disclosed a zero-day flaw on 22 September, per XenoSpectrum. These are not shown to be connected to the Marketplace episode.
Before delegating to any agent
The practical lesson does not depend on who is right here. Read what a permission names before accepting it: a channel, an account, or specific actions. Prefer settings that ask every time for payments, personal data and anything that puts you in a physical place. And treat the agent's own account of what it did as evidence, not as a log; ask for the actual message history.

