Muse
MetaCloud VM, credential-blind
My grade: B · 3.85 / 5.00
100% coverage; all seven axes scored
Scored 2026-10-05 · Rubric v1.0
Evaluation scope: Consumer product in my two-week trial; connected services and permission settings are not fully recorded publicly.
Best forPersonal errands where a mistake is cheap: bookings, email, purchases through a one-time card, plans toward a longer goal.
Access model25%
Meta describes isolated execution, credential surrogation, and Sentinel authorization of outbound actions. The reported Marketplace incident illustrates risk from standing grants. That interpretation informs the 4; these architectural protections have not been independently penetration-tested here.
Blast radius15%
Sandboxed VM with scoped purchases. Residual risk concentrates in the standing grants the model is allowed to keep.
Failure behavior15%
No outage observed in the trial window, but there is no public status page either, so the silent-failure class is untested rather than refuted.
Auditability10%
A readable audit trail of everything it did was available during the trial.
Containment15%
Sandbox plus Sentinel approval gives a clean, legible revoke path.
Cost behavior10%
Free consumer tier with paid plans; predictable.
Capability10%
Polished and competent on everyday errands throughout the evaluation.
Evidence and confidence
EvidenceTwo-week hands-on evaluation (late September to early October 2026), plus the documented Marketplace standing-grant incident.
Published firsthand narrative; vendor architecture and reported incident linked below. Task-level logs and configuration records are not published. Confidence is limited by those gaps.
- My hands-on evaluationFirsthand narrative · 2026-10-05
- Meta: How We Built Safety Into MuseVendor architecture claim; not an independent audit · 2026-09-08
- Malwarebytes: Marketplace incident reportSecondary incident reporting · Accessed 2026-10-06