not-a-mused
not-a-mused is First, one of 0day PoCs. It is ranked #81 on the Dev Radar, in Security, first seen 17 h ago and shared in 3 posts (50.2k views).
What not-a-mused says about itself
Not a Mused. Contribute to pwardle/not-a-mused development by creating an account on GitHub.
GitHub - pwardle/not-a-mused: Not a Mused · GitHub Skip to content Navigation Menu Sign in Appearance settings Search / Sign in Sign up Appearance settings You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert {{ message }} pwardle / not-a-mused Public Notifications You must be signed in to change notification settings Fork 0 Star 0 main Branches Tags Go to file Code Open more actions menu Latest commit History 3 Commits 3 Commits Folders and files Name…
What people said about not-a-mused on X
Meta’s Muse can send your prompts to an attacker and allow them to see all your data and manipulate it. Attacker needs local access already, but you’d make it VERY convenient for them to hook into a process you expect to read all your data and execute arbitrary commands.
— @IceSolst, 17 h ago · 116 likes · see the post
Used it to hack itself? 💀 But please fix, its trivial to exploit and (locally) take over the agent 😭 https://github.com/pwardle/not-a-mused/blob/main/README.md
— @patrickwardle, 17 h ago · 116 likes · see the post
🚨 SlowMist TI Alert: Muse Zero-Day 🚨 According to a disclosure by @patrickwardle, a zero-day vulnerability in Muse for Mac could allow a local process without special privileges to hijack the AI assistant by modifying an undocumented setting. ⚠️ The flaw can redirect dictated prompts to an attacker-controlled…
— @SlowMist_Team, 5 h ago · 5 likes · see the post
Alternatives to not-a-mused
- security-audit-skill — A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings -…
- Cloudflare Blog — Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose…
- entratrace — EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling…
- CSA — Traditional threat modeling assumes you can map the attack surface ahead of time. An autonomous agent doesn't work…
- Gist — ZCode (zai-org/ZCode) 凭据加密的兜底密钥机制:默认情况下加密密钥由平台/家目录/用户名推导,偷取密文文件即等于拿到全部 API Key - ZCode-credential-fallback-gist.md
- anthropic-credited-cves — Tracking Vulnerabilities That Appear to be Credited to the Anthropic Research Team -…
not-a-mused in numbers
- Rank on the Dev Radar: #81 of 2352
- Shared in 3 posts by 3 accounts: @IceSolst, @patrickwardle, @SlowMist_Team
- 50.2k views on those posts
- First seen 17 h ago, last shared 5 h ago
- Pricing seen by Jev: open source
- Market: Security
FAQ
What is not-a-mused?
First, one of 0day PoCs It was first shared on X 17 h ago and is ranked #81 on the Dev Radar.
Is not-a-mused free?
It is open source.
Who shared not-a-mused?
3 accounts on X, including @IceSolst, @patrickwardle, @SlowMist_Team, in 3 posts totalling 50.2k views.
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 20.7k posts from 4.9k X accounts over the last 21 days, 2.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 08:21 UTC. Full method.