Muse's Web Code References an Unannounced 'Trusted Network' for Connecting People
Reverse-engineered web assets describe invitations, contact approvals, and safety-code screens. Meta has not announced the feature.

Muse’s Web Code References an Unannounced “Trusted Network” for Connecting People
The references describe a flow of picking contacts, exchanging invitations, and approving connections (a different kind of invite from the referral invite codes Meta uses for growth), but code names do not establish a launch date, an enabled feature, or what one Muse would actually share with another.
Meta’s Muse web client contains references to a feature called “Trusted Network” that Meta has never announced, according to an analysis of Muse’s public web assets published October 1 by RuntimeWire. The outlet inspected 69 JavaScript files delivered by muse.ai, totaling nearly 4 megabytes, and found identifiers for contact selection, invitations, connection-request reviews, and safety-code screens across the interaction, screen-view, surface, and logging catalogs.
The clearest traces describe a connection flow. The interaction catalog names adding a person, choosing a contact, accepting or canceling an invitation, and disconnecting. One identifier, chat_trusted_network_connection_request_review_click, places a connection-review action inside chat. The screen-view catalog names a Trusted Network overview, individual person views, invitation screens, an invite-link view, and connection requests. The surface catalog names settings_trusted_network_contacts, and the logging catalog includes Trusted Network settings and chat connection requests.
The code also names a safety-code decision, retry, and close action, with corresponding safety-code and safety-code-access screen views. RuntimeWire notes the terminology is suggestive but unexplained. The files do not say whether safety codes verify cryptographic identities, ask a person to compare a code, or serve some other purpose.
What the Names Do and Do Not Establish
RuntimeWire flagged the limits of its own finding. The references are instrumentation declarations, named actions and screens rather than working code, and such catalogs can retain experiments, abandoned interfaces, or features unavailable to most users. The inspection recovered no implementation of the screens and observed no two Muse agents communicating, so agent-to-agent coordination remains an inference. Meta did not respond to RuntimeWire’s request for comment before publication.
The caution is warranted, since the finding is suggestive without being specific. A system for connecting people inside a personal agent could mean anything from a shared-contact list to assistants coordinating across users, finding meeting times, planning around calendars, splitting tasks between two Muses. The code supplies the vocabulary of invitations and approvals. It says nothing about the permission model that would make those connections safe. Sharing a free time slot is a different act from exposing a calendar’s contents, and the files do not resolve which one a connection permits.
The Context Around the Trace
A competitor has already shipped a version of the idea. In a September 13 post, Instinct founder Noah Shinn said the company’s Trusted Person network was available to all Instinct users, describing assistants finding meeting times, coordinating dinner for ten people, and adjusting recurring tennis sessions when someone’s calendar changed. Muse’s references do not establish that Meta follows Instinct’s design or that the two systems would interoperate (similar naming is no evidence of copying), but they place the trace inside an industry-wide move toward agents that act across people rather than for a single user.
The same inspection turned up more concrete code elsewhere. It found executable client helpers for enrolling in and recovering Confidential VM sessions, an announced Meta security feature for Muse, including a recovery-secret check and browser-side credential storage. Those are implemented functions rather than declarations, but they belong to the already-announced Confidential VM feature and add nothing about the Trusted Network.
Why It Matters
If Meta is building a connection system into Muse, the interesting question is what accepting an invitation would actually grant. An agent that can reach into another person’s data, or act on it, needs a permission model users can actually understand. History suggests those models are the first thing to break under pressure. In Muse’s first month alone, Meta has faced a privacy dispute over Messages access and an incident where the agent handed a stranger a seller’s address. The Trusted Network trace leaves the central question unanswered: the permission model whose rules would govern these connections does not appear in the code.


