How Meta says Sentinel protects Muse from unsafe actions
Meta describes a separate Sentinel agent and system-level controls intended to reduce prompt-injection and unsafe-action risk.
Meta's safety write-up describes Muse as an unusually privileged agent: it can have access to inboxes, calendars, a browser and a shell.
The company says its defense includes a separate Sentinel agent, training for prompt-injection awareness, permission boundaries and other system controls. These are design claims, not a guarantee that attacks are impossible.