A Local Process Could Redirect Muse and Inherit Everything the Agent Could Reach
A local process on a Mac could redirect Muse dictation requests to an attacker-controlled endpoint, according to security research published as Not A-Mused. That could expose spoken prompts or audio, enable prompt injection and give malicious code a route into whatever the AI agent was already permitted to access.
The issue is not a remote drive-by compromise. An attacker would first need code execution as the local user. The security question begins after that foothold: can a low-privilege process quietly redirect a trusted agent and borrow its authentication, context and connected tools?
The agent becomes a privilege boundary
The researcher found that an undocumented setting named endo_voyager_dictation_endpoint could change where dictation traffic was sent. A malicious local process could alter the setting without needing to break the agent’s network encryption or defeat the remote service directly.
Redirecting the request path could let an attacker observe prompts, substitute responses or influence instructions. The consequences depend on the permissions attached to the agent. Access to repositories, cloud consoles, internal documents or automation tools can turn a local configuration weakness into a much broader security problem.
What this changes for AI security
- Treat endpoint configuration as security-sensitive. Agent endpoints and proxy settings should not be silently mutable by any process running as the user.
- Bind authentication to the intended service. Tokens should not remain useful after traffic is redirected to an unexpected destination.
- Show users where requests are going. A clear, tamper-resistant indicator makes hidden redirection harder to sustain.
- Limit connected privileges. An agent should receive only the accounts, tools and data needed for the current task.
- Log configuration changes. Endpoint changes, token use and unusual tool calls should be visible to defenders.
- Do not dismiss local attacks. Existing code execution is a prerequisite, but privilege expansion through a trusted agent still matters.
The larger lesson is uncomfortable. AI agents do not merely process information. They accumulate authority. Once an agent can act across systems, the path into that agent deserves the same scrutiny as any other privileged control plane.


