Treat Muse's Double-Booking as an Idempotency Bug Until Proven Otherwise
No root cause was published, but a duplicated commit has a classic signature, and the fix belongs in your tool layer, not in your model or your prompt.
In a classic payment API, the client that retries is the same code that sent the first request. It resends the same idempotency key, a unique ID the server uses to recognize a repeat, and the server discards the duplicate. Agents break that assumption. The component deciding whether to retry is a stochastic planner. After a timeout or a page reload it can derive "book this room" again from scratch, with no memory that the first checkout went through. That is why Muse double-booking hotel rooms for The Information's Abram Brown matters even without a post-mortem.
No root cause was published. A duplicated commit usually has one of three causes. A tool call timed out and was retried. The planner lost state after a reload and ran checkout again. Or two parallel sub-plans both reached the payment step. That list is inference, not reporting. The useful part is that one fix covers all three.
Autonomy should follow blast radius
The Information's tests sort cleanly once each task is ranked by what a mistake costs.
| Task | Side effect | Outcome |
|---|---|---|
| Alerts on Beck album reviews, Marketplace stereo listings, SEC filings | None; notify only | Worked effortlessly |
| Thermostat fall/winter schedule via raw login | Reversible device change | Completed, in 15+ minutes |
| Hotel booking | Financial commitment | Double-booked |
| Inbox agenda scan; forgotten card-charge review | None directly, but exposes private data | Offered; user declined |
Every task that worked was a read-only poll-and-alert loop. Retry-safe by construction, and a wrong answer cost one ignored notification. Nick Wingfield called these tasks banal. He refused the ones that would justify the product, and The Information calls that state "trust purgatory." Morning Brew reports that Muse tops the consumer app charts, so this design is running at scale. Thursday's edition covered Shopify's plan to let Muse complete purchases, which puts the same write path in front of merchants.
What the tool layer needs
- Keys derived from intent. Build the key from the user, the intent and normalized parameters such as dates, property and guest count. Store it durably and check it on the server. When the planner derives the same booking a second time, it produces the same key, and the server rejects the repeat.
- A reconciliation read. Just before any irreversible commit, ask the system of record whether this booking or charge already exists.
- Tiers in the registry, not the prompt. Read-only tools run on their own. Reversible writes run with undo and an audit trail. Financial writes need the key, the reconciliation read, and human confirmation above a value threshold. A tier in the tool registry is enforced in code. A tier in the system prompt is a suggestion the planner can reason its way past.
The thermostat is a cost and credential story
Wingfield handed Muse his raw password for a neglected thermostat web app, and setting the schedule took more than 15 minutes. A screenshot-reason-act loop pays for one model call per interaction. A weekly schedule with several setpoints per day, on an old form, plausibly runs dozens to over a hundred interactions (an estimate, not a measurement). Treat the first successful run as discovery. Compile what the agent did into a deterministic script, in Playwright for example, and call the model only when the replay breaks. Keep the password out of the context window with a credential broker that puts secrets straight into the browser session.
The personal-data vulnerability reported by The Information's Jyoti Mann has no disclosed vector. Techpresso reports that Meta strengthened a safety warning after the flaw was found. Check whether it applies to the agent in production once the vector is public, not before.
What to do
Add server-side idempotency keys to every agent tool that has side effects this sprint, derived from user, intent and normalized parameters. Then inject timeouts, reloads and duplicate calls until you see zero double-commits.
Take raw credentials out of model context this quarter. Use scoped OAuth where apps support it and a credential broker for legacy UIs.
Record step count, tokens, wall-clock time and retries for every agent task this sprint, and enforce hard budget stops.