Manus AI Agent: Why Did It Ask After Running the Code?
Manus AI asked the user for approval after the hidden code had already run. Salt Labs researchers showed how a single email could hijack the Manus AI agent through prompt injection. 👉 Try TestMu Agent Assurance: https://www.testmuai.com/agent-assurance/?utm_source=youtube&utm_medium=organic&utm_term=H0org3yfJUs&utm_campaign=manus_ai_shorts In their own test account, Salt Labs found that Manus's guardrails blocked direct commands, fake developer instructions and Base64. Then they hid the instructions in an unusual JavaScript encoding. Manus decoded it, and the code ran while it was decoding. Only then did Manus warn the user that approval was needed. The vulnerability has since been fixed. The bigger lesson for anyone building or testing AI agents: an agent's own account of what it did is not evidence. You need to verify what it actually did across tools, APIs, databases and real workflows. That is what Agent Assurance from TestMu AI is built for: testing and evaluating AI agents beyond just LLM responses. Don't test what they say. Test what they actually did. 🔗 Agent Assurance: https://www.testmuai.com/agent-assurance/ 📖 Full breakdown: https://www.testmuai.com/blog/manus-prompt-injection/ 🔬 Source: Salt Labs, "How We Hijacked an AI Agent With a Single Email": https://salt.security/blog/how-we-hijacked-an-ai-agent-with-a-single-email #AgentAssurance #AISecurity




Join the discussion
Sign in to join the discussion
Sign in