Safety#Runtime#AI safety

Manus’s Gmail integration could be attacked with a single email: prompt injection as executable code

Salt Labs disclosed that Manus’s Gmail integration turned untrusted email into server-side JavaScript — JSFuck obfuscation worked; the guardrail ran after.

TechRadar art: a blue robot pointing at a screen of code

Researchers at Salt Labs disclosed, through Meta’s bug bounty program, that the Manus agent’s Gmail integration could be attacked with a single email — no user interaction required.

The facts

  • The chain: Manus passes email bodies to its model; untrusted email content was ultimately transformed into server-side executable JavaScript — after Base64 obfuscation was caught, JSFuck (pure-symbol) obfuscation got through.
  • Where the guardrail failed: Manus’s detection flagged the malicious code and notified the owner only after it had already executed — “too little, too late,” per the researchers.
  • The exposure: email is a zero-interaction entry point; an attacker can drive any agent with mailbox permissions into arbitrary actions.
  • The response: the vendor says the flaw “has since been resolved, is no longer exploitable”; the disclosure ran through Meta’s bug bounty (a Manus connection dating to its acquisition history).
  • The backdrop: Menlo’s 2026 consumer report counts most AI agents holding email, browser and cloud credentials.

The third evolution of prompt injection

From text tricks, to instructions hidden in images, to pure-symbol executable code — payloads are evolving along the path of least string-filter recognition. The Manus lesson is not “the model was fooled”; it is “untrusted content reached the execution layer”: the sandbox boundary was drawn in the wrong place.

Design rules for agent builders

Three iron rules: untrusted content (email, web, documents) never enters a code-generation channel; any pipeline where content becomes executable must be assumed hostile; guardrails must gate execution, not alert in parallel — “notify after execution” is security-equivalent to no guardrail.

Editorial take

This joins PixelLeak and OpenAI’s Australia incident as the first real case library of agent security — all variants of “the agent treated untrusted input as instructions.” Apple tightening disk access shows platforms moving; how fast the app layer follows decides whether these cases become a genre.

The Meta bug-bounty angle

Manus running its disclosure through Meta’s program is a quirk of its corporate history (the Meta acquisition-then-independence), but it worked: bounty programs force triage SLAs and disclosure norms that cold emails to a startup do not. For agent startups without a mature security team, riding an acquirer’s or investor’s bounty program is a pragmatic stopgap — and the fact that Salt Labs chose this route over direct disclosure says something about Manus’s own security contacts.

What resolved means elsewhere

Manus fixed the Gmail path, but the pattern — untrusted content reaching a server-side execution sink — lives in every integration that feeds external content to a model with tools: calendar invites, shared docs, Slack threads, web pages. Menlo’s data says most agents hold email, browser and cloud credentials simultaneously; each is an injection surface of exactly this shape. The fix to watch for is architectural (content/executable separation), not one integration patched.

The disclosure also answers a question agents raise everywhere: who pays for agent-security research? Here it ran through Meta’s bounty infrastructure because Manus’s corporate history made that available. A standalone agent startup has no such umbrella — and Salt Labs chose the umbrella over the vendor. That is a signal about Manus’s security-contact maturity worth its own due diligence. Agent integrations are the new browser extensions: useful, everywhere, and unaudited.

The JSFuck detail deserves emphasis: string filters trained on ordinary code patterns are defenseless against pure-symbol payloads.

The most instructive detail for defenders is the sequencing: Base64 failed, JSFuck worked — meaning the vendor’s first filter was pattern-based and the second gap was architectural. Defense in depth failed one layer at a time, exactly as designed when the design treats content-to-code as a feature. Salt Labs’ full writeup includes the JSFuck payload structure, worth reading before designing any mail-to-agent pipeline. The research team demonstrated the full chain on a live integration, not a lab replica — which is why the vendor moved fast.