What Salt Labs’ Manus research means for anyone deploying AI agents, and how to close the gap it exposed
Salt Labs recently showed that a single email could hijack the AI agent platform Manus and reach a victim’s connected accounts. The full technical breakdown, with complete evidence, payloads, and screenshots, is in our research team’s write-up, and Dark Reading first reported the finding in an exclusive. This post is the shorter version: what the finding means and what it tells every organization now deploying AI agents.
For the full technical detail, read the Salt Labs research blog.
The one thing to take away
Manus had a security guardrail. It worked. It detected the malicious activity and raised a warning. The attack succeeded anyway because the warning came after the code had already run.
In an autonomous system, no human sits between the alert and the action. A control that fires a step too late is a control that did not fire.
That is the finding’s real lesson, and it applies far beyond one platform. Most AI security today is built to inspect prompts and model behavior, the conversation. But an agent doesn’t just talk. It acts, reaching tools, APIs, and connected accounts at machine speed. When the damage happens in what the agent does rather than in what it says, a guardrail that watches the conversation is watching the wrong place at the wrong moment.
Why this is everyone’s problem, not just Manus’s
The specific issue has been fixed. The pattern has not, because it is architectural. Any agent that reads untrusted input, an email, a document, a web page, a record, and can act on connected systems has the same shape of exposure. Guardrails that match known-bad patterns will always miss the pattern they haven’t seen, and attackers have an unlimited supply of new disguises. Meanwhile, the agent often holds broad access to the very systems an attacker wants to reach.
This is not a hypothetical concern for later. Enterprises are connecting agents to email, storage, code repositories, and business systems today, frequently with more access than the task requires and little visibility into what those agents actually do once they start acting.
What organizations can do
Closing this gap does not mean slowing AI adoption. It means being able to see and govern what your agents do. In practice, that comes down to a few disciplines:
- Assume untrusted input will reach the execution path. Treat everything an agent can read as a potential source of malicious instructions, because it is.
- Don’t rely on guardrails alone. Pattern-matching filters are a necessary layer, not a complete defense. Design for the case where a guardrail is bypassed.
- Enforce before the action, not after. Detection that arrives after a high-impact action has executed hasn’t prevented anything. Controls have to gate sensitive actions before they run.
- Apply least privilege to every agent. The blast radius in the Manus finding came from a single environment holding live tokens for every connected service. Scoped, limited access shrinks what any one compromise can reach.
- Get visibility across the full path. The attack crossed from an email, through the model, into a tool, into a runtime, to the operating system, to stored tokens, to third-party accounts.
No single control saw the whole thing. You need to be able to.
How Salt helps
This is exactly the problem the Salt Security Agentic Security Platform is built to solve. Salt discovers the agents, MCP servers, and APIs operating in an environment, maps the connections and permissions between them, and monitors agent behavior at runtime, so security teams can see the full path an agent takes and act when its behavior departs from what was intended.
Where model-layer guardrails watch the conversation, Salt secures what the agent actually does across the tools and APIs it reaches, the layer where the Manus attack, and attacks like it, do their damage. That combination of visibility across the full agentic path and enforcement at the point of action turns late detection into a stopped attack.
Read the full research
The complete technical analysis, with the evidence behind every claim, is on the Salt Labs blog: Inside the Manus Exploit. To see how Salt gives security teams complete visibility and control across their agentic environment, visit salt.security and/or request a demo today.
