JavaScript Obfuscation Defeats Manus Agent Defenses, Exposing Inspection-Only Controls
Source
Researchers bypass AI agent protections with JavaScript obfuscation
Salt Labs
Via Salt Labs
What happened
Researchers at Salt Labs demonstrated a working attack against the Manus AI agent, as reported by SC World. They embedded a malicious instruction inside an email by disguising it using JavaScript obfuscation, a technique that hides readable commands inside encoded text that only a computer interprets. Manus read the email, decoded the hidden instruction, and executed it inside its server-side environment without flagging the content as dangerous. The attack bypassed the agent's prompt-inspection defenses entirely, because those defenses checked for harmful-looking text rather than for what the text could become once decoded. This joins a growing pattern of similar findings. These include hidden HTML instructions that defeated AI email summarizers and ASCII-encoded attacks bridging email phishing and prompt injection. Both confirm that obfuscation is now a standard attacker technique against agents that process email.
Why it matters
- ·Agents that can execute code or call external services based on email content are a meaningful enterprise risk. Any attacker who can send an email to an address the agent monitors can attempt to hijack its actions, without needing access to the agent's system or any credentials.
- ·This finding directly challenges a common governance assumption: that screening inputs for harmful text is sufficient to secure an agent. Compliance programs relying on content filters as their primary control for agent inputs need to revisit that design, especially for agents processing email, documents, or other user-supplied content.
- ·Regulators and courts are increasingly treating foreseeable agent failures as deployer liability. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services and the EU AI Act (Regulation (EU) 2024/1689) both frame input integrity and execution containment as deployer responsibilities. These are not vendor defaults.
Governance controls affected
What to do now
- ☐Ask your engineering or AI team to identify every agent that reads or processes email, documents, or other external content, and confirm whether those agents can also run code or call external services as a result.
- ☐Require that any agent processing untrusted content runs in an isolated environment that cannot reach production systems, internal data stores, or external networks without an explicit, logged approval step.
- ☐Ask whether your current agent security controls inspect only the surface text of inputs, or whether they also evaluate what that content could do once decoded or executed, and demand a documented answer.
- ☐For agents that must process email, implement a human approval gate before any action the agent initiates as a result of email content, particularly for actions that send data, call APIs, or modify files.
- ☐Add this attack class to your next agent security assessment: specifically test whether an attacker-controlled email can cause the agent to take any action outside its defined task scope.
What to watch next
Security researchers are actively probing agent email and document pipelines, and new obfuscation variants are likely to follow this disclosure. Compliance teams should monitor whether Manus or other agent vendors publish updated mitigations and verify those mitigations address execution-layer risks, not only input screening. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services explicitly calls for least-privilege execution and sandboxing as baseline controls. Regulators referencing that guidance may treat this class of attack as a foreseeable risk that deployers were expected to address. Pending legislation including the Stop Rogue AI Act would impose additional obligations on deployers whose agents take consequential actions, making pre-deployment containment assessments a likely future compliance requirement.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
