AI Governance Institute
← News
Research2026-10-08

JavaScript Obfuscation Defeats Manus Agent Defenses, Exposing Inspection-Only Controls

Source

Researchers bypass AI agent protections with JavaScript obfuscation

Salt Labs

Via Salt Labs

What happened

Researchers at Salt Labs demonstrated a working attack against the Manus AI agent, as reported by SC World. They embedded a malicious instruction inside an email by disguising it using JavaScript obfuscation, a technique that hides readable commands inside encoded text that only a computer interprets. Manus read the email, decoded the hidden instruction, and executed it inside its server-side environment without flagging the content as dangerous. The attack bypassed the agent's prompt-inspection defenses entirely, because those defenses checked for harmful-looking text rather than for what the text could become once decoded. This joins a growing pattern of similar findings. These include hidden HTML instructions that defeated AI email summarizers and ASCII-encoded attacks bridging email phishing and prompt injection. Both confirm that obfuscation is now a standard attacker technique against agents that process email.

Why it matters

  • ·Agents that can execute code or call external services based on email content are a meaningful enterprise risk. Any attacker who can send an email to an address the agent monitors can attempt to hijack its actions, without needing access to the agent's system or any credentials.
  • ·This finding directly challenges a common governance assumption: that screening inputs for harmful text is sufficient to secure an agent. Compliance programs relying on content filters as their primary control for agent inputs need to revisit that design, especially for agents processing email, documents, or other user-supplied content.
  • ·Regulators and courts are increasingly treating foreseeable agent failures as deployer liability. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services and the EU AI Act (Regulation (EU) 2024/1689) both frame input integrity and execution containment as deployer responsibilities. These are not vendor defaults.

Governance controls affected

What to do now

  • ☐Ask your engineering or AI team to identify every agent that reads or processes email, documents, or other external content, and confirm whether those agents can also run code or call external services as a result.
  • ☐Require that any agent processing untrusted content runs in an isolated environment that cannot reach production systems, internal data stores, or external networks without an explicit, logged approval step.
  • ☐Ask whether your current agent security controls inspect only the surface text of inputs, or whether they also evaluate what that content could do once decoded or executed, and demand a documented answer.
  • ☐For agents that must process email, implement a human approval gate before any action the agent initiates as a result of email content, particularly for actions that send data, call APIs, or modify files.
  • ☐Add this attack class to your next agent security assessment: specifically test whether an attacker-controlled email can cause the agent to take any action outside its defined task scope.

What to watch next

Security researchers are actively probing agent email and document pipelines, and new obfuscation variants are likely to follow this disclosure. Compliance teams should monitor whether Manus or other agent vendors publish updated mitigations and verify those mitigations address execution-layer risks, not only input screening. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services explicitly calls for least-privilege execution and sandboxing as baseline controls. Regulators referencing that guidance may treat this class of attack as a foreseeable risk that deployers were expected to address. Pending legislation including the Stop Rogue AI Act would impose additional obligations on deployers whose agents take consequential actions, making pre-deployment containment assessments a likely future compliance requirement.

Related Coverage

Research2026-10-02

Six Agentic Failure Modes Show Soft Guardrails Are Not Enough

A practitioner analysis published by CSO Online identifies six named failure modes in deployed AI agents, including prompt injection, context manipulation, and authorization abuse. The analysis draws on real incidents, including the OpenAI Atlas browser hijack and the Microsoft 365 Copilot EchoLeak exploit. It concludes that enterprises relying solely on vendor-configured content filters and system-prompt instructions have not closed the control loop.

Research2026-10-03

Orchestration Framework Flaws Make AI Workflow Pipelines a Primary Attack Target

Research published by Help Net Security finds that agent orchestration frameworks including Flowise and Langflow are among the most actively targeted systems in current vulnerability disclosures. Attackers use prompt injection and manipulated workflow configuration files to reach code execution points inside enterprise AI pipelines. Organizations running agentic workflows need isolation, configuration validation, and red-team coverage at the orchestration layer, not just at the model level.

Research2026-10-07

MCP Threat Guide Turns Six Attack Classes Into Enterprise Controls

The Agentics published the Enterprise MCP Guide 2026 on October 5, cataloging six attack classes targeting the protocol layer that connects AI agents to enterprise tools. The guide recommends per-agent tool allowlists, verified identity binding for each agent, centralized gateways, and mandatory human approval before any destructive or irreversible action. Organizations running AI agents connected to real business systems should treat this taxonomy as an immediate control gap assessment tool.