Researchers at Salt Labs published on 1 October 2026 an account of how they bypassed the prompt-injection protections of the Manus AI agent and achieved code execution through a single email [1]. SC Media, citing TechRadar, also covered the research and notes that the specific flaw has since been patched through a bug bounty programme [2]. The case is relevant to Mac users who connect an AI agent to their mailbox and other accounts.
Background
A prompt injection places instructions in content that an AI agent reads, so that the agent treats them as commands. Salt Labs chose the Gmail integration as a target because email is the primary identity provider for many accounts. According to the write-up, the agent processed email in a cloud sandbox, using tooling based on the Model Context Protocol and the user's OAuth token [1].
What the research describes
The researchers report that a plain shell-command injection was detected and blocked by the platform's guardrails, and that a Base64-encoded variant was also detected. They then encoded the payload in JSFuck, an unusual way of writing JavaScript with a very small character set, and the email asked the agent to decode it using Node.js. The agent invoked the Node.js runtime and executed arbitrary JavaScript in its server-side environment [1].
The payload was then extended to run system commands inside the sandbox and to establish a reverse shell to attacker infrastructure. From there they reached the Gmail OAuth token, the tool interface and the credentials of connected services, with potential access to services such as Google Drive and GitHub [1]. The central finding is a timing gap: the guardrail detected the attack, but "after the code had already run" [1]. SC Media summarises the lesson as: prompt inspection is necessary but not sufficient, and protection must extend to the actions an agent takes across tools, APIs and systems [2].
The write-up states that the specific flaw was submitted through Meta's bug bounty programme and has been resolved and is no longer exploitable. It gives no disclosure timeline [1].
Implications for Mac users
In this case the code ran in the vendor's cloud sandbox, not on a Mac, so the exposure was the tokens and connected accounts that the agent held [1]. The general point applies to local agents as well: content that an agent reads can carry instructions, and a defence that only inspects the prompt can act too late.
Recommendations
- Connect an AI agent only to the accounts it needs, and prefer read-only access where the service offers it.
- Review the connected services and tokens of each agent periodically and revoke those that are not in use.
- Treat any email, web page or document an agent reads as untrusted input.
- Prefer agents whose actions require approval for commands, file changes and new network destinations.
- Watch which network destinations an agent on the Mac contacts, and investigate a destination that is new.
Relevance to FireAI
FireAI's Agent profile recognises AI agents on a Mac, learns where each normally connects, and flags a first-ever destination or an upload spike for review, using only host names and byte counts. In its stricter mode it blocks a new destination until the user allows it.
FireAI does not run in a vendor's cloud, so it cannot see or stop what happened inside the Manus sandbox. It does not read emails or prompts, does not decide whether an instruction is an injection, and does not read the inside of encrypted connections. It acts on the network side of agents that run on the Mac.
Limitations
The technical account is the researchers' own, read here through a Security Boulevard republication; this item did not independently reproduce it. The sources do not report exploitation by anyone other than the researchers, and the date of the fix is not given. SC Media states that creative bypasses beyond JSFuck are likely to emerge [2].
Try FireAI, by HisnLabs free for 17 days.