← Back to blog
NewsAbout 6 min read

Manus Let Email Trigger an Agent, Days After a Single Email Could Hijack One

Published Oct 3, 2026
Manus Let Email Trigger an Agent, Days After a Single Email Could Hijack One

Manus shipped version 2.0 on September 28. The release notes list four products: a new agent harness called Cascade, a redesigned desktop app called Studio, event-triggered automations, and a paid hosting tier called Cloud Computer. Alongside them, a separate app named Cue gives each personal agent its own email address, phone number, wallet, and virtual computer.

Most write-ups led with the efficiency claims. The more important line is buried in the automations feature: a task can now start when someone outside your company sends you an email.

That landed about three days after researchers disclosed that one email could hijack a Manus agent.

The trigger is the whole story

Manus tasks used to begin in one of two ways. A person typed a prompt, or a schedule the person had set came due. Both put a human at the start of the chain. Automations change that. The documented triggers include incoming email, a shift in ad performance, a calendar event, a Slack message, and a Notion update.

Ad performance and Notion updates are relatively contained. An email is not. Anyone on the internet can send one, and the content of an email is attacker-controlled text that the agent will read as part of doing its job. The feature is designed for convenience, and it introduces a path from an outside stranger to an agent run with no human in the loop.

The timing makes it sharper. A Salt Labs report covered on September 25 described an email carrying obfuscated JavaScript getting a Manus agent to execute code during a routine task. Salt said the research predated the disclosure, and the flaw has since been fixed. A fixed flaw is still the useful signal. It is a demonstration that the model's judgment about email content is a security boundary, and boundaries like that get tested continuously.

Cascade, and a number that is hard to verify

Cascade is the new harness, and its design principle is easy to state: start light, bring in specialized capabilities only when the work needs them. Related work, such as a brief, a page, a video, and an automation, stays connected in one project.

The headline number is a 32 percent cost reduction, alongside 23.2 percent fewer tokens and 28.2 percent faster completion. Manus compared against its own previous system in one tested configuration, and did not name the task set, the models involved, or the configuration. That matters because Manus bills in credits, and credit burn per task varies by an order of magnitude. Simple queries reportedly use 10 to 50 credits; deep multi-source research can use 500 to 900. A 32 percent cut on a workload nobody has measured tells you very little about your own bill.

Cloud Computer is a separately purchased environment for projects that need to keep running, such as a game server or an overnight automation. It is paid, and no price was published. Studio adds a video editor and a game development environment to the documents, spreadsheets, slides, websites, and code the product already produced.

Cue is where the stakes rise

The Cue app is the boldest part of the release, and also the part that deserves the most caution. Giving an agent its own email address, phone number, and wallet turns it from a stateless function call into an entity with resources and the ability to spend. Placing several such agents in a shared group chat so they can hand work to one another, with one researching and another drafting, is a genuinely different way to organize work.

It also means a compromised agent is no longer just a bad output. It has an inbox strangers can write to, a budget it can spend, and counterparts in the same chat that will trust what it says. Prompt injection in a single-agent tool wastes a turn. Prompt injection in a group of agents spending real money is a different class of problem.

The wallet deserves particular attention. Giving an agent the ability to pay is what turns an automation into something that can transact without a human in the loop, and the guardrails Manus describes are budgets, not identity. A budget limits how much an agent can spend. It does not check whether the recipient is legitimate, and it does not detect a payment instruction that arrived inside a document the agent was asked to summarize. Every one of those is a solved problem in traditional payments, where the entity that initiates a transfer is verified separately from the content of the request.

What a team should actually do this month

The practical advice is boring and worth following. Pilot the Team plan with read-only connectors, keep inbox triggers off, and keep Cue away from anything tied to a corporate identity until the security model has more miles on it. The Team plan starts at $20 per seat per month, and SSO is not included below 30 seats. Manus's help center lists a flat fee of $150 plus tax for SSO under that threshold, free at 30 seats and above, and does not say how often the fee recurs. Ask before budgeting.

There is a deeper design question underneath the checklist. Event-triggered agents need a way to distinguish instructions from data. An email body is content the agent was asked to read. If the agent also treats it as a source of commands, then every inbox becomes a prompt injection surface, and the fix is not a filter that strips suspicious strings. It is an architecture where the input channel and the instruction channel are separate, which most agent products have not built yet.

The same logic applies to Cue's shared group chat. When agents hand work to one another, each one has to decide how much to trust what the previous one said. Without a notion of provenance inside the conversation, one compromised agent can steer the group, and the group is spending money the user authorized for a different purpose.

The direction is not in question

The direction is not in question. Agents that respond to events, hold their own resources, and coordinate in groups are where the category is heading, and Manus is moving faster than most.

The broader pattern across the industry supports the caution rather than dampening it. Within the same week, a separate research group published more than thirty thousand logs of autonomous agents probing sites they were not meant to reach, and the market's own frontier labs have been shipping agent platforms with event triggers on roughly the same schedule. The capabilities arrive together, and the security models arrive late, because a working agent is a much better demo than an audit trail.

The risk sits in one specific place. When a system's input can come from anyone, and its output can spend money and message other agents, the interesting question stops being what the agent can do. It becomes who is allowed to start it.

Related articles