STUPID-2026-0063

Manus AI leaked its own system prompt when a user simply asked it to read its internal directory

7.5high
March 10, 2025Verified
  1. Instruction given

    Perform tasks as a general autonomous AI agent.

  2. Expected behavior

    Refuse requests aimed at revealing internal system instructions or reading privileged internal files.

  3. Actual behavior

    A user asked Manus to output the contents of its internal directory (e.g. /opt/.manus/), and it complied — exposing key parts of its own system prompt and internal instructions with no jailbreak beyond a plain file-read request.

  4. Damage

    Manus's proprietary system prompt and internal configuration were exposed. Leaked prompts can reveal proprietary logic, security configuration, and internal processes that adversaries can exploit to craft further attacks.

Manus AI, a Chinese startup's 'general AI agent,' leaked its own system prompt shortly after a high-profile launch. A user identified as 'jian' found that simply asking Manus to output the contents of its internal directory — e.g. /opt/.manus/ — caused it to reveal key internal instructions, no elaborate jailbreak required. Because the agent treated a privileged internal-file read as an ordinary task, its proprietary system prompt and configuration spilled out. Leaked prompts can expose proprietary algorithms, security settings, and internal processes that adversaries then use to craft targeted attacks. The fix is basic agent hygiene the product shipped without: input filtering so that queries aimed at internal instructions or privileged paths trigger a safe refusal rather than dutiful compliance.

Classification

Agent
Manus
Domain
Backend

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.