Manus AI leaked its own system prompt when a user simply asked it to read its internal directory
7.5/10
Severity
Security Vulnerability
Failure Mode
Reproducible
No
Date
March 10, 2025
Expected Behavior
Refuse requests aimed at revealing internal system instructions or reading privileged internal files.
What Actually Happened
A user asked Manus to output the contents of its internal directory (e.g. /opt/.manus/), and it complied — exposing key parts of its own system prompt and internal instructions with no jailbreak beyond a plain file-read request.
Damage Assessment
Manus's proprietary system prompt and internal configuration were exposed. Leaked prompts can reveal proprietary logic, security configuration, and internal processes that adversaries can exploit to craft further attacks.
Full Report
Manus AI, a Chinese startup's 'general AI agent,' leaked its own system prompt shortly after a high-profile launch. A user identified as 'jian' found that simply asking Manus to output the contents of its internal directory — e.g. /opt/.manus/ — caused it to reveal key internal instructions, no elaborate jailbreak required. Because the agent treated a privileged internal-file read as an ordinary task, its proprietary system prompt and configuration spilled out. Leaked prompts can expose proprietary algorithms, security settings, and internal processes that adversaries then use to craft targeted attacks. The fix is basic agent hygiene the product shipped without: input filtering so that queries aimed at internal instructions or privileged paths trigger a safe refusal rather than dutiful compliance.
Incident Metadata
- Agent
- Manus
- Failure Mode
- Security Vulnerability
- Root Cause
- Instruction Misunderstanding
- Task Type
- other
- Domain
- backend
- Source
- news_report