When an AI Agent Warns After the Code Has Already Run
Salt Labs’ patched Manus finding shows why security teams should test whether approval gates stop tool execution before it starts.

On October 1, Salt Labs published research showing that a malicious email could cause Manus to execute code when a user asked the agent to check their inbox. The researchers reported that the security warning appeared after execution. Salt says the vulnerability has been resolved and is no longer exploitable. This was a research demonstration; the report does not establish exploitation against real users.
The failure crossed a concrete boundary: email content became executable instructions. In Salt’s test, Manus used Node.js to process obfuscated JavaScript presented as content to decode, running it inside the user’s cloud sandbox. The researchers reported access to integration credentials there, potentially extending exposure to other connected services. This did not require a demonstrated sandbox escape. The lesson is that a sandbox can contain a process while still exposing the credentials available inside it.
OWASP’s 2025 Excessive Agency guidance provides a separate architectural reference, not independent confirmation of the Manus finding. It recommends limiting available tools and permissions, requiring approval before high-impact actions, and enforcing authorization in downstream systems. For an inbox summarizer, that means providing only the mailbox functions needed for reading and summarizing. A model’s decision that an operation is acceptable should not replace the authorization check at the service performing it.
Our practical recommendation is to test the order of events. In an authorized staging environment with synthetic accounts, introduce an email that asks the assistant to perform an out-of-scope action. Compare the tool request, policy decision, approval, and execution timestamps. A passing result requires the prohibited action to remain unexecuted while approval is pending or denied. Include intermediate processing steps in the review: a workflow labelled decoding or previewing can still invoke a powerful interpreter.
For this Wednesday’s review, choose one email-connected agent and document its readable data, available tools, and credential access. Remove unused connectors, check that high-impact operations have enforced approval gates, and retain tool-level logs alongside the chat transcript. Track whether an unauthorized action actually occurred, not just whether the assistant eventually displayed a warning. That gives the team a measurable control to retest whenever integrations or execution paths change.
Source notes
Follow these links to check the reporting and documentation behind this article.