STUPID-2026-0063
Manus AI leaked its own system prompt when a user simply asked it to read its internal directory
Instruction given
Perform tasks as a general autonomous AI agent.
Expected behavior
Refuse requests aimed at revealing internal system instructions or reading privileged internal files.
Actual behavior
A user asked Manus to output the contents of its internal directory (e.g. /opt/.manus/), and it complied — exposing key parts of its own system prompt and internal instructions with no jailbreak beyond a plain file-read request.
Damage
Manus's proprietary system prompt and internal configuration were exposed. Leaked prompts can reveal proprietary logic, security configuration, and internal processes that adversaries can exploit to craft further attacks.
Classification
- Agent
- Manus
- Failure mode
- Security Vulnerability
- Root cause
- Instruction Misunderstanding
- Domain
- Backend
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.