Skip to content
Agents for Humanity
Public draft. All results are preliminary desk assessments against criteria v1.0, updated 27 Sept 2026. No agent has been certified yet. How we assess
Autonomous agenthostedProprietary

Manus

Manus · manus.im

Manus is a proprietary, cloud-hosted agent whose runtime, system instructions, memory and credentials sit on provider infrastructure, so it fails most portability, auditability and verifiability tests. It offers meaningful owner-side controls: skills in the open SKILL.md format that can be exported, custom MCP and API connectors, per-command approval for local execution and self-serve account deletion. None of these provide an exit path for the agent itself.

Strengths
  • Skills use the open SKILL.md format and export as .skill/.zip files
  • Custom MCP and API connectors can be added
  • Per-command approval ('Allow Once'/'Always Allow') for local execution
  • Self-serve, irreversible account deletion
Gaps
  • No complete agent export; backup archives are encrypted and restore only into Manus
  • Runtime is closed source and cannot run without Manus servers
  • System instructions not disclosed; no complete, tamper-evident action record
  • No local or open-weight model option
  • Training opt-out rather than opt-in; client-side analytics
Evidence

All 34 findings

Manus web app, desktop app ('My Computer') and API as documented in September 2026, after Manus returned to independent operation following the Chinese-ordered unwinding of Meta's December 2025 acquisition. Free and paid individual plans; Team/Enterprise features noted where relevant.

Portable · Can you leave, and take the whole agent with you?

8%

Transparent · Can you see everything the agent is, with ordinary tools?

25%
  • T1
    Open storage format

    Agent state is stored server-side in an undocumented format, and backups are encrypted archives. Manus documents a plaintext export of task data for team members, and skills are plain Markdown plus scripts.

    Partial
  • T2
    No hidden instructions

    Manus does not publish or show owners the system prompt and tool definitions it places in the model context. Versions that circulate publicly come from unofficial extraction.

    Fail
  • T3
    No shadow memory

    Manus processes prompts and usage data server-side and uses de-identified or aggregated data to improve its services. Its web client loads third-party analytics (Amplitude, Sentry, FingerprintJS), so provider-held data exists outside the owner's inspectable state.

    Fail
  • T4
    Complete action history

    Each task shows its step-by-step actions and can be shared as a replay link, but the history lives on Manus servers, backups are encrypted, and no complete owner-held record of tool calls leaves with the agent.

    Partial
  • T5
    Readable logic

    Owner-created skills are stored as human-readable SKILL.md files with optional scripts. The core agent loop and orchestration logic are closed source.

    Partial
  • T6
    No third-party influence channel

    No advertising or sponsored-content channel into the agent's context is documented, but no public commitment rules one out either.

    Unverified

Auditable · Can you reconstruct exactly what the agent did?

0%
  • A1
    No unrecorded actions

    Task views show steps, but no durable record of every consequential action is documented, nor that an action which cannot be recorded does not proceed.

    Fail
  • A2
    Tamper evidence

    Owners can permanently delete tasks, and deleted tasks cannot be recovered, so deletions from the action record are not detectable.

    Fail
  • A3
    Separation from the audited

    Manus does not document whether the agent can alter or delete the task records of its own actions.

    Unverified
  • A4
    Readable with ordinary tools

    Task records are readable only through the Manus UI or API. Backup archives are encrypted and cannot be read with general-purpose tools.

    Fail
  • A5
    Corroborated interactions

    No record of the agent's exchanges with other agents or services is documented that could be matched against a counterpart's record.

    Fail

Verifiable · Can you prove the agent runs what it claims?

0%
  • V1
    Open, reproducible runtime

    The Manus runtime is proprietary and not published under an OSI-approved license.

    Fail
  • V2
    Active config is inspectable config

    The effective configuration, including system instructions and model routing, is not visible to the owner, so it cannot be checked against what the owner inspects.

    Fail
  • V3
    Attributable messages

    Outbound messages (email, Slack, Telegram, connectors) go through Manus-held accounts or tokens; recipients have no documented way to verify they came from this agent under the owner's authority.

    Fail
  • V4
    Independently checkable record

    Task records are readable only through Manus and backups are encrypted, so the record's integrity cannot be checked with open tools.

    Fail
  • V5
    Comparable state

    State sits server-side and exports are encrypted, so the owner cannot verify whether the agent's state changed between two points in time.

    Fail

Modifiable · Can you change anything, without asking?

33%

Controllable · Is your word final?

33%
Something wrong or out of date?

Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.

Dispute a finding