Manus
Manus · manus.im
Manus is a proprietary, cloud-hosted agent whose runtime, system instructions, memory and credentials sit on provider infrastructure, so it fails most portability, auditability and verifiability tests. It offers meaningful owner-side controls: skills in the open SKILL.md format that can be exported, custom MCP and API connectors, per-command approval for local execution and self-serve account deletion. None of these provide an exit path for the agent itself.
- Skills use the open SKILL.md format and export as .skill/.zip files
- Custom MCP and API connectors can be added
- Per-command approval ('Allow Once'/'Always Allow') for local execution
- Self-serve, irreversible account deletion
- No complete agent export; backup archives are encrypted and restore only into Manus
- Runtime is closed source and cannot run without Manus servers
- System instructions not disclosed; no complete, tamper-evident action record
- No local or open-weight model option
- Training opt-out rather than opt-in; client-side analytics
All 34 findings
Manus web app, desktop app ('My Computer') and API as documented in September 2026, after Manus returned to independent operation following the Chinese-ordered unwinding of Meta's December 2025 acquisition. Free and paid individual plans; Team/Enterprise features noted where relevant.
Portable · Can you leave, and take the whole agent with you?
8%- P1Round-trip portability
Incomplete and not restorable in one action: the 2026 Data Backup Tool omits Knowledge, connector credentials and logic, and its encrypted archives are produced in several steps and restore only into Manus through a separate portal. Outside that window, only individual files and skills can be downloaded.
Fail - P2Complete export
The backup covers tasks, generated files and configuration data, but the docs do not say it includes Knowledge entries, connector credentials or the agent's executable logic, or anything that identifies the agent.
Partial - P3Independent execution
Backup archives are meant to be restored only through Manus's own restoration tool, and the agent runtime is not distributed. No exported artifact runs on an open-source runtime.
Fail - P4Identity continuity
Agent identity is the Manus account, and nothing lets peers verify it is the same agent after a migration.
Fail - P5No kill switch
The agent runs only on Manus infrastructure, so the provider can suspend or change it at any time. The 2026 regulatory deletion of data for some accounts showed this in practice.
Fail - P6Capability independence
Tools, sandbox, connectors, scheduling and memory are all provided by Manus's hosted platform, and none of them survive a move to another model provider or runtime.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
25%- T1Open storage format
Agent state is stored server-side in an undocumented format, and backups are encrypted archives. Manus documents a plaintext export of task data for team members, and skills are plain Markdown plus scripts.
Partial - T2No hidden instructions
Manus does not publish or show owners the system prompt and tool definitions it places in the model context. Versions that circulate publicly come from unofficial extraction.
Fail - T3No shadow memory
Manus processes prompts and usage data server-side and uses de-identified or aggregated data to improve its services. Its web client loads third-party analytics (Amplitude, Sentry, FingerprintJS), so provider-held data exists outside the owner's inspectable state.
Fail - T4Complete action history
Each task shows its step-by-step actions and can be shared as a replay link, but the history lives on Manus servers, backups are encrypted, and no complete owner-held record of tool calls leaves with the agent.
Partial - T5Readable logic
Owner-created skills are stored as human-readable SKILL.md files with optional scripts. The core agent loop and orchestration logic are closed source.
Partial - T6No third-party influence channel
No advertising or sponsored-content channel into the agent's context is documented, but no public commitment rules one out either.
Unverified
Auditable · Can you reconstruct exactly what the agent did?
0%- A1No unrecorded actions
Task views show steps, but no durable record of every consequential action is documented, nor that an action which cannot be recorded does not proceed.
Fail - A2Tamper evidence
Owners can permanently delete tasks, and deleted tasks cannot be recovered, so deletions from the action record are not detectable.
Fail - A3Separation from the audited
Manus does not document whether the agent can alter or delete the task records of its own actions.
Unverified - A4Readable with ordinary tools
Task records are readable only through the Manus UI or API. Backup archives are encrypted and cannot be read with general-purpose tools.
Fail - A5Corroborated interactions
No record of the agent's exchanges with other agents or services is documented that could be matched against a counterpart's record.
Fail
Verifiable · Can you prove the agent runs what it claims?
0%- V1Open, reproducible runtime
The Manus runtime is proprietary and not published under an OSI-approved license.
Fail - V2Active config is inspectable config
The effective configuration, including system instructions and model routing, is not visible to the owner, so it cannot be checked against what the owner inspects.
Fail - V3Attributable messages
Outbound messages (email, Slack, Telegram, connectors) go through Manus-held accounts or tokens; recipients have no documented way to verify they came from this agent under the owner's authority.
Fail - V4Independently checkable record
Task records are readable only through Manus and backups are encrypted, so the record's integrity cannot be checked with open tools.
Fail - V5Comparable state
State sits server-side and exports are encrypted, so the owner cannot verify whether the agent's state changed between two points in time.
Fail
Modifiable · Can you change anything, without asking?
33%- M1Instructions
Owners can write Knowledge entries, project-level instructions and skills. They cannot read or rewrite the platform system prompt.
Partial - M2Memory
Knowledge entries can be viewed and deleted, subject to per-plan caps (for example 50 on Free, 100 on Pro). Any derived memory or usage data held by the provider is not exposed for editing.
Partial - M3Logic
Owners can create, edit, import and export skills, including scripts. The underlying agent logic cannot be modified.
Partial - M4Tools and permissions
Owners can add custom MCP and API connectors with OAuth-scoped permissions, and can limit local access to chosen folders. Built-in sandbox tools cannot be removed or re-scoped below the platform level.
Partial - M5Model choice
Owners can choose only among Manus-defined agent tiers (for example 1.6 Lite, 1.6, 1.6 Max). There is no option for other providers or local open-weight models.
Fail - M6No gatekeeping
Stronger agent tiers and higher Knowledge limits require paid plans, and the e-discovery export requires provider approval.
Fail
Controllable · Is your word final?
33%- C1Communication boundaries
Connectors can be enabled or disconnected per app, but owners have no documented way to decide which recipients or peers the agent may contact, enforced outside the model.
Unverified - C2Approval gates
In the desktop app, every local command requires explicit approval ('Allow Once' or 'Always Allow'). No equivalent owner-configurable gates are documented for cloud-sandbox or connector actions.
Partial - C3Immediate halt
Browser Operator tasks can be stopped by closing the dedicated tab, and scheduled tasks can be toggled off. The desk review found no documented guarantee of an immediate stop for cloud-sandbox tasks.
Partial - C4Data sovereignty
Third-party policy analyses of the April 2026 policy report a training opt-out setting, not opt-in, and Manus says it uses de-identified or aggregated data to improve its services. The web client also loads third-party analytics and error telemetry.
Fail - C5Credential custody
Connectors use OAuth and can be disconnected by the owner. The tokens and API keys are stored by Manus and do not travel with any export.
Partial - C6Full deletion
Self-serve account deletion is irreversible. Manus may keep some personal data for legal, accounting, claims-defence and fraud-prevention purposes without a stated period.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.