C1 Identity & least privilege
Minimal 0.00 / 1.00
OpenManus runs entirely as the operating-system user who launched it, with no identity of its own and no authorization check on any action. Model-written Python runs in a forked child of the agent process with the full user environment, and the file editor accepts any absolute path, so the agent can use whatever the user can: SSH keys, cloud credential files, the LLM API key in the config file. The default browser tool (Browser Use) is documented as attaching to the user's local Chrome automatically, which can extend that to the user's logged-in web sessions. A hijacked agent therefore holds the user's full authority.
C2 Approval gates
Minimal 0.00 / 1.00
There is no approval step anywhere in OpenManus. Python execution, file creation and editing, MCP tool calls (including Browser Use's browser_exec, which runs Python against the browser), and web actions all run as soon as the model asks for them. The only human-interaction tool, ask_human, is invoked at the model's discretion and gates nothing. Writes and code execution are immediate and mostly irreversible beyond the editor's in-memory undo.
C3 Tool & action scoping
Minimal 0.07 / 1.00
The default tool set is about as broad as it gets: a tool that executes any Python code, a file editor that reads and writes any absolute path on the machine, and a browser tool that itself executes Python. The editor checks only that paths are absolute and that create does not overwrite, with no containment to the workspace, and its directory view is not confined either. Every tool is on by default.
C4 Code-execution isolation
Minimal 0.25 / 1.00
Model-written Python runs with exec() in a forked child process of the agent, as the same user, with full builtins, the full environment and unrestricted network; the code even comments that it has 'safety restrictions', but only a timeout exists. Browser Use's browser_exec is a second Python execution path outside OpenManus' control. A Docker sandbox exists but is off by default, and even when enabled it is used only by the file editor, never by python_execute or MCP tools.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
OpenManus feeds tool results, web content from Browser Use, MCP tool descriptions and MCP server instructions straight into the model's context; server instructions are even inserted as system messages. Nothing marks this content as untrusted, and nothing restricts what the agent can do after reading it. A web page that hijacks the agent can make it read local secrets with the editor or Python and send them anywhere over the network, or delete files, with no human involved.
C6 Memory, context & configuration integrity
Minimal 0.10 / 1.00
OpenManus has no long-term memory store; conversation memory lives only in the running process. Its configuration (config/config.toml and config/mcp.json) is loaded from the installation directory rather than the current directory, so a cloned repository can't plant settings. However, the agent's own file editor and Python tool can write those files, and the next launch silently starts any MCP server listed in mcp.json and uses the LLM endpoint in config.toml. A single injected instruction can therefore persist as code that runs at every later start.
C7 Third-party extensions
Minimal 0.10 / 1.00
By default OpenManus launches Browser Use with `uvx browser-use --cli-mcp` at every start: an unpinned package fetched from PyPI and run without any explicit consent step, which exposes a tool that executes Python in the browser harness. Additional MCP servers come from config/mcp.json with no pinning or verification. Extension processes are separate, and the MCP client library passes them a reduced environment by default, but they run as the same user with full filesystem and network access.
C8 Secrets & sensitive-data protection
Minimal 0.00 / 1.00
The LLM API key sits in plaintext in config/config.toml inside the install directory, which the agent's own editor and Python tool can read, and the forked Python child inherits the agent's full environment. There is no redaction anywhere: the default log file at DEBUG level records model thoughts, tool arguments and full tool results. There is no telemetry, which is good, but nothing keeps credentials away from the model or from code it runs.
C9 Audit & traceability
Minimal 0.33 / 1.00
OpenManus writes a loguru text log at DEBUG level to logs/ under the install directory by default, recording each step, each tool name, and each tool's full result. Arguments are logged only for the first tool call of each step, so parallel calls lose their arguments, and records are unstructured text with no actor or correlation fields. The log directory is reachable by the agent's own editor and Python tool, so a hijacked agent can rewrite or delete its own record.
C10 Limits & kill switch
Minimal 0.33 / 1.00
The Manus agent stops after 20 steps, and Python execution has a 5-second default timeout. But the model can pass a larger timeout argument, which the tool accepts even though it isn't in the schema; there is no token budget by default, no wall-clock limit, and MCP/browser calls have no timeout. Terminating a timed-out Python run kills only the direct child, so anything it spawned keeps running.