BoundBench

OpenManus

Open-source general agent (Manus alternative) with Python exec, browser and file tools

github.com/FoundationAgents/OpenManus · 2026-10-03 · 3309bf4

Defense-in-depth score

1.2 / 10

Minimal

OpenManus as shipped runs model-written Python directly on your machine as you, with your files, environment and network, and edits any file by absolute path, with no approval step anywhere. It also auto-launches an unpinned Browser Use package from PyPI that can drive your local Chrome. Any web page that hijacks the agent can read secrets (including the plaintext LLM key) and send them out, or destroy files, unattended. Run it only in a disposable VM or container that holds nothing you care about.

Key gaps (4)

  1. Model-written Python runs via exec() in a same-user child process with full builtins, environment and network; the Docker sandbox is off by default and never used for python_execute. C4 · Code-execution isolation
  2. The agent holds the launching user's entire authority with no authorization layer, including the user's Chrome via Browser Use. C1 · Identity & least privilege
  3. Untrusted web/MCP content enters context unmarked and a hijacked session can exfiltrate and destroy data unattended (C5-WORSTCASE). C5 · Untrusted input blast radius
  4. Browser Use is fetched unpinned from PyPI via uvx and executed at every start without consent (C7-RCELOAD). C7 · Third-party extensions

Criteria

C1 Identity & least privilege

Minimal 0.00 / 1.00

OpenManus runs entirely as the operating-system user who launched it, with no identity of its own and no authorization check on any action. Model-written Python runs in a forked child of the agent process with the full user environment, and the file editor accepts any absolute path, so the agent can use whatever the user can: SSH keys, cloud credential files, the LLM API key in the config file. The default browser tool (Browser Use) is documented as attaching to the user's local Chrome automatically, which can extend that to the user's logged-in web sessions. A hijacked agent therefore holds the user's full authority.

C2 Approval gates

Minimal 0.00 / 1.00

There is no approval step anywhere in OpenManus. Python execution, file creation and editing, MCP tool calls (including Browser Use's browser_exec, which runs Python against the browser), and web actions all run as soon as the model asks for them. The only human-interaction tool, ask_human, is invoked at the model's discretion and gates nothing. Writes and code execution are immediate and mostly irreversible beyond the editor's in-memory undo.

C3 Tool & action scoping

Minimal 0.07 / 1.00

The default tool set is about as broad as it gets: a tool that executes any Python code, a file editor that reads and writes any absolute path on the machine, and a browser tool that itself executes Python. The editor checks only that paths are absolute and that create does not overwrite, with no containment to the workspace, and its directory view is not confined either. Every tool is on by default.

C4 Code-execution isolation

Minimal 0.25 / 1.00

Model-written Python runs with exec() in a forked child process of the agent, as the same user, with full builtins, the full environment and unrestricted network; the code even comments that it has 'safety restrictions', but only a timeout exists. Browser Use's browser_exec is a second Python execution path outside OpenManus' control. A Docker sandbox exists but is off by default, and even when enabled it is used only by the file editor, never by python_execute or MCP tools.

C5 Untrusted input blast radius

Minimal 0.00 / 1.00

OpenManus feeds tool results, web content from Browser Use, MCP tool descriptions and MCP server instructions straight into the model's context; server instructions are even inserted as system messages. Nothing marks this content as untrusted, and nothing restricts what the agent can do after reading it. A web page that hijacks the agent can make it read local secrets with the editor or Python and send them anywhere over the network, or delete files, with no human involved.

C6 Memory, context & configuration integrity

Minimal 0.10 / 1.00

OpenManus has no long-term memory store; conversation memory lives only in the running process. Its configuration (config/config.toml and config/mcp.json) is loaded from the installation directory rather than the current directory, so a cloned repository can't plant settings. However, the agent's own file editor and Python tool can write those files, and the next launch silently starts any MCP server listed in mcp.json and uses the LLM endpoint in config.toml. A single injected instruction can therefore persist as code that runs at every later start.

C7 Third-party extensions

Minimal 0.10 / 1.00

By default OpenManus launches Browser Use with `uvx browser-use --cli-mcp` at every start: an unpinned package fetched from PyPI and run without any explicit consent step, which exposes a tool that executes Python in the browser harness. Additional MCP servers come from config/mcp.json with no pinning or verification. Extension processes are separate, and the MCP client library passes them a reduced environment by default, but they run as the same user with full filesystem and network access.

C8 Secrets & sensitive-data protection

Minimal 0.00 / 1.00

The LLM API key sits in plaintext in config/config.toml inside the install directory, which the agent's own editor and Python tool can read, and the forked Python child inherits the agent's full environment. There is no redaction anywhere: the default log file at DEBUG level records model thoughts, tool arguments and full tool results. There is no telemetry, which is good, but nothing keeps credentials away from the model or from code it runs.

C9 Audit & traceability

Minimal 0.33 / 1.00

OpenManus writes a loguru text log at DEBUG level to logs/ under the install directory by default, recording each step, each tool name, and each tool's full result. Arguments are logged only for the first tool call of each step, so parallel calls lose their arguments, and records are unstructured text with no actor or correlation fields. The log directory is reachable by the agent's own editor and Python tool, so a hijacked agent can rewrite or delete its own record.

C10 Limits & kill switch

Minimal 0.33 / 1.00

The Manus agent stops after 20 steps, and Python execution has a 5-second default timeout. But the model can pass a larger timeout argument, which the tool accepts even though it isn't in the schema; there is no token budget by default, no wall-clock limit, and MCP/browser calls have no timeout. Terminating a timed-out Python run kills only the direct child, so anything it spawned keeps running.