skills/vm0-ai/vm0-skills/manus/Gen Agent Trust Hub

manus

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes curl for performing HTTP operations to create tasks, manage projects, and upload binary file data.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with external API endpoints at api.manus.ai and manus.im to transmit task data and retrieve agent execution results.
  • [PROMPT_INJECTION]: There is an inherent surface for indirect prompt injection as the skill processes user-supplied task prompts and project instructions (ingestion points: SKILL.md). These inputs are delimited within JSON structures (boundary markers) and sent to external services via network requests (capabilities: curl network access). While no specific sanitization is mentioned, this behavior is a standard requirement for the skill's primary functionality of agent task automation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 04:44 PM