Quick safety summary
Manus AI at a glance
22/100
not recommended
Ages 18+
Not recommended
Low
Score 20/100
18/100
Inconsistent
Best use cases
- Autonomous AI Agent workflows
- Personal exploration
Main risks
- Privacy & Data
- Content Exposure
- Generative Safety
Not ideal for
Product overview
How Manus AI works
Manus AI (manus.im) by Butterfly Effect is a fully autonomous AI agent capable of browsing the web, writing and executing arbitrary code, and managing files — all without per-action user approval. It is restricted to adults 18+ by its own terms, carries documented critical security vulnerabilities including zero-click prompt-injection exploits (SilentBridge), and was founded by Chinese developers who relocated to Singapore, creating unresolved data-sovereignty concerns. It is wholly unsuitable for minors or educational environments.
Student usage
Prohibited — platform is 18+ only
Modality
Text, code, image generation, web browsing, file handling
Underlying model
Proprietary autonomous agent (multi-model orchestration; underlying models not fully disclosed)
Common use cases
- Automated research and report generation
- Full-stack web app development
- Data analysis and visualization
- Presentation/slide creation
- Email and workflow automation
Free full report — 0 of 3 used
You can open 3 complete evaluations on the free plan. Already-opened reports stay unlocked. Upgrade to School Pro for unlimited full reports and the K-12 governance workspace.
Risk intelligence
Risk level breakdown
Risk dimensions derived directly from the SafeGradeAI rubric scores (higher score = higher risk). Additional dimensions appear when entered by an evaluator.
Scores derived from the SafeGradeAI rubric. Methodology: read more.
Safety framework
Framework analysis
Five evaluation categories from the SafeGradeAI rubric. Each shows the rubric score, evaluator confidence, and (where documented) analysis, strengths, and concerns.
Strengths & concerns
Detailed pros & concerns
Strengths
- Explicitly acknowledges 18+ age restriction in policy
- Appointed a Data Protection Officer and published GDPR-aligned policy
- SOC 2 Type 2 and ISO 27001:2022 certifications claimed for infrastructure
- Offers some user controls (Connector revocation, account deletion)
- Above-average disclosure score (61/100) vs. category average 48
Concerns
- Explicitly 18+ with zero technical age verification
- Zero-click indirect prompt injection (SilentBridge) documented
- Hidden telemetry and proxied API calls discovered (March 2026)
- Chinese-founded; China blocked Meta acquisition via national security review
- Autonomous code execution, root shell access, arbitrary port exposure by default
- Cross-app user tracking via Facebook SDK, Amplitude, Adjust
- Broad royalty-free sublicensable content license to company and affiliates
- No content filtering, safe-search, or topic restrictions
- Browser Operator can access authenticated third-party sessions
- Delv Safety Grade C (58/100); AIRQ rates execution risks as critical
Guidance at a glance
Recommendations for parents, teachers, and administrators
Parent guidance
Manus AI is explicitly an 18+ platform, not designed for and not safe for children or teenagers of any age. The platform autonomously browses the web, executes code, and manages files — creating significant risk if accessed by a minor. The company is Chinese-founded; Chinese regulators demonstrated in 2026 that they view its data as within their oversight. The app tracks users across other apps via Facebook SDK, Amplitude, and Adjust. No parental controls or monitoring features exist.
Classroom-use recommendation
Not recommended for classroom use. Its open agentic capabilities (autonomous web browsing and task execution) exceed what is appropriate for K-12 supervision; if piloted at all, restrict to teacher-only professional workflows with school-provided credentials and no student access.
School policy recommendation
Schools and districts should not allow Manus AI on any school device, network, or account. No COPPA or FERPA-compatible DPA for K-12 students, restricted to 18+ adults, documented unpatched security vulnerabilities. Autonomous code execution and unrestricted web-browsing violate standard acceptable-use policies. The geopolitical dimension — Chinese government blocking of the Meta acquisition — adds a data-sovereignty risk most district legal counsel would consider disqualifying.
Trust & credibility
Evaluation integrity
Last reviewed
June 29, 2026
Report version
v1
Evaluator confidence
22/100
Monitoring
Active continuous monitoring
Methodology
Scored against the SafeGradeAI rubric covering privacy, moderation, generative safeguards, age-appropriate design, and transparency.
Read full methodology →Change log
- June 29, 2026Evaluation published.
Re-tested at least every 6 months and after any major release.
What changed since the previous evaluation
Reviewed June 29, 2026 · Confidence: high
- 2025-03: Manus AI publicly launched by Butterfly Effect as an autonomous agent product
- 2025: Independent researchers document prompt-injection vulnerabilities
- 2025-12-30: Meta announces $2-3B acquisition of Manus
- 2026-03: Researcher H3k discloses hidden-telemetry findings
- 2026-04-27: China blocks the Meta-Manus deal via national security review
- 2026-04-30: Privacy policy last updated
Sources & citations
Every major claim in this evaluation is backed by at least one credible public source. Last reviewed June 29, 2026.
- 1Privacy PolicyManus / Butterfly Effect · 2026-04-30 · manus.im
- 2Can minors use Manus?Manus Help Center · 2025-12-08 · help.manus.im
- 3SilentBridge: Zero-Click AI Agent Takeover in Meta ManusAurascape AuraLabs · 2025-2026 · aurascape.ai
- 4Manus Agent Security Risks – AIRQ FrameworkAdversa AI · 2025 · airq.adversa.ai
- 5Prompt Injection Exposes Manus' VS Code ServerEmbrace The Red · 2025 · embracethered.com
- 6Meta to buy Chinese-founded startup ManusReuters · 2025-12-30 · reuters.com
- 7Why Did Beijing Kill a $2 Billion AI Deal?Foreign Policy · 2026-05-06 · foreignpolicy.com
- 8Is Manus safe with your data? Grade B (61/100)VerifyWise · 2025-2026 · verifywise.ai
Methodology
How this score was produced
Scored against the SafeGradeAI framework v2.5 across five dimensions — privacy, moderation, GenAI safeguards, age-appropriate design, and transparency — with COPPA, FERPA, and GDPR-K lenses. Independent. No vendor pay-for-rating.
Independent evaluation. SafeGradeAI does not accept payment from vendors for ratings.
Official website
Visit Manus AI directly
For the most current product capabilities, pricing, and policies, visit the official Butterfly Effect Pte. Ltd. website.
manus.im