An email just hijacked an AI agent.
Not a phishing link. Not a malicious attachment. A plain email and the victim did nothing except ask their AI assistant to check their inbox.
Salt Labs did this to Manus, the agentic AI platform, this week. First they tried the obvious: an email saying execute whoami. Manuss guardrails caught it instantly. Good.
Then they got clever. They hid the same instruction inside JSFuck an obscure JavaScript obfuscation trick. Manus decoded it, ran it, and only then fired a security warning. Too late: they had a reverse shell in the agents environment, one hop from the victims Gmail, Drive, GitHub, and cloud credentials.
Heres the scary part: the guardrail worked. It just fired after the action. On an autonomous agent, detection without prevention is decoration.
If your agent can read the internet, the internet can write instructions to it. When did you last threat-model what your AI is allowed to touch?