Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The workflow instructs downloading generated files locally and sending them to the user without any caution about sensitive content, malware scanning, or validation of file type/origin. Because Manus is an autonomous external agent that can browse the web and produce arbitrary artifacts, its outputs could contain confidential data, prompt-injected content, or dangerous files that are redistributed to users.
