Agent Frameworks & Harnesses 2026-09-28

Manus 2.0 and Cue: Personal Agents Get Their Own Email, Phone Number and Wallet

Manus launched a rebuilt agent architecture and Cue, an app that gives each agent its own identity and a budget to spend. Giving agents their own accounts makes their actions easier to attribute, and also gives prompt injection a much bigger inbox.

On Monday, September 28, 2026, Manus launched Manus 2.0 and Cue, a standalone app for personal agents. Each Cue agent gets its own email address, phone number, wallet and computer. It can send messages, take calls and leave a summary afterwards, and make payments within a budget the user sets. Cue is in early access on web, desktop and mobile, free with an invite code, with iOS awaiting App Store review. The Cloud Computer is a separate purchase.

Manus 2.0 runs on a new architecture Manus calls Cascade. The company claims that in one tested configuration it used 23.2% fewer tokens, finished tasks 28.2% faster and cost 32% less than its previous system. Manus hasn't published a methodology, so treat those as vendor figures. The business backdrop is unusual. Beijing blocked Meta's roughly $2 billion acquisition of the Chinese-founded startup; founders and backers bought back Meta's shares, and Manus is now reported to be raising $500 million at a $4 billion valuation, a round not yet closed.

The design choice is the interesting part. Most personal agents today act as the user, through the user's own inbox, card and browser session. Cue agents act as themselves. That has real benefits: actions are attributable to the agent rather than blended into the user's history, a compromised agent's accounts can be revoked without touching the user's, and counterparties at least have a separate identity to deal with.

It also creates a new attack surface. An agent with its own inbox and phone number accepts instructions-shaped text from anyone who can reach it, and it can spend money. Implicator reports that Salt Labs disclosed a prompt-injection flaw on September 24 in which obfuscated emails could lead to code execution, since patched. That is exactly this risk. A spending budget is the only financial control Manus has described. Compare the agent-payments work around protocols like AP2, which bind each purchase to a signed, scoped mandate rather than a running balance. The questions to watch: whether counterparties are told they are dealing with an agent, how phone numbers and wallets are verified, and what the approval flow looks like above trivial amounts.

Cue's agent-owned email, phone and wallet make agent actions attributable and revocable, but they also turn every inbound message into a possible instruction to an entity that can spend -- and a budget cap alone is a thin control compared with per-transaction mandates.