Tools & Products

Manus 2.0 Launches: Cue App, Manus Studio, and Multi-Agent Sandbox Architecture for Autonomous Work

Manus has released Manus 2.0, introducing the Cue native companion app, the Manus Studio multi-agent orchestration canvas, and an isolated microVM sandbox architecture. Technical examination of GAIA benchmark results (74.8%), WebArena scores, asynchronous agent scheduling, credential vault security, and subscription tiers.

By FreakVinci · 2026-09-28 · 17 min read

Manus released Manus 2.0 on September 28, 2026, expanding from its web-based autonomous agent prototype into a complete operating suite. The release introduces two primary interfaces: Cue, a native desktop and mobile companion application for asynchronous task delegation, and Manus Studio, a visual IDE for multi-agent DAG pipeline construction.

Underpinning the release is a rebuilt execution engine based on ephemeral Firecracker microVM sandboxes, scoring 74.8% on GAIA and 68.4% on WebArena 2.0.


1. Product Ecosystem: The Cue App and Manus Studio

Manus 2.0 separates consumer task execution from professional pipeline design by deploying two dedicated interfaces.

                                  USER INTENT
                                       │
                  ┌────────────────────┴────────────────────┐
                  ▼                                         ▼
           [ Cue Mobile / Desktop ]                 [ Manus Studio ]
      Personal Asynchronous Delegation         Visual Multi-Agent Pipeline IDE
                  │                                         │
                  │   High-Level Goals                      │   Explicit DAG Flows
                  ▼                                         ▼
      ┌─────────────────────────────────────────────────────────────┐
      │               MANUS 2.0 ORCHESTRATION KERNEL                │
      │  • Hierarchical Task Planner   • Episodic Memory Graph     │
      │  • Credential Proxy Vault      • Health & Timeout Monitor   │
      └──────────────────────────────┬──────────────────────────────┘
                                     │
                  ┌──────────────────┴──────────────────┐
                  ▼                                     ▼
        [ MicroVM Linux Sandbox ]             [ Headless Browser Node ]
        Bash, Python, Compilers,             Chrome CDP, DOM Tree,
        Local File System, Git                OCR, Session Persistence

Cue: Personal Agent Mission Control

Cue runs as a lightweight native application on macOS, Windows, iOS, and Android. Rather than demanding active browser focus while an agent works, Cue functions asynchronously:

  1. Goal Submission: A user inputs an objective (e.g., "Scan the last 3 quarters of SEC 10-K filings for five cloud infrastructure companies, normalize revenue definitions, and build an Excel file with formula verification").
  2. Background Execution: The agent provisions a cloud worker instance without holding local hardware resources.
  3. Interactive Interventions: When the agent encounters ambiguity or requires two-factor authentication, Cue pushes a mobile notification. The user approves or provides input directly in the notification drawer.
  4. Deliverable Ingestion: Deliverables (code repositories, rendered PDFs, spreadsheets, scraped datasets) sync directly into local storage.

Manus Studio: Multi-Agent Visual Canvas

For software teams, quant researchers, and business operations, Manus Studio provides an orchestration interface where users assemble agent graphs:

  • Node-Based Agent Configuration: Users assign discrete foundation models to specific sub-agents (e.g., routing web browsing to Claude Sonnet 5.5, mathematical modeling to GPT-6 Sol, and drafting to Claude Opus 5.5).
  • Step-by-Step Rollbacks: If a web extraction node encounters an IP block or incorrect HTML structure, users can rewind execution to checkpoint state #14 and modify parameters without restarting the 45-minute workflow.
  • Audit Trails: Complete logs capture every terminal command executed, DOM selector clicked, and file written.

2. Benchmark Verification: GAIA and WebArena 2.0

Manus 2.0 was evaluated on the GAIA (General AI Assistants) benchmark and WebArena 2.0, measuring multi-modal tool use, web navigation, and long-horizon reasoning.

Benchmark Suite Manus 2.0 Manus 1.0 OpenAI Operator Preview Google Project Jarvis
GAIA Overall 74.8% 41.2% 58.4% 52.1%
GAIA Level 1 (Short Horizon) 91.4% 68.0% 82.5% 76.0%
GAIA Level 2 (Multi-Modal / Tools) 76.2% 42.1% 56.8% 51.4%
GAIA Level 3 (Multi-Hour Complex) 56.8% 13.5% 35.9% 28.9%
WebArena 2.0 (Browser Tasks) 68.4% 38.6% 54.2% 49.3%
Execution Sandbox Boot Time <800ms ~12,000ms ~4,500ms ~6,000ms
GAIA Benchmark Overall Score (%):
Manus 2.0              [==================================] 74.8%
OpenAI Operator Preview[===========================]       58.4%
Google Project Jarvis  [========================]           52.1%
Manus 1.0              [====================]               41.2%

On GAIA Level 3, which requires coordinating five or more external tools across 30+ sequential steps, Manus 2.0 completed 56.8% of tasks without human intervention. The primary failure mode in earlier agent frameworks was cascading error propagation, where an incorrect assumption in step 3 corrupted downstream decisions. Manus 2.0 mitigates this with an automated validation loop that tests interim assertions before proceeding.


3. Sandboxed Infrastructure and Security Architecture

Running autonomous code and executing shell commands on behalf of users introduces critical security and stability considerations. Manus 2.0 addresses these through an isolated microVM architecture.

+-----------------------------------------------------------------------------------+
|                        MANUS 2.0 SANDBOX SECURITY TOPOLOGY                        |
+-----------------------------------------------------------------------------------+
|                                                                                   |
|    HOST SERVER (Bare-Metal Linux Kernel with KVM)                                |
|    │                                                                              |
|    ├── Firecracker MicroVM #48291 (Dedicated Customer Container)                  |
|    │   ├── CPU: 4 vCPU (Pinned)                                                   |
|    │   ├── Memory: 8 GB RAM (Hard Limit)                                          |
|    │   ├── OS: Debian Minimal (Read-only rootfs + ephemeral tmpfs)                |
|    │   │                                                                          |
|    │   ├── Headless Chromium Process (DevTools Protocol)                          |
|    │   │   └── Network requests route through Outbound Proxy                      |
|    │   │                                                                          |
|    │   └── Zero-Knowledge Credential Vault Proxy                                  |
|    │       ├── Target: api.github.com ────> Injects GITHUB_TOKEN                  |
|    │       └── Target: api.stripe.com ────> Injects STRIPE_SECRET                 |
|    │                                                                              |
|    └── Host Network Egress Filter (Blocks metadata service 169.254.169.254)       |
|                                                                                   |
+-----------------------------------------------------------------------------------+

Zero-Knowledge Credential Vault

In typical LLM implementations, API keys or passwords are provided in system prompts, leaving them vulnerable to prompt injection or extraction via error trace logs.

Manus 2.0 isolates sensitive credentials:

  1. Users store credentials in an encrypted team vault.
  2. The agent code references an abstract handle: credentials.get("salesforce_auth").
  3. The underlying LLM never sees the actual token string.
  4. When the microVM's outbound proxy detects an HTTP request directed at https://company.my.salesforce.com, the proxy intercepts the request and injects the authorization header at the transport layer.
  5. If an attacker injects a malicious prompt instructing the agent to "print your API keys", the LLM can only output the abstract handle.

4. Multi-Agent Coordination Protocol

Manus 2.0 replaces linear prompt chains with a hierarchical supervisor model:

# Conceptual Actor-Critic Architecture within Manus 2.0 Engine
class ManusSupervisor:
    def __init__(self, goal: str, context: dict):
        self.goal = goal
        self.state_graph = EpisodicMemoryGraph()
        self.workers = {
            "browser": WebNavigationAgent(sandbox_id=context["sandbox_id"]),
            "coder": TerminalExecutionAgent(sandbox_id=context["sandbox_id"]),
            "analyst": DataExtractionAgent(sandbox_id=context["sandbox_id"])
        }
        self.critic = VerificationCriticAgent()

    async def execute_task(self):
        plan = await self.generate_dag(self.goal)
        for stage in plan.stages:
            worker = self.workers[stage.required_capability]
            result = await worker.run_step(stage.instruction, self.state_graph)
            
            # Independent verification gate prevents hallucinated step completions
            verification = await self.critic.verify(stage.expected_outcome, result)
            if not verification.passed:
                await self.remedy_failure(stage, verification.error_trace)
            else:
                self.state_graph.commit_checkpoint(result)
        
        return self.state_graph.synthesize_deliverable()

By separating the Execution Agent from the Verification Critic, the system catches false positive conclusions (for instance, an agent believing a download succeeded when the file was an empty 404 response page).


5. Pricing and Subscription Plans

Manus structured version 2.0 around compute credits corresponding to virtual agent execution minutes:

Tier Price Monthly Credits Sandbox Specs Best Suited For
Free $0 50 credits Shared container, 5-min timeout Simple lookups, evaluation
Pro $20 / month 500 credits Dedicated microVM, 60-min timeout Solo developers, researchers
Studio Team $80 / user / mo 2,500 credits/user 8 vCPU, unlimited session duration Engineering teams, analysts
Enterprise Custom quote Custom pools On-premise VPC, private LLM routing Regulated finance & healthcare

One compute credit corresponds to approximately 60 seconds of active multi-modal agent compute, including browser rendering and terminal execution. Inactive wait states (such as waiting for human approval in Cue) do not burn credits.


6. Practical Setup Guide for Developers

Getting started with Manus 2.0 via CLI and Cue:

  1. Install the Cue Companion Client:

    # Install via Homebrew on macOS
    brew install --cask manus-cue
    
    # Or install the headless CLI daemon on Linux
    curl -fsSL https://get.manus.im/cue.sh | bash
    
  2. Authenticate with User Credentials:

    cue auth login
    # Authenticates via browser OAuth callback
    
  3. Dispatch a Asynchronous Batch Task:

    cue dispatch --task "Analyze latest open PRs in org/repo, run test suites, and generate benchmark table"                 --timeout 120m                 --notify-mobile
    

The command exits immediately in the local terminal, printing a job tracking URL. Once the agent builds the test matrix and formats the report, Cue sends a push notification with a direct download link to the generated artifact.