# Mantis: A Modular AI Security Review Toolkit for Coding Agents

> Mantis is a Google-released Apache-2.0 Python toolkit that gives AI coding agents a library of security review skills to find, reproduce, and patch vulnerabilities autonomously. The README states the project is intended for demonstration purposes only, is not an officially supported Google product, and must be run in isolated, restricted environments.

**google/mantis** — A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.

- Repository: https://github.com/google/mantis
- Website: https://cloud.google.com/
- Stars: 2,016 · Forks: 179
- Language: Python
- License: Apache-2.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/google-mantis

## What Mantis is for and who the README says should use it

Mantis is described in the README as a set of skills along with an ADK reference harness for building secure software. Its design intent is to give AI coding agents a structured way to audit a codebase: building a semantic index, generating a threat model, forming hypotheses, running research plans, reproducing findings, patching them, and calibrating severity.

The primary audience is a security or platform engineering team that wants to experiment with automated vulnerability discovery as a complement to their existing process. The README frames it as a starting point rather than a finished product and explicitly recommends adapting and tuning it to an organisation's specific stack.

Two caveats appear prominently in the README. First, the system generates and executes autonomously generated code that may be unstable or perform unexpected actions, so it must run only in isolated, restricted environments, never on machines with access to production systems, sensitive data, or internal networks. Second, AI models are non-deterministic and can hallucinate findings or generate incorrect patches, so all findings must be manually verified by a security expert before being reported. The README also warns explicitly against mass-filing unverified AI-generated reports to open-source maintainers.

## The skill modules and the ADK reference harness

The repository is organised as a collection of named skill modules, each covering one phase of the security review pipeline. The top-level directory contains: mantis-history, mantis-structural-index, mantis-summarize, mantis-architecture, mantis-threat-model, mantis-plan, mantis-researcher, mantis-review, mantis-dedupe, mantis-critic, mantis-reproduce, mantis-chain, mantis-patch, mantis-calibrate, mantis-report, mantis-reflect, mantis-meta-agent, mantis-pipeline-adapter, and mantis-advise.

Each module is a discrete skill the agent can call during a review campaign. The pipeline defined in reference/workflow.json shows how a deep review chains these skills together. The meta-agent skill can generate custom graph topologies on the fly when an objective is specified at launch, which allows ad-hoc review campaigns without modifying workflow.json.

The mantis-advise skill serves a different purpose from the others. The README describes it as a development-time tool that uses the collected threat model and knowledge base to guide code written during the session, helping developers avoid repeating patterns that were previously identified as vulnerabilities or that conflict with guards already in place.

The reference harness is built on google-adk 0.5.0, which is visible in requirements.txt. The README notes that any competent coding agent framework should be able to run the skills without the ADK harness, because the skills are designed to be stack-agnostic.

## Setting up Mantis and running a first scan

The install target is inside the reference directory. The README specifies that python3-venv is required first:

```bash
cd reference && ./install.sh
```

After installation, the configure script handles capability detection and credential setup. Two modes are available:

```bash
# 0. Authenticate Google Cloud Application Default Credentials (ADC) if using Vertex AI
gcloud auth application-default login

# 1. Fast Configuration & Capability Auto-Detection (or --interactive wizard)
python3 scripts/configure.py --auto

# 2. Fast Preflight Validation (~1s) & Live Reachability Probe
python3 scripts/configure.py --test --probe
```

The `--interactive` flag launches a wizard for manual setup. The `--test --probe` run validates configuration and checks that the target model is reachable before starting a long campaign.

To start a review, pass a file or directory path:

```bash
# 3. Launch Vulnerability Review Campaign (file or repository)
./run.sh path/to/code
```

Custom research objectives, rather than the default full-pipeline scan, are expressed with the `--objective` flag:

```bash
./run.sh target --objective "..."
```

The README describes this as generating a custom research graph topology on the fly, allowing targeted hunts without changing the workflow definition.

The setup assumes the operator has already created an appropriately isolated environment. The README does not provide specific isolation recipes beyond noting that example sandboxes exist in the reference harness and that operators using frontier models should add a second sandboxing layer with strong monitoring.

## Pipeline phases: from codebase history to patched vulnerability

A full Mantis review campaign follows a sequence that the README summarises in the mantis-architecture skill. The pipeline first reviews the codebase history for patterns it should not repeat, then builds a semantic index and optional summaries for efficient navigation. The threat-model skill generates a structured threat model from the codebase, which subsequent skills use as context.

The plan skill builds hypotheses for individual agents to research. These can be specific files or a broad sweep. The researcher skill executes the research plan; the review skill processes each candidate finding. The dedupe skill removes duplicates; the critic skill applies a triage pass designed to reduce hallucinations and filter out findings that cannot be statically confirmed as production-viable.

Reproduction depth varies. The reproduce skill can produce a static guess at an exploit, a unit test, or a mock server depending on what environment is available. The chain skill looks for combinations of findings that could be combined into more impactful exploits.

After reproduction, the patch skill attempts to fix the vulnerability, using an adversarial loop to verify that the patch actually closes the issue. The calibrate skill scores all findings against an established rubric, surfacing the most significant risks to the human reviewer instead of reporting every possible finding at maximum severity. The reflect skill records what the completed round of research learned for use in future campaigns.

## Hallucination risk and the manual verification requirement

The README opens with two prominent caution blocks. The first warns that the system generates and executes autonomously generated code that may be unstable or perform unexpected actions. The second is specific to the quality of output: AI models are non-deterministic and can hallucinate findings or generate incorrect patches.

Two conclusions follow from this. A failure to automatically reproduce a vulnerability does not mean it is a false positive. A successful reproduction does not guarantee the vulnerability is exploitable in all contexts. Both need human judgment to interpret correctly.

Semgrep, a widely used open-source static analysis tool, takes a different approach: it applies deterministic pattern rules to source code without executing anything. That means its results do not require the same level of isolation, do not carry the same risk of autonomous code execution side effects, and do not require a sandbox. The trade-off is that Semgrep cannot model runtime behaviour, does not reproduce exploits, and cannot reason about multi-step vulnerability chains in the way Mantis's reproduce and chain skills attempt to.

Mantis's value relative to static analysis tools depends on whether the additional reproduction and patching capability justifies the isolation overhead and the manual verification requirement.

## Scope, limitations, and what the project is not

The README states: "This is not an officially supported Google product. This project is not eligible for the Google Open Source Software Vulnerability Rewards Program." It also states: "This project is intended for demonstration purposes only. It is not intended for use in a production environment."

These are hard constraints on the project's current scope. Teams should not deploy Mantis as part of an automated CI pipeline that files issues without human review, and should not treat its output as equivalent to a professional security assessment.

The project does not document a versioning or stability guarantee for the skill interfaces. Individual skill modules can be adapted for specialised domains including hardware and RTL, infrastructure as code, ML pipelines, and compiled firmware, as the README notes. That adaptability requires direct modification of the skill files, which means operators take on the maintenance cost of staying aligned with the reference harness as it evolves.

The risk calibration rubric is customisable, and the README recommends adapting it to an organisation's actual risk tolerance and environment. A misconfigured rubric can cause the system to surface trivial findings at high severity or suppress significant ones. The last push to the repository was on 2026-09-18.

## Conclusion

Security engineers who want to experiment with AI-driven vulnerability discovery will find the modular skill structure and ADK reference harness a practical starting point for building a custom review pipeline. The README is explicit that the project is intended for demonstration purposes only and is not eligible for the Google Open Source Software Vulnerability Rewards Program. Teams considering it for regular use should first stand up a fully isolated environment with strong monitoring, adapt the risk calibration rubric to their stack, and confirm that every finding is manually verified before it leaves the sandbox. The reference harness runs out of the box with `./run.sh`; adaptation to an organisation's own framework or risk tolerance requires extending the skill files.

## FAQ

### What does the ADK reference harness in Mantis do?

The reference harness, located in the reference/ directory, provides a working implementation of the Mantis skill pipeline using Google's ADK. The README describes reference/workflow.json as showing how a deep review is chained together, and notes that any coding agent framework can replace it since the skills are stack-agnostic.

### Does Mantis support scanning hardware designs or firmware?

The README states the skills can be adapted to specialised domains including hardware and RTL, infrastructure as code, ML pipelines, and compiled firmware. This requires direct modification of the skill files; the default reference harness is configured for software codebases.

### What is the mantis-advise skill used for?

The README describes mantis-advise as a development-time skill that uses the collected threat model and organisational knowledge base to guide code written during active development, helping engineers avoid patterns that were previously identified as vulnerabilities or that conflict with existing security guards.

## Sources

- [google/mantis on GitHub](https://github.com/google/mantis)
- [Issues](https://github.com/google/mantis/issues)
- [License: Apache-2.0](https://github.com/google/mantis/blob/main/LICENSE)
- [Project website](https://cloud.google.com/)
- [README](https://github.com/google/mantis/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/google-mantis
