Google Open-Sources Mantis: A Modular Skills Toolkit That Lets Coding Agents Find, Reproduce and Patch Vulnerabilities
| Source: MarkTechPost
Tags: Google, Mantis, security, AI agents, vulnerability scanning, Gemini CLI, code security
Google open-sourced Mantis, a modular skills toolkit that lets AI coding agents handle the full vulnerability lifecycle — finding, reproducing, patching, and scoring bugs — with sandboxed execution in gVisor or a VM and over 85% token-cost reduction via hierarchical summarization.
Details
Google has open-sourced Mantis, a stack-agnostic toolkit of security review skills for AI coding agents. Rather than a standalone scanner, Mantis structures vulnerability work as a sequential pipeline of slash commands — from /mantis-history, which mines version control for past security fixes, through to /mantis-report, which produces a human-readable review packet. The toolkit's core differentiator is grounded validation: every finding must pass through /mantis-reproduce, which executes payloads inside gVisor or a VM with networking disabled. Only bugs that are confirmed reproducible proceed to /mantis-patch and /mantis-chain. Google cites sub-7% true-positive rates for naive AI code scanning as the problem Mantis targets — sandboxed reproduction is the gate that cuts false positives. A hierarchical summary tree reduces token overhead by over 85%, making the full pipeline practical in long-running agent sessions without ballooning costs. A newer skill, /mantis-advise, inverts the loop: it queries accumulated threat models and past bug lineages before new code is written, so the same vulnerability class does not land twice. Mantis is compatible with Gemini CLI, Antigravity CLI, and the Google ADK. It is available today for local and internal evaluation but is explicitly not a supported Google product and is not production-ready.