Google has released Mantis, a framework for finding and fixing vulnerabilities. Google’s Mantis guide provides a practical starting point for reviewing your code.

Mantis automates finding, triaging, reproducing, and fixing software vulnerabilities. To reduce hallucinations and the low accuracy of AI scanning, the framework combines critic and review agents with vulnerability reproduction in an isolated environment.

Mantis examines repository history to account for past fixes. The framework automatically creates architecture and threat model documentation.

Mantis’s hierarchical summary tree reduced token overhead by more than 85%. The hierarchical summary tree preserved the structured context of large repositories.

Terms:

  • threat models — Descriptions of possible threats to a system, their sources, and ways to defend against them. They are used when designing and reviewing security.

Claim check:

  • Google published a guide to getting started with Mantis, an open framework for finding and fixing vulnerabilities. (confirmed by the primary source: evidence; «Getting started with Mantis, our open-source bug finding-and-fixing harness»)
  • Mantis automates the discovery, triage, reproduction, and fixing of software vulnerabilities. (confirmed by the primary source: evidence; «To help defenders gain the advantage with AI, we built the Mantis harness to automate the discovery, triage, reproduction, and patching of software vulnerabilities.»)
  • Google says Mantis is available to everyone as an open framework. (confirmed by the primary source: evidence; «Available to all as an open-source framework, Mantis is part of Google’s internal approach to find and fix vulnerabilities at machine-speed.»)
  • To reduce hallucinations and the low accuracy of AI scanning, Mantis combines critic and review agents with vulnerability reproduction in a sandbox. (confirmed by the primary source: evidence; «While sloppiness in AI code scanning frequently leads to hallucinated bugs and weak true-positive rates under 7%, we designed Mantis to be effective by combining industry-standard agentic techniques like critic and review agents with sandboxed reproduction of vulnerabilities for grounding.»)
  • Mantis examines repository history to account for past fixes and automatically create architecture and threat model documentation. (confirmed by the primary source: evidence; «As we detailed in June , it examines the history of the repository to learn from past security fixes and automatically builds up architectural and threat model documentation, even if these are not provided.»)
  • Mantis’s hierarchical summary tree reduced token overhead by more than 85% while preserving the structured context of large repositories. (confirmed by the primary source: evidence; «This technique reduced token overhead by over 85%, while preserving critical structural context across massive repositories.»)
  • The article gives a practical starting point: clone the Mantis repository and ask a coding agent, using a ready-made prompt, to review your code. (confirmed by the primary source: evidence; «Second , open your favorite coding agent and use the prompt, “I would like to use Mantis framework in path/to/mantis to review my code in path/to/your/code , can you help me get started?”»)
  • The Mantis repository includes examples of sandbox isolation options, and users can implement their own sandbox for their workflow. (confirmed by the primary source: evidence; «As part of the Mantis repository on GitHub, we’ve included sample sandboxing options. You can also implement your own sandbox to match your own workflow.»)
  • Mantis is organized as a modular set of more than 15 tools that can run sequentially or in parallel. (not found in the primary source)
  • Google recommends using lightweight models for classification and clustering and more capable models for reproducing vulnerabilities and creating fixes. (not found in the primary source)

Publications:

Primary sources:

score 77.1 · kind announcement · revision 1 · stories st-v8tqk5