mantis-report

Synthesize security finding logs and exploit chains into structured markdown review documentation.

731|84|Updated Jun 15, 2026
One-click install
npx skills add https://github.com/google/mantis --skill mantis-report
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: mantis-report
Source: https://github.com/google/mantis/tree/main/mantis-report
Command: npx skills add https://github.com/google/mantis --skill mantis-report

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the challenge of translating complex, fragmented security finding logs into coherent, professional-grade review packets for developers and stakeholders.

Core Features & Use Cases

  • Automated Synthesis: Aggregates findings across multiple passes, handling deduplication and status tracking automatically.
  • Provenance Tracking: Maintains clear links between findings, snapshots, and reproduction evidence to ensure auditability.
  • Use Case: After a multi-stage security review, use this skill to generate a comprehensive markdown report that highlights confirmed vulnerabilities, exploit chains, and remediation status for your engineering team.

Quick Start

Use the mantis-report skill to compile all current findings and exploit chains into a final review packet for the latest snapshot.

Frequently Asked Questions about mantis-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate security audit reports from fragmented vulnerability finding logs?

Security vulnerability reporting aggregates technical finding logs and exploit chains across multi-pass review cycles into a unified, human-readable markdown review packet tracking remediation status and provenance.

How does multi-pass security review deduplication work for vulnerability tracking?

Multi-pass security review deduplication works by aggregating findings across multiple review cycles, automatically handling deduplication and status tracking to provide a unified view of vulnerability remediation progress.

What is the best way to compile exploit chains into a final compliance review packet?

Compiling exploit chains into a compliance review packet requires synthesizing technical finding logs with workspace finding JSONs and state metadata to ensure accurate provenance and snapshot-tagged audit documentation.

Do I need workspace finding JSONs to track vulnerability remediation status?

Yes, tracking vulnerability remediation status requires access to workspace finding JSONs and state metadata to ensure accurate provenance and snapshot-tagged reporting.

Can I maintain provenance tracking between security findings and reproduction evidence?

Provenance tracking maintains clear links between security findings, snapshots, and reproduction evidence to ensure auditability throughout the security review documentation process.

When do I need snapshot-tagged reporting for security vulnerabilities?

Snapshot-tagged reporting for security vulnerabilities is needed when synthesizing technical finding logs across multi-pass security review cycles to provide stakeholders with accurate provenance and remediation progress.