📦
Audit History
mantis-calibrate - 1 audit
Audit version 1 Latest
Oct 4, 2026, 01:37 PM
All 203 static detections are false positives involving Markdown syntax, workflow metadata, or descriptions of vulnerability evidence. One semantic finding identifies helper reuse without integrity verification, enabling code execution if an attacker controls the workspace helper. No evidence found of deliberate prompt injection or data exfiltration in the supplied files.
2
Files scanned
914
Lines analyzed
3
Review items
0
False positives ignored
Confirmed security concerns (1)
High
Workspace Helper Reuse Without Integrity Verification
The skill executes an existing workspace helper after checking only "# MANTIS_HELPER_VERSION = 2". An attacker controlling that helper can retain the comment and execute arbitrary code with agent permissions.
The instructions explicitly combine helper execution with a first-line version check, without requiring body verification. Exploitation requires attacker control of the workspace helper; no malicious helper is supplied.
Risk Factors
⚙️ External commands (50)
SKILL.md:19 SKILL.md:26 SKILL.md:27 SKILL.md:29 SKILL.md:30 SKILL.md:34 SKILL.md:35 SKILL.md:36 SKILL.md:37 SKILL.md:38 SKILL.md:39 SKILL.md:41 SKILL.md:43 SKILL.md:61-100 SKILL.md:100-103 SKILL.md:103 SKILL.md:104-106 SKILL.md:106-107 SKILL.md:107-108 SKILL.md:108-110 SKILL.md:110-111 SKILL.md:111-116 SKILL.md:116 SKILL.md:117-120 SKILL.md:120-121 SKILL.md:121 SKILL.md:124-126 SKILL.md:126 SKILL.md:127-128 SKILL.md:128 SKILL.md:132 SKILL.md:133 SKILL.md:137 SKILL.md:138 SKILL.md:139 SKILL.md:142-144 SKILL.md:144-148 SKILL.md:148-149 SKILL.md:149-153 SKILL.md:153-154 SKILL.md:154 SKILL.md:155 SKILL.md:156-157 SKILL.md:157 SKILL.md:159-161 SKILL.md:161 SKILL.md:163-165 SKILL.md:165-166 SKILL.md:166 SKILL.md:169-170
📁 Filesystem access (7)
Audited by: codex