Skills mantis-dedupe
📦

mantis-dedupe

Content revision r1 High Risk ⚙️ External commands📁 Filesystem access

Consolidate Duplicate Security Findings

Repeated security findings increase review effort and can obscure regressions. This skill guides consolidation while preserving provenance, active regression candidates, and transaction history.

Supports: Claude Codex Code(CC)
⚠️ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "mantis-dedupe" from https://skillstore.io/skills/google-mantis-dedupe.md and its manifest at https://skillstore.io/api/skills/google-mantis-dedupe/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "mantis-dedupe". Two findings describe the same flaw at the same line and share discovery provenance.

Expected outcome:

  • One primary finding retains its identifier and the highest reported severity.
  • Descriptions, code paths, and history are consolidated.
  • The duplicate is staged with linkage to the primary finding, and its move is logged.

Using "mantis-dedupe". A new finding matches a resolved archived issue, but their discovery snapshots differ.

Expected outcome:

  • The new finding remains active.
  • A possible duplicate hint references the archived finding.
  • History records a possible regression; the finding is not moved to staging.

Using "mantis-dedupe". Two findings have matching signatures and titles but identify different lines in the same file.

Expected outcome:

  • The findings remain separate because their line-inclusive locations differ.
  • Signature agreement alone does not justify a duplicate status or staged removal.

Security Audit

High Risk
v1 • 10/4/2026 Open versioned report

The 160 static alerts describe Markdown notation, legitimate workspace operations, and defensive snapshot checks rather than the alleged execution or reconnaissance threats. Semantic review found unsafe helper reuse and potential disclosure of sensitive vulnerability summaries through external embeddings. No evidence found of malicious intent or instructions to manipulate this audit.

1
Files scanned
372
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Version Comment Does Not Authenticate Reused Helpers
The skill says, "Only reuse it when the marker matches." A modified helper can retain the expected comment and execute unauthorized code.
The instructions explicitly authorize helper reuse based on a version comment and later execute it. No content-integrity verification is specified.
Medium
External Embeddings May Disclose Vulnerability Details
The semantic fallback embeds root-cause summaries using a configured provider, defaulting to Vertex AI. These summaries include vulnerability mechanisms and dataflow without a disclosure-approval requirement.
The instructions specify sensitive summary fields and an external default embedding provider. Actual transmission depends on configured integration; no evidence found of malicious exfiltration intent.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/google-mantis-dedupe/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/google-mantis-dedupe/security.svg)](https://skillstore.io/skills/google-mantis-dedupe?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/google-mantis-dedupe?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/google-mantis-dedupe/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/google-mantis-dedupe.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA · BibTeX · CFF)

APA citation

google. (2026). mantis-dedupe security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/google-mantis-dedupe/audits/1

BibTeX citation

@techreport{google-google-mantis-dedupe-2026, author = {google}, title = {mantis-dedupe security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/google-mantis-dedupe/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "mantis-dedupe security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "google" date-released: "2026-10-04" url: "https://skillstore.io/skills/google-mantis-dedupe/audits/1" identifiers: - type: other value: "skillstore:google-mantis-dedupe:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Prepare a Security Review Queue

Consolidate repeated reports at identical locations while retaining severity, supporting details, and review history.

Preserve Regression Candidates Across Passes

Compare new findings with archived records and retain possible regressions when discovery snapshots differ.

Maintain Traceable Finding Pipelines

Process large queues with grouped comparisons, provenance checks, staged duplicates, and transaction records.

Try These Prompts

Inspect a Small Finding Queue
Review the existing findings and identify duplicate candidates. Explain the matching evidence before changing any files.
Consolidate Current-Batch Duplicates
Consolidate findings with identical line-inclusive locations and matching titles. Preserve provenance and history, stage duplicates, and summarize changes.
Compare Findings Across Snapshots
Compare current and archived findings using pairwise discovery provenance. Keep unmatched findings active and annotate regressions against resolved archived issues.
Process a Large Queue Safely
Group findings by component, verify helpers before execution, and apply snapshot-gated matching. Require approval before external embeddings and summarize staged moves.

Best Practices

  • Back up workspace state and review matching evidence before applying consolidation.
  • Verify helper contents independently before execution; a version comment does not establish trust.
  • Approve external embedding use explicitly and redact sensitive vulnerability details before transmission.

Avoid

  • Marking findings as duplicates based only on signatures, without line-inclusive location agreement.
  • Suppressing potential regressions or merging findings from different discovery versions.
  • Executing existing helpers solely because their version comments match.

Frequently Asked Questions

Which AI tools can use this skill?
The marketplace lists Claude, Codex, and Claude Code. Workspace file access and command execution are needed to apply merges.
Does this skill discover new vulnerabilities?
No. It consolidates existing findings and identifies possible regressions during archive comparisons. Initial auditing and patch generation are outside its scope.
Are duplicate files permanently deleted?
No. Duplicates receive status and linkage metadata, move into a staging directory, and generate transaction records.
What happens when discovery snapshots differ?
Snapshot-gated archive matches remain active with a possible duplicate hint. Resolved archived matches receive possible regression notes.
Does deduplication require an external service?
Exact matching does not inherently require external embeddings. Semantic fallback requires configured embedding infrastructure and defaults to a Vertex AI model.
Is an existing helper safe when its version matches?
No. A matching comment does not verify script contents. Independently inspect or regenerate helpers before execution.

Developer Details

Author

google

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

ac1a468421c65e380e46c4c08b5b3b8faaa5aa45

Maintenance freshness

10/5/2026

Usage

0 downloads · 0 views

File structure

📄 SKILL.md

More from google

View all
View all