Skills mantis-history
๐Ÿ“ฆ

mantis-history

Content revision r1 Medium Risk โš™๏ธ External commands๐Ÿ“ Filesystem access

Extract Historical Security Fixes with Mantis

Past security fixes are difficult to track across repository history. This skill guides an AI agent to extract, classify, and cache historical vulnerabilities for later analysis.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 69 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "mantis-history" from https://skillstore.io/skills/google-mantis-history.md and its manifest at https://skillstore.io/api/skills/google-mantis-history/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "mantis-history". Illustrative request: Extract historical authentication fixes from this repository.

Expected outcome:

  • Example finding: An authentication check was added before accessing an account resource.
  • The historical record links the revision, affected file, vulnerability type, and mitigation.
  • The conclusion requires verification against the actual revision diff.

Using "mantis-history". Illustrative request: Analyze security history from a shallow Git clone.

Expected outcome:

  • History status: PARTIAL_SHALLOW.
  • Available revisions were analyzed; older history remains unavailable.
  • Missing historical findings do not establish that a component is secure.

Using "mantis-history". Illustrative request: Analyze a directory without accessible VCS history.

Expected outcome:

  • History status: UNSUPPORTED_VCS.
  • An empty historical learnings database was written.
  • No historical vulnerabilities were fabricated.

Security Audit

Medium Risk
v1 โ€ข 10/4/2026 Open versioned report

All 58 static findings are false positives involving Markdown, legitimate workspace access, or read-only repository checks. A separate semantic risk concerns sending repository diffs and messages to unspecified LLM services without data-sharing safeguards. No evidence found of malicious commands, credential theft, or an actual prompt injection attempt.

1
Files scanned
240
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Repository Data Sharing Without Defined Safeguards
The skill requests LLM calls containing commit diffs and messages without specifying provider approval, secret redaction, or local-only processing. External implementations could disclose proprietary code or historical secrets.
The instructions explicitly batch diffs and messages into LLM calls but define no data-sharing controls. Actual disclosure depends on the selected execution backend.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/google-mantis-history/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/google-mantis-history/security.svg)](https://skillstore.io/skills/google-mantis-history?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/google-mantis-history?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/google-mantis-history/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/google-mantis-history.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

google. (2026). mantis-history security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/google-mantis-history/audits/1

BibTeX citation

@techreport{google-google-mantis-history-2026, author = {google}, title = {mantis-history security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/google-mantis-history/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "mantis-history security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "google" date-released: "2026-10-04" url: "https://skillstore.io/skills/google-mantis-history/audits/1" identifiers: - type: other value: "skillstore:google-mantis-history:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Prepare Historical Security Context

Build a repository-specific database of earlier vulnerabilities and mitigations before a broader security investigation.

Track Recurring Vulnerability Patterns

Review historical fixes by component and vulnerability type to identify recurring maintenance risks.

Feed Downstream Mantis Analysis

Generate state-relative historical learnings with cached records and provenance for subsequent analysis stages.

Try These Prompts

Beginner: Summarize Security History
Use mantis-history to extract past security fixes from this repository. Report the output location and any history limitations.
Intermediate: Tailor History Filters
Inspect this repository's stack and choose relevant security keywords. Extract historical findings and explain which commits your filters may exclude.
Advanced: Refresh Cached Learnings
Refresh historical learnings from the existing cache. Verify revision reachability and repository identity; rebuild the cache if history was rewritten.
Expert: Coordinate Snapshot Analysis
Use mantis-history with --snapshot_root <snapshot>, --snapshot_id <id>, and --state_root <state>. Read live VCS history and preserve snapshot provenance.

Best Practices

  • Approve the analysis backend and redact sensitive repository content before any external LLM processing.
  • Keep scripts, caches, and outputs under the designated state workspace, outside the target tree.
  • Verify extracted findings against their revisions and record partial or unsupported history explicitly.

Avoid

  • Treating an empty or filtered history database as proof that the repository has no vulnerabilities.
  • Reusing cached findings after history rewrites without checking revision reachability and repository identity.
  • Sending private diffs or historical secrets to an unapproved external analysis service.

Frequently Asked Questions

Which AI tools are listed as supported?
The report lists Claude, Codex, and Claude Code. Extraction also requires repository access and an environment capable of running generated scripts.
Does this skill review or patch current code?
No. It extracts historical vulnerabilities and fixes. Its stated scope excludes code reviews, test-script creation, and patching.
Where are the generated files stored?
With --state_root, scripts, caches, and historical_learnings.jsonl belong under its workspace directory. Without locator arguments, the workflow uses the live working directory.
How does it handle missing or shallow history?
Missing or unsupported history produces an empty database marked UNSUPPORTED_VCS. Shallow Git history is analyzed with the PARTIAL_SHALLOW marker.
How are repeated runs handled?
The output is rebuilt from cached records. New revisions are analyzed incrementally, and rewritten history or changed repository identity invalidates the cache.
Can repository content reach an external service?
Yes, if the selected LLM backend is external. The skill requests diff and message analysis but does not define redaction or provider approval.

Developer Details

Author

google

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

17c5d34add4a2cc29dbf3b76753657cb3b83523e

Maintenance freshness

10/5/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“„ SKILL.md

More from google

View all
View all