# Coordinate Continuous Mantis Security Reviews

Long security reviews require coordinated specialist stages and reliable campaign state across repeated passes. This skill supervises Mantis subagents, preserves findings, and manages optional synchronization and snapshot provenance.

## Install

```bash
npx skillstore add google/mantis-meta-agent
```

## Metadata

- Status: approved
- Slug: google-mantis-meta-agent
- Skillstore revision: r1
- Version status: missing
- Tree hash: dece022311070c21b9b8178382c629967fc7abb2ac37fc1c41770aea8a3b0e0a
- Author: google
- GitHub username: google
- License: MIT
- Repository: https://github.com/google/mantis/tree/f48a85e8823ee6f4824ae9a24b9b2efb8aab8c9a/mantis-meta-agent
- Ref: 44cf00a7ced88385654599ad1ed145fec23ee8ed
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: blocked
- Manual install advisory: allowed\_with\_warning
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands, filesystem
- Quality score: 38
- Quality tier: warning
- Public page: https://skillstore.pages.dev/skills/google-mantis-meta-agent
- Manifest: https://skillstore.pages.dev/api/skills/google-mantis-meta-agent/manifest

## Capabilities

- Sequence specialist stages for threat modeling, research, review, reproduction, patch verification, calibration, and reporting.
- Track pass numbers and preserve campaign state, knowledge bases, and archived findings.
- Perform opt-in upstream synchronization with repository checks that avoid destructive reset commands.
- Manage optional per-pass snapshots, provenance arguments, retention, and crash-resume checks.
- Delegate execution-log reflection and retry subagents after recoverable failures.
- Apply target changes at pass boundaries and distinguish reproduced findings from low-priority or nonviable results.

## Use Cases

- Coordinate a Repository Review: Supervise specialist review stages and preserve validated findings across repeated passes on an explicitly authorized repository.
- Track Review Provenance: Use optional synchronization, pass snapshots, and archives to compare campaign results across repository revisions.
- Supervise an Artifact Campaign: Coordinate appropriate analysis specialists for an authorized binary or firmware artifact in an isolated testing environment.

## Prompt Templates

### Inspect Campaign Readiness

```
Inspect readiness for a Mantis campaign on [authorized repository]. List missing subagents, tools, and state inputs. Do not start testing or modify files.
```

### Supervise a Bounded Review

```
Supervise one Mantis pass on [authorized repository] using [external state directory]. Do not sync. Stop after archiving and summarize reproduced findings.
```

### Request a Synchronized Pass

```
Run one authorized Mantis pass with --sync and --state_root=[external directory]. Preserve local changes and unknown artifacts. Halt if snapshot completeness or protection fails.
```

### Resume and Steer a Campaign

```
Resume [authorized campaign] from its existing state. Check snapshot provenance and archive integrity. Focus the next pass on [component]. Require consent before sensitive-log processing.
```

## Limitations

- The package contains instructions only; specialist subagents, campaign schemas, and orchestration tools must be supplied separately.
- The supervisor delegates security analysis and patching rather than performing those tasks directly.
- Synchronization and snapshot pinning are opt-in; default passes use the mutable live target.
- Testing authorization, artifact ownership, transcript privacy, and snapshot guarantees require additional safeguards before operational use.

## Best Practices

- Define authorized targets, permitted testing methods, and stopping conditions before launching a campaign.
- Keep campaign state outside the target tree, preserve unknown artifacts, and verify snapshot completeness before trusting provenance.
- Use isolated reproduction environments and redact sensitive campaign transcripts before sharing them with reflection subagents.

## Anti Patterns

- Treating the skill's authorization statement as permission to test arbitrary endpoints or execute untrusted binaries.
- Deleting files solely because their names resemble generated Mantis artifacts.
- Treating unpinned, incomplete, or writable snapshots as immutable evidence for authoritative findings.

## Security Audit

- Audited at: 2026-10-04T13:37:47.722\+00:00
- Summary: Most static findings are Markdown formatting, campaign state references, or legitimate repository checks, not shell execution or system reconnaissance. Confirmed concerns include unproven backup ownership and unredacted transcript access; semantic findings identify self-declared testing authorization and permissive snapshot verification. No evidence found of credential exfiltration, malware installation, or instructions to manipulate this marketplace audit.

## Stats

- Views: 0
- Downloads: 0
- Favorites: 0
- Popularity score: 0
