📦

Audit History

mantis-structural-index - 1 audit

Oct 4, 2026, 01:37 PM

All 225 static matches are documentation syntax or legitimate indexing operations, not the reported threats. Semantic review identifies forgeable helper-version checks and missing remote-query disclosure controls. No evidence found of malicious payloads, credential theft, or audit-directed prompt injection in the supplied skill.

1
Files scanned
747
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Helper Reuse Relies on a Forgeable Version Marker
Existing executable helpers are reused after checking only the marker '# MANTIS_HELPER_VERSION = 5'. An attacker who can modify workspace helpers can retain that marker and substitute code executed during indexing or queries.
The instructions explicitly permit helper reuse based on a public version comment without requiring content integrity or trusted ownership. Exploitation requires workspace write access; no actual substituted helper was supplied.
Medium
Remote Queries Lack an Explicit Data-Disclosure Boundary
Remote query providers can be selected through MANTIS_STRUCTURAL_INDEX_URL or manifest configuration. Symbol and file queries may disclose repository metadata without required endpoint approval, transport protection, or a data-sharing policy.
The specification offers remote access to operations accepting symbol names and file paths but states no explicit endpoint or disclosure restrictions. No evidence found of a malicious destination or implemented transfer; this is a conditional design risk.
Audited by: codex