Skills mantis-threat-model
๐Ÿ“ฆ

mantis-threat-model

Content revision r1 Low Risk โš™๏ธ External commands๐Ÿ“ Filesystem access

Build Threat Models from Your Mantis Knowledge Base

Architecture notes often leave attacker access and trust boundaries unclear. This skill turns existing Mantis knowledge into a structured threat model with deployment intent and snapshot provenance.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 74 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "mantis-threat-model" from https://skillstore.io/skills/google-mantis-threat-model.md and its manifest at https://skillstore.io/api/skills/google-mantis-threat-model/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "mantis-threat-model". Generate a model from a KB describing a public API, an authentication service, and a customer database.

Expected outcome:

  • System overview: The public API accepts client requests and delegates identity checks to the authentication service.
  • Deployment intent: Production, because the KB describes an externally reachable service.
  • Trust boundary: Untrusted requests cross into authenticated application operations at the API authorization layer.
  • Threat actor: An unauthenticated network attacker can reach the API entry point.
  • High-risk asset: Customer records require confidentiality and integrity protections.

Using "mantis-threat-model". Rerun the model using the same recorded snapshot and reuse the existing model content.

Expected outcome:

  • Snapshot provenance: The model retains the current snapshot identifier.
  • Freshness warning: The threat model was not reevaluated this pass and was carried forward from the unchanged snapshot.
  • Archive action: The prior model is copied to the pass archive before replacement.

Security Audit

Low Risk
v1 โ€ข 10/4/2026 Open versioned report

All 101 static findings are false positives involving Markdown formatting, expected workspace metadata, or locator checks skipped by this KB-only stage. No evidence found of credential theft, exfiltration, malicious execution, or audit-directed prompt injection. One semantic finding identifies potential archive-history loss when the same pass is rerun.

1
Files scanned
252
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Repeated Passes Can Replace Archive History
The same pass number selects the same archive filename on repeated runs. Copying the current model there can replace earlier history without a collision check.
The procedure explicitly copies to a pass-number filename but provides no protection for an existing archive. This establishes a potential history-loss risk, not observed exploitation.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/google-mantis-threat-model/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/google-mantis-threat-model/security.svg)](https://skillstore.io/skills/google-mantis-threat-model?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/google-mantis-threat-model?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/google-mantis-threat-model/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/google-mantis-threat-model.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

google. (2026). mantis-threat-model security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/google-mantis-threat-model/audits/1

BibTeX citation

@techreport{google-google-mantis-threat-model-2026, author = {google}, title = {mantis-threat-model security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/google-mantis-threat-model/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "mantis-threat-model security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "google" date-released: "2026-10-04" url: "https://skillstore.io/skills/google-mantis-threat-model/audits/1" identifiers: - type: other value: "skillstore:google-mantis-threat-model:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Review Architectural Exposure

Identify attacker entry points and trust boundaries from an existing Mantis architecture knowledge base.

Refresh Models After Snapshot Changes

Regenerate threat-model sections and reassess deployment intent when the recorded snapshot changes.

Prepare Security Planning Context

Provide downstream planning agents with attacker profiles, entity references, and asset availability classifications.

Try These Prompts

Create an Initial Model
Run /mantis-threat-model using the populated Mantis knowledge base in the current workspace.
Use a Separate State Directory
Run /mantis-threat-model --state_root [state_directory]. Use its architecture and entity documents, archive the prior model, and save the replacement.
Refresh for a New Snapshot
Run /mantis-threat-model --state_root [state_directory] --snapshot_id [snapshot_id]. Recompute deployment intent when provenance changes and default to production for uncertain evidence.
Review Reuse and Archive Integrity
Run /mantis-threat-model --state_root [state_directory] --snapshot_id [snapshot_id]. Preserve existing archives; add the required STALE banner if unchanged provenance leads to reused content.

Best Practices

  • Populate architecture and entity documents with current deployment, entrypoint, and availability evidence before running the skill.
  • Keep snapshot identifiers consistent with the knowledge base revision and review models marked stale.
  • Preserve existing pass archives and verify the backup before replacing the live threat model.

Avoid

  • Using this skill as a source-code scanner or JSONL learning extractor.
  • Declaring a system sample-only when production evidence is missing, contradictory, or uncertain.
  • Treating unchanged snapshot labels as proof that the knowledge base is current or rerunning passes without archive protection.

Frequently Asked Questions

What inputs does this skill require?
It requires populated Mantis architecture and entity documents. Workflow state and an existing model provide optional pass and provenance metadata.
Does it inspect application source code?
No. This KB-only stage reads synthesized architecture and entity documents, not target source code or raw JSONL learnings.
Where is the threat model saved?
It saves THREAT_MODEL.md in the selected state workspace KB and copies the previous model into the pass archive.
What happens when snapshot metadata is missing?
Without an explicit snapshot identifier or pinned state metadata, it uses UNPINNED provenance and rederives the model.
How does it classify deployment intent?
It allows sample-only classification only when all five production-signal checks pass. Any uncertainty requires production classification.
Can repeated runs affect model history?
Yes. Reusing a pass number can replace its archived model. Preserve existing archives before rerunning the same pass.

Developer Details

Author

google

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

afe56992452feed3201cea1348a69613bf5d0a6d

Maintenance freshness

10/5/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“„ SKILL.md

More from google

View all
View all