Repository
deonmenezes/mantishack agent skills
- skills
- 11
- GitHub stars
- 505
GitHub description: “Mantis Hack”
- Stars
- 505 (74 forks)
- Licence
- Apache-2.0
- Last push
- Oct 2026
- Created
- Apr 2026
- Homepage
- mantishack.com
- agent-harness
- ai-agents
- autonomous-agents
- bug-bounty
- claude-code
- mcp
- security
- mantis
- offensive-security
Install all skills
npx skills add deonmenezes/mantishackAdd --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).
Skills in deonmenezes/mantishack, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Run a GitHub issue digest for openai/codex by feature-area labels, all areas, and configurable time windows. | deonmenezes/ | 505 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 2 | Diagnose GitHub bug reports in openai/codex. An agent skill from deonmenezes/mantishack. | deonmenezes/ | 505 | — | ~643 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 3 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 505 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 4 | Turn a captured HTTP request/response into a bounded, redacted evidence pack with a stable request-ref using the mantishttpaudit MCP server, instead of pasting raw traffic into a finding | deonmenezes/ | 505 | — | ~455 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 5 | Use astgrepscan, sourcesinkscan, and smtcheckreachability (mantisprogramanalysis MCP server) to move a candidate toward a proven-reachable finding | deonmenezes/ | 505 | — | ~551 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 6 | What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result | deonmenezes/ | 505 | — | ~376 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 7 | Build a CodeQL database and run dataflow-backed query-suite analysis via the mantiscodeql MCP server | deonmenezes/ | 505 | — | ~325 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 8 | Run osv-scanner via the mantisosvscanner MCP server for SCA (vulnerable dependency) findings | deonmenezes/ | 505 | — | ~298 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 9 | Pushing GitHub Actions changes, resolving push rejection, requesting upload exceptions. | deonmenezes/ | 505 | — | ~224 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 10 | 10.Secrets Scan Run trufflehog via the mantistrufflehog MCP server and handle secret findings without ever exposing the raw secret | deonmenezes/ | 505 | — | ~347 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 11 | Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle | deonmenezes/ | 505 | — | ~312 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
Questions, answered from the data.
What is the best skill in deonmenezes/mantishack?
Codex Issue Digest from deonmenezes/mantishack ranks first of the 11 skills in deonmenezes/mantishack listed here, with the highest score: its repository has 505 GitHub stars, its SKILL.md loads about 2.3k tokens and it passes the automated safety check with no findings. Next come Codex Bug and Detection Breadth.
Are the skills in deonmenezes/mantishack official?
None yet. All 11 skills in deonmenezes/mantishack listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How do I install all skills from deonmenezes/mantishack?
Run npx skills add deonmenezes/mantishack in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.