Agent skill

Program Analysis

by deonmenezes in deonmenezes/mantishack

Use astgrepscan, sourcesinkscan, and smtcheckreachability (mantisprogramanalysis MCP server) to move a candidate toward a proven-reachable finding

Apache-2.0Auto-check passedSecurity

Install Program Analysis

skills CLI
$ npx skills add deonmenezes/mantishack --skill program-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install deonmenezes/mantishack program-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/deonmenezes/mantishack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/program-analysis .claude/skills/program-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
program-analysis
GitHub stars
505
Token cost
~551 tokens
SKILL.md length
283 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use astgrepscan, sourcesinkscan, and smtcheckreachability (mantisprogramanalysis MCP server) to move a candidate toward a proven-reachable finding

  • Security work in your project
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Program Analysis is an agent skill from deonmenezes/mantishack. Use astgrepscan, sourcesinkscan, and smtcheckreachability (mantisprogramanalysis MCP server) to move a candidate toward a proven-reachable finding

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with Model Context Protocol. The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/program-analysis”

What it can do on your machine

Read from SKILL.md and the folder at commit c3a2e68. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Program Analysis loads about 551 tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 283 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~551

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from deonmenezes/mantishack at commit c3a2e68, republished under its Apache-2.0 licence (© deonmenezes). 283 words, ~551 tokens.

Download SKILL.mdSave it as .claude/skills/program-analysis/SKILL.md (or your agent's skills folder).
name
program-analysis
description
Use ast_grep_scan, source_sink_scan, and smt_check_reachability (mantis_program_analysis MCP server) to move a candidate toward a proven-reachable finding

The mantis_program_analysis MCP server is the program-analysis substrate (PRD FR-3.1/3.2/3.3): it doesn't find vulnerabilities by itself, it gives you the primitives to prove or disprove reachability for candidates surfaced elsewhere (semgrep, CodeQL, manual reading).

Three tools, three different jobs:

  • source_sink_scan: fast, dependency-free regex proxy for attacker-controlled-input sources (req.query, request.args, os.Args, ...) and dangerous sinks (eval, exec, innerHTML, pickle.loads, ...) across JS/TS, Python, Go, and Java. This is a recall tool, not proof -- it will surface sources and sinks in the same file or project without knowing if they're actually connected. Use it to cheaply widen your candidate list early in Recon/Detect, then manually trace whether a specific source really flows to a specific sink.
  • ast_grep_scan: precise structural search when you need to find every call site of a specific pattern (e.g. exec($CMD, $CB)) with real AST semantics instead of regex guessing. Use this to enumerate all call sites of a sink once you've picked a vulnerability class to chase, or to confirm a source-sink pair you suspect from source_sink_scan actually appears in the same statement/scope.
  • smt_check_reachability: once you've traced a concrete path from source to sink and can express the path condition (e.g. "sink fires when cmd is attacker-controlled and no allowlist check occurred on that branch") as SMT-LIB2 constraints, hand it to z3. sat means an attacker-controlled assignment exists that reaches the sink -- move the candidate to Validate. unsat means the path is provably unreachable under those constraints -- reject it and cite the unsat result as the roadblock. unknown proves nothing either way; don't treat it as a pass.

None of these three tools replace attacker-simulation validation -- they narrow candidates and prove/disprove reachability so validation time is spent on things that can actually matter.

© deonmenezes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .codex/skills/program-analysis of deonmenezes/mantishack.

Open the folder on GitHubat commit c3a2e68

Compare with similar skills

Program Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Program Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Program Analysis this skilldeonmenezes/mantishack505—~551Automated safety check: PassApache-2.0
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
Agent Security AuditOWASP/secure-agent-playbook186—~542Automated safety check: PassCC-BY-4.0
Webcrypt MCPputervision/state-memory-mcp111—~847Automated safety check: PassMIT
Security Passcyanheads/pubmed-mcp-server154—~6.4kAutomated safety check: PassApache-2.0

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Agent Security Audit

    OWASP/secure-agent-playbook

    Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

    186 GitHub stars~542 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    111 GitHub stars~847 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Security Pass

    cyanheads/pubmed-mcp-server

    Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth…

    154 GitHub stars~6.4k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

    239 GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed

More from deonmenezes/mantishack

All 11 skills in this repo
  • Codex Issue Digest

    deonmenezes/mantishack

    Run a GitHub issue digest for openai/codex by feature-area labels, all areas, and configurable time windows.

    505 GitHub stars~2.3k tokensUpdated 4 days ago
    Auto-check passed
  • Codex Bug

    deonmenezes/mantishack

    Diagnose GitHub bug reports in openai/codex. An agent skill from deonmenezes/mantishack.

    505 GitHub stars~643 tokensUpdated 4 days ago
    Auto-check passed
  • Detection Breadth

    deonmenezes/mantishack

    When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

    505 GitHub stars~510 tokensUpdated 4 days ago
    Auto-check passed
  • HTTP Evidence

    deonmenezes/mantishack

    Turn a captured HTTP request/response into a bounded, redacted evidence pack with a stable request-ref using the mantishttpaudit MCP server, instead of pasting raw traffic into a finding

    505 GitHub stars~455 tokensUpdated 4 days ago
    Auto-check passed
  • Canary Tripwire Response

    deonmenezes/mantishack

    What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result

    505 GitHub stars~376 tokensUpdated 4 days ago
    Auto-check passed
  • Codeql Audit

    deonmenezes/mantishack

    Build a CodeQL database and run dataflow-backed query-suite analysis via the mantiscodeql MCP server

    505 GitHub stars~325 tokensUpdated 4 days ago
    Auto-check passed

Questions about Program Analysis

What does Program Analysis do?

Use astgrepscan, sourcesinkscan, and smtcheckreachability (mantisprogramanalysis MCP server) to move a candidate toward a proven-reachable finding. Program Analysis is an agent skill from deonmenezes/mantishack.

When should I use Program Analysis?

Program Analysis fits situations like: security work in your project.

How do I install Program Analysis in Claude Code?

Run `npx skills add deonmenezes/mantishack --skill program-analysis -a claude-code`. Or copy the skill folder (.codex/skills/program-analysis in deonmenezes/mantishack) into .claude/skills/program-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Program Analysis in Codex?

Run `npx skills add deonmenezes/mantishack --skill program-analysis -a codex`. Or copy the skill folder (.codex/skills/program-analysis in deonmenezes/mantishack) into .agents/skills/program-analysis in your project. Codex loads it when a task matches its description.

Can I use Program Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add deonmenezes/mantishack --skill program-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/program-analysis, .gemini/skills/program-analysis, .github/skills/program-analysis and .opencode/skills/program-analysis in your project.

What does Program Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Program Analysis is instructions for the agent only.

Does Program Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Program Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Program Analysis use?

Program Analysis is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Program Analysis use?

About 551 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Program Analysis?

Skills that share tags, products or a category with Program Analysis: Forensify (alexgreensh/repo-forensics, 187 stars), Plugin Scanner (iflytek/skillhub, 5.2k stars), Agent Security Audit (OWASP/secure-agent-playbook, 186 stars) and Webcrypt MCP (putervision/state-memory-mcp, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Program Analysis?

deonmenezes (a GitHub user) maintains it in deonmenezes/mantishack, which has 505 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 3, 2026.

Source: deonmenezes/mantishack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.