ComputeLabs Research

Google open-sourced Mantis, a vulnerability-discovery and patching harness whose hierarchical summaries reduced token overhead by more than 85%.

· ComputeLabs Research · from the September 2, 2026 edition

Google released Mantis as an open-source framework for automating software-vulnerability discovery, triage, reproduction and patching. Google described it as part of its internal approach to finding and fixing vulnerabilities at machine speed.

Mantis combines agentic methods, including critic and review agents, with sandboxed vulnerability reproduction for grounding. Google contrasted this design with AI code-scanning approaches that can produce hallucinated bugs and true-positive rates below 7%.

The framework analyzes repository history to learn from prior security fixes and automatically develops architectural and threat-model documentation when these materials are not already provided. It creates a hierarchical security-summary tree that condenses individual files into directory-level and repository-root summaries.

Google said this hierarchical method reduced token overhead by more than 85% while retaining structural context across large repositories. The Mantis repository also includes sample sandboxing options and a `mantis-advise` skill intended to make accumulated security knowledge available to coding agents.

  • Google
  • Mantis

All 19 stories from September 2, 2026