Skip to main content

Google Mantis

Category: AI in Cybersecurity

Google's open-source multi-agent AI framework that autonomously discovers, reproduces, and patches software vulnerabilities, cutting token overhead by over 85% via hierarchical repository summarization. Google Mantis was founded in 2026. Based in Mountain View, California, USA.

Founded
2026
Headquarters
Mountain View, California, USA

Value proposition

Mantis is a modular, stack-agnostic toolkit of security review skills that lets AI coding agents autonomously discover, validate, reproduce, chain, and patch software vulnerabilities. It combines industry-standard agentic techniques (critic and review agents) with sandboxed reproduction for grounding, addressing the low true-positive rates (under 7%) of naive AI code scanning. Its hierarchical security summary tree condenses files into directory/root-level summaries, reducing token overhead by over 85% while preserving structural context across massive repositories.

Products and solutions

Mantis open-source framework (github.com/google/mantis): modular skills including mantis-history, mantis-structural-index, mantis-summarize, mantis-architecture, mantis-threat-model, mantis-plan, mantis-researcher, mantis-dedupe, mantis-review, mantis-critic, mantis-reproduce, mantis-chain, mantis-patch, mantis-calibrate, mantis-reflect, mantis-report, mantis-meta-agent, mantis-pipeline-adapter, mantis-advise (proactive secure-code generation). Compatible with Gemini CLI, Antigravity CLI, Google ADK, and Antigravity SDK.

Unique value

Distills decades of Google cybersecurity expertise into a portable, open-source (Apache-2.0) harness that automates the full vulnerability lifecycle — discovery, triage, reproduction, and patching — at machine speed, with hierarchical repo summarization that cuts token overhead >85% and multi-agent verification to slash false positives.

Target customer

Engineering and security teams, open-source maintainers, and DevSecOps organizations seeking AI-assisted defensive vulnerability discovery and remediation; adaptable to specialized domains (Hardware/RTL, Infrastructure as Code, ML pipelines, compiled firmware).

Industries served

Software security / DevSecOps, adaptable to hardware/RTL, infrastructure-as-code, ML pipelines, and firmware domains.

Technology advantage

Multi-agent orchestration framework (critic + review agents) for grounding and false-positive reduction; hierarchical security summary tree that reduces token overhead by >85%; automatic construction of architectural and threat-model documentation from repo history even when none exists; sandboxed reproduction of vulnerabilities (with gVisor/runsc networkless execution support); platform-agnostic design compatible with any coding agent framework; Apache-2.0 open-source license.

How they differentiate

Unlike naive AI code scanners with true-positive rates under 7%, Mantis uses multi-agent critic/review verification plus sandboxed reproduction for grounding, and a hierarchical security summary tree that cuts token overhead by >85% — enabling scalable, context-aware analysis of massive repositories. It is open-source (Apache-2.0) and platform-agnostic, distilling Google's internal defensive-security expertise.

Main competitors

Cloudflare security-audit-skill (open-source multi-agent audit skill), Semgrep (AI code security harness), other open-source AI code security harnesses and agentic vulnerability-scanning tools.

Key partnerships

Part of Google Cloud Security, integrates with Gemini CLI, Antigravity CLI, Google ADK, and Antigravity SDK, aligned with Google's Secure AI Framework (SAIF).

Notable customers

Used internally at Google to find real vulnerabilities across Google's many code repositories.

Major milestones

June 29–30, 2026: Google Cloud CISO Perspectives (Chris Betz & Ruchi Shah) details Mantis and states core skills are open source on github.com/google/mantis (Apache-2.0), September 2–3, 2026: Google Cloud Blog getting-started guide for the Mantis harness; highlights mantis-advise for proactive secure-code generation

Growth metrics

GitHub: ~922 stars, 96 forks, 70 commits, 3 contributors (as of 2026-09-05); Apache-2.0 licensed.

Market positioning

Positioned as Google's open-source defensive-security answer to AI-driven vulnerability exploitation, packaging a research-grade multi-agent security workflow that any engineering team can install and point at its own repository. Distinct from commercial scanners by being a stack-agnostic, agent-skill toolkit rather than a closed product.

Geographic focus

Global (open-source project); US-based Google Cloud Security origin.

Latest news about Google Mantis

More AI in Cybersecurity companies

Official website: