Skip to main content
Back to News
Google's Mantis open-sources AI-driven vulnerability discovery and remediation, cutting token overhead by more than 85%.
Technology
2 min read

Google's Mantis open-sources AI-driven vulnerability discovery and remediation, cutting token overhead by more than 85%.

The AMW Read

Google extends its known agentic-security push (alongside CodeMender) with a concrete multi-agent verification and hierarchical-summarization technique, a segment-level devtool/agent update rather than a new player or debate-resolving event.
NoveltySignificance
AI Agents · Player Map

Google's Mantis open-sources AI-driven vulnerability discovery and remediation, cutting token overhead by more than 85%.

On September 2, 2026, Google published technical details on Mantis, an open-source framework that automates vulnerability discovery, reproduction, and remediation in software repositories. Google states that raw AI code scans can produce a true-positive rate below 7%, so Mantis chains discovery agents with separate review and critique agents that confirm exploit conditions, reproduce the issue in an isolated sandbox, and only then generate a fix. Before analysis, Mantis mines a repository's change history and code structure to auto-build a threat model, working even when developers have no existing security documentation. To manage cost on large codebases, it builds hierarchical security summaries at the file and directory level before assembling a repository-wide view, which Google says cuts token overhead by more than 85% while preserving structural detail. Mantis integrates with Gemini CLI and Antigravity CLI, and ships a companion mode, mantis-advise, that surfaces prior fixes during development. Google still recommends human verification of AI-generated reports and patches, and isolation from production systems.

The release formalizes a defensive counterpart to AI's now-demonstrated offensive capability in vulnerability discovery, and pairs it with a concrete engineering answer to the context-cost problem that has limited AI security review on large repositories. Multi-agent verification chains aimed at suppressing false positives, plus automatic threat-model generation, position code-security review as a native layer of the coding-agent stack rather than a separate scanning product bolted on afterward.

For builders, the layered discovery-critique-sandbox pattern is a usable template for cutting false-positive burden in any AI code-review pipeline. For investors, standalone AI vulnerability-scanning startups now compete against a free, Google-distributed baseline wired directly into the CLI tools developers already run, which raises the bar for differentiation on accuracy, remediation quality, or workflow depth.

#Google #Mantis #AISecurity #DevTools #OpenSource #VulnerabilityManagement

#Google Mantis#AI vulnerability scanning#open-source security framework#Gemini CLI#multi-agent verification#token overhead reduction

How This Connects

Based on AI Agents · Player Map

  1. 1d agoMCP's largest spec revision since launch ships with a prompt-injection flaw that can leak credentials.Model Context Protocol (MCP) spec update
  2. 1d agoKakao Launches 'AI for All', South Korea's Government-Backed National AI Agent Platform'AI for All' ('모두의 AI') national AI platform, operated by Kakao
  3. 2d agoGoogle's Mantis open-sources AI-driven vulnerability discovery and remediation, cutting token overhead by more than 85%. · THIS ARTICLE
  4. 2w agoNvidia Research Puts Agent Harness Design Ahead of Base-Model QualityNvidia
  5. 3w agoTencent is set to become the largest shareholder of AI developer Manus, as Meta unwinds its acquisit...Manus
  6. 3w agoMeta will unwind its $2 billion acquisition of Manus AI after Beijing ordered the deal to be reverse...Manus

More news from Google Mantis

Stay updated with the latest news and announcements from Google Mantis.

View all Google Mantis news

Discover AI Startups

Explore 5,000+ AI companies with VC-grade analysis, funding data, and investment insights.

Explore Dashboard