mantis-threat-model

A security planning step that describes where trust changes inside a system, where attackers can enter, and what kinds of attackers to consider. A trust boundary is a point where data or permissions move between parts of a system.

In plain words
What is it for?
Use it to create or update a THREAT_MODEL.md file from a knowledge base containing the system’s architecture and entities.
Why use it?
It turns architecture information into a shared threat model, so security risks can be considered systematically.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/google/mantis/mantis-threat-model
Any agent
npx skills add google/mantis --skill mantis-threat-model
Clone the repo
git clone --depth 1 https://github.com/google/mantis

Made for: Claude Code, Codex.

Per session 59 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,281 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00059 $0.03281
Opus 5 $0.00030 $0.01640
Sonnet 5 $0.00012 $0.00656
Haiku 4.5 $0.00006 $0.00328

Measured 3d ago against content hash ced15d440489, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

mantis-threat-model scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

mantis-threat-model/SKILL.md · 252 lines

How it starts

The opening of the file, as written. The whole thing — 252 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Threat Modeler (/mantis-threat-model)

System Goal

Security Architect. Synthesizes trust boundaries, attack surfaces, and attacker profiles into THREAT_MODEL.md based exclusively on the entities and architecture defined in the Knowledge Base (KB).

Command Definition

  • Command: /mantis-threat-model
  • Description: Evaluates architectural perimeters, entry points, and trust boundaries to construct the threat model.
  • Arguments (all optional; absent → today's behavior):
    • --state_root <dir>: parent of workspace/. If absent, use ./workspace/... relative to the current directory. Locates .mantis_state.json, the KB, and the archive directory.
    • --snapshot_id <id>: the SNAPSHOT_ID this pass is pinned to. Used ONLY as the provenance value stamped into THREAT_MODEL.md (the KB_SNAPSHOT: line). If absent, fall back to active_snapshot.snapshot_id from state; if that is also absent or snapshot_pinned is false, the stamp is the literal UNPINNED.
    • --snapshot_root <dir>: accepted for interface uniformity but NOT used — this stage never reads target source (Block A step 0, findings-only role).

Input/Output Contract

  • Reads:
    • workspace/.mantis_state.jsonpass_number (to archive per pass) and, for provenance only, active_snapshot ({root, snapshot_id, snapshot_pinned}). Both optional; absent → degraded (see Backward-compat).
    • workspace/kb/architecture.md.
    • workspace/kb/entities/*.md.
    • The EXISTING workspace/kb/THREAT_MODEL.md from the previous pass, if present — only its first KB_SNAPSHOT: line, for the freshness check in step 0.
  • Writes:
    • workspace/kb/THREAT_MODEL.md (first line is a KB_SNAPSHOT: provenance header).
    • Archives the previous workspace/kb/THREAT_MODEL.md (if any) to workspace/archive/kb/THREAT_MODEL_pass_${N}.md BEFORE overwriting.
  • Preconditions:
    • Knowledge Base files must exist and be populated.
  • Idempotency Guarantee:
    • Copies the prior THREAT_MODEL.md (if any) to the pass archive, then deterministically overwrites workspace/kb/THREAT_MODEL.md in-place. Re-running a pass with an unchanged snapshot reproduces an equivalent model plus a STALE banner (see step 0 and the final save step).

Read the full file on GitHub · 252 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 252 lines · 59 tokens per session scan A ced15d440489

Subscribe to this mod's changes

mantis-threat-model is a skill published in the GitHub repository google/mantis (853 stars, last pushed 5d ago), licensed Apache-2.0. It adds 59 tokens to every session and 3,281 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.