{"repo":"deonmenezes/mantishack","free":true,"listed":false,"github":"https://github.com/deonmenezes/mantishack","clone":"git clone https://github.com/deonmenezes/mantishack.git","description":"Mantis Hack","language":"Rust","stars":488,"topics":["agent-harness","ai-agents","autonomous-agents","bug-bounty","claude-code","mcp","security","mantis","offensive-security"],"license":"Apache-2.0","category":"ai-agents","readme_excerpt":"Mantishack stalk - wait - strike - hold Ethically hack and discover vulnerabilities in any software with the power of AI. mantishack.com --- What is Mantishack? Mantishack is Mantis AI: an autonomous vulnerability-discovery agent built on top of OpenAI's Codex CLI (Rust, Apache-2.0), rebranded and wired end-to-end as an offensive-AppSec harness. It runs a staged detect-then-validate pipeline over a codebase - recon, detect, reachability, attacker-simulation validation, chaining, gated exploitation, fixing, and reporting - with every finding owned by a tool, not tracked in prose. The core bet is the same one this project has always made: detection is commodity, validation precision is the product. What survives attacker-simulation is real; everything else gets rejected with a cited roadblock. It is not polished software. It is a working harness with real gaps (see \"Project history\" and MANTIS.md for what's wired vs. what still needs external binaries or a running target), usable in the field, rough in the corners. --- Quick start Build from source Install the capability-catalog binaries The MCP tool servers under .codex/mcp-servers/ are pure Node.js and need no install of their own, but the scanners they wrap degrade to available: false until you install the underlying binaries: Nothing is fabricated when a binary is missing - each server reports plainly that the tool isn't installed rather than inventing findings. --- What's wired Layer Where What it does --------------------","default_branch":null,"files":null,"tree":[],"storefront":"/r/deonmenezes","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/deonmenezes/mantishack/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}