๐Ÿ•ต๏ธ
QualityRust

Findings Spine

by deonmenezes

Findings Spine is a Quality skill for Claude Code, published by deonmenezes in mantishack.

490 stars73 forkson deonmenezes/mantishackAdded 2026/08/26Repository updated 2026/08/11
agent-harnessai-agentsautonomous-agentsbug-bountyclaude-codemantismcpoffensive-securitysecurity
Install in seconds
Install Findings Spine
Copy Findings Spine into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/deonmenezes/mantishack/tree/main/.codex/skills/findings-spine ~/.claude/skills/findings-spine

Requires Node.js. Downloads this skill only โ€” not the rest of the repository โ€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/deonmenezes/mantishack.git

Clones the whole repository, then copy the skillโ€™s own directory into your skills folder yourself.

In this catalog

Source file
.codex/skills/findings-spine/SKILL.md in deonmenezes/mantishack
Installs to
~/.claude/skills/findings-spine
Collection
One of 25 skills cataloged from this repository
Category
Quality โ€” 1354 skills

What Findings Spine does

Findings Spine records vulnerability findings in the mantis_findings service instead of prose. Use it to create, confirm, reject, grade, and list findings with append-only evidence and lifecycle state.

Findings Spine is cataloged under Quality on DirSkills. Findings Spine comes from a repository tagged agent-harness, ai-agents, autonomous-agents, bug-bounty and claude-code.

Documentation

README

The mantis_findings MCP server owns finding state (PRD section 9, FR-9.*). Findings live in an append-only event log at .codex/findings/events.jsonl, not in your message history -- so a run is reconstructable and nothing is silently dropped. Never track confirmed/rejected findings only in prose; write them through this service so ids, lifecycle, severity, evidence, and grade are authoritative.

Lifecycle (PRD section 5): candidate -> confirmed | rejected -> exploited -> fixed -> verified. rejected is terminal. Detect is generous, Validate is ruthless.

When to call each tool:

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Findings Spine

  • What else does deonmenezes publish alongside Findings Spine?

    Findings Spine is one of 25 skills that DirSkills catalogs from deonmenezes/mantishack, the repository it ships in. Its siblings there include Canary Tripwire Response, Code Breaking Changes and Code Review. Each one is a separate skill with its own page in this directory, installs the same way Findings Spine does, and is maintained by deonmenezes in that same repository. The rest of the collection is listed on the deonmenezes/mantishack page.

  • How does Findings Spine compare to other Quality skills?

    Findings Spine ranks #1246 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Findings Spine against them. Open each page to compare what they document and how they install.

More from deonmenezes/mantishack

Findings Spine is one of 25 skills cataloged on DirSkills from deonmenezes/mantishack.

See all 25 skills โ†’
๐Ÿšจ
5d ago

Canary Tripwire Response

Canary Tripwire Response tells you how to react if a mantis_canary decoy tool is mentioned or called. It treats the event as a security incident, preserves evidence, and stops normal execution.
AI Engineering
49073
โš ๏ธ
5d ago

Code Breaking Changes

Code Breaking Changes searches external integration surfaces for breaking changes in app-server APIs, CLI parameters, configuration loading, and session resuming. Use it when reviewing changes for compatibility risks across these interfaces.
Quality
49073
๐Ÿ”Ž
5d ago

Code Review

Code Review runs a final review on a pull request by delegating to other code-review subagents and collecting their findings. Use it to surface every issue with file paths and line numbers before merging.
Quality
49073
๐Ÿงฉ
5d ago

Code Review Change Size

Code Review Change Size sets limits for how many lines a change should touch and asks for staged delivery when a diff is too large. Use it to judge whether a change is reviewable in one pass or should be split.
Quality
49073
๐Ÿงฉ
5d ago

Code Review Context

Code Review Context defines constraints for building model context incrementally, with bounded fragments and hard caps. Use it when reviewing changes that inject visible context into Codex requests.
Quality
49073
๐Ÿงช
5d ago

Code Review Testing

Code Review Testing gives guidance for authoring tests for agent changes, with a preference for integration tests in core/suite. It is used when changes affect agent logic and need readable, maintainable test coverage.
Quality
49073