🔎
QualityRust

Program Analysis

by deonmenezes

Program Analysis is a Quality skill for Claude Code, published by deonmenezes in mantishack.

490 stars73 forkson deonmenezes/mantishackAdded 2026/08/26Repository updated 2026/08/11
agent-harnessai-agentsautonomous-agentsbug-bountyclaude-codemantismcpoffensive-securitysecurity
Install in seconds
Install Program Analysis
Copy Program Analysis into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/deonmenezes/mantishack/tree/main/.codex/skills/program-analysis ~/.claude/skills/program-analysis

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/deonmenezes/mantishack.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
.codex/skills/program-analysis/SKILL.md in deonmenezes/mantishack
Installs to
~/.claude/skills/program-analysis
Collection
One of 25 skills cataloged from this repository
Category
Quality1354 skills

What Program Analysis does

Program Analysis uses source-sink scanning, AST pattern search, and SMT reachability checks to narrow candidates and prove whether a path to a sink is reachable. Use it after finding a potential issue to confirm or reject exploitability.

Program Analysis is cataloged under Quality on DirSkills. Program Analysis comes from a repository tagged agent-harness, ai-agents, autonomous-agents, bug-bounty and claude-code.

Documentation

README

The mantis_program_analysis MCP server is the program-analysis substrate (PRD FR-3.1/3.2/3.3): it doesn't find vulnerabilities by itself, it gives you the primitives to prove or disprove reachability for candidates surfaced elsewhere (semgrep, CodeQL, manual reading).

Three tools, three different jobs:

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Program Analysis

  • What else does deonmenezes publish alongside Program Analysis?

    Program Analysis is one of 25 skills that DirSkills catalogs from deonmenezes/mantishack, the repository it ships in. Its siblings there include Canary Tripwire Response, Code Breaking Changes and Code Review. Each one is a separate skill with its own page in this directory, installs the same way Program Analysis does, and is maintained by deonmenezes in that same repository. The rest of the collection is listed on the deonmenezes/mantishack page.

  • How does Program Analysis compare to other Quality skills?

    Program Analysis ranks #1249 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Program Analysis against them. Open each page to compare what they document and how they install.

More from deonmenezes/mantishack

Program Analysis is one of 25 skills cataloged on DirSkills from deonmenezes/mantishack.

See all 25 skills
🚨
5d ago

Canary Tripwire Response

Canary Tripwire Response tells you how to react if a mantis_canary decoy tool is mentioned or called. It treats the event as a security incident, preserves evidence, and stops normal execution.
AI Engineering
49073
⚠️
5d ago

Code Breaking Changes

Code Breaking Changes searches external integration surfaces for breaking changes in app-server APIs, CLI parameters, configuration loading, and session resuming. Use it when reviewing changes for compatibility risks across these interfaces.
Quality
49073
🔎
5d ago

Code Review

Code Review runs a final review on a pull request by delegating to other code-review subagents and collecting their findings. Use it to surface every issue with file paths and line numbers before merging.
Quality
49073
🧩
5d ago

Code Review Change Size

Code Review Change Size sets limits for how many lines a change should touch and asks for staged delivery when a diff is too large. Use it to judge whether a change is reviewable in one pass or should be split.
Quality
49073
🧩
5d ago

Code Review Context

Code Review Context defines constraints for building model context incrementally, with bounded fragments and hard caps. Use it when reviewing changes that inject visible context into Codex requests.
Quality
49073
🧪
5d ago

Code Review Testing

Code Review Testing gives guidance for authoring tests for agent changes, with a preference for integration tests in core/suite. It is used when changes affect agent logic and need readable, maintainable test coverage.
Quality
49073