.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/deonmenezes/mantishack
home/skills/deonmenezes/mantishack
deonmenezes avatar

deonmenezes/mantishack

29 skills

View on GitHub
$npx skills add deonmenezes/mantishack
SkillInstalls
babysit-prcanary-tripwire-responseWhat to do if a mantis_canary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result—code-reviewRun a final code review on a pull request—code-review-breaking-changesBreaking changes—code-review-change-sizeChange size guidance (800 lines)—code-review-contextModel visible context—code-review-testingTest authoring guidance—codeql-auditBuild a CodeQL database and run dataflow-backed query-suite analysis via the mantis_codeql MCP server—codex-bugDiagnose GitHub bug reports in openai/codex. Use when given a GitHub issue URL from openai/codex and asked to decide next steps such as verifying against the…—codex-issue-digestRun a GitHub issue digest for openai/codex by feature-area labels, all areas, and configurable time windows.—codex-pr-bodyUpdate the title and body of one or more pull requests.—detection-breadthWhen and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core…—findings-spineRecord and advance every vulnerability finding through the tool-owned mantis_findings service instead of tracking findings in prose—http-evidenceTurn a captured HTTP request/response into a bounded, redacted evidence pack with a stable request-ref using the mantis_http_audit MCP server, instead of…—imagegenmantis-pipelineThe master Mantis playbook -- how to run an authorized vulnerability-discovery engagement end to end, which subagent owns each stage, which MCP tool feeds it,…—openai-docsosv-dependency-scanRun osv-scanner via the mantis_osv_scanner MCP server for SCA (vulnerable dependency) findings—path-typesChoose Rust types for operating system paths across the Codex repository. Use when defining new path-bearing types or explicitly migrating existing ones.—plugin-creatorprogram-analysisUse ast_grep_scan, source_sink_scan, and smt_check_reachability (mantis_program_analysis MCP server) to move a candidate toward a proven-reachable finding—pushing-ci-changesPushing GitHub Actions changes, resolving push rejection, requesting upload exceptions.—remote-testsTesting against remote executors in integration tests.—secrets-scanRun trufflehog via the mantis_trufflehog MCP server and handle secret findings without ever exposing the raw secret—semgrep-triageRun semgrep via the mantis_semgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle—skill-creatorskill-installertest-tuiupdate-v8-versionUpdate Codex's pinned `v8` / `rusty_v8` versions, validate the release-candidate path, and investigate failed V8 canary or artifact builds.—