Skip to content

Commit 59435dd

Browse files
committed
Add SAST seeding + structural code index patterns
- Schema: optional sast_provenance field on findings - Guideline 8: SAST seeding via platform-agnostic JSONL IR - Guideline 9: structural code index (ctags/tree-sitter) - Reference blueprints for both patterns - Pre-commit formatting fixes for mantis-kb-query.md TAG=agy CONV=8f41d111-5b37-45ab-915d-403e1c52742b Change-Id: I3c9f0062bdfd53095d2c005ed3df2fa137607b66
1 parent 36ad24f commit 59435dd

6 files changed

Lines changed: 1213 additions & 51 deletions

File tree

‎README_AGENTS.md‎

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -360,6 +360,25 @@ efficiency (such as using UUID-based referencing), and adaptability to custom
360360
environments (via MCP), see the
361361
[Pipeline Adapter Guide](mantis-pipeline-adapter/SKILL.md).
362362

363+
### SAST Seeding (External Tool Ingestion)
364+
365+
For teams that want to augment LLM discovery with findings from external SAST
366+
tools (CodeQL, Semgrep, etc.), the Pipeline Adapter Guide includes a **SAST
367+
Seeding** pattern (Guideline 8). This opt-in adapter ingests external tool
368+
findings as `PROVISIONALLY_VALID` / `NEEDS_RESEARCH` candidates that must earn
369+
their verdict through the unchanged downstream gates. It is purely additive — no
370+
existing skills are modified. The adapter uses a platform-agnostic JSONL IR
371+
format (not SARIF) that any SAST tool can convert to. See
372+
[mantis-pipeline-adapter/references/mantis-sast-seed.md](mantis-pipeline-adapter/references/mantis-sast-seed.md).
373+
374+
### Structural Code Index (AST-Level Context)
375+
376+
For large codebases where grep-based call-site discovery is unreliable, the
377+
Pipeline Adapter Guide includes a **Structural Code Index** pattern (Guideline
378+
9). This opt-in adapter builds a function-level call graph and symbol table
379+
using ctags (zero-dependency) or tree-sitter (pip-installable). See
380+
[mantis-pipeline-adapter/references/mantis-structural-index.md](mantis-pipeline-adapter/references/mantis-structural-index.md).
381+
363382
> **Note on Standalone vs. Harness Mode:** When using Mantis Skills directly
364383
> from the CLI in standalone mode, skills like `/mantis-review` or
365384
> `/mantis-patch` will instruct the LLM to write temporary reusable Python

0 commit comments

Comments
 (0)