Google Open-Sources Mantis Framework to Curb AI Security Scanner False Alarms

Google released an open-source AI-agent framework aimed at automating vulnerability management while reducing erroneous findings from code scans.
Google has made publicly available a new open-source framework called Mantis, which uses AI agents to automate the complete vulnerability handling process—from initial detection and validation through to reproduction and patching. The project is designed to address a persistent problem in modern security tooling: the tendency for AI-assisted code scanners to generate a large number of false positives and even hallucinate vulnerabilities that do not actually exist in the codebase.
According to the company, traditional AI-powered scanning methods often overwhelm security teams with unreliable alerts, leading to wasted effort and potential oversight of genuine threats. Mantis aims to reduce that noise by structuring the scanning workflow into distinct stages, each handled by specialized agents that verify findings before they are escalated. This approach helps ensure that only confirmed vulnerabilities move forward for remediation.
By releasing Mantis as open-source software, Google hopes to give security researchers and development teams a practical tool to integrate into their pipelines. The framework represents a step toward more trustworthy automated security analysis, potentially easing the burden on human reviewers who currently spend significant time triaging false positives.