mantis vs open-kritt
The two are close in size: 1.7k stars for mantis, 2.2k for open-kritt. Over the days we have tracked them mantis moved +9782.4% and open-kritt +31.1%, so mantis is growing faster right now.
Neither one leads on the six capability axes, so the choice comes down to which of them fits the way you already work.
Stars and commit dates come from our own daily tracking. The six axes are read off each project's documentation by our review pipeline, so they describe what a project says about itself, not what we measured in its code.
Where they stand today
A modular, stack-agnostic suite of security review skills that lets coding agents find, reproduce, dedupe, and patch vulnerabilities with sandboxed execution and a sequential pipeline.
- Stars
- 1.7k
- Tracked growth
- +9782.4%
- Maturity
- ●●●●●
- Last commit
- 2d ago
- Language
- Python
- License
- Apache-2.0
- Cost to run
- Your API key; model/compute costs apply.
Orchestrates focused AI agent workflows in disposable job containers to find, validate and de-duplicate real vulnerabilities with PoC generation and ranking.
- Stars
- 2.2k
- Tracked growth
- +31.1%
- Maturity
- ●●●●●
- Last commit
- 3h ago
- Language
- JavaScript
- License
- AGPL-3.0
- Cost to run
- Requires model API key (your provider's billing applies).
Six axes, head to head
Each axis runs 0 to 5. The label under a score is what that project's own docs claim, not a category average.
| Axis | mantis | open-kritt |
|---|---|---|
Context depth How much of your codebase it sees before it answers: the open diff, the diff plus related files, or the whole repository. | ●●●●● Whole-repo analysis | ●●●●● Whole-repo analysis |
Noise control How it keeps output volume down — severity thresholds, deduplication, incremental runs over new commits only. | ●●●●● Dedupe & filters | ●●●●● Deduplication & ranking |
Customization How far it bends to your team: custom rules, prompts, style guides, per-path config. | ●●●●● Customizable prompts | ●●●●● Workflow & rules |
Privacy Whether your code stays on your own infrastructure: fully local, self-hostable, or cloud API only. | ●●●●● Self-hostable | ●●●●● Self-hosted (cloud models) |
Model freedom Whether you can point it at any provider, or it is wired to one. | ●●●●● Bring-your-own-key | ●●●●● Bring-your-key (multiple) |
Setup ease What it takes to get a first useful run out of it. | ●●●●● Agent + API key | ●●●●● Docker + CLI setup |
Which one to pick
Pick mantis if…
Security-first — pick Mantis when you need a focused, extensible toolkit of agent skills specialized for end-to-end vulnerability discovery, reproduction, and patching in isolated environments.
Pick open-kritt if…
Self-hosted — run customizable, security-focused AI research workflows locally with built-in validation, de-duplication and BYO model access.
What people want from each one
Kritt-ai/open-kritt
Questions people ask
Is mantis better than open-kritt?
Neither one leads on the six capability axes, so the choice comes down to which of them fits the way you already work. mantis is worth picking when security-first — pick Mantis when you need a focused, extensible toolkit of agent skills specialized for end-to-end vulnerability discovery, reproduction, and patching in isolated environments.
Which of mantis and open-kritt keeps my code private?
mantis: Self-hostable (4/5). open-kritt: Self-hosted (cloud models) (4/5).
What does each one cost to run?
mantis: Your API key; model/compute costs apply.. open-kritt: Requires model API key (your provider's billing applies)..
Full profiles: google/mantis and Kritt-ai/open-kritt. Everything else in Code review agents.