Agent skill

Security Diff Scan

by CoWork-OS in CoWork-OS/CoWork-OS

A skill your agent uses when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.

MITAuto-check passedSecurity

Install Security Diff Scan

skills CLI
$ npx skills add CoWork-OS/CoWork-OS --skill security-diff-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CoWork-OS/CoWork-OS security-diff-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CoWork-OS/CoWork-OS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/resources/plugin-packs/codex-security/skills/security-diff-scan .claude/skills/security-diff-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-diff-scan
GitHub stars
473
Token cost
~2.5k tokens
SKILL.md length
1,307 words
Files
2
Skills in repo
81
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.

  • Works in 5 steps: $threat-model → $finding-discovery → $validation → …
  • The user asks for a security review of a pull request
  • SKILL.md covers Phase Sequence, Goal Setup, Artifact Resolution and Execution Plan, plus 6 more sections
  • Calls python3

What it does

Security Diff Scan is an agent skill from CoWork-OS/CoWork-OS. Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Security review and Pull requests. It works with Git. The repository describes itself as: Local-first personal agentic OS and everything app for coding, knowledge work, web design, automations, and artifacts. The licence is MIT.

When your agent uses it

  • The user asks for a security review of a pull request
  • Working-tree patch
  • Other Git-backed change set

Example prompts

  • “/security-diff-scan”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. $threat-model
  2. $finding-discovery
  3. $validation
  4. $attack-path-analysis
  5. Generate final output

What it can do on your machine

Read from SKILL.md and the folder at commit 0380874. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Diff Scan loads about 2.5k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 1,307 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from CoWork-OS/CoWork-OS at commit 0380874, republished under its MIT licence (© CoWork-OS). 1,307 words, ~2,459 tokens.

Download SKILL.mdSave it as .claude/skills/security-diff-scan/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-diff-scan
description
Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.
metadata.short-description
Run security diff scan

Security Diff Scan

Used when a user wants to review a Git-backed change set for security regressions. Keep the scan phases separate and produce final HTML and markdown reports.

Phase Sequence

Keep these phases distinct and run them in linear order:

  1. $threat-model
  2. $finding-discovery
  3. $validation
  4. $attack-path-analysis
  5. Generate final output

Treat this skill as the top-level orchestrator for the four skills plus the final report assembly step. Do not collapse the phases together.

For each phase:

  1. Read that phase's skill.
  2. Load only the inputs required for that phase.
  3. Complete that phase's workflow and checklist.
  4. Only then read the next phase's skill.

Do not read ahead into later-phase skills until the current phase has completed. Do not amortize effort across phases: complete each phase to the full depth expected by that phase before moving on.

Goal Setup

Before substantive scan work, create a Codex goal for the scan if the runtime exposes goal tools and no active goal already covers this scan. The objective should state that the scan must not stop until the resolved diff-scoped files have been covered and the required coverage artifacts prove that closure.

Use objective wording shaped like:

Run the Codex Security diff scan for <resolved target>; do not stop until every diff-scoped file/worklist row has a completion receipt or explicit deferred closure, every candidate has required ledger receipts, and the final report is written.

If a compatible active goal already exists, continue under it instead of creating a duplicate. If goal tools are unavailable, state the same coverage objective in the first visible scan update and continue.

Do not mark the goal complete until:

  • every deep_review_input.csv row has a completion receipt in work_ledger.jsonl, or an explicit deferred, not_applicable, or suppressed closure with exact reason
  • every candidate that reached discovery has the required discovery, validation, and attack-path ledger receipts, or an explicit deferred reason for the missing proof
  • the final markdown and HTML reports have been written to the resolved scan paths

Artifact Resolution

The path references in this skill are the default locations for this phase. If the user explicitly provides a different path for a required input or output, use the user-provided path instead of the corresponding default path referenced in this skill. If a required input is still missing, stop and ask the user for it before continuing. Use the shared scan artifact path conventions in ../../references/scan-artifacts.md.

Execution Plan

Follow this plan in order. Do not skip ahead to a later phase until the current phase has produced its intended output.

  1. Resolve the Git-backed scan target, repo_name, security_scans_dir, scan_id, scan_dir, and artifacts_dir using ../../references/scan-artifacts.md.
  2. Create or adopt the scan goal described in Goal Setup.
  3. Run $threat-model first.
  • Copy the repository-scoped threat model to the per-scan threat model path without alteration for auditability.
  • Treat the per-scan threat model path as the source of truth threat model for later phases.
  1. Run $finding-discovery as the second step, against the resolved diff and using the per-scan threat model as context.
  • If discovery produces no technically plausible candidates, stop there, skip validation and attack-path analysis, and assemble the final markdown report immediately.
  1. Run $validation as the third step, for each candidate that came out of discovery.
  • Pass the resolved diff scope, discovery notes, and candidate inventory to validation. Validation should preserve or suppress the provided instances; it should not independently broaden the review into a repository-wide scan.
  • Each candidate finding's findings/<candidate_id>/candidate_ledger.jsonl is part of the validation input. Every candidate finding that came out of discovery must have a discovery receipt before validation starts and a validation receipt before the scan can proceed to final reporting.
  1. Run $attack-path-analysis as the fourth step, for findings that still need reportability, attack-path, and severity analysis after validation.
  • Each candidate finding's findings/<candidate_id>/candidate_ledger.jsonl is part of the attack-path input. Every candidate finding that reaches attack-path analysis must have an attack-path receipt before final reporting, even when the final decision is ignore, suppressed, or deferred.
  1. Assemble the final output last using ../../references/final-report.md and the outputs of the earlier phases: finding discovery plus each candidate finding's validation and attack-path reports.

Phase Scope

  • Phase 1 (threat model generation) is repository-scope by default, unless the user explicitly asks for narrower scope or provides an authoritative threat model or sufficiently repository-specific security scan guidance such as AGENTS.md.
  • Phase 2 onward (finding discovery, validation, attack path analysis) are diff-focused and should follow the changed code and its supporting files.

Treat this asymmetry as intentional:

  • use the diff to locate the scan target for later phases
  • do not let the diff bias Phase 1 threat model generation, if applicable
  • do not let the touched subsystem become the repository threat model unless the user explicitly asks for that narrower scope
Show full SKILL.md (515 more words)Show less

Scan Target

Resolve the exact Git-backed diff before starting:

  • PR: compare base branch against current HEAD
  • commit: scan the target commit against its parent or requested baseline
  • branch diff: scan the requested merge-base to head range
  • local patch: scan staged and unstaged working-tree changes against the requested base

Diff-Scoped Discovery

Use ../security-scan/references/scan-artifacts-and-ledger.md for the shared scoped file-review, candidate-ledger, subagent, and dedupe rules.

Diff scans should:

  • generate rank_input.csv deterministically from changed source-like files with python3 <plugin_dir>/scripts/generate_rank_input.py make-diff-rank-input --repo <repo_root> --base <base> --mode revisions --head <head> --out <artifacts_dir>/rank_input.csv for PR, commit, and branch diffs, or python3 <plugin_dir>/scripts/generate_rank_input.py make-diff-rank-input --repo <repo_root> --base <base> --mode local-patch --out <artifacts_dir>/rank_input.csv for a local patch
  • copy every diff row into deep_review_input.csv with python3 <plugin_dir>/scripts/generate_rank_input.py copy-deep-review-input --rank-input <artifacts_dir>/rank_input.csv --out <artifacts_dir>/deep_review_input.csv
  • deep-review every file in deep_review_input.csv
  • add directly supporting files only when repository evidence shows they are needed to understand the changed security behavior
  • stay anchored to the changed code and directly supporting files rather than broadening into unrelated repository-wide enumeration

Diff-Scoped Sibling Coverage

For PR, commit, branch, and local-patch scans, stay diff-focused but preserve repeated vulnerable instances that are created or affected by the same changed pattern.

Diff scans should:

  • start from the changed files and the supporting files needed to understand the changed behavior
  • expand from a changed route, handler, shared helper, guard, template pattern, query builder, serializer/deserializer, filesystem/network sink, config block, or wrapper to sibling instances that the diff also changes, newly reaches, or affects through the same modified shared dependency
  • when the diff adds, removes, or reshapes a guard around an existing parser, deserializer, expression evaluator, filesystem/path helper, archive utility, or auth/authz helper, use the adjacent pre-existing sink/control as supporting context for the changed behavior; keep the candidate anchored to the changed guard or newly exposed path unless the user explicitly asks for wider instance expansion
  • when a changed wrapper, guard, or API delegates to a shared parser/deserializer/path/archive/auth helper, keep both the wrapper call site and the underlying shared sink/control line addressable; do not replace the root sink/control evidence with wrapper-only evidence
  • carry each vulnerable sibling instance through discovery and validation with its own affected location, source, closest control, sink, impact, and suppression evidence
  • use unchanged siblings as context and negative controls, but report them only when the diff makes them newly vulnerable or changes the shared control or sink they depend on
  • stop when the diff-linked pattern family is exhausted, rather than broadening into repository-wide enumeration

This keeps diff scans precise while avoiding the common failure mode where one representative route or sink hides additional vulnerable siblings introduced by the same patch.

Final Output

Assemble the final markdown report, final HTML report, and Codex app review directives using ../../references/final-report.md. Commit scans use this same final-output contract because they are a diff-scan target type.

Hard Rules

Read ../../references/shared-hard-rules.md before applying scan-mode-specific hard rules.

  • Create or adopt the scan goal before substantive scan work, and do not complete it until the resolved diff-scoped files/worklist rows, candidate ledgers, and final report meet the Goal Setup closure criteria.
  • Do not claim diff coverage until every deep_review_input.csv row has a completion receipt in work_ledger.jsonl.

© CoWork-OS, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in resources/plugin-packs/codex-security/skills/security-diff-scan of CoWork-OS/CoWork-OS.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 0380874

Compare with similar skills

Security Diff Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Diff Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Diff Scan this skillCoWork-OS/CoWork-OS473—~2.5kAutomated safety check: PassMIT
Claude Securityanthropics/claude-plugins-official37k—~1.4kAutomated safety check: PassApache-2.0
Trailmark Review Gatetrailofbits/skills7.4k—~1.1kAutomated safety check: NotesCC-BY-SA-4.0
Differential Security Reviewtrailofbits/skills7.4k—~1.8kAutomated safety check: NotesCC-BY-SA-4.0
Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit259—~2kAutomated safety check: PassCustom licence
Qv Devops PR Reviewtetherto/qvac674—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Claude Security

    anthropics/claude-plugins-official

    Official

    Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself.

    37k GitHub stars~1.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Trailmark Review Gate

    trailofbits/skills

    Official

    Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.

    7.4k GitHub stars~1.1k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Official

    Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.

    7.4k GitHub stars~1.8k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    259 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • Qv Devops PR Review

    tetherto/qvac

    PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

    674 GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Review

    softspark/ai-toolkit

    Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check: notes

More from CoWork-OS/CoWork-OS

All 81 skills in this repo
  • Calendly

    CoWork-OS/CoWork-OS

    Manage Calendly scheduling via the v2 API. An agent skill from CoWork-OS/CoWork-OS.

    473 GitHub stars~595 tokensUpdated yesterday
    Auto-check passed
  • Humanizer

    CoWork-OS/CoWork-OS

    Rewrite AI-generated text to sound natural and human-written.

    473 GitHub stars~557 tokensUpdated yesterday
    Auto-check passed
  • Marketing Strategist

    CoWork-OS/CoWork-OS

    Comprehensive marketing strategy across 25 disciplines — positioning, copywriting frameworks, buyer psychology, SEO, CRO, paid ads, funnel architecture, content strategy, growth loops, analytics…

    473 GitHub stars~893 tokensUpdated yesterday
    Auto-check passed
  • Moltbook

    CoWork-OS/CoWork-OS

    Interact with Moltbook — the social network for AI agents. An agent skill from CoWork-OS/CoWork-OS.

    473 GitHub stars~579 tokensUpdated yesterday
    Auto-check passed
  • Polymarket

    CoWork-OS/CoWork-OS

    Query Polymarket prediction markets — search events, check odds and prices, view trending markets, track price momentum, get orderbook depth, analyze volume, and monitor market resolution timelines.

    473 GitHub stars~616 tokensUpdated yesterday
    Auto-check passed
  • Skill Creator

    CoWork-OS/CoWork-OS

    Create or update AgentSkills for CoWork-OSS. An agent skill from CoWork-OS/CoWork-OS.

    473 GitHub stars~493 tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Security Diff Scan

What does Security Diff Scan do?

A skill your agent uses when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set. Security Diff Scan is an agent skill from CoWork-OS/CoWork-OS. Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.

When should I use Security Diff Scan?

Security Diff Scan fits situations like: the user asks for a security review of a pull request; working-tree patch; other Git-backed change set.

How do I install Security Diff Scan in Claude Code?

Run `npx skills add CoWork-OS/CoWork-OS --skill security-diff-scan -a claude-code`. Or copy the skill folder (resources/plugin-packs/codex-security/skills/security-diff-scan in CoWork-OS/CoWork-OS) into .claude/skills/security-diff-scan in your project. Claude Code loads it when a task matches its description.

How do I install Security Diff Scan in Codex?

Run `npx skills add CoWork-OS/CoWork-OS --skill security-diff-scan -a codex`. Or copy the skill folder (resources/plugin-packs/codex-security/skills/security-diff-scan in CoWork-OS/CoWork-OS) into .agents/skills/security-diff-scan in your project. Codex loads it when a task matches its description.

Can I use Security Diff Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CoWork-OS/CoWork-OS --skill security-diff-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-diff-scan, .gemini/skills/security-diff-scan, .github/skills/security-diff-scan and .opencode/skills/security-diff-scan in your project.

What does Security Diff Scan need to run?

Going by SKILL.md and its folder, Security Diff Scan needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Security Diff Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Diff Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Diff Scan use?

Security Diff Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Diff Scan use?

About 2.5k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Diff Scan?

Skills that share tags, products or a category with Security Diff Scan: Claude Security (anthropics/claude-plugins-official, 37k stars), Trailmark Review Gate (trailofbits/skills, 7.4k stars), Differential Security Review (trailofbits/skills, 7.4k stars) and Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 259 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Diff Scan?

CoWork-OS (a GitHub organization) maintains it in CoWork-OS/CoWork-OS, which has 473 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 7, 2026.

Source: CoWork-OS/CoWork-OS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.