Agent skill

Debug Diff

by lidofinance in lidofinance/diffyscan

Diagnoses failed or incomplete Diffyscan runs, unexpected source or bytecode differences, compilation failures and explorer or RPC errors.

MITAuto-check passedBackend & APIs

Install Debug Diff

skills CLI
$ npx skills add lidofinance/diffyscan --skill debug-diff -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lidofinance/diffyscan debug-diff --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lidofinance/diffyscan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/debug-diff .claude/skills/debug-diff && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
debug-diff
GitHub stars
142
Token cost
~1.2k tokens
SKILL.md length
557 words
Files
2 (incl. references)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Diagnoses failed or incomplete Diffyscan runs, unexpected source or bytecode differences, compilation failures and explorer or RPC errors.

  • Works in 3 steps: Establish the failing run → Trace the cause → Fix and verify
  • Tasks that involve Smart contracts
  • SKILL.md covers 1. Establish the failing run, 2. Trace the cause and 3. Fix and verify
  • Calls uv

What it does

Debug Diff is an agent skill from lidofinance/diffyscan. Diagnoses failed or incomplete Diffyscan runs, unexpected source or bytecode differences, compilation failures and explorer or RPC errors. Use also when JSON reports error despite exit code 0. Explained exception changes belong to allowed-diffs; static config review belongs to validate-config.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/diagnostic-recipes.md`).

It sits in Backend & APIs, covering Smart contracts. It works with Solidity. The repository describes itself as: Diffyscan detects deployment drift by comparing GitHub source with explorer-verified source and on-chain bytecode across EVM networks. The licence is MIT.

When your agent uses it

  • Tasks that involve Smart contracts

Example prompts

  • “Use the debug-diff skill to diagnose failed or incomplete Diffyscan runs, unexpected source or bytecode differences, compilation failures and…”
  • “/debug-diff”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Establish the failing run
  2. Trace the cause
  3. Fix and verify

What it can do on your machine

Read from SKILL.md and the folder at commit 9fd6833. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Debug Diff loads about 1.2k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 557 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from lidofinance/diffyscan at commit 9fd6833, republished under its MIT licence (© lidofinance). 557 words, ~1,227 tokens.

Download SKILL.mdSave it as .claude/skills/debug-diff/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
debug-diff
description
Diagnoses failed or incomplete Diffyscan runs, unexpected source or bytecode differences, compilation failures and explorer or RPC errors. Use also when JSON reports error despite exit code 0. Explained exception changes belong to allowed-diffs; static config review belongs to validate-config.
argument-hint
[config-path-or-contract-address]

Find the cause while preserving requested verification scope. Run commands from the repository root.

1. Establish the failing run

Use the supplied JSON report and its log_file, or locate the digest matching the config, command and contract. Do not assume the newest digest belongs to the task. Read JSON output for status and partial-result semantics.

When a rerun is needed:

sh
uv run diffyscan path/to/config.yaml --json -E -G --contract 0xADDRESS

Omit the filter for the full config. --json implies --yes; stdout is the report and tracebacks go to stderr. Read status, top-level and contract errors, comparison results and coverage. Exit code 0 alone is insufficient. Missing entries after an abort are not verified contracts. Distinguish an unmatched filter, an empty config and both comparisons disabled from success.

Caches accelerate diagnosis. Omit -E if explorer metadata may be stale; do not delete shared caches indiscriminately. Keep tokens and credential-bearing URLs out of shared output.

Use diagnostic recipes for locating digest evidence, recovering constructor calldata or following an error-specific check.

2. Trace the cause

Read configuration for prerequisites and bytecode comparison for the trust model and overrides. Consult the relevant implementation:

EvidenceCheck next
Missing source or GitHub 404Commit, relative_root and import-prefix resolution in diffyscan/utils/github.py; distinguish a wrong path from a missing dependency.
Source hunksInspect report HTML and actual changes. Confirm deployment provenance before changing the pinned commit. --support-brownie enables recursive filename lookup that can select the first same-named file in another directory; confirm the resolved path before trusting the comparison.
Compilation errorrun_bytecode_diff in diffyscan/diffyscan.py, compiler/settings, dependencies, extra_sources and library definition paths.
Calldata or simulation errordiffyscan/utils/calldata.py, explorer metadata, constructor ABI, deployment_from, RPC state and deployment_gas_limit. Recover calldata from exact creation input and ABI, not an address substring or cross-chain address match.
Bytecode differencesanalyze_bytecode_diff in diffyscan/utils/binary_verifier.py and evaluation in diffyscan/utils/allowed_diffs.py; inspect uncovered ranges, metadata, runtime length and immutable values.
Explorer errorDispatch in diffyscan/utils/explorer.py, token lookup, response shape and verification status. A name mismatch may mean the wrong name, address or chain; it does not alone prove the contract is unverified.
HTTP 429 or transient 5xxhttp_client.fetch retries up to five times within a 300-second wait budget. Check Retry-After, or Blockscout's millisecond reset only with bypass-429-option; do not treat GitHub's epoch reset as milliseconds. Warnings show the delay and attempt. A budget error is an unresolved request, not verification success. RPC POST is not retried.
HTTP challenge or RPC errordiffyscan/utils/http_client.py, DIFFYSCAN_USER_AGENT, endpoint availability, chain and supported RPC methods.
Show full SKILL.md (156 more words)Show less

Flattened submissions may lack settings needed to reproduce bytecode. Inspect the payload and compilation before attributing a mismatch to that limitation. Proxy immutable differences need an explanation for the observed values. Neither case alone justifies a wildcard or dropping bytecode verification.

Draft exception examples only for observed and explained differences. In particular, flattened source does not by itself establish a metadata mismatch: omit cbor_metadata unless that difference is evidenced. Leave unknown causes and values unresolved rather than filling them into a plausible reason.

3. Fix and verify

Make the smallest correction supported by evidence. For diagnosis-only requests, report it without editing. For intended differences, use allowed-diffs. Keep unresolved contracts in scope instead of commenting them out or disabling comparisons to pass.

Rerun the affected contract after a fix, then the requested scope when available. Report root cause, evidence paths, changed fields, final statuses and unknowns. State any missing credentials or external dependency that prevented live confirmation.

© lidofinance, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .claude/skills/debug-diff of lidofinance/diffyscan.

  • SKILL.md
  • references/diagnostic-recipes.md

Open the folder on GitHubat commit 9fd6833

Compare with similar skills

Debug Diff next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Debug Diff compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Debug Diff this skilllidofinance/diffyscan142—~1.2kAutomated safety check: PassMIT
Fizz Convertpashov/skills1.2k2 repos~3.7kAutomated safety check: PassMIT
Feynman Auditor0xiehnnkta/nemesis-auditor2441 repos~11kAutomated safety check: PassMIT
Smart Contract Auditgreatpie/smart-contract-audit-skill101—~1.1kAutomated safety check: PassNone
RadarAuditware/radar154—~2.1kAutomated safety check: PassGPL-3.0
Solidity AuditorGabson0x/bountyforge443—~3.7kAutomated safety check: PassNone

Similar skills

  • Fizz Convert

    pashov/skills

    Convert English-language properties in PROPERTIES.md (produced by the Fizz skill) into Solidity assertions inside the existing fuzz harness, then flip their checkboxes.

    1.2k GitHub starsUsed in 2 repos~3.7k tokens
    Backend & APIsAuto-check passed
  • Feynman Auditor

    0xiehnnkta/nemesis-auditor

    Deep business logic bug finder using the Feynman technique. An agent skill from 0xiehnnkta/nemesis-auditor.

    244 GitHub starsUsed in 1 repo~11k tokens
    Backend & APIsAuto-check passed
  • Smart Contract Audit

    greatpie/smart-contract-audit-skill

    Script-backed, out-of-box auditing workflow for Solidity/EVM repositories based on EVMbench detect/patch/exploit methodology.

    101 GitHub stars~1.1k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Radar

    Auditware/radar

    Use radar for smart contract security analysis, AST generation, and detection template development.

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    443 GitHub stars~3.7k tokensUpdated 20 days ago
    Backend & APIsAuto-check passed
  • Scv Scan

    kadenzipfel/scv-scan

    Systematically audit Solidity smart contract codebases for security vulnerabilities using a 4-phase approach - load a vulnerability cheatsheet, sweep code with grep and semantic analysis…

    109 GitHub stars~1.4k tokensUpdated 6 mo ago
    Backend & APIsAuto-check passed

More from lidofinance/diffyscan

  • Add Explorer

    lidofinance/diffyscan

    Adds or repairs Diffyscan explorer API routing and response adapters for a new host, chain or payload format.

    142 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Allowed Diffs

    lidofinance/diffyscan

    Adds, reviews or tightens Diffyscan alloweddiffs rules for explained source or bytecode differences, including replacing any wildcards with granular rules.

    142 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • New Config

    lidofinance/diffyscan

    Creates or extends a Diffyscan verification config for a deployed contract or deployment.

    142 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Validate Config

    lidofinance/diffyscan

    Reviews an existing Diffyscan YAML or JSON config for load errors, runtime prerequisites, pinned sources, address mappings and broad exceptions.

    142 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Debug Diff

What does Debug Diff do?

Diagnoses failed or incomplete Diffyscan runs, unexpected source or bytecode differences, compilation failures and explorer or RPC errors. Debug Diff is an agent skill from lidofinance/diffyscan. Diagnoses failed or incomplete Diffyscan runs, unexpected source or bytecode differences, compilation failures and explorer or RPC errors.

When should I use Debug Diff?

Debug Diff fits situations like: tasks that involve Smart contracts.

How do I install Debug Diff in Claude Code?

Run `npx skills add lidofinance/diffyscan --skill debug-diff -a claude-code`. Or copy the skill folder (.claude/skills/debug-diff in lidofinance/diffyscan) into .claude/skills/debug-diff in your project. Claude Code loads it when a task matches its description.

How do I install Debug Diff in Codex?

Run `npx skills add lidofinance/diffyscan --skill debug-diff -a codex`. Or copy the skill folder (.claude/skills/debug-diff in lidofinance/diffyscan) into .agents/skills/debug-diff in your project. Codex loads it when a task matches its description.

Can I use Debug Diff in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lidofinance/diffyscan --skill debug-diff -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/debug-diff, .gemini/skills/debug-diff, .github/skills/debug-diff and .opencode/skills/debug-diff in your project.

What does Debug Diff need to run?

Going by SKILL.md and its folder, Debug Diff needs the command-line tools its instructions call (uv).

Does Debug Diff access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Debug Diff safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Debug Diff use?

Debug Diff is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Debug Diff use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Debug Diff?

Skills that share tags, products or a category with Debug Diff: Fizz Convert (pashov/skills, 1.2k stars), Feynman Auditor (0xiehnnkta/nemesis-auditor, 244 stars), Smart Contract Audit (greatpie/smart-contract-audit-skill, 101 stars) and Radar (Auditware/radar, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Debug Diff?

lidofinance (a GitHub organization) maintains it in lidofinance/diffyscan, which has 142 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 6, 2026.

Source: lidofinance/diffyscan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.