Agent skill

Differential Review

by waybarrios in waybarrios/opencode-power-pack

Performs security-focused differential review of code changes (PRs, commits, diffs).

MITAuto-check passedTesting & QA

Install Differential Review

skills CLI
$ npx skills add waybarrios/opencode-power-pack --skill differential-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install waybarrios/opencode-power-pack differential-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/differential-review .claude/skills/differential-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
differential-review
GitHub stars
534
Used in
5 other repos
Token cost
~1.6k tokens
SKILL.md length
518 words
Files
5
Skills in repo
32
Repo updated
First seen
Licence
MIT

At a glance

Performs security-focused differential review of code changes (PRs, commits, diffs).

  • Works in 5 steps: Risk-First: Focus on auth, crypto, value… → Evidence-Based: Every finding backed by… → Adaptive: Scale to codebase size… → …
  • Tasks that involve Git workflow
  • SKILL.md covers Core Principles, Rationalizations (Do Not Skip), Quick Reference and Workflow Overview, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Differential Review is an agent skill from waybarrios/opencode-power-pack. Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `adversarial.md`, `methodology.md` and `patterns.md`).

It sits in Testing & QA, covering Git workflow and Test coverage. The repository describes itself as: 54 rigorous skills for Codex, OpenCode, and Pi: code review, security audit, feature development, frontend design, MCP tools, Hugging Face ML/training, and more. The licence is MIT.

When your agent uses it

  • Tasks that involve Git workflow
  • Tasks that involve Test coverage

Example prompts

  • “Use the differential-review skill to perform security-focused differential review of code changes (PRs, commits, diffs)”
  • “/differential-review”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Risk-First: Focus on auth, crypto, value transfer, external calls
  2. Evidence-Based: Every finding backed by git history, line numbers, attack scenarios
  3. Adaptive: Scale to codebase size (SMALL/MEDIUM/LARGE)
  4. Honest: Explicitly state coverage limits and confidence level
  5. Output-Driven: Always generate comprehensive markdown report file

What it can do on your machine

Read from SKILL.md and the folder at commit 9dccb6d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Differential Review loads about 1.6k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 518 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from waybarrios/opencode-power-pack at commit 9dccb6d, republished under its MIT licence (© waybarrios). 518 words, ~1,620 tokens.

Download SKILL.mdSave it as .claude/skills/differential-review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
differential-review
description
Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.
license
MIT (modified; see UPSTREAMS.json)

Differential Security Review

Security-focused code review for PRs, commits, and diffs.

Core Principles

  1. Risk-First: Focus on auth, crypto, value transfer, external calls
  2. Evidence-Based: Every finding backed by git history, line numbers, attack scenarios
  3. Adaptive: Scale to codebase size (SMALL/MEDIUM/LARGE)
  4. Honest: Explicitly state coverage limits and confidence level
  5. Output-Driven: Always generate comprehensive markdown report file

Rationalizations (Do Not Skip)

RationalizationWhy It's WrongRequired Action
"Small PR, quick review"Heartbleed was 2 linesClassify by RISK, not size
"I know this codebase"Familiarity breeds blind spotsBuild explicit baseline context
"Git history takes too long"History reveals regressionsNever skip Phase 1
"Blast radius is obvious"You'll miss transitive callersCalculate quantitatively
"No tests = not my problem"Missing tests = elevated risk ratingFlag in report, elevate severity
"Just a refactor, no security impact"Refactors break invariantsAnalyze as HIGH until proven LOW
"I'll explain verbally"No artifact = findings lostAlways write report

Quick Reference

Codebase Size Strategy
Codebase SizeStrategyApproach
SMALL (<20 files)DEEPRead all deps, full git blame
MEDIUM (20-200)FOCUSED1-hop deps, priority files
LARGE (200+)SURGICALCritical paths only
Risk Level Triggers
Risk LevelTriggers
HIGHAuth, crypto, external calls, value transfer, validation removal
MEDIUMBusiness logic, state changes, new public APIs
LOWComments, tests, UI, logging

Workflow Overview

Pre-Analysis → Phase 0: Triage → Phase 1: Code Analysis → Phase 2: Test Coverage
    ↓              ↓                    ↓                        ↓
Phase 3: Blast Radius → Phase 4: Deep Context → Phase 5: Adversarial → Phase 6: Report

Decision Tree

Starting a review?

├─ Need detailed phase-by-phase methodology?
│  └─ Read: methodology.md
│     (Pre-Analysis + Phases 0-4: triage, code analysis, test coverage, blast radius)
│
├─ Analyzing HIGH RISK change?
│  └─ Read: adversarial.md
│     (Phase 5: Attacker modeling, exploit scenarios, exploitability rating)
│
├─ Writing the final report?
│  └─ Read: reporting.md
│     (Phase 6: Report structure, templates, formatting guidelines)
│
├─ Looking for specific vulnerability patterns?
│  └─ Read: patterns.md
│     (Regressions, reentrancy, access control, overflow, etc.)
│
└─ Quick triage only?
   └─ Use Quick Reference above, skip detailed docs

Quality Checklist

Before delivering:

  • All changed files analyzed
  • Git blame on removed security code
  • Blast radius calculated for HIGH risk
  • Attack scenarios are concrete (not generic)
  • Findings reference specific line numbers + commits
  • Report file generated
  • User notified with summary

Integration

audit-context-building skill:

  • Pre-Analysis: Build baseline context
  • Phase 4: Deep context on HIGH RISK changes

issue-writer skill:

  • Transform findings into formal audit reports
  • Command: issue-writer --input DIFFERENTIAL_REVIEW_REPORT.md --format audit-report

Example Usage

Quick Triage (Small PR)
Input: 5 file PR, 2 HIGH RISK files
Strategy: Use Quick Reference
1. Classify risk level per file (2 HIGH, 3 LOW)
2. Focus on 2 HIGH files only
3. Git blame removed code
4. Generate minimal report
Time: ~30 minutes
Standard Review (Medium Codebase)
Input: 80 files, 12 HIGH RISK changes
Strategy: FOCUSED (see methodology.md)
1. Full workflow on HIGH RISK files
2. Surface scan on MEDIUM
3. Skip LOW risk files
4. Complete report with all sections
Time: ~3-4 hours
Deep Audit (Large, Critical Change)
Input: 450 files, auth system rewrite
Strategy: SURGICAL + audit-context-building
1. Baseline context with audit-context-building
2. Deep analysis on auth changes only
3. Blast radius analysis
4. Adversarial modeling
5. Comprehensive report
Time: ~6-8 hours

Show full SKILL.md (212 more words)Show less

When NOT to Use This Skill

  • Greenfield code (no baseline to compare)
  • Documentation-only changes (no security impact)
  • Formatting/linting (cosmetic changes)
  • User explicitly requests quick summary only (they accept risk)

For these cases, use standard code review instead.


Red Flags (Stop and Investigate)

Immediate escalation triggers:

  • Removed code from "security", "CVE", or "fix" commits
  • Access control modifiers removed (onlyOwner, internal → external)
  • Validation removed without replacement
  • External calls added without checks
  • High blast radius (50+ callers) + HIGH risk change

These patterns require adversarial analysis even in quick triage.


Tips for Best Results

Do:

  • Start with git blame for removed code
  • Calculate blast radius early to prioritize
  • Generate concrete attack scenarios
  • Reference specific line numbers and commits
  • Be honest about coverage limitations
  • Always generate the output file

Don't:

  • Skip git history analysis
  • Make generic findings without evidence
  • Claim full analysis when time-limited
  • Forget to check test coverage
  • Miss high blast radius changes
  • Output report only to chat (file required)

Supporting Documentation


For first-time users: Start with methodology.md to understand the complete workflow.

For experienced users: Use this page's Quick Reference and Decision Tree to navigate directly to needed content.

© waybarrios, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in skills/differential-review of waybarrios/opencode-power-pack.

  • SKILL.md
  • adversarial.md
  • methodology.md
  • patterns.md
  • reporting.md

Open the folder on GitHubat commit 9dccb6d

Used in 5 other repositories

We found 14 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in waybarrios/opencode-power-pack, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Differential Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Differential Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Differential Review this skillwaybarrios/opencode-power-pack5345 repos~1.6kAutomated safety check: PassMIT
Xray Pre Auditccashwell/evm-cortex131—~25kAutomated safety check: PassMIT
Test Gap Auditgithub/awesome-copilot40k—~3.4kAutomated safety check: PassMIT
Evaluate PR Testsdotnet/maui23k—~2.9kAutomated safety check: PassMIT
Test Guidelinesgetsentry/sentry-dart873—~3.1kAutomated safety check: PassMIT
Testingdoorkeeper-gem/doorkeeper5.5k—~1.6kAutomated safety check: PassMIT

Similar skills

  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Test Gap Audit

    github/awesome-copilot

    Official

    Run a read-only audit for missing, weak, stale, or mis-scoped test coverage.

    40k GitHub stars~3.4k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Official

    Reviews the tests added in a pull request for fix coverage, quality, edge cases and test type, and recommends lighter test types where they would do.

    23k GitHub stars~2.9k tokensUpdated today
    Testing & QAAuto-check passed
  • Test Guidelines

    getsentry/sentry-dart

    Official

    Enforce Sentry Dart/Flutter SDK test conventions for naming, structure, and fixtures.

    873 GitHub stars~3.1k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Testing

    doorkeeper-gem/doorkeeper

    Write correct and complete RSpec tests for Doorkeeper. An agent skill from doorkeeper-gem/doorkeeper.

    5.5k GitHub stars~1.6k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Review

    webern/cargo-readme

    Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage.

    385 GitHub stars~2k tokensUpdated 2 days ago
    Testing & QAAuto-check: notes

More from waybarrios/opencode-power-pack

All 32 skills in this repo
  • Hf Cloud Sagemaker Iam Preflight

    waybarrios/opencode-power-pack

    Verify or select a SageMaker execution role before creating models, endpoints, or training jobs.

    534 GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • Huggingface LLM Trainer

    waybarrios/opencode-power-pack

    Train or fine-tune language models with TRL or Unsloth on Hugging Face Jobs, including SFT, DPO, GRPO, reward models, and GGUF conversion.

    534 GitHub stars~3k tokensUpdated 4 days ago
    Auto-check passed
  • Huggingface Vision Trainer

    waybarrios/opencode-power-pack

    Train object-detection, image-classification, or SAM segmentation models on Hugging Face Jobs.

    534 GitHub stars~2.7k tokensUpdated 4 days ago
    Auto-check passed
  • Codeql

    waybarrios/opencode-power-pack

    Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.

    534 GitHub starsUsed in 2 repos~3.7k tokens
    Auto-check passed
  • Semgrep

    waybarrios/opencode-power-pack

    Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

    534 GitHub stars~2.4k tokensUpdated 4 days ago
    Auto-check passed
  • Insecure Defaults

    waybarrios/opencode-power-pack

    Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production.

    534 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed

Questions about Differential Review

What does Differential Review do?

Performs security-focused differential review of code changes (PRs, commits, diffs). Differential Review is an agent skill from waybarrios/opencode-power-pack. Performs security-focused differential review of code changes (PRs, commits, diffs).

When should I use Differential Review?

Differential Review fits situations like: tasks that involve Git workflow; tasks that involve Test coverage.

How do I install Differential Review in Claude Code?

Run `npx skills add waybarrios/opencode-power-pack --skill differential-review -a claude-code`. Or copy the skill folder (skills/differential-review in waybarrios/opencode-power-pack) into .claude/skills/differential-review in your project. Claude Code loads it when a task matches its description.

How do I install Differential Review in Codex?

Run `npx skills add waybarrios/opencode-power-pack --skill differential-review -a codex`. Or copy the skill folder (skills/differential-review in waybarrios/opencode-power-pack) into .agents/skills/differential-review in your project. Codex loads it when a task matches its description.

Can I use Differential Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waybarrios/opencode-power-pack --skill differential-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/differential-review, .gemini/skills/differential-review, .github/skills/differential-review and .opencode/skills/differential-review in your project.

What does Differential Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Differential Review is instructions for the agent only.

Does Differential Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Differential Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Differential Review use?

Differential Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Differential Review use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Differential Review?

Skills that share tags, products or a category with Differential Review: Xray Pre Audit (ccashwell/evm-cortex, 131 stars), Test Gap Audit (github/awesome-copilot, 40k stars), Evaluate PR Tests (dotnet/maui, 23k stars) and Test Guidelines (getsentry/sentry-dart, 873 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Differential Review?

waybarrios (a GitHub user) maintains it in waybarrios/opencode-power-pack, which has 534 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on October 6, 2026.

Source: waybarrios/opencode-power-pack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.