Code Review with Beads Tasks
maslennikov-ig/claude-code-orchestrator-kit
Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.
Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.
$ npx skills add trailofbits/skills --skill differential-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills differential-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/differential-review/skills/differential-review .claude/skills/differential-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "differential-review" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/differential-review/skills/differential-review into .claude/skills/differential-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "differential-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/differential-review/skills/differential-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill differential-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills differential-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/differential-review/skills/differential-review .agents/skills/differential-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "differential-review" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/differential-review/skills/differential-review into .agents/skills/differential-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "differential-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill differential-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills differential-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/differential-review/skills/differential-review .cursor/skills/differential-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "differential-review" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/differential-review/skills/differential-review into .cursor/skills/differential-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "differential-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/differential-review/skills/differential-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill differential-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills differential-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/differential-review/skills/differential-review .gemini/skills/differential-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "differential-review" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/differential-review/skills/differential-review into .gemini/skills/differential-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "differential-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills differential-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill differential-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/differential-review/skills/differential-review .github/skills/differential-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "differential-review" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/differential-review/skills/differential-review into .github/skills/differential-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "differential-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill differential-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills differential-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/differential-review/skills/differential-review .opencode/skills/differential-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "differential-review" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/differential-review/skills/differential-review into .opencode/skills/differential-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "differential-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
differential-reviewReviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.
Review depth adapts to codebase size, from reading every dependency on small codebases to critical paths only on large ones, and changes are classified by risk (authentication, crypto, external calls, value transfer and removed validation rank high) rather than by size. Git blame and history supply context, and blast radius is computed by counting callers.
The phases run from triage through code analysis, test coverage checks for modified code, blast radius, deep context and an adversarial phase that models attackers, ending in a report. Every finding cites history, line numbers and an attack scenario. A rationalizations table pushes back on shortcuts such as skipping git history, and methodology, patterns, adversarial and reporting notes live in separate files.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteGrepGlobBashFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Differential Security Review loads about 1.8k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 583 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Write, Grep, Glob, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 583 words, ~1,835 tokens.
.claude/skills/differential-review/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Security-focused code review for PRs, commits, and diffs.
| Rationalization | Why It's Wrong | Required Action |
|---|---|---|
| "Small PR, quick review" | Heartbleed was 2 lines | Classify by RISK, not size |
| "I know this codebase" | Familiarity breeds blind spots | Build explicit baseline context |
| "Git history takes too long" | History reveals regressions | Never skip Phase 1 |
| "Blast radius is obvious" | You'll miss transitive callers | Calculate quantitatively |
| "No tests = not my problem" | Missing tests = elevated risk rating | Flag in report, elevate severity |
| "Just a refactor, no security impact" | Refactors break invariants | Analyze as HIGH until proven LOW |
| "I'll explain verbally" | No artifact = findings lost | Always write report |
| Codebase Size | Strategy | Approach |
|---|---|---|
| SMALL (<20 files) | DEEP | Read all deps, full git blame |
| MEDIUM (20-200) | FOCUSED | 1-hop deps, priority files |
| LARGE (200+) | SURGICAL | Critical paths only |
| Risk Level | Triggers |
|---|---|
| HIGH | Auth, crypto, external calls, value transfer, validation removal |
| MEDIUM | Business logic, state changes, new public APIs |
| LOW | Comments, tests, UI, logging |
Pre-Analysis → Phase 0: Triage → Phase 1: Code Analysis → Phase 2: Test Coverage
↓ ↓ ↓ ↓
Phase 3: Blast Radius → Phase 4: Deep Context → Phase 5: Adversarial → Phase 6: ReportStarting a review?
├─ Need detailed phase-by-phase methodology?
│ └─ Read: methodology.md
│ (Pre-Analysis + Phases 0-4: triage, code analysis, test coverage, blast radius)
│
├─ Analyzing HIGH RISK change?
│ ├─ Read: adversarial.md
│ │ (Phase 5: Attacker modeling, exploit scenarios, exploitability rating)
│ └─ Or delegate to: differential-review:adversarial-modeler agent
│ (Autonomous attacker modeling with concrete exploit scenarios)
│
├─ Writing the final report?
│ └─ Read: reporting.md
│ (Phase 6: Report structure, templates, formatting guidelines)
│
├─ Looking for specific vulnerability patterns?
│ └─ Read: patterns.md
│ (Regressions, reentrancy, access control, overflow, etc.)
│
└─ Quick triage only?
└─ Use Quick Reference above, skip detailed docsdifferential-review:adversarial-modeler — Models attacker perspectives and
builds exploit scenarios for HIGH RISK code changes. Follows the 5-step
adversarial methodology (attacker model, attack vectors, exploitability rating,
exploit scenario, baseline cross-reference) and produces structured vulnerability
reports. Delegate to this agent when Phase 5 analysis is needed on high-risk
changes, passing that full namespaced name as subagent_type — a bare
adversarial-modeler is unregistered and the dispatch fails at runtime.
Before delivering:
audit-context-building skill:
issue-writer skill:
issue-writer --input DIFFERENTIAL_REVIEW_REPORT.md --format audit-reportInput: 5 file PR, 2 HIGH RISK files
Strategy: Use Quick Reference
1. Classify risk level per file (2 HIGH, 3 LOW)
2. Focus on 2 HIGH files only
3. Git blame removed code
4. Generate minimal report
Time: ~30 minutesInput: 80 files, 12 HIGH RISK changes
Strategy: FOCUSED (see methodology.md)
1. Full workflow on HIGH RISK files
2. Surface scan on MEDIUM
3. Skip LOW risk files
4. Complete report with all sections
Time: ~3-4 hoursInput: 450 files, auth system rewrite
Strategy: SURGICAL + audit-context-building
1. Baseline context with audit-context-building
2. Deep analysis on auth changes only
3. Blast radius analysis
4. Adversarial modeling
5. Comprehensive report
Time: ~6-8 hoursFor these cases, use standard code review instead.
Immediate escalation triggers:
These patterns require adversarial analysis even in quick triage.
Do:
Don't:
For first-time users: Start with methodology.md to understand the complete workflow.
For experienced users: Use this page's Quick Reference and Decision Tree to navigate directly to needed content.
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (assets) in plugins/differential-review/skills/differential-review of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Differential Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Differential Security Review this skilltrailofbits/skills | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit | 260 | — | ~2k | Automated safety check: Pass | Custom licence | |
| Review Codetobihagemann/turbo | 407 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Reviewsoftspark/ai-toolkit | 179 | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | |
| Evaluate PR Testsdotnet/maui | 23k | — | ~2.9k | Automated safety check: Pass | MIT | |
| Openqodexopenqodex/openqodex | 303 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 |
maslennikov-ig/claude-code-orchestrator-kit
Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.
tobihagemann/turbo
Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in…
softspark/ai-toolkit
Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.
dotnet/maui
Reviews the tests added in a pull request for fix coverage, quality, edge cases and test type, and recommends lighter test types where they would do.
openqodex/openqodex
Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.
anthropics/claude-plugins-official
Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Works with
Categories
Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. Review depth adapts to codebase size, from reading every dependency on small codebases to critical paths only on large ones, and changes are classified by risk (authentication, crypto, external calls, value transfer and removed validation rank high) rather than by size. Git blame and history supply context, and blast radius is computed by counting callers.
Differential Security Review fits situations like: reviewing a PR or commit for security vulnerabilities; checking whether a change reintroduces a bug that was fixed before; working out what else a change could break; finding modified code that no test covers.
Run `npx skills add trailofbits/skills --skill differential-review -a claude-code`. Or copy the skill folder (plugins/differential-review/skills/differential-review in trailofbits/skills) into .claude/skills/differential-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill differential-review -a codex`. Or copy the skill folder (plugins/differential-review/skills/differential-review in trailofbits/skills) into .agents/skills/differential-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill differential-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/differential-review, .gemini/skills/differential-review, .github/skills/differential-review and .opencode/skills/differential-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Differential Security Review is instructions for the agent only. Our summary lists: A Git repository containing the change to review. Its frontmatter pre-approves these tools: Read, Write, Grep, Glob, Bash.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Differential Security Review is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Differential Security Review: Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Review Code (tobihagemann/turbo, 407 stars), Review (softspark/ai-toolkit, 179 stars) and Evaluate PR Tests (dotnet/maui, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.