Official agent skill

Differential Security Review

by trailofbits in trailofbits/skills

Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.

OfficialCC-BY-SA-4.0Auto-check: notesSecurity

Install Differential Security Review

skills CLI
$ npx skills add trailofbits/skills --skill differential-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills differential-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/differential-review/skills/differential-review .claude/skills/differential-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
differential-review
GitHub stars
7.4k
Token cost
~1.8k tokens
SKILL.md length
583 words
Files
7 (incl. assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.

  • Works in 5 steps: Risk-First: Focus on auth, crypto, value… → Evidence-Based: Every finding backed by… → Adaptive: Scale to codebase size… → …
  • Reviewing a PR or commit for security vulnerabilities
  • SKILL.md covers Core Principles, Rationalizations (Do Not Skip), Quick Reference and Workflow Overview, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Review depth adapts to codebase size, from reading every dependency on small codebases to critical paths only on large ones, and changes are classified by risk (authentication, crypto, external calls, value transfer and removed validation rank high) rather than by size. Git blame and history supply context, and blast radius is computed by counting callers.

The phases run from triage through code analysis, test coverage checks for modified code, blast radius, deep context and an adversarial phase that models attackers, ending in a report. Every finding cites history, line numbers and an attack scenario. A rationalizations table pushes back on shortcuts such as skipping git history, and methodology, patterns, adversarial and reporting notes live in separate files.

When your agent uses it

  • Reviewing a PR or commit for security vulnerabilities
  • Checking whether a change reintroduces a bug that was fixed before
  • Working out what else a change could break
  • Finding modified code that no test covers

Example prompts

  • “Do a security review of this diff against main.”
  • “Check whether this commit reverts the earlier fix for the auth bypass, using git blame.”
  • “Which functions touched by this PR have no tests, and how many callers do they have?”

Requirements

  • A Git repository containing the change to review
  • Pre-approved tools (allowed-tools): Read, Write, Grep, Glob, Bash

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Risk-First: Focus on auth, crypto, value transfer, external calls
  2. Evidence-Based: Every finding backed by git history, line numbers, attack scenarios
  3. Adaptive: Scale to codebase size (SMALL/MEDIUM/LARGE)
  4. Honest: Explicitly state coverage limits and confidence level
  5. Output-Driven: Always generate comprehensive markdown report file

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Differential Security Review loads about 1.8k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 583 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 583 words, ~1,835 tokens.

Download SKILL.mdSave it as .claude/skills/differential-review/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
differential-review
description
Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and generates a markdown report. Use when reviewing a PR, commit, or diff for security vulnerabilities, checking whether a change re-introduces a previously fixed bug, asking what else a change could break, or finding which modified code has no test covering it.
allowed-tools
Read, Write, Grep, Glob, Bash

Differential Security Review

Security-focused code review for PRs, commits, and diffs.

Core Principles

  1. Risk-First: Focus on auth, crypto, value transfer, external calls
  2. Evidence-Based: Every finding backed by git history, line numbers, attack scenarios
  3. Adaptive: Scale to codebase size (SMALL/MEDIUM/LARGE)
  4. Honest: Explicitly state coverage limits and confidence level
  5. Output-Driven: Always generate comprehensive markdown report file

Rationalizations (Do Not Skip)

RationalizationWhy It's WrongRequired Action
"Small PR, quick review"Heartbleed was 2 linesClassify by RISK, not size
"I know this codebase"Familiarity breeds blind spotsBuild explicit baseline context
"Git history takes too long"History reveals regressionsNever skip Phase 1
"Blast radius is obvious"You'll miss transitive callersCalculate quantitatively
"No tests = not my problem"Missing tests = elevated risk ratingFlag in report, elevate severity
"Just a refactor, no security impact"Refactors break invariantsAnalyze as HIGH until proven LOW
"I'll explain verbally"No artifact = findings lostAlways write report

Quick Reference

Codebase Size Strategy
Codebase SizeStrategyApproach
SMALL (<20 files)DEEPRead all deps, full git blame
MEDIUM (20-200)FOCUSED1-hop deps, priority files
LARGE (200+)SURGICALCritical paths only
Risk Level Triggers
Risk LevelTriggers
HIGHAuth, crypto, external calls, value transfer, validation removal
MEDIUMBusiness logic, state changes, new public APIs
LOWComments, tests, UI, logging

Workflow Overview

Pre-Analysis → Phase 0: Triage → Phase 1: Code Analysis → Phase 2: Test Coverage
    ↓              ↓                    ↓                        ↓
Phase 3: Blast Radius → Phase 4: Deep Context → Phase 5: Adversarial → Phase 6: Report

Decision Tree

Starting a review?

├─ Need detailed phase-by-phase methodology?
│  └─ Read: methodology.md
│     (Pre-Analysis + Phases 0-4: triage, code analysis, test coverage, blast radius)
│
├─ Analyzing HIGH RISK change?
│  ├─ Read: adversarial.md
│  │  (Phase 5: Attacker modeling, exploit scenarios, exploitability rating)
│  └─ Or delegate to: differential-review:adversarial-modeler agent
│     (Autonomous attacker modeling with concrete exploit scenarios)
│
├─ Writing the final report?
│  └─ Read: reporting.md
│     (Phase 6: Report structure, templates, formatting guidelines)
│
├─ Looking for specific vulnerability patterns?
│  └─ Read: patterns.md
│     (Regressions, reentrancy, access control, overflow, etc.)
│
└─ Quick triage only?
   └─ Use Quick Reference above, skip detailed docs

Agents

differential-review:adversarial-modeler — Models attacker perspectives and builds exploit scenarios for HIGH RISK code changes. Follows the 5-step adversarial methodology (attacker model, attack vectors, exploitability rating, exploit scenario, baseline cross-reference) and produces structured vulnerability reports. Delegate to this agent when Phase 5 analysis is needed on high-risk changes, passing that full namespaced name as subagent_type — a bare adversarial-modeler is unregistered and the dispatch fails at runtime.


Quality Checklist

Before delivering:

  • All changed files analyzed
  • Git blame on removed security code
  • Blast radius calculated for HIGH risk
  • Attack scenarios are concrete (not generic)
  • Findings reference specific line numbers + commits
  • Report file generated
  • User notified with summary

Integration

audit-context-building skill:

  • Pre-Analysis: Build baseline context
  • Phase 4: Deep context on HIGH RISK changes

issue-writer skill:

  • Transform findings into formal audit reports
  • Command: issue-writer --input DIFFERENTIAL_REVIEW_REPORT.md --format audit-report

Show full SKILL.md (227 more words)Show less

Example Usage

Quick Triage (Small PR)
Input: 5 file PR, 2 HIGH RISK files
Strategy: Use Quick Reference
1. Classify risk level per file (2 HIGH, 3 LOW)
2. Focus on 2 HIGH files only
3. Git blame removed code
4. Generate minimal report
Time: ~30 minutes
Standard Review (Medium Codebase)
Input: 80 files, 12 HIGH RISK changes
Strategy: FOCUSED (see methodology.md)
1. Full workflow on HIGH RISK files
2. Surface scan on MEDIUM
3. Skip LOW risk files
4. Complete report with all sections
Time: ~3-4 hours
Deep Audit (Large, Critical Change)
Input: 450 files, auth system rewrite
Strategy: SURGICAL + audit-context-building
1. Baseline context with audit-context-building
2. Deep analysis on auth changes only
3. Blast radius analysis
4. Adversarial modeling
5. Comprehensive report
Time: ~6-8 hours

When NOT to Use This Skill

  • Greenfield code (no baseline to compare)
  • Documentation-only changes (no security impact)
  • Formatting/linting (cosmetic changes)
  • User explicitly requests quick summary only (they accept risk)

For these cases, use standard code review instead.


Red Flags (Stop and Investigate)

Immediate escalation triggers:

  • Removed code from "security", "CVE", or "fix" commits
  • Access control modifiers removed (onlyOwner, internal → external)
  • Validation removed without replacement
  • External calls added without checks
  • High blast radius (50+ callers) + HIGH risk change

These patterns require adversarial analysis even in quick triage.


Tips for Best Results

Do:

  • Start with git blame for removed code
  • Calculate blast radius early to prioritize
  • Generate concrete attack scenarios
  • Reference specific line numbers and commits
  • Be honest about coverage limitations
  • Always generate the output file

Don't:

  • Skip git history analysis
  • Make generic findings without evidence
  • Claim full analysis when time-limited
  • Forget to check test coverage
  • Miss high blast radius changes
  • Output report only to chat (file required)

Supporting Documentation


For first-time users: Start with methodology.md to understand the complete workflow.

For experienced users: Use this page's Quick Reference and Decision Tree to navigate directly to needed content.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (assets) in plugins/differential-review/skills/differential-review of trailofbits/skills.

  • SKILL.md
  • adversarial.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • methodology.md
  • patterns.md
  • reporting.md

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Differential Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Differential Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Differential Security Review this skilltrailofbits/skills7.4k—~1.8kAutomated safety check: NotesCC-BY-SA-4.0
Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit260—~2kAutomated safety check: PassCustom licence
Review Codetobihagemann/turbo407—~3.2kAutomated safety check: PassMIT
Reviewsoftspark/ai-toolkit179—~3.1kAutomated safety check: NotesApache-2.0
Evaluate PR Testsdotnet/maui23k—~2.9kAutomated safety check: PassMIT
Openqodexopenqodex/openqodex303—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    260 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • Review Code

    tobihagemann/turbo

    Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in…

    407 GitHub stars~3.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Review

    softspark/ai-toolkit

    Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Official

    Reviews the tests added in a pull request for fix coverage, quality, edge cases and test type, and recommends lighter test types where they would do.

    23k GitHub stars~2.9k tokensUpdated today
    Testing & QAAuto-check passed
  • Openqodex

    openqodex/openqodex

    Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

    303 GitHub stars~1.9k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Claude Security

    anthropics/claude-plugins-official

    Official

    Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself.

    38k GitHub stars~1.4k tokensUpdated yesterday
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 4 repos~4.2k tokens
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes

Works with

Questions about Differential Security Review

What does Differential Security Review do?

Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report. Review depth adapts to codebase size, from reading every dependency on small codebases to critical paths only on large ones, and changes are classified by risk (authentication, crypto, external calls, value transfer and removed validation rank high) rather than by size. Git blame and history supply context, and blast radius is computed by counting callers.

When should I use Differential Security Review?

Differential Security Review fits situations like: reviewing a PR or commit for security vulnerabilities; checking whether a change reintroduces a bug that was fixed before; working out what else a change could break; finding modified code that no test covers.

How do I install Differential Security Review in Claude Code?

Run `npx skills add trailofbits/skills --skill differential-review -a claude-code`. Or copy the skill folder (plugins/differential-review/skills/differential-review in trailofbits/skills) into .claude/skills/differential-review in your project. Claude Code loads it when a task matches its description.

How do I install Differential Security Review in Codex?

Run `npx skills add trailofbits/skills --skill differential-review -a codex`. Or copy the skill folder (plugins/differential-review/skills/differential-review in trailofbits/skills) into .agents/skills/differential-review in your project. Codex loads it when a task matches its description.

Can I use Differential Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill differential-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/differential-review, .gemini/skills/differential-review, .github/skills/differential-review and .opencode/skills/differential-review in your project.

What does Differential Security Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Differential Security Review is instructions for the agent only. Our summary lists: A Git repository containing the change to review. Its frontmatter pre-approves these tools: Read, Write, Grep, Glob, Bash.

Does Differential Security Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Differential Security Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Differential Security Review use?

Differential Security Review is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Differential Security Review use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Differential Security Review?

Skills that share tags, products or a category with Differential Security Review: Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Review Code (tobihagemann/turbo, 407 stars), Review (softspark/ai-toolkit, 179 stars) and Evaluate PR Tests (dotnet/maui, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Differential Security Review?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.