Agent skill

Differential Review

by vibeeval in vibeeval/vibecosystem

Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

MITAuto-check passedDevelopment

Install Differential Review

skills CLI
$ npx skills add vibeeval/vibecosystem --skill differential-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vibeeval/vibecosystem differential-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/differential-review .claude/skills/differential-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
differential-review
GitHub stars
532
Token cost
~1.6k tokens
SKILL.md length
556 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

  • Works in 3 steps: Blast Radius Assessment → Git History Correlation → Structured Review
  • Code changes for security implications
  • SKILL.md covers Review Depth Modes, Review Process, Finding Format and Severity Classification, plus 4 more sections
  • Calls git

What it does

Differential Review is an agent skill from vibeeval/vibecosystem. Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format. Adapted from Trail of Bits. Use when reviewing PRs, commits, or code changes for security implications.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Git workflow and Code review. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.

When your agent uses it

  • Code changes for security implications
  • Tasks that involve Git workflow
  • Tasks that involve Code review

Example prompts

  • “/differential-review”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Blast Radius Assessment
  2. Git History Correlation
  3. Structured Review

What it can do on your machine

Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Differential Review loads about 1.6k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 556 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 556 words, ~1,578 tokens.

Download SKILL.mdSave it as .claude/skills/differential-review/SKILL.md (or your agent's skills folder).
name
differential-review
description
Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format. Adapted from Trail of Bits. Use when reviewing PRs, commits, or code changes for security implications.

Differential Review

Security-focused code review that adapts depth to codebase size and change risk. Goes beyond style -- finds vulnerabilities, logic errors, and blast radius.

Review Depth Modes

DEEP (Small codebase, < 5K lines changed)
  • Line-by-line analysis of every changed file
  • Full control flow tracing through changed paths
  • Cross-reference every function call to its definition
  • Check all error paths and edge cases
FOCUSED (Medium codebase, 5K-50K lines)
  • Prioritize files touching auth, crypto, input parsing, state mutation
  • Trace data flow from inputs to outputs through changed code
  • Skip cosmetic changes (formatting, comments, renames)
  • Deep-dive only on security-sensitive paths
SURGICAL (Large codebase, > 50K lines)
  • Review only the diff, not surrounding code
  • Focus exclusively on: new attack surface, removed security controls, changed trust boundaries
  • Flag anything that needs a separate deep review

Review Process

Phase 1: Blast Radius Assessment

Before reading any code:

bash
# What changed?
git diff --stat <base>...<head>

# How much changed?
git diff --shortstat <base>...<head>

# Which files are security-sensitive?
git diff --name-only <base>...<head> | grep -iE '(auth|crypto|token|secret|permission|middleware|validator|sanitiz)'

Classify the change:

  • Surface area: How many files, functions, modules touched?
  • Trust boundary crossing: Does data flow between trust levels?
  • Security control modification: Are auth/authz/validation/crypto paths changed?
  • Data model change: Are schemas, types, or storage formats modified?
Phase 2: Git History Correlation

Check if the changed code has a history of bugs:

bash
# How often has this file been changed? (churn = risk)
git log --oneline --follow <file> | wc -l

# Were there recent security fixes in this area?
git log --oneline --grep="fix\|vuln\|security\|CVE" -- <file>

# Who else has touched this code?
git log --format='%an' -- <file> | sort | uniq -c | sort -rn

High churn + security fix history = increase review depth.

Phase 3: Structured Review

For each changed file, analyze in this order:

  1. Input validation: Are new inputs validated? Are existing validations preserved?
  2. Authentication/Authorization: Do access controls apply to new code paths?
  3. Data flow: Can untrusted data reach sensitive operations?
  4. Error handling: Do error paths leak information or skip cleanup?
  5. State mutation: Are state changes atomic? Race conditions possible?
  6. Crypto usage: Correct algorithms, key sizes, modes, IVs?
  7. Logging: Are sensitive values logged? Are security events NOT logged?

Finding Format

## [SEVERITY] Finding Title

**Location**: file.ts:42-58
**Category**: [Input Validation | Auth | Crypto | Data Flow | State | Logic]
**Confidence**: [HIGH | MEDIUM | LOW]

**Description**:
What the vulnerability is, in one paragraph.

**Impact**:
What an attacker can achieve by exploiting this.

**Proof**:
The specific code path or data flow that demonstrates the issue.

**Recommendation**:
Concrete fix with code example if possible.

Severity Classification

SeverityCriteriaExamples
CRITICALRemote exploitation, no auth required, data breachSQL injection, auth bypass, RCE
HIGHRequires some access, significant impactPrivilege escalation, IDOR, stored XSS
MEDIUMLimited impact or complex exploitationReflected XSS, info disclosure, CSRF
LOWMinimal impact, defense-in-depthMissing headers, verbose errors, weak config
INFOBest practice, no direct vulnerabilityCode quality, missing rate limit, logging gap
Show full SKILL.md (210 more words)Show less

Rationalizations to Reject

Common excuses that lead to missed findings. Do NOT accept these:

RationalizationWhy It's WrongRequired Action
"It's behind auth"Auth can be bypassedVerify auth is enforced AND correct
"We trust this input"Trust boundaries changeValidate at every boundary
"It's just internal"Internal networks get compromisedApply defense in depth
"Nobody would do that"Attackers do unexpected thingsTest the unexpected case
"We'll fix it later"Later never comes in securityFlag it NOW with severity
"The framework handles it"Frameworks have bypassesVerify the framework actually applies
"It's the same as before"Before might have been wrong tooReview the original if suspicious

Anti-Hallucination Rules

  • Never say "It probably..." -- say "Unclear; need to inspect X"
  • Never assume a function is safe without reading its implementation
  • Never skip a finding because it seems minor -- document everything
  • Every claim must reference a specific file and line number
  • If you haven't read the code, say so -- don't infer behavior from names

Diff Review Checklist

[ ] Blast radius assessed (files, trust boundaries, security controls)
[ ] Git history checked for churn and past security fixes
[ ] All new inputs validated
[ ] Auth/authz applied to new endpoints/paths
[ ] Error handling doesn't leak sensitive info
[ ] No hardcoded secrets or credentials
[ ] State mutations are atomic
[ ] Crypto usage follows current best practices
[ ] Logging doesn't include sensitive data
[ ] Removed code didn't contain security controls that are now missing
[ ] Dependencies added/updated are from trusted sources
[ ] Test coverage exists for security-critical paths

Integration with vibecosystem

  • code-reviewer agent: Use this skill for security-focused review depth
  • security-reviewer agent: Primary consumer of this skill
  • coroner agent: Use blast radius analysis for post-mortem propagation
  • /review skill: Automatically applies differential review to PRs

Inspired by Trail of Bits differential-review plugin.

© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/differential-review of vibeeval/vibecosystem.

Open the folder on GitHubat commit 3b763b1

Compare with similar skills

Differential Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Differential Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Differential Review this skillvibeeval/vibecosystem532—~1.6kAutomated safety check: PassMIT
Git History Bug Auditben-manes/caffeine18k—~3.3kAutomated safety check: PassApache-2.0
Address PR Feedback for ruby-gitruby-git/ruby-git1.8k—~657Automated safety check: PassMIT
PR Review Triagestickerdaniel/linkedin-mcp-server3.8k—~1.4kAutomated safety check: PassApache-2.0
Beyond Compare Git Diff OpenerSensoriumEmbedded/TeensyROM227—~2.4kAutomated safety check: PassMIT
GitHub Workflowtransilienceai/communitytools563—~812Automated safety check: NotesMIT

Similar skills

  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Addresses unresolved pull request review threads and suppressed (low-confidence) Copilot review comments on the current branch, folds each fix into the…

    1.8k GitHub stars~657 tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • PR Review Triage

    stickerdaniel/linkedin-mcp-server

    Collects every review comment on a pull request, checks each against the real code, fixes the valid ones, pushes, and replies on and resolves each thread.

    3.8k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Beyond Compare Git Diff Opener

    SensoriumEmbedded/TeensyROM

    Opens Beyond Compare on a git diff for the current work, a pull request, a branch, a commit or a range, without touching the checkout.

    227 GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    563 GitHub stars~812 tokensUpdated 2 mo ago
    DevelopmentAuto-check: notes
  • Git CL for Gerrit

    webrtc-sdk/webrtc

    Provides commands for interacting with Gerrit CLs using git cl, including issue management and non-interactive uploads.

    446 GitHub starsUsed in 1 repo~146 tokens
    DevelopmentAuto-check passed

More from vibeeval/vibecosystem

All 12 skills in this repo
  • Agent Benchmark

    vibeeval/vibecosystem

    Framework for measuring and tracking agent response quality over time.

    532 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Factcheck Guard

    vibeeval/vibecosystem

    A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.

    532 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Fp Check

    vibeeval/vibecosystem

    Systematic false positive verification for security findings.

    532 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • N8n Workflows

    vibeeval/vibecosystem

    n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.

    532 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Notepad System

    vibeeval/vibecosystem

    A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.

    532 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Property Based Testing

    vibeeval/vibecosystem

    Property-based testing (PBT) patterns with fast-check (JS/TS), Hypothesis (Python), and gopter (Go).

    532 GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Differential Review

What does Differential Review do?

Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format. Differential Review is an agent skill from vibeeval/vibecosystem. Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

When should I use Differential Review?

Differential Review fits situations like: code changes for security implications; tasks that involve Git workflow; tasks that involve Code review.

How do I install Differential Review in Claude Code?

Run `npx skills add vibeeval/vibecosystem --skill differential-review -a claude-code`. Or copy the skill folder (skills/differential-review in vibeeval/vibecosystem) into .claude/skills/differential-review in your project. Claude Code loads it when a task matches its description.

How do I install Differential Review in Codex?

Run `npx skills add vibeeval/vibecosystem --skill differential-review -a codex`. Or copy the skill folder (skills/differential-review in vibeeval/vibecosystem) into .agents/skills/differential-review in your project. Codex loads it when a task matches its description.

Can I use Differential Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill differential-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/differential-review, .gemini/skills/differential-review, .github/skills/differential-review and .opencode/skills/differential-review in your project.

What does Differential Review need to run?

Going by SKILL.md and its folder, Differential Review needs the command-line tools its instructions call (git).

Does Differential Review access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Differential Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Differential Review use?

Differential Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Differential Review use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Differential Review?

Skills that share tags, products or a category with Differential Review: Git History Bug Audit (ben-manes/caffeine, 18k stars), Address PR Feedback for ruby-git (ruby-git/ruby-git, 1.8k stars), PR Review Triage (stickerdaniel/linkedin-mcp-server, 3.8k stars) and Beyond Compare Git Diff Opener (SensoriumEmbedded/TeensyROM, 227 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Differential Review?

vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 532 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 8, 2026.

Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.