Source profileQuality 91/100

trailofbits/skills/plugins/differential-review/skills/differential-review/SKILL.md

differential-review

Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.

Source repository stars
6,424
Declared platforms
0
Static risk flags
0
Last source update
2026-08-04
Source checked
2026-08-04

Decision brief

What it does—and where it fits

Security-focused code review for PRs, commits, and diffs.

Best for

    Not for

    • Greenfield code (no baseline to compare)
    • Documentation-only changes (no security impact)

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/trailofbits/skills --skill "plugins/differential-review/skills/differential-review"
    Safe inspection promptEditorial

    Inspect the Agent Skill "differential-review" from https://github.com/trailofbits/skills/blob/9ea55c598763f7cb87ab56933d773d7dc34344a0/plugins/differential-review/skills/differential-review/SKILL.md at commit 9ea55c598763f7cb87ab56933d773d7dc34344a0. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      Workflow Overview

      Review the “Workflow Overview” section in the pinned source before continuing.

      Review and apply the “Workflow Overview” source section.
    2. 02

      Example Usage

      Review the “Example Usage” section in the pinned source before continuing.

      Review and apply the “Example Usage” source section.
    3. 03

      Standard Review (Medium Codebase)

      Review the “Standard Review (Medium Codebase)” section in the pinned source before continuing.

      Review and apply the “Standard Review (Medium Codebase)” source section.
    4. 04

      Core Principles

      1. Risk-First: Focus on auth, crypto, value transfer, external calls 2. Evidence-Based: Every finding backed by git history, line numbers, attack scenarios 3. Adaptive: Scale to codebase size (SMALL/MEDIUM/LARGE) 4. Honest: Explicitly state coverage limits and confidence level 5…

      Risk-First: Focus on auth, crypto, value transfer, external callsEvidence-Based: Every finding backed by git history, line numbers, attack scenariosAdaptive: Scale to codebase size (SMALL/MEDIUM/LARGE)
    5. 05

      Rationalizations (Do Not Skip)

      Review the “Rationalizations (Do Not Skip)” section in the pinned source before continuing.

      Review and apply the “Rationalizations (Do Not Skip)” source section.

    Permission review

    Static risk signals and limitations

    No configured static risk pattern was detected

    This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score91/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars6,424SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    trailofbits/skills
    Skill path
    plugins/differential-review/skills/differential-review/SKILL.md
    Commit
    9ea55c598763f7cb87ab56933d773d7dc34344a0
    License
    CC-BY-SA-4.0
    Collected
    2026-08-04
    Default branch
    main
    View the original SKILL.md

    Differential Security Review

    Security-focused code review for PRs, commits, and diffs.

    Core Principles

    1. Risk-First: Focus on auth, crypto, value transfer, external calls
    2. Evidence-Based: Every finding backed by git history, line numbers, attack scenarios
    3. Adaptive: Scale to codebase size (SMALL/MEDIUM/LARGE)
    4. Honest: Explicitly state coverage limits and confidence level
    5. Output-Driven: Always generate comprehensive markdown report file

    Rationalizations (Do Not Skip)

    RationalizationWhy It's WrongRequired Action
    "Small PR, quick review"Heartbleed was 2 linesClassify by RISK, not size
    "I know this codebase"Familiarity breeds blind spotsBuild explicit baseline context
    "Git history takes too long"History reveals regressionsNever skip Phase 1
    "Blast radius is obvious"You'll miss transitive callersCalculate quantitatively
    "No tests = not my problem"Missing tests = elevated risk ratingFlag in report, elevate severity
    "Just a refactor, no security impact"Refactors break invariantsAnalyze as HIGH until proven LOW
    "I'll explain verbally"No artifact = findings lostAlways write report

    Quick Reference

    Codebase Size Strategy

    Codebase SizeStrategyApproach
    SMALL (<20 files)DEEPRead all deps, full git blame
    MEDIUM (20-200)FOCUSED1-hop deps, priority files
    LARGE (200+)SURGICALCritical paths only

    Risk Level Triggers

    Risk LevelTriggers
    HIGHAuth, crypto, external calls, value transfer, validation removal
    MEDIUMBusiness logic, state changes, new public APIs
    LOWComments, tests, UI, logging

    Workflow Overview

    Pre-Analysis → Phase 0: Triage → Phase 1: Code Analysis → Phase 2: Test Coverage
        ↓              ↓                    ↓                        ↓
    Phase 3: Blast Radius → Phase 4: Deep Context → Phase 5: Adversarial → Phase 6: Report
    

    Decision Tree

    Starting a review?

    ├─ Need detailed phase-by-phase methodology?
    │  └─ Read: methodology.md
    │     (Pre-Analysis + Phases 0-4: triage, code analysis, test coverage, blast radius)
    │
    ├─ Analyzing HIGH RISK change?
    │  ├─ Read: adversarial.md
    │  │  (Phase 5: Attacker modeling, exploit scenarios, exploitability rating)
    │  └─ Or delegate to: adversarial-modeler agent
    │     (Autonomous attacker modeling with concrete exploit scenarios)
    │
    ├─ Writing the final report?
    │  └─ Read: reporting.md
    │     (Phase 6: Report structure, templates, formatting guidelines)
    │
    ├─ Looking for specific vulnerability patterns?
    │  └─ Read: patterns.md
    │     (Regressions, reentrancy, access control, overflow, etc.)
    │
    └─ Quick triage only?
       └─ Use Quick Reference above, skip detailed docs
    

    Agents

    adversarial-modeler — Models attacker perspectives and builds exploit scenarios for HIGH RISK code changes. Follows the 5-step adversarial methodology (attacker model, attack vectors, exploitability rating, exploit scenario, baseline cross-reference) and produces structured vulnerability reports. Delegate to this agent when Phase 5 analysis is needed on high-risk changes.


    Quality Checklist

    Before delivering:

    • All changed files analyzed
    • Git blame on removed security code
    • Blast radius calculated for HIGH risk
    • Attack scenarios are concrete (not generic)
    • Findings reference specific line numbers + commits
    • Report file generated
    • User notified with summary

    Integration

    audit-context-building skill:

    • Pre-Analysis: Build baseline context
    • Phase 4: Deep context on HIGH RISK changes

    issue-writer skill:

    • Transform findings into formal audit reports
    • Command: issue-writer --input DIFFERENTIAL_REVIEW_REPORT.md --format audit-report

    Example Usage

    Quick Triage (Small PR)

    Input: 5 file PR, 2 HIGH RISK files
    Strategy: Use Quick Reference
    1. Classify risk level per file (2 HIGH, 3 LOW)
    2. Focus on 2 HIGH files only
    3. Git blame removed code
    4. Generate minimal report
    Time: ~30 minutes
    

    Standard Review (Medium Codebase)

    Input: 80 files, 12 HIGH RISK changes
    Strategy: FOCUSED (see methodology.md)
    1. Full workflow on HIGH RISK files
    2. Surface scan on MEDIUM
    3. Skip LOW risk files
    4. Complete report with all sections
    Time: ~3-4 hours
    

    Deep Audit (Large, Critical Change)

    Input: 450 files, auth system rewrite
    Strategy: SURGICAL + audit-context-building
    1. Baseline context with audit-context-building
    2. Deep analysis on auth changes only
    3. Blast radius analysis
    4. Adversarial modeling
    5. Comprehensive report
    Time: ~6-8 hours
    

    When NOT to Use This Skill

    • Greenfield code (no baseline to compare)
    • Documentation-only changes (no security impact)
    • Formatting/linting (cosmetic changes)
    • User explicitly requests quick summary only (they accept risk)

    For these cases, use standard code review instead.


    Red Flags (Stop and Investigate)

    Immediate escalation triggers:

    • Removed code from "security", "CVE", or "fix" commits
    • Access control modifiers removed (onlyOwner, internal → external)
    • Validation removed without replacement
    • External calls added without checks
    • High blast radius (50+ callers) + HIGH risk change

    These patterns require adversarial analysis even in quick triage.


    Tips for Best Results

    Do:

    • Start with git blame for removed code
    • Calculate blast radius early to prioritize
    • Generate concrete attack scenarios
    • Reference specific line numbers and commits
    • Be honest about coverage limitations
    • Always generate the output file

    Don't:

    • Skip git history analysis
    • Make generic findings without evidence
    • Claim full analysis when time-limited
    • Forget to check test coverage
    • Miss high blast radius changes
    • Output report only to chat (file required)

    Supporting Documentation


    For first-time users: Start with methodology.md to understand the complete workflow.

    For experienced users: Use this page's Quick Reference and Decision Tree to navigate directly to needed content.

    Alternatives

    Compare before choosing