---
title: "differential-review skill: security review of a PR or diff"
canonical_url: https://cookiesforai.app/skills/trailofbits/differential-review
last_updated: 2026-10-02T03:01:13+02:00
type: skill
summary: "differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report."
install: "npx skills add trailofbits/skills --skill differential-review"
related:
  - "https://cookiesforai.app/skills/firebase/firebase-security-rules-auditor"
  - "https://cookiesforai.app/skills/getsentry/gha-security-review"
  - "https://cookiesforai.app/skills/getsentry/security-review"
  - "https://cookiesforai.app/skills/trailofbits/semgrep-rule-creator"
  - "https://cookiesforai.app/skills/trailofbits/mutation-testing"
  - "https://cookiesforai.app/skills/trailofbits/supply-chain-risk-auditor"
---

# Differential review

differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report.

| Fact | Value |
|---|---|
| Publisher | Trail of Bits (official, own GitHub account) |
| Source | https://github.com/trailofbits/skills/tree/HEAD/plugins/differential-review/skills/differential-review |
| License | CC-BY-SA-4.0 |
| Repository stars | 7,328 on 2026-10-02 |
| Skill name | differential-review |
| Category | Security |
| Skill last changed | 2026-09-16 |
| Page updated | 2026-10-02 |
| Facts checked | 2026-10-02 |

## Install

Install this skill with the skills CLI:

```
npx skills add trailofbits/skills --skill differential-review
```

Or, in Claude Code, add Trail of Bits' plugin marketplace:

```
/plugin marketplace add trailofbits/skills
```

Or, in Codex, add the same marketplace from your terminal:

```
codex plugin marketplace add trailofbits/skills
```

Then install the differential-review plugin in Codex:

```
codex plugin add differential-review@trailofbits
```

In Claude Code, open /plugin menu after adding the marketplace and install the differential-review plugin. For a ChatGPT workspace, Trail of Bits' README says to import the repository's .claude-plugin/marketplace.json.

## Ask your coding agent

A skill can include scripts that run on your computer, so read its source first: https://github.com/trailofbits/skills/tree/HEAD/plugins/differential-review/skills/differential-review

```text
Install the agent skill differential-review from github.com/trailofbits/skills.
```

## What it does

differential-review is an agent skill from security firm Trail of Bits for reviewing code changes rather than a whole codebase. It classifies each change by risk, not size: authentication, cryptography, external calls, value transfer and removed validation are high risk; business logic and new public APIs are medium; comments, tests, UI and logging are low. Review depth scales with codebase size, from reading everything under 20 files to critical paths only above 200.

The differential-review workflow runs in phases: triage, code analysis that runs git blame when security code is deleted, test coverage of the changed lines, blast radius by counting callers, deeper context on high-risk changes, adversarial modeling with concrete exploit scenarios, and a final report. Supporting files cover the methodology, attacker modeling, vulnerability patterns such as regressions, reentrancy and access control, and the report format.

The skill lists shortcuts it rejects, such as treating a small PR or a refactor as low risk by default, and always writes a markdown report file with line numbers and commits behind each finding. Its own principles ask it to state coverage limits and confidence honestly rather than imply a clean bill of health.

## When to use it

- You want a security review of one pull request before it merges.
- You suspect a change reintroduces a bug that was fixed before.
- You want to know what else in the codebase a change could break.
- You need a written review report with line references for an audit trail.

## When to pick something else

- Auditing a whole codebase from scratch: Trail of Bits pairs this skill with its audit-context-building skill for that.

## What it needs

- A git repository with history for the changed files

## Which agents it works in

Trail of Bits documents it for Claude Code, Codex, ChatGPT workspace marketplace. The open skills CLI also installs it into 78 agents (listed with the CLI on 2026-10-01).

For high-risk changes the skill can hand attacker modeling to a Claude Code subagent, differential-review:adversarial-modeler, which ships in the plugin and not in the skill folder. Through the skills CLI, the agent follows the adversarial.md guide in the folder instead.

## License

CC-BY-SA-4.0. CC-BY-SA-4.0 is a share-alike license. You can copy the skill into a project and change it, even for commercial work, if you credit Trail of Bits, link the license and say what you changed. If you share a changed version, for example in a public repository, it must stay under CC-BY-SA-4.0. It is a content license, not a software license, so ask your legal team before bundling it inside a closed product.

## Questions people ask

### Can I copy Trail of Bits' differential-review skill into my own repository?

Yes, with conditions. The skills are CC-BY-SA-4.0. You may copy and adapt them, even commercially, if you credit Trail of Bits, link the license and note your changes. Any changed version you share must carry the same CC-BY-SA-4.0 license. Using the skill unchanged in your own work does not put your code under that license.

### Does differential-review work outside Claude Code?

Yes. Trail of Bits documents Codex through its plugin marketplace and ships an agents/openai.yaml file in the skill folder for ChatGPT workspace imports. The optional adversarial-modeler subagent is a Claude Code plugin feature; other agents use the adversarial.md guide in the same folder.

## Related

### Related skills for security

- [Firebase security rules auditor](https://cookiesforai.app/skills/firebase/firebase-security-rules-auditor): firebase-security-rules-auditor is the Firebase team's agent skill for auditing Firestore and Cloud Storage security rules for privilege escalation, update bypasses and missing limits, returning a 1 to 5 score in JSON.
- [GitHub Actions security review](https://cookiesforai.app/skills/getsentry/gha-security-review): gha-security-review is Sentry's agent skill for auditing GitHub Actions workflows for attacks an outsider can run, such as pwn requests, expression injection and credential theft, with a concrete exploit for each finding.
- [Security review](https://cookiesforai.app/skills/getsentry/security-review): security-review is Sentry's agent skill for reviewing code for exploitable vulnerabilities, such as injection, XSS, broken access control and weak crypto, reporting only findings it has confirmed with high confidence.
- [Semgrep rule creator](https://cookiesforai.app/skills/trailofbits/semgrep-rule-creator): semgrep-rule-creator is Trail of Bits' agent skill for writing custom Semgrep rules that detect vulnerabilities and bug patterns, test-first, with taint mode preferred and every test required to pass.

### More from Trail of Bits

- [Mutation testing](https://cookiesforai.app/skills/trailofbits/mutation-testing): mutation-testing is Trail of Bits' agent skill for configuring mutation testing campaigns with its mewt or muton tools, reading surviving mutants, telling equivalent mutants from real test gaps, and hunting bugs they expose.
- [Supply chain risk auditor](https://cookiesforai.app/skills/trailofbits/supply-chain-risk-auditor): supply-chain-risk-auditor is Trail of Bits' agent skill for auditing a project's npm, PyPI and Go dependencies for known advisories, abandoned upstreams, publisher concentration and install scripts, measured by bundled scripts.

