
Differential Review
Securityby trailofbits
3/3 audits passCC-BY-SA-4.0
Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and…
Differential Review is Trail of Bits' skill (publisher trailofbits, CC-BY-SA-4.0) for security-focused review of PRs, commits and diffs. It follows five principles (risk-first, evidence-based, adaptive, honest about coverage, and always producing a written report) and a phased workflow: triage, code analysis with git blame on removed security code, test-coverage checks, a quantitative blast-radius count of callers, deep context, adversarial modeling for high-risk changes, and a markdown report. Strategy scales with codebase size, from deep review under 20 files to surgical review of critical paths above 200, and risk levels are triggered by what the change touches: auth, crypto, external calls, value transfer or removed validation are HIGH. A table of rationalizations to reject, such as "small PR, quick review", keeps the agent from cutting corners, and supporting files cover methodology, adversarial analysis, reporting and vulnerability patterns.
Use it when reviewing a PR for vulnerabilities, checking whether a change re-introduces a fixed bug, or finding modified code no test covers. It is a code-review skill, not a full-repository scanner.
It is mainly for coding agents such as Claude Code with access to the repository and its git history. BusinessMCP can import it as a playbook, but its value lies in local code review.
What you can do with it
- Security-review a pull request that touches authentication
- Check whether a diff re-introduces a previously fixed bug
- Count callers to estimate the blast radius of a change
- Find modified code that has no test coverage
Run it on your business data
Imported into BusinessMCP, Differential Review becomes a playbook your AI business analyst applies to your connected GitHub repositories.
Use Differential Review in BusinessMCPInstall it in a coding agent
One command adds Differential Review to your project.
npx skills add https://github.com/trailofbits/skills --skill differential-reviewHow we vetted it
- Source
- trailofbits/skills at 0cc1c73
- Licence
- CC-BY-SA-4.0
- Security audits (skills.sh)
- Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
- Bundled scripts
- None, instructions only
Checked 2026-09-25 against its skills.sh listing. How we vet skills
Related skills
All skillsSemgrep
Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep…
Security and Hardening
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe…
Supply Chain Risk Auditor
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script…
Frequently asked questions
How does Differential Review decide how deep to go?
It classifies by risk, not size, and scales strategy to codebase size: deep for under 20 files, focused for 20-200, and surgical on critical paths for 200 or more.
What does it produce?
A markdown report file with findings tied to specific line numbers and commits, concrete attack scenarios for high-risk changes, and stated coverage limits and confidence.
How do I install Differential Review?
Run `npx skills add trailofbits/skills --skill differential-review`, or import it from the BusinessMCP dashboard as a playbook.
Run Differential Review against your whole business
Free plan, no credit card.
Use Differential Review in BusinessMCP