BusinessMCP
Differential Review logo

Differential Review

Security

by trailofbits

3/3 audits passCC-BY-SA-4.0

Use Differential Review in BusinessMCP

Free · imported in one click after signup

View on GitHub

Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and…

Differential Review is Trail of Bits' skill (publisher trailofbits, CC-BY-SA-4.0) for security-focused review of PRs, commits and diffs. It follows five principles (risk-first, evidence-based, adaptive, honest about coverage, and always producing a written report) and a phased workflow: triage, code analysis with git blame on removed security code, test-coverage checks, a quantitative blast-radius count of callers, deep context, adversarial modeling for high-risk changes, and a markdown report. Strategy scales with codebase size, from deep review under 20 files to surgical review of critical paths above 200, and risk levels are triggered by what the change touches: auth, crypto, external calls, value transfer or removed validation are HIGH. A table of rationalizations to reject, such as "small PR, quick review", keeps the agent from cutting corners, and supporting files cover methodology, adversarial analysis, reporting and vulnerability patterns.

Use it when reviewing a PR for vulnerabilities, checking whether a change re-introduces a fixed bug, or finding modified code no test covers. It is a code-review skill, not a full-repository scanner.

It is mainly for coding agents such as Claude Code with access to the repository and its git history. BusinessMCP can import it as a playbook, but its value lies in local code review.

What you can do with it

  • Security-review a pull request that touches authentication
  • Check whether a diff re-introduces a previously fixed bug
  • Count callers to estimate the blast radius of a change
  • Find modified code that has no test coverage

Run it on your business data

Imported into BusinessMCP, Differential Review becomes a playbook your AI business analyst applies to your connected GitHub repositories.

Use Differential Review in BusinessMCP

Install it in a coding agent

One command adds Differential Review to your project.

npx skills add https://github.com/trailofbits/skills --skill differential-review

How we vetted it

Source
trailofbits/skills at 0cc1c73
Licence
CC-BY-SA-4.0
Security audits (skills.sh)
Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
Bundled scripts
None, instructions only

Checked 2026-09-25 against its skills.sh listing. How we vet skills

Frequently asked questions

How does Differential Review decide how deep to go?

It classifies by risk, not size, and scales strategy to codebase size: deep for under 20 files, focused for 20-200, and surgical on critical paths for 200 or more.

What does it produce?

A markdown report file with findings tied to specific line numbers and commits, concrete attack scenarios for high-risk changes, and stated coverage limits and confidence.

How do I install Differential Review?

Run `npx skills add trailofbits/skills --skill differential-review`, or import it from the BusinessMCP dashboard as a playbook.

Run Differential Review against your whole business

Free plan, no credit card.

Use Differential Review in BusinessMCP