IN PLAIN ENGLISH
What it does—and when it fits
Differential Review is Trail of Bits' risk-first security review for pull requests, commits, and diffs. It adapts depth to repository size, uses history and test coverage, estimates blast radius, and escalates high-risk changes into adversarial analysis.
This is aimed at Security reviewers assessing consequential code changes. Compare the examples below with your task, then review the limitations, permissions, and risks before installing.
- Triage changed filesClassify authentication, cryptography, external calls, and state changes by risk.
- Trace blast radiusUse callers, dependencies, history, and removed safeguards to identify downstream impact.
- Write evidence-backed findingsConnect each issue to lines, commits, tests, and concrete attack scenarios.
- Prioritizes risky behavior over diff size and cosmetic change volume.
- Makes coverage limits and confidence explicit in a durable report.
No verified review text is in the current dataset. Use the linked source for the latest discussion.
Read the source note ↗INSTALL BY AGENT
Choose your Agent
Paths come from official Agent docs or the universal installer behind skills.sh. Compatibility still follows this Skill's record.
npx skills add trailofbits/skills --skill differential-review --agent claude-codenpx skills add trailofbits/skills --skill differential-review --agent claude-code -gProject install stays with this repository for team sharing. Personal install adds -g and works across repositories.
View install paths
.claude/skills/differential-review/~/.claude/skills/differential-review/Claude Code discovers custom Skill folders automatically at project or personal scope.
View path evidence ↗TYPICAL WORKFLOW
A practical workflow
Triage changed files
Classify authentication, cryptography, external calls, and state changes by risk.
Trace blast radius
Use callers, dependencies, history, and removed safeguards to identify downstream impact.
Write evidence-backed findings
Connect each issue to lines, commits, tests, and concrete attack scenarios.
THE TRADEOFFS
Advantages and tradeoffs
Notable strengths
- Prioritizes risky behavior over diff size and cosmetic change volume.
- Makes coverage limits and confidence explicit in a durable report.
Limitations
- Not intended for greenfield code or broad initial vulnerability discovery.
- Large, high-risk changes can require hours of focused human review despite the workflow.
BEST FIT
Who it is for
Security reviewers assessing consequential code changes
Maintainers who need a traceable PR risk record
BEFORE YOU USE IT
Risks to review before use
False assurance from incomplete context
A diff review can miss unchanged vulnerable dependencies, runtime configuration, or callers outside the available repository. State scope and do not convert review coverage into a security guarantee.
SECURITY
What the permission profile means
- Treat repository history and issue links as potentially sensitive evidence.
- Require reproducible attack paths before escalating a speculative finding.
Not a security certification. External ratings are attributed references. SkillSignal has not independently executed or security-reviewed this Skill.
COMMON QUESTIONS
Differential Review Skill FAQ
What is the Differential Review Skill?
Risk-first security review for diffs, commits, and pull requests with blast-radius analysis. Differential Review is Trail of Bits' risk-first security review for pull requests, commits, and diffs. It adapts depth to repository size, uses history and test coverage, estimates blast radius, and escalates high-risk changes into adversarial analysis.
How do I install the Differential Review Skill?
Open and review the listed source, choose the project or personal path for your Agent, then verify the first run in a controlled project. Open the pinned commit and read the current SKILL.md.
Is the Differential Review Skill safe to use?
SkillSignal checked the source on 2026-09-23, but that is not a runtime test or security certification. Review the “False assurance from incomplete context” risk first and begin with the least access required.
INSIDE THE PACKAGE
Indexed files
TAGS
Original SkillSignal editorial profile grounded in Trail of Bits commit 32e34f81, checked 2026-09-23; not independently executed or security-certified.