When to choose it
Reviewing a commit, PR or saved diff against an identified baseline.
Choose it if: you need to review the security implications of an existing change.
Look elsewhere if: you want proof that a repository is secure or a workflow for a greenfield feature.
What the source describes
- Coordinates a change-focused review using surrounding code, history and test coverage.
- Provides a diff-review command and a namespaced adversarial review agent.
Requirements
- Claude Code with plugin support.
- Readable Git checkout with the target and baseline history.
- Remote PR access only when using a PR URL; local files can be reviewed without that integration.
A Skill distributed inside the differential-review plugin, together with a command and an agent. This listing documents the Skill’s distinct change-review workflow.
Install the plugin
- Review the containing plugin. The installation below supplies the Skill, diff-review command and adversarial-modeler agent. Review all three before enabling it.
- Prepare the comparison. Identify the target and baseline in a readable checkout; use a local diff when remote access is unnecessary.
- Activate the plugin. Check /plugin and follow its activation/reload instruction. Confirm the command appears in the picker.
Run the installation command in your shell after reviewing the source. Local scope enables the package for you in this repository. It does not enable it for every collaborator.
claude plugin marketplace add trailofbits/skills
claude plugin install differential-review@trailofbits --scope localHow to use it
Documented command shape. Replace the target and optional baseline; do not paste the angle-bracket placeholders unchanged.
/differential-review:diff-review <pr-url|commit-sha|diff-path> [--baseline <ref>]An original example for a bounded task. This request example is written by ClaudeStack; it is not a transcript of a tested session.
/differential-review:diff-review ./auth-changes.diff --baseline mainThe upstream content is CC-BY-SA-4.0. ClaudeStack provides original descriptions and examples, with author attribution and pinned source/license links; it does not redistribute the Skill text.
What to expect
The reviewed source describes these observations. ClaudeStack has not loaded or run this extension.
- A Markdown review with prioritized findings and source locations.
- History, affected code, testing gaps and review limitations where the source workflow can establish them.
Self-check: Confirm the report names the intended target and baseline. Reproduce suspected defects locally and have a qualified reviewer assess the findings.
Troubleshooting
There is no useful comparison
Supply a valid baseline, the surrounding checkout and enough history. A detached diff can leave the review incomplete.
The delegated agent is unavailable
Its documented name is differential-review:adversarial-modeler. Verify the containing plugin is active rather than using an unqualified name.
Disable or remove it
- Disable or uninstall differential-review from /plugin at the same installation scope.
- Reports and any reviewed or edited project files remain; assess them separately.
Limitations & considerations
- AI findings require human validation; a clean report is not a security guarantee.
- Missing history or surrounding code limits the review and impact analysis.
Source & review record
Our description is based on public documentation and manifests available on 2026-10-05. Installation formats were checked against Claude Code and the relevant installer documentation. No extension code was executed: this is a source review, not a runtime compatibility test or security audit.
- Original source and documentation
- Reviewed definition source
- License of the reviewed source
- Official plugin installation documentation
Repository last pushed at the time of review: 2026-10-02T10:05:35Z. This date does not prove that the extension works with a particular Claude Code release.
Usage guide sources
Upstream revision checked for this guide: 82fe8226252622fa807643bdca1710901198553a. Command names and behavior in this guide are documentation and registration-source findings, not runtime verification.