Performs security-focused differential review of code changes (PRs, commits, diffs)...
Security-focused code review for PRs, commits, and diffs.
| Rationalization | Why It's Wrong | Required Action |
|---|---|---|
| "Small PR, quick review" | Heartbleed was 2 lines | Classify by RISK, not size |
| "I know this codebase" | Familiarity breeds blind spots | Build explicit baseline context |
| "Git history takes too long" | History reveals regressions | Never skip Phase 1 |
| "Blast radius is obvious" | You'll miss transitive callers | Calculate quantitatively |
| "No tests = not my problem" | Missing tests = elevated risk rating | Flag in report, elevate severity |
| "Just a refactor, no security impact" | Refactors break invariants | Analyze as HIGH until proven LOW |
| "I'll explain verbally" | No artifact = findings lost | Always write report |
| Codebase Size | Strategy | Approach |
|---|---|---|
| SMALL (<20 files) | DEEP | Read all deps, full git blame |
| MEDIUM (20-200) | FOCUSED | 1-hop deps, priority files |
| LARGE (200+) | SURGICAL | Critical paths only |
| Risk Level | Triggers |
|---|---|
| HIGH | Auth, crypto, external calls, value transfer, validation removal |
| MEDIUM | Business logic, state changes, new public APIs |
| LOW | Comments, tests, UI, logging |
Pre-Analysis ā Phase 0: Triage ā Phase 1: Code Analysis ā Phase 2: Test Coverage
ā ā ā ā
Phase 3: Blast Radius ā Phase 4: Deep Context ā Phase 5: Adversarial ā Phase 6: Report
Starting a review?
āā Need detailed phase-by-phase methodology?
ā āā Read: methodology.md
ā (Pre-Analysis + Phases 0-4: triage, code analysis, test coverage, blast radius)
ā
āā Analyzing HIGH RISK change?
ā āā Read: adversarial.md
ā ā (Phase 5: Attacker modeling, exploit scenarios, exploitability rating)
ā āā Or delegate to: differential-review:adversarial-modeler agent
ā (Autonomous attacker modeling with concrete exploit scenarios)
ā
āā Writing the final report?
ā āā Read: reporting.md
ā (Phase 6: Report structure, templates, formatting guidelines)
ā
āā Looking for specific vulnerability patterns?
ā āā Read: patterns.md
ā (Regressions, reentrancy, access control, overflow, etc.)
ā
āā Quick triage only?
āā Use Quick Reference above, skip detailed docs
differential-review:adversarial-modeler ā Models attacker perspectives and
builds exploit scenarios for HIGH RISK code changes. Follows the 5-step
adversarial methodology (attacker model, attack vectors, exploitability rating,
exploit scenario, baseline cross-reference) and produces structured vulnerability
reports. Delegate to this agent when Phase 5 analysis is needed on high-risk
changes, passing that full namespaced name as subagent_type ā a bare
adversarial-modeler is unregistered and the dispatch fails at runtime.
Before delivering:
audit-context-building skill:
issue-writer skill:
issue-writer --input DIFFERENTIAL_REVIEW_REPORT.md --format audit-reportInput: 5 file PR, 2 HIGH RISK files
Strategy: Use Quick Reference
1. Classify risk level per file (2 HIGH, 3 LOW)
2. Focus on 2 HIGH files only
3. Git blame removed code
4. Generate minimal report
Time: ~30 minutes
Input: 80 files, 12 HIGH RISK changes
Strategy: FOCUSED (see methodology.md)
1. Full workflow on HIGH RISK files
2. Surface scan on MEDIUM
3. Skip LOW risk files
4. Complete report with all sections
Time: ~3-4 hours
Input: 450 files, auth system rewrite
Strategy: SURGICAL + audit-context-building
1. Baseline context with audit-context-building
2. Deep analysis on auth changes only
3. Blast radius analysis
4. Adversarial modeling
5. Comprehensive report
Time: ~6-8 hours
For these cases, use standard code review instead.
Immediate escalation triggers:
These patterns require adversarial analysis even in quick triage.
Do:
Don't:
For first-time users: Start with methodology.md to understand the complete workflow.
For experienced users: Use this page's Quick Reference and Decision Tree to navigate directly to needed content.