security-scan-diff

A security review for the changes between a chosen Git tag or commit and the current code. It checks changed workflows, source files, configuration, and documentation for signs of malicious code.

In plain words
What is it for?
Use it before merging or releasing changes to review the commit history and file differences for security risks.
Why use it?
It helps spot attacks hidden in recent changes, such as stolen secrets, unsafe commands, suspicious downloads, or misuse of build-system permissions.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/dyoshikawa/rulesync/security-scan-diff
Any agent
npx skills add dyoshikawa/rulesync --skill security-scan-diff
Clone the repo
git clone --depth 1 https://github.com/dyoshikawa/rulesync

Made for: Claude Code, Codex.

Per session 20 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 682 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 3 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00020 $0.00682
Opus 5 $0.00010 $0.00341
Sonnet 5 $0.00004 $0.00136
Haiku 4.5 $0.00002 $0.00068

Measured 2d ago against content hash 237e8e247ad2, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

security-scan-diff scanned grade B with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Downloads and executes remote codemediumSupply chain

curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.

- Malicious command execution (`curl | bash`, `eval`, base64 decode execution)

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- Malicious command execution (`curl | bash`, `eval`, base64 decode execution)

Runs shell commandslowCapability

Expected in a hook, worth knowing in a rule or an instructions file.

- Arbitrary code execution (`eval`, `Function` constructor, suspicious `child_process` usage)
.rulesync/skills/security-scan-diff/SKILL.md · 77 lines

How it starts

The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.

target_ref = $ARGUMENTS

If target_ref is not provided, ask the user which tag or commit to compare against HEAD.

Overview

Thoroughly check for malicious code in the diff between ${target_ref} and the latest commit (HEAD).

Steps

  1. Verify the target ref exists and get the diff scope.

    • Run git log ${target_ref}..HEAD --oneline to list commits.
    • Run git diff ${target_ref}..HEAD --stat to get file change statistics.
    • Categorize changed files into: CI/CD workflows, source code, and config/docs.
  2. Execute the following security reviews in parallel using subagents:

    • Call security-reviewer subagent to review CI/CD and workflow files (.github/, scripts/) for:

      • Secret exfiltration
      • Script injection (${{ github.event.* }} direct expansion in run:)
      • Suspicious external URLs/API connections
      • Privilege escalation or token misuse
      • Malicious command execution (curl | bash, eval, base64 decode execution)
      • Supply chain attack patterns (suspicious npm packages, unsigned action references)
      • Dangerous pull_request_target usage
    • Call security-reviewer subagent to review source code files (src/) for:

      • Arbitrary code execution (eval, Function constructor, suspicious child_process usage)
      • Path traversal (../.. directory escape)
      • Command injection (user input passed directly to shell commands)
      • Suspicious external communication (fetch, http.request, axios to external URLs)
      • Unauthorized filesystem operations
      • Credential/token leakage (hardcoded tokens, logging sensitive values)
      • Dependency tampering (suspicious package.json changes)
      • Backdoor patterns (obfuscated code, suspicious conditionals, hidden functionality)
      • Prototype pollution and deserialization vulnerabilities
      • Supply chain attacks (suspicious new dependency packages)
    • Call security-reviewer subagent to review config and documentation files for:

      • Suspicious dependencies or scripts in package.json
      • Suspicious registries or URLs in lockfiles
      • Security rule relaxation in config schemas or linter configs
      • Suspicious settings in devcontainer or editor configs
      • Phishing URLs in documentation
      • Malicious instructions in AI rule/subagent/skill definitions

Read the full file on GitHub · 77 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 77 lines · 20 tokens per session scan B 237e8e247ad2

Subscribe to this mod's changes

security-scan-diff is a skill published in the GitHub repository dyoshikawa/rulesync (1,362 stars, last pushed 2d ago), licensed MIT. It adds 20 tokens to every session and 682 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 3 findings (downloads and executes remote code, makes network calls, runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

deep-clean

Full-spectrum consolidation of AI agent configuration files. Goes beyond memory-only dream skills: audits and optimizes context files (AGENTS.md/AGENTS.md/GEMINI.md/.cursorrules), rules, skills, and memory. Detects stale references, dead file paths, duplicated rules, stack mismatches, contradictions, vague directives…

opencue/cuecards · 87 tokens

turborepo

Turborepo monorepo build system guidance. Triggers on: turbo.json, task pipelines, dependsOn, caching, remote cache, the "turbo" CLI, --filter, --affected, CI optimization, environment variables, internal packages, monorepo structure/best practices, and boundaries. Use when user: configures tasks/workflows/pipelines…

Bosh-Kuo/awesome-agent-toolkit · 111 tokens

skill-creator-openai

Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Codex's capabilities with specialized knowledge, workflows, or tool integrations.

Bosh-Kuo/awesome-agent-toolkit · 48 tokens

shadcn

Manages shadcn components and projects — adding, searching, fixing, debugging, styling, and composing UI. Provides project context, component docs, and usage examples. Applies when working with shadcn/ui, component registries, presets, --preset codes, or any project with a components.json file. Also triggers for…

Bosh-Kuo/awesome-agent-toolkit · 90 tokens

skill-creator-anthropic

Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Claude's capabilities with specialized knowledge, workflows, or tool integrations.

Bosh-Kuo/awesome-agent-toolkit · 48 tokens

impeccable

Use when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a frontend interface. Covers websites, landing pages, dashboards, product UI, app shells, components, forms, settings, onboarding, and empty states.…

Bosh-Kuo/awesome-agent-toolkit · 189 tokens