diff-review

diff-review is a skill for Claude Code, Codex from fmind/dot. It costs 48 tokens per session (1,264 once invoked), scanned A, original, MIT.

A focused review workflow for examining the exact changes in a diff, patch, branch, or pull request. It checks whether the changed code matches its requirements and whether tests cover likely defects.

In plain words
What is it for?
Use it for pre-merge reviews, self-review, checking specification compliance, and tracing changed code through permissions, data rules, errors, concurrency, and compatibility.
Why use it?
It helps find correctness problems, missing tests, regressions, and risky behavior before a change is merged.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/fmind/dot/diff-review
Any agent
npx skills add fmind/dot --skill diff-review
Clone the repo
git clone --depth 1 https://github.com/fmind/dot

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for diff-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/fmind/dot/diff-review.svg)](https://agentmods.dev/skills/fmind/dot/diff-review)
Your own site
<a href="https://agentmods.dev/skills/fmind/dot/diff-review"><img src="https://agentmods.dev/badge/skills/fmind/dot/diff-review.svg" alt="Measured on agentmods" height="20"></a>
Per session 48 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,264 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00048 $0.01264
Opus 5 $0.00024 $0.00632
Sonnet 5 $0.00010 $0.00253
Haiku 4.5 $0.00005 $0.00126

Measured yesterday against content hash d978589b1e38, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

diff-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/diff-review/SKILL.md · 54 lines

How it starts

The opening of the file, as written. The whole thing — 54 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Diff Review

Find defects in one exact change that would justify altering it, with evidence the author can reproduce; repository-review owns whole-repository audits and plan-review owns plans.

Workflow

  1. Resolve the target: Read the request, issue, spec, and change description; record base, head, and whether the candidate is a dirty tree, local commit, or remote pull-request head. Preserve staged, unstaged, and untracked work.
  2. Inventory the delta: Inspect changed files, generated artifacts, dependency or schema changes, and the nearby code that holds the invariants; never review the diff in isolation.
  3. Read tests first: Determine what behavior the candidate claims, whether the tests can fail for that defect class, and which requirements stay unproved.
  4. Trace intended versus implemented: Map permissions, user journeys, data rules, failure semantics, and operational promises to concrete code paths and tests.
  5. Review by risk: Weigh correctness, data integrity, authorization, input boundaries, concurrency, resource lifecycle, error propagation, compatibility, migration, performance, observability, and rollback in proportion to the change.
  6. Classify scope: Compare every changed dependency, config, public API, generated artifact, and unrelated-looking hunk with the stated contract and its real call or build path.
    • Classify it as keep (necessary and connected), split (independently valuable or unrelated), or justify (real but non-obvious coupling).
    • Path names alone do not prove scope creep; never stage, revert, discard, or rewrite the candidate because a detector labels a path unrelated.
  7. Verify each finding: Reproduce it by code tracing, a focused test, or a safe temporary experiment, and quote the file and line that make it real.
  8. Run proportional checks: Start with focused tests and static analysis, and record which candidate each result covers.
  9. Gate when proportionate: Run the full gate (mise run all); if the tree carries unrelated changes and the gate write-formats, run it in a temporary git worktree or fall back to mise run check and mise run test (see mise).
  10. Calibrate: Discard preferences and speculation; rank what remains by user impact, exploitability, data loss, regression likelihood, and confidence. Do not manufacture findings to make the review look useful.
  11. Report: Lead with findings ordered by severity, or say there are none and list test and proof gaps; end with the target identity, checks run, and residual risks. Other review skills reuse this scale:
    • P0: immediate security breach, irreversible data loss, or broad outage risk.
    • P1: likely correctness, security, or availability defect that should block merge.
    • P2: material edge-case, maintainability, performance, or test defect worth fixing before or soon after merge.
    • P3: minor issue, reported only when the user asked for an exhaustive review.

Read the full file on GitHub · 54 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 54 lines · 48 tokens per session scan A d978589b1e38

Subscribe to this mod's changes

diff-review is a skill published in the GitHub repository fmind/dot (4 stars, last pushed today), licensed MIT. It adds 48 tokens to every session and 1,264 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.