Source profileQuality 76/100

dyoshikawa/rulesync/.rulesync/skills/security-scan-diff/SKILL.md

security-scan-diff

Scan for malicious code in git diff between a tag/commit and HEAD

Source repository stars
1,263
Declared platforms
0
Static risk flags
0
Last source update
2026-07-28
Source checked
2026-07-28

Decision brief

What it does—and where it fits

Thoroughly check for malicious code in the diff between ${targetref} and the latest commit (HEAD).

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/dyoshikawa/rulesync --skill ".rulesync/skills/security-scan-diff"
    Safe inspection promptEditorial

    Inspect the Agent Skill "security-scan-diff" from https://github.com/dyoshikawa/rulesync/blob/310b711fbe8cffc14debb276ade8a384c2b89083/.rulesync/skills/security-scan-diff/SKILL.md at commit 310b711fbe8cffc14debb276ade8a384c2b89083. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      Steps

      1. Verify the target ref exists and get the diff scope. - Run git log ${targetref}..HEAD --oneline to list commits. - Run git diff ${targetref}..HEAD --stat to get file change statistics. - Categorize changed files into: CI/CD workflows, source code, and config/docs.

      Verify the target ref exists and get the diff scope.Run git log ${targetref}..HEAD --oneline to list commits.Run git diff ${targetref}..HEAD --stat to get file change statistics.

    Permission review

    Static risk signals and limitations

    No configured static risk pattern was detected

    This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score76/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars1,263SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guidecatalog recordEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    dyoshikawa/rulesync
    Skill path
    .rulesync/skills/security-scan-diff/SKILL.md
    Commit
    310b711fbe8cffc14debb276ade8a384c2b89083
    License
    MIT
    Collected
    2026-07-28
    Default branch
    main
    View the original SKILL.md

    target_ref = $ARGUMENTS

    If target_ref is not provided, ask the user which tag or commit to compare against HEAD.

    Overview

    Thoroughly check for malicious code in the diff between ${target_ref} and the latest commit (HEAD).

    Steps

    1. Verify the target ref exists and get the diff scope.

      • Run git log ${target_ref}..HEAD --oneline to list commits.
      • Run git diff ${target_ref}..HEAD --stat to get file change statistics.
      • Categorize changed files into: CI/CD workflows, source code, and config/docs.
    2. Execute the following security reviews in parallel using subagents:

      • Call security-reviewer subagent to review CI/CD and workflow files (.github/, scripts/) for:

        • Secret exfiltration
        • Script injection (${{ github.event.* }} direct expansion in run:)
        • Suspicious external URLs/API connections
        • Privilege escalation or token misuse
        • Malicious command execution (curl | bash, eval, base64 decode execution)
        • Supply chain attack patterns (suspicious npm packages, unsigned action references)
        • Dangerous pull_request_target usage
      • Call security-reviewer subagent to review source code files (src/) for:

        • Arbitrary code execution (eval, Function constructor, suspicious child_process usage)
        • Path traversal (../.. directory escape)
        • Command injection (user input passed directly to shell commands)
        • Suspicious external communication (fetch, http.request, axios to external URLs)
        • Unauthorized filesystem operations
        • Credential/token leakage (hardcoded tokens, logging sensitive values)
        • Dependency tampering (suspicious package.json changes)
        • Backdoor patterns (obfuscated code, suspicious conditionals, hidden functionality)
        • Prototype pollution and deserialization vulnerabilities
        • Supply chain attacks (suspicious new dependency packages)
      • Call security-reviewer subagent to review config and documentation files for:

        • Suspicious dependencies or scripts in package.json
        • Suspicious registries or URLs in lockfiles
        • Security rule relaxation in config schemas or linter configs
        • Suspicious settings in devcontainer or editor configs
        • Phishing URLs in documentation
        • Malicious instructions in AI rule/subagent/skill definitions
    3. Integrate the results from all subagents and produce a unified report in the following format:

      ## Security Review Report: ${target_ref} -> HEAD
      
      ### Conclusion
      - Whether malicious code was detected or not
      
      ### Check Results Summary Table
      | Check Item | Result |
      |------------|--------|
      | ... | ... |
      
      ### Findings (if any)
      | Severity | Description | File | Risk |
      |----------|-------------|------|------|
      | ... | ... | ... | ... |
      
      ### Recommendations (if any)
      - Actionable recommendations for each finding
      
      ### Positive Observations
      - Good security practices found in the diff
      

    Alternatives

    Compare before choosing