Diff Explainer — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Diff Explainer (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
AI-powered git diff analysis: human-readable explanations, risk flags, and review checklists.
Works as a CLI, Python library, and MCP server tool.
pip install -r requirements.txt
# Optional: set for LLM-powered summaries
export OPENAI_API_KEY="sk-..."Risk detection works without an API key. Only summaries and review checklists require the LLM.
# Pipe from git diff
git diff | python cli.py
# Read from file
python cli.py --file examples/sample.diff
# Auto-run git diff in current repo
python cli.py --git
# JSON output
python cli.py --file examples/sample.diff --format jsonfrom explainer import explain_diff
with open("changes.diff") as f:
diff_text = f.read()
result = explain_diff(diff_text)
print(result.summary)
print(result.risk_flags)
print(result.files_changed)Add to your opencode.json:
{
"mcpServers": {
"diff-explainer": {
"type": "stdio",
"command": "python",
"args": ["server.py"],
"cwd": "/path/to/diff-explainer"
}
}
}Available tools:
explain_diff_tool(diff_text) — Explain any diff textexplain_staged() — Explain currently staged git changesRun standalone: python server.py
# Diff Explanation
## Summary
This change reduces retry resilience in the auth service and introduces a hardcoded API key.
**Category:** config_change
## Files Changed
- `src/auth.py` — +3/-7 lines
- `src/config.py` — +5/-1 lines
## Risk Flags
- 🔴 **HIGH**: Removed error handling code
- 🔴 **HIGH**: Modified auth/permission checks
- 🔴 **HIGH**: Possible hardcoded secret
- 🟡 **MEDIUM**: Changed retry/timeout values
- 🟢 **LOW**: Added TODO/FIXME/HACK comment
## Review Checklist
- [ ] Is removing the try/except intentional? What handles AuthError now?
- [ ] Why were retries reduced from 3 to 1?
- [ ] The hardcoded API key should be moved to a secrets manager.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.