# Review a security-sensitive diff — acceptance checklist

Record evidence for every checked item. Unchecked or untested is not a pass. This checklist does not execute an integration or authorise external actions.

## Required inputs

- [ ] A fixed base/head diff and the relevant authentication or data-flow contract.

- [ ] A clean review worktree, selected scanner rules and permission to inspect the source.

## Output checks

- [ ] Removed checks are examined with their history and callers.

- [ ] Scanner version, rules, mode and data-flow choices are recorded.

- [ ] Each confirmed finding has a controlled witness or a clearly labelled reasoning limit.

- [ ] No finding severity is presented as a measured probability.

## Deliverables

- [ ] Trust-boundary scope

- [ ] Baseline/head evidence map

- [ ] Scanner receipt

- [ ] Findings with exploit prerequisites and coverage limits

## Evidence and decision

Evidence links: [fill in]
Untested paths: [fill in]
Unresolved findings: [fill in]
Reviewer: [fill in]
Decision and scope: [fill in]

## Boundaries

- The differential-review plugin has required companion files and agent handoffs; a single SKILL.md is incomplete. Its caller counts are heuristics, not a complete call graph.

- Semgrep capabilities and data flows vary by mode and entitlement. A clean scan does not prove absence of vulnerabilities, and exploit checks must stay inside authorised fixtures.

Workflow: https://undominated.ai/workflows/#review-a-security-sensitive-diff
