# Security diff worksheet

Blank working document. Replace placeholders with your own evidence; an empty field is unknown, not a passing result.

Owner: [fill in]
Source revision: [fill in]
Environment: [fill in]
Evidence date: [fill in]

## Boundary

Base/head: ___
Assets and attacker-controlled inputs: ___
Paths included/excluded: ___
Review worktree: ___

## Removed protection

Changed guard and source line: ___
Original rationale/history: ___
Reachable caller: ___
Exploit prerequisites: ___

## Scanner evidence

Version/rules/mode: ___
Network or platform access: ___
Command, exit and report: not run
False-positive rationale: ___

## Finding disposition

Witness and expected impact: ___
Confirmed/unverified/dismissed: ___
Suggested repair and regression case: ___
Coverage gaps: ___

## Boundaries

- The differential-review plugin has required companion files and agent handoffs; a single SKILL.md is incomplete. Its caller counts are heuristics, not a complete call graph.

- Semgrep capabilities and data flows vary by mode and entitlement. A clean scan does not prove absence of vulnerabilities, and exploit checks must stay inside authorised fixtures.

Workflow: https://undominated.ai/workflows/#review-a-security-sensitive-diff

Original worksheet: MIT. Linked resources retain their own licences and setup requirements.
