# Diff Scope Guardian

> >-

- **Type:** Skill
- **Install:** `agentstack add skill-zaixincheng174-ai-codex-agent-governance-skills-diff-scope-guardian`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [zaixincheng174-ai](https://agentstack.voostack.com/s/zaixincheng174-ai)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [zaixincheng174-ai](https://github.com/zaixincheng174-ai)
- **Source:** https://github.com/zaixincheng174-ai/codex-agent-governance-skills/tree/main/core/skills/diff-scope-guardian
- **Website:** https://github.com/zaixincheng174-ai/codex-agent-governance-skills/blob/main/docs/demo-false-pass.md

## Install

```sh
agentstack add skill-zaixincheng174-ai-codex-agent-governance-skills-diff-scope-guardian
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# diff-scope-guardian —— 改完代码后的 diff 扩散审计

## 1. 触发条件

必须触发:
- `project-lifecycle` PHASE 2 Builder 宣称实现完成后,进入 PHASE 3 Review 之前。
- 非平凡代码改动完成后、最终回复或交付前。
- `git status` 或实际文件变更超出 preflight 的 Planned touch set 时。

不触发:
- 纯只读任务。
- 没有文件改动的问答/解释。
- 用户明确只要求展示某个命令输出且未修改文件。

## 2. 角色边界

只做:只读审计 diff 范围,产出《Diff Scope Report》。
不做:修改文件、替 Builder 修复、重新设计、把 advisory 发现直接当事实。

发现 blocker 时,结论是打回 Builder,不是在本 skill 内顺手改掉。

## 3. 审计输入

- 《目标契约》或用户请求的一句话目标。
- PHASE 1 设计文档/ADR,若本任务走了 lifecycle。
- `repo-preflight` 的 Planned touch set 和 Do-not-touch 边界,若已存在。
- 实际变更清单和 diff。

优先使用 `git status --short`, `git diff --stat`, `git diff --name-only`,
`git diff --check`, 以及针对变更文件的定向读取。非 git 现场要改用文件清单和读回核对,
并明确无法提供 git diff 证据。

## 4. 输出格式

```
Diff Scope Report
Intended scope: 
Actual changed files: 
Unexpected changes: 
Design deviations: 
Orthogonal changes: 
Diff hygiene: 
Validation evidence: 
Blockers: 
Warnings: 
Verdict:  hand off to Review/Verify / BLOCKED -> return to Builder>
```

## 5. 门禁

| 门禁项 | 严重度 | 检查 |
|---|---|---|
| DG0 NS/设计一致 | blocker | diff 是否仍服务目标契约和设计,无未声明偏离? |
| DG1 范围未扩散 | blocker | 变更文件是否都在 Planned touch set 或有明确理由? |
| DG2 无正交改动 | blocker | 是否没有顺手重构、格式化、重命名、清理无关代码? |
| DG3 变更可审 | blocker | 是否没有冲突标记、明显生成物误入、秘密/凭证模式? |
| DG4 验证对应 | warning | 已跑验证是否覆盖本次改动面?未跑必须显式报告。 |

任何 blocker 未解决时不得进入 PHASE 3 Review,也不得向用户宣称交付完成。

## 6. Advisory 纪律

- 静态扫描、审查建议、AI finding 都只是线索,必须用 diff、代码位置或可复现命令验证。
- 没有定位和证据的 finding 不得升级为 blocker。
- 发现真实问题时写清文件/位置/证据,不要用笼统质量判断替代审计。

## 7. 反例

- 不要把全仓格式化混在一个小 bug fix 里。
- 不要因为测试通过就忽略无关 diff。
- 不要在 guardian 阶段修改文件;应打回 Builder。

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [zaixincheng174-ai](https://github.com/zaixincheng174-ai)
- **Source:** [zaixincheng174-ai/codex-agent-governance-skills](https://github.com/zaixincheng174-ai/codex-agent-governance-skills)
- **License:** MIT
- **Homepage:** https://github.com/zaixincheng174-ai/codex-agent-governance-skills/blob/main/docs/demo-false-pass.md

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-zaixincheng174-ai-codex-agent-governance-skills-diff-scope-guardian
- Seller: https://agentstack.voostack.com/s/zaixincheng174-ai
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
