validate_code_change
Check a code diff for security regressions and issues before merging. Scans for removed security controls, dangerous patterns, secrets, and AI defense problems, returning pass/fail results with findings.
Instructions
Validate a code diff for security regressions and issues before it lands.
Takes a unified diff and checks for:
Security control regressions (auth, CSRF, TLS, rate limiting removal)
New dangerous patterns (eval, exec, SQL injection, etc.)
Secrets in added code
AI defense issues in added code
Returns pass/fail with findings.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| diff | Yes | ||
| path | No | . | |
| policy | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |