Recipe catalog / diff-hazards
Flag hazards in a code diff
Which hazards does diff introduce: leaked secrets, destructive commands, debug leftovers, weakened tests, or dependency changes?
A coding agent or pre-commit hook needs a fast screen of a diff for the mistakes that reviewers most often catch late.
Explore this recipe interactively ยท Source and implementation guide
Use diff-hazards in TypeScript
Install with npm install jev-recipes. Requires Node.js 22.9 or newer and ES modules. Set TYPESAFE_API_KEY in your server environment for live calls, which send input to TypeSafe and use API quota. See the installation guide.
import { diffHazards } from 'jev-recipes/diff-hazards';
const result = await diffHazards({
"diff": "--- a/src/payments.ts\n+++ b/src/payments.ts\n@@ -1,6 +1,9 @@\n import { Stripe } from 'stripe';\n-const stripe = new Stripe(process.env.STRIPE_KEY);\n+const stripe = new Stripe('sk_prod_51Hq9zLKj3mD8vXyZ2pQ7rT4wN6bF0cE1gA5hJ8kL');\n+console.log('DEBUG charge payload', payload);\n export async function charge(payload) {\n return stripe.charges.create(payload);\n }",
"context": "Pre-commit screen for a payments service.",
"minConfidence": 0.8
});
console.log(result);
Input contract
| Field | Type | Needed |
|---|---|---|
| diff | string | Required |
| context | string | Optional |
| minConfidence | number | Optional |
Full input and result schemas
{
"input": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"diff": {
"type": "string"
},
"context": {
"type": "string"
},
"minConfidence": {
"type": "number",
"minimum": 0,
"maximum": 1
}
},
"required": [
"diff"
]
},
"result": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"model": {
"type": "string"
},
"usage": {
"type": "object",
"properties": {
"input_tokens": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
},
"output_tokens": {
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
}
},
"required": [
"input_tokens",
"output_tokens"
],
"additionalProperties": false
},
"status": {
"type": "string",
"enum": [
"ready",
"review"
]
},
"detected": {
"type": "array",
"items": {
"type": "string",
"enum": [
"secretLeak",
"destructiveCommand",
"debugLeftover",
"testsWeakened",
"dependencyChange"
]
}
},
"labels": {
"type": "object",
"properties": {
"secretLeak": {
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"ready",
"review"
]
},
"verdict": {
"type": "string",
"enum": [
"present",
"absent"
]
},
"probability": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"confidence": {
"type": "number",
"minimum": 0,
"maximum": 1
}
},
"required": [
"status",
"verdict",
"probability",
"confidence"
],
"additionalProperties": false
},
"destructiveCommand": {
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"ready",
"review"
]
},
"verdict": {
"type": "string",
"enum": [
"present",
"absent"
]
},
"probability": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"confidence": {
"type": "number",
"minimum": 0,
"maximum": 1
}
},
"required": [
"status",
"verdict",
"probability",
"confidence"
],
"additionalProperties": false
},
"debugLeftover": {
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"ready",
"review"
]
},
"verdict": {
"type": "string",
"enum": [
"present",
"absent"
]
},
"probability": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"confidence": {
"type": "number",
"minimum": 0,
"maximum": 1
}
},
"required": [
"status",
"verdict",
"probability",
"confidence"
],
"additionalProperties": false
},
"testsWeakened": {
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"ready",
"review"
]
},
"verdict": {
"type": "string",
"enum": [
"present",
"absent"
]
},
"probability": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"confidence": {
"type": "number",
"minimum": 0,
"maximum": 1
}
},
"required": [
"status",
"verdict",
"probability",
"confidence"
],
"additionalProperties": false
},
"dependencyChange": {
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"ready",
"review"
]
},
"verdict": {
"type": "string",
"enum": [
"present",
"absent"
]
},
"probability": {
"type": "number",
"minimum": 0,
"maximum": 1
},
"confidence": {
"type": "number",
"minimum": 0,
"maximum": 1
}
},
"required": [
"status",
"verdict",
"probability",
"confidence"
],
"additionalProperties": false
}
},
"required": [
"secretLeak",
"destructiveCommand",
"debugLeftover",
"testsWeakened",
"dependencyChange"
],
"additionalProperties": false
}
},
"required": [
"model",
"usage",
"status",
"detected",
"labels"
],
"additionalProperties": false
}
}Saved example result
This hand-authored response demonstrates the contract. It is not a model accuracy measurement. Run it without an API key: npx jev-recipes demo diff-hazards.
{
"model": "demo-fixture",
"usage": {
"input_tokens": 0,
"output_tokens": 0
},
"status": "ready",
"detected": [
"secretLeak",
"debugLeftover"
],
"labels": {
"secretLeak": {
"status": "ready",
"verdict": "present",
"probability": 0.97,
"confidence": 0.97
},
"destructiveCommand": {
"status": "ready",
"verdict": "absent",
"probability": 0.03,
"confidence": 0.97
},
"debugLeftover": {
"status": "ready",
"verdict": "present",
"probability": 0.93,
"confidence": 0.93
},
"testsWeakened": {
"status": "ready",
"verdict": "absent",
"probability": 0.04,
"confidence": 0.96
},
"dependencyChange": {
"status": "ready",
"verdict": "absent",
"probability": 0.05,
"confidence": 0.95
}
}
}
Evaluation evidence
No verified live accuracy measurement is available. Evaluate representative cases before using this decision in your workflow.
Use the evaluation guide to measure this decision on your own labeled cases.
Limitations
- Reads only the supplied diff text. It does not run the code, resolve imports, or see files outside the diff.
- A pattern that looks like a secret, such as an example key in documentation, may be flagged; treat detections as a prompt for review, not proof.
Related recipes
- change-risk: Use change-risk to grade the overall shipping risk of a described change rather than flag specific hazards in the diff text.
- commit-message-fit: Use commit-message-fit to check whether the commit message describes the change.
- breaking-change-signal: Use breaking-change-signal to check whether a change breaks callers.