Read every diff

Reading · 6 min · Module 4, lesson 1 of 319 min left in this module

Module 4 · Read every diffLesson 1 of 3

Goal: Read an agent's diff against its brief with a short checklist, and undo a change at any stage.

Key idea

Tests check what you thought of. The diff shows what actually changed, including what nobody thought of. Read every line before it's merged: once it ships, it's your code, whoever typed it.

Where to see it

  • Before you commit: git diff shows your uncommitted changes.
  • On a branch: git diff main shows everything the branch changes.
  • In a pull request: the Files changed tab on GitHub, one file at a time.

Lines starting with + were added, lines with - removed. The rest is context, so you can see where the change sits.

What to look for

Go through a diff with the same questions every time, in this order:

  1. Scope. Do the changed files match the brief? A diff to one endpoint that also edits config, CI or unrelated files needs an explanation.
  2. Dependencies. Did package.json or the lockfile change? Look up every new package yourself before accepting it (lesson 4.1.2).
  3. Input. Find everything that comes from a request: body, headers, query, URL. Is it checked? Where does it end up: a page, a database query, a file, a shell command?
  4. Who may do this. For every new or changed endpoint: does it check which user is asking, and whether they're allowed?
  5. Secrets. Any key, token or password typed into the code?
  6. Weakened checks. Deleted or skipped tests, loosened validation, errors caught and ignored. Agents sometimes make a failure go away instead of fixing it.
  7. The criteria. For each acceptance criterion, point to the lines that do it and the test that proves it.

If a part doesn't make sense, ask the agent to explain it. Then check the explanation against the code: an explanation is a claim too.

Undo at any stage

git restore server.js

Discards the uncommitted changes to one file; git restore . does the whole project.

A revert undoes code, not everything the code did. Anything it deleted, sent or charged while it was live stays done, which is why the reading happens before the merge.

Check yourself

An agent's diff for a new endpoint also changes the test file, marking one existing test as skipped. What do you do?
A bad change was merged to main an hour ago. How do you undo it without rewriting history?