Open Code Review CLI
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
Give an AG2 beta Agent the ability to run shell commands. An agent skill from ag2ai/build-with-ag2.
$ npx skills add ag2ai/build-with-ag2 --skill ag2-shell-tool -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ag2ai/build-with-ag2 ag2-shell-tool --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ag2ai/build-with-ag2.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ag2-shell-tool .claude/skills/ag2-shell-tool && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ag2-shell-tool" agent skill from https://github.com/ag2ai/build-with-ag2/tree/main/.agents/skills/ag2-shell-tool into .claude/skills/ag2-shell-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ag2-shell-tool", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ag2ai/build-with-ag2/tree/main/.agents/skills/ag2-shell-toolType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ag2ai/build-with-ag2 --skill ag2-shell-tool -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ag2ai/build-with-ag2 ag2-shell-tool --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ag2ai/build-with-ag2.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/ag2-shell-tool .agents/skills/ag2-shell-tool && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ag2-shell-tool" agent skill from https://github.com/ag2ai/build-with-ag2/tree/main/.agents/skills/ag2-shell-tool into .agents/skills/ag2-shell-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ag2-shell-tool", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ag2ai/build-with-ag2 --skill ag2-shell-tool -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ag2ai/build-with-ag2 ag2-shell-tool --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ag2ai/build-with-ag2.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/ag2-shell-tool .cursor/skills/ag2-shell-tool && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ag2-shell-tool" agent skill from https://github.com/ag2ai/build-with-ag2/tree/main/.agents/skills/ag2-shell-tool into .cursor/skills/ag2-shell-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ag2-shell-tool", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ag2ai/build-with-ag2.git --path .agents/skills/ag2-shell-tool--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ag2ai/build-with-ag2 --skill ag2-shell-tool -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ag2ai/build-with-ag2 ag2-shell-tool --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ag2ai/build-with-ag2.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/ag2-shell-tool .gemini/skills/ag2-shell-tool && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ag2-shell-tool" agent skill from https://github.com/ag2ai/build-with-ag2/tree/main/.agents/skills/ag2-shell-tool into .gemini/skills/ag2-shell-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ag2-shell-tool", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ag2ai/build-with-ag2 ag2-shell-toolInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ag2ai/build-with-ag2 --skill ag2-shell-tool -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ag2ai/build-with-ag2.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/ag2-shell-tool .github/skills/ag2-shell-tool && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ag2-shell-tool" agent skill from https://github.com/ag2ai/build-with-ag2/tree/main/.agents/skills/ag2-shell-tool into .github/skills/ag2-shell-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ag2-shell-tool", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ag2ai/build-with-ag2 --skill ag2-shell-tool -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ag2ai/build-with-ag2 ag2-shell-tool --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ag2ai/build-with-ag2.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/ag2-shell-tool .opencode/skills/ag2-shell-tool && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ag2-shell-tool" agent skill from https://github.com/ag2ai/build-with-ag2/tree/main/.agents/skills/ag2-shell-tool into .opencode/skills/ag2-shell-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ag2-shell-tool", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ag2-shell-toolGive an AG2 beta Agent the ability to run shell commands. An agent skill from ag2ai/build-with-ag2.
Ag2 Shell Tool is an agent skill from ag2ai/build-with-ag2. Give an AG2 beta Agent the ability to run shell commands. Covers LocalShellTool (client-side subprocess, works with any provider) and the provider-native ShellTool (Anthropic / OpenAI execution). Use when the user wants the Agent to execute commands, build/test code, manage files, or operate on a workspace. Always pair with sandboxing — allowed, blocked, ignore, or readonly.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with OpenAI and Git. The repository describes itself as: Sample code and application showcases to get you going with AG2 (formally AutoGen). The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 29eeac3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ag2 Shell Tool loads about 2k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 628 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ignore=["**/.env", "*.key", "secrets/**"],Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ag2ai/build-with-ag2 at commit 29eeac3, republished under its Apache-2.0 licence (© ag2ai). 628 words, ~2,017 tokens.
.claude/skills/ag2-shell-tool/SKILL.md (or your agent's skills folder).Two distinct tools, both named "shell" — pick deliberately:
| Need | Use | Why |
|---|---|---|
| Works with any model provider; full control over what runs and where | LocalShellTool | Client-side subprocess. You own the sandbox. |
| Provider-managed sandbox (container, network policy) on Anthropic / OpenAI | ShellTool | Server-side execution. No local subprocess. |
LocalShellTool is the workhorse. Reach for it unless you specifically need provider-managed isolation and you're on Anthropic or OpenAI.
LocalShellToolfrom autogen.beta import Agent
from autogen.beta.config import AnthropicConfig
from autogen.beta.tools import LocalShellTool
agent = Agent(
"coder",
"You write and run Python code.",
config=AnthropicConfig(model="claude-sonnet-4-6"),
tools=[LocalShellTool()],
)
reply = await agent.ask("Write a hello world script and run it.")
print(await reply.content())LocalShellTool is provider-agnostic — swap AnthropicConfig for OpenAIConfig(model="gpt-4.1"), GeminiConfig(model="gemini-2.5-pro"), etc. Make sure you've installed the matching ag2[<provider>] extra and set the matching env var (see ag2-quickstart → Prerequisites).
With no arguments, LocalShellTool creates a temporary working directory (prefixed ag2_shell_) and cleans it up when the process exits. Pass a path to use a specific directory:
from pathlib import Path
LocalShellTool("/tmp/my_project")
LocalShellTool(Path("/tmp/my_project"))When a path is given, the directory is created if it does not exist and is not deleted on exit. Inspect the resolved working directory via tool.workdir.
LocalShellEnvironment)For anything beyond a throwaway demo, use LocalShellEnvironment and lock down what the agent can do. Filtering is applied in this order on every call:
allowed — if set, the command must match at least one prefix.blocked — if set, the command must not match any prefix.ignore — literal path tokens in the command are checked against gitignore-style patterns; matches return "Access denied: <path>".subprocess.run.from autogen.beta.tools import LocalShellTool
from autogen.beta.tools.shell import LocalShellEnvironment
sh = LocalShellTool(
LocalShellEnvironment(
path="/tmp/my_project",
allowed=["python", "uv run", "git"],
blocked=["rm -rf", "curl", "wget"],
ignore=["**/.env", "*.key", "secrets/**"],
timeout=30,
max_output=50_000,
)
)For inspection-only access (cat, head, tail, ls, grep, find, git log, git diff, git status, …):
from autogen.beta.tools import LocalShellTool
from autogen.beta.tools.shell import LocalShellEnvironment
sh = LocalShellTool(LocalShellEnvironment(path="/my/codebase", readonly=True))Pass an explicit allowed=[...] to override the built-in read-only allowlist.
LocalShellEnvironment parameter reference| Parameter | Default | Description |
|---|---|---|
path | None | Working dir. None → temp dir, deleted on exit |
cleanup | None | None → auto (True when path=None, False otherwise). Deletes path on process exit |
allowed | None | Whitelist of command prefixes. None → all commands allowed |
blocked | None | Blacklist of command prefixes |
ignore | None | Gitignore-style path patterns; matches block the command |
readonly | False | When True and allowed unset, restricts to a built-in read-only list |
env | None | Extra env vars merged into each command |
timeout | 60 | Per-command timeout in seconds (returns "Command timed out after Ns [exit code: 124]") |
max_output | 100_000 | Max characters returned (truncated output is suffixed [truncated: …]) |
Files persist in workdir across ask() calls, so the agent can build on prior work:
from autogen.beta.tools import LocalShellTool
from autogen.beta.tools.shell import LocalShellEnvironment
sh = LocalShellTool(LocalShellEnvironment(path="/tmp/counter_demo"))
agent = Agent("coder", "You manage files.", config=config, tools=[sh])
reply1 = await agent.ask("Create counter.txt with value 0")
reply2 = await reply1.ask("Increment the counter by 1")
reply3 = await reply2.ask("Read the counter and tell me the value")ShellTool (Anthropic / OpenAI)from autogen.beta.tools import ShellTool
agent = Agent("devops", config=AnthropicConfig(model="claude-sonnet-4-6"), tools=[ShellTool()])OpenAI lets you configure the execution environment:
from autogen.beta.config import OpenAIResponsesConfig
from autogen.beta.tools import ShellTool
from autogen.beta.tools.builtin.shell import ContainerAutoEnvironment, NetworkPolicy
agent = Agent(
"devops",
config=OpenAIResponsesConfig(model="gpt-4.1"),
tools=[
ShellTool(
environment=ContainerAutoEnvironment(
network_policy=NetworkPolicy(allowed_domains=["pypi.org"]),
),
),
],
)Environment options:
| Environment | Description |
|---|---|
ContainerAutoEnvironment | Provider-managed container with optional network policy |
ContainerReferenceEnvironment | Reference an existing container by ID |
ShellTool is not supported on Gemini — the request will raise UnsupportedToolError.
LocalShellTool vs ShellToolLocalShellTool | ShellTool | |
|---|---|---|
| Execution | Client-side subprocess | Provider-side container |
| Provider support | Any provider | Anthropic, OpenAI |
| Environment control | Full (allowed, blocked, ignore, readonly, …) | Limited (provider-dependent) |
| Local FS access | Yes (you choose what's exposed) | No |
| Network control | Via blocked / allowed patterns | OpenAI: NetworkPolicy |
| Import | from autogen.beta.tools import LocalShellTool (env: from autogen.beta.tools.shell import LocalShellEnvironment) | from autogen.beta.tools import ShellTool |
website/docs/beta/tools/local_shell.mdx — full LocalShellTool reference, command-filtering semantics.website/docs/beta/tools/builtin_tools.mdx#shell — provider-native ShellTool setup and environment configs.approval_required() middleware (see ag2-hitl).LocalShellTool() with no environment runs anything anywhere with a 60s timeout. Set allowed, blocked, or readonly for any non-trivial use.ignore only checks literal paths in the command string — variable substitution, command substitution (`cat secrets.key`), and dynamic glob expansion are not inspected. Layer in blocked=["cat", "less"] if you also want to block readers.ShellTool on Gemini — unsupported, will raise. Use LocalShellTool instead./tmp/my_project will race. Use tempfile.mkdtemp(prefix="...") for parallel runs.ShellTool to access local files — it doesn't; it runs in the provider's container. Use LocalShellTool for anything on your filesystem.prompts that scope what's allowed and consider pairing with approval_required() for destructive operations.© ag2ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/ag2-shell-tool of ag2ai/build-with-ag2.
Open the folder on GitHubat commit 29eeac3
Ag2 Shell Tool next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ag2 Shell Tool this skillag2ai/build-with-ag2 | 252 | — | ~2k | Automated safety check: Notes | Apache-2.0 | |
| Open Code Review CLIalibaba/open-code-review | 44k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Codexskills-directory/skill-codex | 1.5k | 3 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Changeset Validationopenai/openai-agents-js | 3.9k | — | ~607 | Automated safety check: Pass | MIT | |
| Openai Security Ownership Maptrailofbits/skills-curated | 512 | 5 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Pulse Releasequnqin24/Pulse | 516 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 |
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
skills-directory/skill-codex
A skill your agent uses when the user asks to run Codex CLI (codex exec, codex resume) or references OpenAI Codex for code analysis, refactoring, or automated editing
openai/openai-agents-js
Validate changesets in openai-agents-js using LLM judgment against git diffs (including uncommitted local changes).
trailofbits/skills-curated
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.
qunqin24/Pulse
Release a new Pulse version end to end — checks, bilingual CHANGELOG entry, VERSION, tag, the release workflow, syncing main, and the issue replies that go with it.
alchemiststudiosDOTai/tunacode
This skill should be used when releasing tunacode-cli to PyPI.
ag2ai/build-with-ag2
Add a custom Python tool to an AG2 beta Agent using the @tool decorator.
ag2ai/build-with-ag2
Intercept the AG2 beta agent loop with BaseMiddleware — wrap full turns (onturn), each LLM call (onllmcall), each tool execution (ontoolexecution), or each human-input request (onhumaninput).
ag2ai/build-with-ag2
Wire AG2 beta's shipped tools into an Agent — both provider-native server-side tools (web search, web fetch, code execution, MCP, image generation, memory) and locally-executed common toolkits…
ag2ai/build-with-ag2
Persist agent state across runs, shape what the LLM sees per turn, and cap history to fit a context window.
ag2ai/build-with-ag2
Monitor an AG2 beta agent's stream — log events, detect repeated tool calls, track token spend, build trigger-driven observers, route observer alerts to the model, and halt on FATAL conditions.
ag2ai/build-with-ag2
Build a minimal AG2 beta Agent end to end — pick a model provider, set a prompt, call agent.ask(), then continue the conversation with reply.ask() (multi-turn).
Categories
Give an AG2 beta Agent the ability to run shell commands. An agent skill from ag2ai/build-with-ag2. Ag2 Shell Tool is an agent skill from ag2ai/build-with-ag2. Give an AG2 beta Agent the ability to run shell commands.
Ag2 Shell Tool fits situations like: the user wants the Agent to execute commands; build/test code; operate on a workspace.
Run `npx skills add ag2ai/build-with-ag2 --skill ag2-shell-tool -a claude-code`. Or copy the skill folder (.agents/skills/ag2-shell-tool in ag2ai/build-with-ag2) into .claude/skills/ag2-shell-tool in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ag2ai/build-with-ag2 --skill ag2-shell-tool -a codex`. Or copy the skill folder (.agents/skills/ag2-shell-tool in ag2ai/build-with-ag2) into .agents/skills/ag2-shell-tool in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ag2ai/build-with-ag2 --skill ag2-shell-tool -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ag2-shell-tool, .gemini/skills/ag2-shell-tool, .github/skills/ag2-shell-tool and .opencode/skills/ag2-shell-tool in your project.
Going by SKILL.md and its folder, Ag2 Shell Tool needs the command-line tools its instructions call (git). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Ag2 Shell Tool is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ag2 Shell Tool: Open Code Review CLI (alibaba/open-code-review, 44k stars), Codex (skills-directory/skill-codex, 1.5k stars), Changeset Validation (openai/openai-agents-js, 3.9k stars) and Openai Security Ownership Map (trailofbits/skills-curated, 512 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ag2ai (a GitHub organization) maintains it in ag2ai/build-with-ag2, which has 252 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on September 6, 2026.
Source: ag2ai/build-with-ag2 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.