Agent skill

Open Code Review CLI

by alibaba in alibaba/open-code-review

Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

Apache-2.0Auto-check passedDevelopment

Install Open Code Review CLI

skills CLI
$ npx skills add alibaba/open-code-review --skill open-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alibaba/open-code-review open-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alibaba/open-code-review.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/open-code-review .claude/skills/open-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
open-code-review
GitHub stars
44k
Token cost
~3.1k tokens
SKILL.md length
1,432 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

  • Works in 4 steps: Gather Business Context → Run Code Review → Report → …
  • Reviewing staged and unstaged changes before committing
  • SKILL.md covers Workflow, Output Format, Custom Review Rules and Advanced Review Options, plus 4 more sections
  • Calls npm; reaches api.anthropic.com

What it does

The agent first gathers business context from the review target, whether commits, a branch or workspace changes, and passes it to ocr through the --background flag to improve the review. It then runs ocr review with the audience set to agent, without pre-checking that the CLI is installed, and installs it through npm only if the command is not found. By default it reviews staged, unstaged and untracked changes.

Flags cover a single commit, comparing two refs, a preview mode that lists the files that would be reviewed without calling the model, an output file, a per-group timeout multiplied by the number of review rounds, and a concurrency setting that can be lowered when rate limits hit. If an older install lacks the output flag, the agent asks you before upgrading instead of carrying on with plain output. With suitable review rules the tool can flag bugs, security vulnerabilities, performance problems and code quality issues, and it can apply fixes when you ask.

The ocr CLI must be installed, through npm or a GitHub release binary, and an LLM provider must be configured before the first run, using the Anthropic, OpenAI Chat Completions, OpenAI Responses or AWS Bedrock protocols.

When your agent uses it

  • Reviewing staged and unstaged changes before committing
  • Reviewing a single commit or a pull request branch
  • Comparing two branches for code quality issues
  • Applying suggested fixes from a review

Example prompts

  • “Review my uncommitted changes with ocr and give me line-level comments.”
  • “Review the last commit and apply the fixes for anything that looks like a bug.”
  • “Compare feature/export against main and report security and performance concerns.”

Requirements

  • The ocr CLI from @alibaba-group/open-code-review
  • A configured LLM provider such as Anthropic, OpenAI or AWS Bedrock
  • Node.js with npm, or the GitHub release binary
  • Compatibility (from SKILL.md): Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Requires a configured supported LLM provider before first run (protocols: Anthropic, OpenAI Chat Completions, OpenAI Responses, AWS Bedrock).

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gather Business Context
  2. Run Code Review
  3. Report
  4. Fix

What it can do on your machine

Read from SKILL.md and the folder at commit 182898c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.anthropic.com

    Also links to:

    • npmjs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Requires a configured supported LLM provider before first run (protocols: Anthropic, OpenAI Chat Completions, OpenAI Responses, AWS Bedrock).

    From compatibility in the SKILL.md frontmatter.

Context cost

Open Code Review CLI loads about 3.1k tokens when it runs. Until then it costs about 128 tokens; SKILL.md has 1,432 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~128
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alibaba/open-code-review at commit 182898c, republished under its Apache-2.0 licence (© alibaba). 1,432 words, ~3,145 tokens.

Download SKILL.mdSave it as .claude/skills/open-code-review/SKILL.md (or your agent's skills folder).
name
open-code-review
description
Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.
compatibility
Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Requires a configured supported LLM provider before first run (protocols: Anthropic, OpenAI Chat Completions, OpenAI Responses, AWS Bedrock).
license
Apache-2.0
metadata.author
alibaba
metadata.homepage
https://github.com/alibaba/open-code-review
metadata.version
1.0.0

Open Code Review

A skill for invoking open-code-review (ocr) — an open-source AI code review CLI that reads Git diffs and generates structured, line-level review comments.

Workflow

Step 1: Gather Business Context

Analyze the review target (commits, branch, or changes) to extract concise business context. Pass this context via --background to improve review quality.

Step 2: Run Code Review

Do not pre-check whether ocr is installed — skip probes like command -v ocr or ocr --version. Assume the CLI is available and run the review directly; that saves a tool call on the common path. Only if the review fails with command not found should you install it per Troubleshooting.

Run the OCR command with appropriate flags. Always pass business context via --background when available:

bash
ocr review --audience agent --background "business context here" [user-args]

Argument handling:

  • Background context (RECOMMENDED): use --background "context" or -b "context" to provide business context for better review quality
  • Default (no user arguments): reviews staged, unstaged, and untracked changes (workspace mode)
  • Specific commit: use --commit or -c to review a single commit against its parent
  • Branch comparison: use --from <ref> and --to <ref> to review diff between two refs
  • Timeout: effective timeout per review group = --timeout × review rounds. Default --timeout 15 with default effort medium (2 rounds) gives 30 minutes; low/high give 15/45 minutes.
  • Concurrency: default concurrency is 8 file workers; reduce with --concurrency <n> if rate limits are hit
  • Preview mode: use --preview or -p to preview which files will be reviewed without running the LLM
  • Output file: use --output <path> to write the full result to a file instead of stdout. If the command fails with unknown flag: --output, do not continue the review with plain stdout. Ask the user whether to upgrade (npm i -g @alibaba-group/open-code-review@latest) and wait for the answer before proceeding. After the user confirms and the upgrade succeeds, rerun with --output.
  • Installation: if ocr command is not found, install it by running npm i -g @alibaba-group/open-code-review

Common invocation patterns:

User saysCommand to run
"review my changes" / "review the working copy"ocr review --audience agent -b "context"
"review this PR" / "review feature branch"ocr review --audience agent -b "context" --from main --to <branch>
"review commit abc123"ocr review --audience agent -b "context" --commit abc123
"what would be reviewed?" (dry-run)ocr review --preview

Output mode:

  • Always use --audience agent to suppress progress UI and emit only the final summary
  • Prevent output truncation: For large reviews or restricted tool environments, pass --output /tmp/ocr_out.txt and inspect the file in full via a file reading tool instead of piping stdout through tail or head, which drops earlier review comments.

On failure: If ocr review exits non-zero (e.g. an LLM connection error), do not retry blindly — consult the Troubleshooting section below for the matching fix before re-running.

Step 3: Report

OCR output includes structured severity (critical / high / medium / low) and category (bug / security / performance / maintainability / test / style / documentation / other) on each comment. Present results grouped by severity, discarding low severity items that are likely false positives or nitpicks.

Step 4: Fix

Before applying fixes, check whether the user requested automatic fixes:

  • If the user explicitly requested "review and fix" or similar, proceed with automatic fixes
  • If the user only requested "review" without fix intent, ask for permission before applying any changes

When fixing issues and suggestions:

  • Focus on critical, high, and medium severity items
  • Apply fixes directly to the code when safe and well-defined
  • For complex fixes requiring manual intervention, clearly describe what needs to be done
  • Always verify fixes with the user before committing

Output Format

Each comment in OCR's output contains:

  • path: File path
  • content: Review comment text
  • start_line / end_line: Line range (both 0 means positioning failed)
  • category: Issue category (bug, security, performance, maintainability, test, style, documentation, other)
  • severity: Issue severity (critical, high, medium, low)
  • suggestion_code: Optional fix suggestion
  • existing_code: Optional original code snippet
  • thinking: Optional LLM reasoning process

Present results grouped by severity using this template:

markdown
## Code Review Results

**Files reviewed**: N
**Issues found**: X critical, Y high, Z medium

### Critical

- **`path/to/file.java:42`** [bug] — Brief description
  > Recommendation: How to fix

### High

- **`path/to/file.java:26`** [bug] — Brief description
  > Recommendation: How to fix

### Medium

- **`path/to/file.ts:88`** [performance] — Brief description
  > Recommendation: How to fix (if applicable)

If no critical, high, or medium severity issues remain after filtering, state: "Review complete — no critical, high, or medium issues found in N files."

Handling mispositioned comments:

When start_line and end_line are both 0, the comment failed to locate the exact position in the file. In such cases:

  1. Read the comment content to understand the issue
  2. Examine the target file mentioned in the comment
  3. Identify the relevant code section based on the comment's context
  4. Apply the fix or suggestion to the correct location

Custom Review Rules

If the user wants project-specific rules, OCR resolves them in this priority order:

  1. --rule <path> flag (highest)
  2. <repo>/.opencodereview/rule.json
  3. ~/.opencodereview/rule.json
  4. Built-in system defaults (lowest)

By default, the first matching user rule replaces the built-in system rule. Set merge_system_rule: true on a rule entry when the matched system rule and user rule should both be included.

Rule file format:

json
{
  "rules": [
    {
      "path": "**/*.java",
      "rule": "All new methods must validate required parameters for null",
      "merge_system_rule": true
    },
    {
      "path": "**/*mapper*.xml",
      "rule": "Check SQL for injection risks and missing closing tags"
    }
  ]
}

To preview which rule applies to a file before reviewing:

bash
ocr rules check src/main/java/com/example/Foo.java
Show full SKILL.md (628 more words)Show less

Advanced Review Options

Beyond the common flags above, ocr review exposes a few groups of controls. Run ocr review --help for the complete list.

Scoping

  • --exclude '<patterns>' — comma-separated gitignore-style patterns (for example --exclude '**/generated/*,**/testdata/*'), merged with rule.json excludes.
  • --background-file <path> — read review context from a Markdown file. Takes precedence over --background.

Output

  • --format text|json|sarif — text (default) for humans; json for machine-readable findings; sarif for code-scanning integrations such as GitHub Code Scanning.

Model

  • --provider <name> / --model <name> — override the configured provider/model for this run only (for example, to recheck a diff with a different model; the user names the model, ocr llm providers lists the built-ins).

Budget

  • --max-tokens <n> — per-group prompt ceiling; defaults to the configured value or the template default (200000).
  • --max-tokens-budget <n> — cap total input + output tokens for the run. Checked before every LLM round: a group already over budget gets one final round to submit findings, no further groups are dispatched, partial results are still published, and skipped files are reported as failed(budget).
  • --no-filter — keep all review comments and skip the LLM post-filtering call.

Gotchas

  • LLM must be configured first — ocr review will fail loudly if no LLM is reachable. See the Troubleshooting section below if this happens.
  • Working directory matters — ocr review operates on the Git repo at the current directory. Use --repo /path/to/repo to run from elsewhere.
  • Untracked files are reviewed in workspace mode — running bare ocr review includes staged, unstaged, and untracked changes. Stage selectively if you want narrower scope.
  • Large diffs may hit token limits — MAX_TOKENS sets the prompt budget (200000 in the review template; ocr scan uses 58888); conversation context is compressed to stay within this prompt budget. Model output is capped separately by MAX_COMPLETION_TOKENS (16384). A file whose diff alone exceeds ~80% of MAX_TOKENS is skipped before the LLM is called.
  • Plan phase triggers on either of two thresholds — a group runs an extra risk-analysis phase before main review when its largest changed file reaches PLAN_MODE_LINE_THRESHOLD (default 50) or it holds 2+ files whose combined changed lines reach PLAN_MODE_GROUP_LINE_THRESHOLD (default 100). This adds latency but improves quality.
  • Don't pass --audience human — it streams progress UI that pollutes output. Always use --audience agent.
  • Comment language follows config — the language config controls review comment language, defaults to English, and accepts any language name (for example English or 中文).
  • Avoid output truncation — Large review runs produce verbose output. Never pipe command output to tail or head as it drops review comments from earlier sections. Use --output <path> and read it in full; on older CLIs, follow the Output file guidance above.
  • Resume an interrupted review — a failed or interrupted range/commit review can be continued with ocr review --resume <id> using the same --from/--to or --commit target (the id is printed as retry with: --resume <id> on failure, or find it with ocr session list). Workspace resume is not supported.

Validation

After the review completes, verify success by checking:

  1. The command exited with code 0
  2. Comments were generated (or "No comments generated" message appears)
  3. Warnings (if any) are displayed in stderr

If errors occurred, check the stderr warnings for details about which files failed and why.

Troubleshooting

ocr: command not found

Install the CLI:

bash
npm install -g @alibaba-group/open-code-review

unknown flag: --output

The CLI is older than v1.10.0. Do not continue the review with plain stdout. Ask the user whether to upgrade (npm i -g @alibaba-group/open-code-review@latest) and wait for the answer before proceeding. After the user confirms and the upgrade succeeds, rerun with --output.

ocr review fails with LLM connection error

Prompt the user to configure an LLM provider.

Interactive setup (recommended):

bash
ocr config provider

Manual setup (alternative):

bash
ocr config set llm.url https://api.anthropic.com/v1/messages
ocr config set llm.auth_token <api-key>
ocr config set llm.model claude-opus-4-6
ocr config set llm.use_anthropic true

Verify connectivity with ocr llm test. Stop here and ask the user to provide credentials — never invent or hardcode API keys.

References

© alibaba, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/open-code-review of alibaba/open-code-review.

Open the folder on GitHubat commit 182898c

Compare with similar skills

Open Code Review CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Open Code Review CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Open Code Review CLI this skillalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Code Reviewyaklang/yakit7.8k—~1.4kAutomated safety check: NotesAGPL-3.0
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Knowledge Graph PR Reviewtirth8205/code-review-graph32k—~452Automated safety check: PassMIT

Similar skills

  • Code Review

    yaklang/yakit

    对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…

    7.8k GitHub stars~1.4k tokensUpdated 7 days ago
    DevelopmentAuto-check: notes
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Knowledge Graph PR Review

    tirth8205/code-review-graph

    Reviews a pull request or branch diff with a code knowledge graph and produces a structured review that includes blast-radius analysis.

    32k GitHub stars~452 tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.

    48k GitHub stars~995 tokensUpdated today
    DevelopmentAuto-check passed

More from alibaba/open-code-review

  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    44k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Open Code Review CLI

What does Open Code Review CLI do?

Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes. The agent first gathers business context from the review target, whether commits, a branch or workspace changes, and passes it to ocr through the --background flag to improve the review. It then runs ocr review with the audience set to agent, without pre-checking that the CLI is installed, and installs it through npm only if the command is not found.

When should I use Open Code Review CLI?

Open Code Review CLI fits situations like: reviewing staged and unstaged changes before committing; reviewing a single commit or a pull request branch; comparing two branches for code quality issues; applying suggested fixes from a review.

How do I install Open Code Review CLI in Claude Code?

Run `npx skills add alibaba/open-code-review --skill open-code-review -a claude-code`. Or copy the skill folder (skills/open-code-review in alibaba/open-code-review) into .claude/skills/open-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Open Code Review CLI in Codex?

Run `npx skills add alibaba/open-code-review --skill open-code-review -a codex`. Or copy the skill folder (skills/open-code-review in alibaba/open-code-review) into .agents/skills/open-code-review in your project. Codex loads it when a task matches its description.

Can I use Open Code Review CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alibaba/open-code-review --skill open-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/open-code-review, .gemini/skills/open-code-review, .github/skills/open-code-review and .opencode/skills/open-code-review in your project.

What does Open Code Review CLI need to run?

Going by SKILL.md and its folder, Open Code Review CLI needs the command-line tools its instructions call (npm). Our summary lists: The ocr CLI from @alibaba-group/open-code-review; A configured LLM provider such as Anthropic, OpenAI or AWS Bedrock; Node.js with npm, or the GitHub release binary. Compatibility (from SKILL.md): Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Requires a configured supported LLM provider before first run (protocols: Anthropic, OpenAI Chat Completions, OpenAI Responses, AWS Bedrock). .

Does Open Code Review CLI access the network?

SKILL.md names 2 domains. In commands or code: api.anthropic.com; the agent is likely to contact it when it follows the instructions. As links in the text: npmjs.com. This is read from the text; nothing was executed.

Is Open Code Review CLI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Open Code Review CLI use?

Open Code Review CLI is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Open Code Review CLI use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Open Code Review CLI?

Skills that share tags, products or a category with Open Code Review CLI: Code Review (yaklang/yakit, 7.8k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars), PR Review State Fetch (prisma/orm, 48k stars) and Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Open Code Review CLI?

alibaba (a GitHub organization) maintains it in alibaba/open-code-review, which has 44,069 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 5, 2026.

Source: alibaba/open-code-review on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.