Agent skill

Open Code Review Delegate

by alibaba in alibaba/open-code-review

Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

Apache-2.0Auto-check passedDevelopment

Install Open Code Review Delegate

skills CLI
$ npx skills add alibaba/open-code-review --skill open-code-review-delegate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alibaba/open-code-review open-code-review-delegate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alibaba/open-code-review.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/open-code-review-delegate .claude/skills/open-code-review-delegate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
open-code-review-delegate
GitHub stars
44k
Token cost
~2k tokens
SKILL.md length
927 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

  • Works in 7 steps: Preview — Determine What to Review → Get Rules for Files → Get Diffs → …
  • Reviewing uncommitted workspace changes with the agent's own model
  • SKILL.md covers Workflow, Sub-commands Reference, Shared Flags and Gotchas
  • Calls git and npm

What it does

In delegation mode the `ocr` CLI does only deterministic work and the agent supplies the intelligence, so no LLM endpoint needs to be configured on the OCR side. A preview command reports what is under review, which can be the workspace changes, a range between two refs or one commit, with ref metadata, the reviewable files and their insertions and deletions, and the excluded files with reasons. A rule command then takes those paths and returns the review rules, grouped so that files sharing a rule appear once.

The agent gets each diff straight from git, using the merge base for ranges, `git show` for commits, and `git diff HEAD` plus a direct read for new untracked files in the workspace. It keeps a checklist keyed by path and status, reviews every file against its rule group, and marks each one reviewed or skipped with a concrete reason. Large changes are reviewed in bounded batches grouped by rules and diff size, and the agent does not stop at the first high-severity issue. Comments follow a fixed structure that includes the file path and a description of the issue.

When your agent uses it

  • Reviewing uncommitted workspace changes with the agent's own model
  • Reviewing a branch against main using the project's review rules
  • Reviewing a single commit

Example prompts

  • “Review my uncommitted changes using the open-code-review delegate flow.”
  • “Review the diff between main and my feature branch with the ocr rules.”
  • “Do a code review of commit abc123 and list the problems per file.”

Requirements

  • The `ocr` CLI, from the npm package `@alibaba-group/open-code-review` or a release binary
  • Git
  • Compatibility (from SKILL.md): Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Does NOT require a configured LLM endpoint — delegation mode is LLM-free on the OCR side.

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Preview — Determine What to Review
  2. Get Rules for Files
  3. Get Diffs
  4. Review Each File
  5. Format Output
  6. Classify and Report
  7. Fix (Optional)

What it can do on your machine

Read from SKILL.md and the folder at commit 182898c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Does NOT require a configured LLM endpoint — delegation mode is LLM-free on the OCR side.

    From compatibility in the SKILL.md frontmatter.

Context cost

Open Code Review Delegate loads about 2k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 927 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alibaba/open-code-review at commit 182898c, republished under its Apache-2.0 licence (© alibaba). 927 words, ~1,983 tokens.

Download SKILL.mdSave it as .claude/skills/open-code-review-delegate/SKILL.md (or your agent's skills folder).
name
open-code-review-delegate
description
Delegation mode for open-code-review (OCR). Instead of OCR calling an LLM endpoint, this skill instructs the host agent to perform the code review itself, using OCR only for deterministic engineering: file selection and rule resolution. Use when the host agent should drive the review with its own LLM capabilities.
compatibility
Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Does NOT require a configured LLM endpoint — delegation mode is LLM-free on the OCR side.
license
Apache-2.0
metadata.author
alibaba
metadata.homepage
https://github.com/alibaba/open-code-review
metadata.version
1.0.0

Open Code Review — Delegation Mode

A skill for performing AI code review where OCR provides deterministic engineering (file filtering, rule resolution) and the host agent performs the actual review using its own intelligence and tools.

Workflow

Step 1: Preview — Determine What to Review
bash
ocr delegate preview --format json [--from <ref> --to <ref>] [--commit <hash>] [--exclude <patterns>]

This outputs:

  • mode (workspace / range / commit)
  • from / to / commit / merge_base — ref metadata for constructing git commands
  • Reviewable file list — paths, status, insertions/deletions
  • Excluded files — with exclusion reason

Common invocations:

ScenarioCommand
Workspace changesocr delegate preview
Branch comparisonocr delegate preview --from main --to feature
Single commitocr delegate preview -c abc123
Step 2: Get Rules for Files
bash
ocr delegate rule --format json <path1> <path2> ...

Pass the reviewable file paths from Step 1. Output is grouped by rule content — files sharing the same rule appear under one group, avoiding repetition.

Step 3: Get Diffs

Use git directly based on the mode/ref info from Step 1:

Range mode (merge_base provided in preview output):

bash
git diff <merge_base>..<to> -- <path>

Commit mode:

bash
git show <commit> -- <path>

Workspace mode:

bash
# Tracked files
git diff HEAD -- <path>
# New untracked files — read directly (entire file is new code)
cat <path>
Step 4: Review Each File

Create a checklist containing every reviewable_files entry. For each reviewable file:

Use (path, status) as the checklist identity. Workspace mode can report the same path twice when a staged deletion is followed by an untracked recreation.

  1. Get its diff (Step 3)
  2. Consult its Rule Group (from Step 2) for the review checklist
  3. Conduct a thorough review, using appropriate context tools as needed
  4. Mark the file reviewed, or skipped with a concrete reason

For large changes, review in bounded batches grouped by shared rules and diff size. Do not stop after finding the first high-severity issue.

Step 5: Format Output

Each comment must follow this structure:

FieldTypeRequiredDescription
pathstringyesRelative file path
contentstringyesReview comment describing the issue
start_lineintegernoStart line in the new file
end_lineintegernoEnd line in the new file
categoryenumnobug, security, performance, maintainability, test, style, documentation, other
severityenumnocritical, high, medium, low
Step 6: Classify and Report

Before reporting, verify that every previewed file is accounted for. Include total_files, reviewed_files, skipped_files, and coverage_rate in the summary. A skipped file must include its reason.

Group findings by severity:

  • Critical/High: Bugs, security issues, data loss risks — always report
  • Medium: Performance concerns, error handling gaps, maintainability issues — report with context
  • Low: Style nits, minor suggestions — report only if clearly valuable

Discard likely false positives silently.

Step 7: Fix (Optional)

If the user requested "review and fix":

  • Apply High/Critical fixes directly
  • Describe Medium fixes that require manual intervention
  • Skip Low-priority items unless trivial

Sub-commands Reference

CommandPurpose
ocr delegate previewWhich files to review + mode/ref metadata
ocr delegate rule <path...>Review rules grouped by content

Shared Flags

FlagDescription
--from <ref>Source ref for range mode
--to <ref>Target ref for range mode
-c, --commit <hash>Single commit mode
--repo <path>Repository root (default: cwd)
--rule <path>Custom rule.json path
--exclude <patterns>Comma-separated exclude patterns
-b, --background <text>Business context
-B, --background-file <path>Business context from Markdown file (takes precedence over -b)
-f, --format <text|json>Output format; use json for agent integrations
Show full SKILL.md (421 more words)Show less

Gotchas

  • No LLM needed on OCR side — delegation mode never calls an LLM. All intelligence comes from the host agent.
  • Rules are grouped — Files sharing the same rule are grouped together in the output. You can pass any number of paths per call; for large changes, fetch rules per-batch as you review.
  • Working directory matters — ocr delegate operates on the Git repo at the current directory. Use --repo /path to override.
  • Untracked files in workspace mode — preview includes untracked files. For these, read the file directly instead of using git diff.
  • Background context — pass --background to preview when you have requirement context; it appears in the output for your reference during review.
  • Coverage is mandatory — every reviewable_files entry must end as reviewed or explicitly skipped; do not silently omit files.
Recovering Oversized Background Context

--background-file has two independent limits. The raw file must not exceed 1 MiB, and the sanitized content must not exceed 8000 characters. Either condition aborts the command. When the command reports either limit:

  1. Do not silently truncate the source file.
  2. Summarize the original material while preserving its requirements, constraints, acceptance criteria, and other review-critical details.
  3. Retry the affected command by passing the summary as one shell-safe argument (for example, use a quoted/escaped argument produced by the host shell, or write it to a new size-bounded file and pass that file). Do not place untrusted summary text directly in a double-quoted shell template; $(), backticks, quotes, and variable references can still be evaluated. Omit the original --background-file so the CLI does not reload the same oversized file and fail again.
  4. If a faithful summary is not possible, omit the OCR background entirely and read the original material directly during the review.
Troubleshooting CLI Version Compatibility

The --format flag is available in ocr v1.9.0 and later. The Skill and the installed CLI can be updated independently. If a requested preview or rule command with --format json fails specifically with unknown flag: --format, rerun it without the flag and use text output for the rest of the delegation run. Preserve the explicit mode, ref, file, and rule information from that output; do not parse text output as JSON or invent missing schema fields. Do not retry without the flag for any other error; report it and stop the affected workflow.

The host-agent Skill may consume the equivalent text output to complete its review checklist. Programmatic integrations that require schema_version or other JSON fields must require a JSON-capable CLI instead: verify with ocr --version and upgrade when necessary:

bash
npm install -g @alibaba-group/open-code-review

© alibaba, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/open-code-review-delegate of alibaba/open-code-review.

Open the folder on GitHubat commit 182898c

Compare with similar skills

Open Code Review Delegate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Open Code Review Delegate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Open Code Review Delegate this skillalibaba/open-code-review44k—~2kAutomated safety check: PassApache-2.0
Code Reviewyaklang/yakit7.8k—~1.4kAutomated safety check: NotesAGPL-3.0
Shipcatlog22/Claude-Code-Workflow2.1k—~1.8kAutomated safety check: NotesMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost55k—~3.8kAutomated safety check: PassMIT

Similar skills

  • Code Review

    yaklang/yakit

    对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…

    7.8k GitHub stars~1.4k tokensUpdated 7 days ago
    DevelopmentAuto-check: notes
  • Ship

    catlog22/Claude-Code-Workflow

    Structured release pipeline with pre-flight checks, AI code review, version bump, changelog, PR creation, platform publish, and GitHub release.

    2.1k GitHub stars~1.8k tokensUpdated 3 mo ago
    DevelopmentAuto-check: notes
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    55k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from alibaba/open-code-review

  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Open Code Review Delegate

What does Open Code Review Delegate do?

Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits. In delegation mode the `ocr` CLI does only deterministic work and the agent supplies the intelligence, so no LLM endpoint needs to be configured on the OCR side. A preview command reports what is under review, which can be the workspace changes, a range between two refs or one commit, with ref metadata, the reviewable files and their insertions and deletions, and the excluded files with reasons.

When should I use Open Code Review Delegate?

Open Code Review Delegate fits situations like: reviewing uncommitted workspace changes with the agent's own model; reviewing a branch against main using the project's review rules; reviewing a single commit.

How do I install Open Code Review Delegate in Claude Code?

Run `npx skills add alibaba/open-code-review --skill open-code-review-delegate -a claude-code`. Or copy the skill folder (skills/open-code-review-delegate in alibaba/open-code-review) into .claude/skills/open-code-review-delegate in your project. Claude Code loads it when a task matches its description.

How do I install Open Code Review Delegate in Codex?

Run `npx skills add alibaba/open-code-review --skill open-code-review-delegate -a codex`. Or copy the skill folder (skills/open-code-review-delegate in alibaba/open-code-review) into .agents/skills/open-code-review-delegate in your project. Codex loads it when a task matches its description.

Can I use Open Code Review Delegate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alibaba/open-code-review --skill open-code-review-delegate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/open-code-review-delegate, .gemini/skills/open-code-review-delegate, .github/skills/open-code-review-delegate and .opencode/skills/open-code-review-delegate in your project.

What does Open Code Review Delegate need to run?

Going by SKILL.md and its folder, Open Code Review Delegate needs the command-line tools its instructions call (git and npm). Our summary lists: The `ocr` CLI, from the npm package `@alibaba-group/open-code-review` or a release binary; Git. Compatibility (from SKILL.md): Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Does NOT require a configured LLM endpoint — delegation mode is LLM-free on the OCR side. .

Does Open Code Review Delegate access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Open Code Review Delegate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Open Code Review Delegate use?

Open Code Review Delegate is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Open Code Review Delegate use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Open Code Review Delegate?

Skills that share tags, products or a category with Open Code Review Delegate: Code Review (yaklang/yakit, 7.8k stars), Ship (catlog22/Claude-Code-Workflow, 2.1k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Open Code Review Delegate?

alibaba (a GitHub organization) maintains it in alibaba/open-code-review, which has 44,069 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 5, 2026.

Source: alibaba/open-code-review on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.