Agent skill

Orca Review Action

by Continuum-AI-Corp in Continuum-AI-Corp/Orca-Code-Review

Set up, reconfigure, troubleshoot, or remove OrcaCode Review — AI pull-request review powered by OrcaRouter — in a GitHub repository.

MITAuto-check passedDevelopment

Install Orca Review Action

skills CLI
$ npx skills add Continuum-AI-Corp/Orca-Code-Review --skill orca-review-action -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Continuum-AI-Corp/Orca-Code-Review orca-review-action --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Continuum-AI-Corp/Orca-Code-Review.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/orca-review-action .claude/skills/orca-review-action && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
orca-review-action
GitHub stars
175
Token cost
~2.9k tokens
SKILL.md length
1,580 words
Files
4 (incl. references, assets)
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Set up, reconfigure, troubleshoot, or remove OrcaCode Review — AI pull-request review powered by OrcaRouter — in a GitHub repository.

  • Works in 8 steps: Preflight → Ask for the key decisions → Write the workflow → …
  • The user mentions OrcaCode Review
  • SKILL.md covers What you can do with this skill, Pick the route, Install and Reconfigure, plus 2 more sections
  • Calls gh and git; reaches github.com; needs ORCAROUTER_API_KEY

What it does

Orca Review Action is an agent skill from Continuum-AI-Corp/Orca-Code-Review. Set up, reconfigure, troubleshoot, or remove OrcaCode Review — AI pull-request review powered by OrcaRouter — in a GitHub repository. Handles the whole lifecycle end to end without asking the user to run a CLI. Use whenever the user mentions OrcaCode Review, OrcaRouter code review, "@orcarouter code review", or /orcacode-review, and whenever they ask to set up AI code review on a repo, add the orca-code-review action, change which severities block merges, find out why a review did not run or did not post…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files and assets (for example `assets/workflow.yml`, `references/inputs.md` and `references/troubleshooting.md`).

It sits in Development, covering Code review and Pull requests. It works with GitHub. The repository describes itself as: OrcaCode Review — the open code review harness. Multi-model reviews, merge gates, and no markup. Pay only for inference. The licence is MIT.

When your agent uses it

  • The user mentions OrcaCode Review
  • OrcaRouter code review
  • @orcarouter code review
  • /orcacode-review

Example prompts

  • “@orcarouter code review”
  • “/orca-review-action”

Requirements

  • A credential in ORCAROUTER_API_KEY

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Preflight
  2. Ask for the key decisions
  3. Write the workflow
  4. Have the user add the API key — with gh, themselves
  5. Switch it on in the OrcaRouter console
  6. Commit and open a test PR
  7. Make the gate real
  8. Report, and close on what they still owe

What it can do on your machine

Read from SKILL.md and the folder at commit a49ffb5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • orcarouter.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ORCAROUTER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Orca Review Action loads about 2.9k tokens when it runs, and up to ~6.1k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 1,580 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Continuum-AI-Corp/Orca-Code-Review at commit a49ffb5, republished under its MIT licence (© Continuum-AI-Corp). 1,580 words, ~2,925 tokens.

Download SKILL.mdSave it as .claude/skills/orca-review-action/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
orca-review-action
description
Set up, reconfigure, troubleshoot, or remove OrcaCode Review — AI pull-request review powered by OrcaRouter — in a GitHub repository. Handles the whole lifecycle end to end without asking the user to run a CLI. Use whenever the user mentions OrcaCode Review, OrcaRouter code review, "@orcarouter code review", or /orcacode-review, and whenever they ask to set up AI code review on a repo, add the orca-code-review action, change which severities block merges, find out why a review did not run or did not post findings, or take the review workflow back out.

OrcaCode Review

OrcaCode Review reviews every pull request with an LLM, posts findings as inline comments, and fails a status check when serious issues are found. Model selection lives in OrcaRouter, not in the repo.

It runs as a GitHub Action: a workflow file in the repo plus one secret. Write access is all it takes, and an agent can complete the whole setup.

Severity contract: P0 critical / P1 high → ❌ block. P2 advisory → 💬 comment.

What you can do with this skill

You carry out all of these yourself — writing files, running gh, and asking the user only for the decisions that are genuinely theirs. Never tell the user to go run an installer; that is what this skill replaces.

The user says something like…You do
"set up OrcaCode Review here", "@orcarouter code review 帮我配置这个仓库"Install
"only block P0", "move the config to the dashboard", "raise the diff limit"Reconfigure
"why didn't the review run?", "no comments appeared", "the check is stuck red"Troubleshoot
"remove OrcaCode Review", "turn the review off"Uninstall
"what can OrcaCode Review do?"Summarize this table and the severity contract. Do not dump the file.

Pick the route

Jump straight to the section the table above points at. Do not run the install flow on a repo that already has the workflow — go to Reconfigure instead.

Run this first in every route — it tells you which one applies:

bash
git rev-parse --show-toplevel && \
  gh repo view --json nameWithOwner,visibility,defaultBranchRef 2>/dev/null; \
  ls .github/workflows/ 2>/dev/null | grep -i 'orca\|code-review'

If gh is missing or unauthenticated, everything still works — you just hand the user web URLs instead of running commands. Say so once and move on.

Install

1. Preflight

Confirm all three, and stop with a specific message if any fails:

  • Inside a git work tree with a GitHub origin remote.
  • No existing OrcaCode workflow (if there is one → Reconfigure).
  • Record the repo's nameWithOwner, visibility, and default branch — later steps need them.
2. Ask for the key decisions

Ask these with one AskUserQuestion call. Include the fourth question only when visibility is PUBLIC — it is a spend-control decision that does not exist on a private repo, and asking it there is noise.

Q1 — "Where should review settings live?" (settings input)

  • OrcaRouter dashboard (recommended) → settings: "true". Models, review mode, severity rules, and rubric change from the console with no workflow edit. Dashboard values win unless a with: input differs from its documented default.
  • This workflow file → settings: "false". Skips the dashboard fetch entirely; the YAML is authoritative and nothing server-side can override it. Pick this for repos under change control.

Q2 — "Which findings should block the merge?" (block-on input)

  • P0 and P1 (recommended) → "P0,P1". The default contract.
  • P0 only → "P0". Blocks only critical issues; P1 still posts inline.
  • Nothing — comment only → "". The check always passes. Good for a trial period.

Q3 — "What happens when a PR's diff is too large to review?" (on-oversized-diff)

  • Fail the check (recommended) → "fail". A diff padded past max-diff-kb / max-diff-files cannot be used to slip past a required merge gate.
  • Pass with a notice → "pass". The skip notice posts and the check stays green.

Q4 — public repos only — "Who gets an automatic review?" (auto-review-authors)

  • Known contributors only (recommended) → "OWNER,MEMBER,COLLABORATOR,CONTRIBUTOR".
  • Everyone → "".

Say plainly why Q4 exists: the workflow runs on pull_request_target with your OrcaRouter secret, so on a public repo a stranger's PR can spend from your wallet. Also tell them to set a budget + alert on the key at https://www.orcarouter.ai/console/token.

Everything else keeps its default. Do not ask about judge-model, concurrency, engine-version, or precision-filter during install — see references/inputs.md if the user brings them up unprompted.

3. Write the workflow

Copy assets/workflow.yml to .github/workflows/orca-code-review.yml, then set the four values from step 2 under with:. Omit any input the user left at its default — a workflow that only lists what it overrides stays readable and lets the dashboard own the rest.

Keep the if: condition and the on: block exactly as shipped. They encode two things that are easy to break: pull_request_target is what lets a fork PR be reviewed at all, and the author-association check on issue_comment is what stops any drive-by commenter from spending your quota with /orcacode-review.

Show the user the final file before committing.

4. Have the user add the API key — with gh, themselves

The secret must be named exactly ORCAROUTER_API_KEY.

This is the one step you do not perform. Stop, hand the user this command, and wait for them to confirm they have run it:

! gh secret set ORCAROUTER_API_KEY --repo <owner/name>

gh prompts for the value on their terminal, so the key goes from their keyboard straight to GitHub. It never passes through you.

Never ask them to paste the key into the chat, read it out of a file or an env var, or pass it on a command line. A pasted key is in the transcript forever; a key in argv is visible to every process on the machine via ps. There is no version of this you can do "carefully" — the only safe handling is not handling it.

They can create or copy a key at https://www.orcarouter.ai/console/token.

Without gh, send them to https://github.com/<owner>/<name>/settings/secrets/actions/new and have them add it in the browser.

Then confirm it exists without ever seeing its value:

bash
gh secret list --repo <owner/name> | grep ORCAROUTER_API_KEY

If it is not there yet, do not continue to the test PR — the run will fail on auth and the failure will look like a configuration bug rather than a missing key. Wait, or skip to step 8 and list it as outstanding.

5. Switch it on in the OrcaRouter console

Point the user at OrcaRouter → Apps → OrcaCode Review (https://www.orcarouter.ai/) to turn it on and choose review models. Reviews will not run until it is enabled.

There is no API for this step today, so it is the user's to do.

Show full SKILL.md (642 more words)Show less
6. Commit and open a test PR

Commit on a branch, push, and open a PR — do not commit straight to the default branch. The PR is also the test: the workflow must run against a real pull request to prove out.

bash
gh pr create --fill && gh run watch
7. Make the gate real

A passing check blocks nothing until it is required. Walk the user through Settings → Branches / Rulesets → Require status checks to pass and adding the review check, or offer to do it:

bash
gh api -X PATCH repos/<owner>/<name>/branches/<default>/protection/required_status_checks \
  -f 'checks[][context]=review'

Confirm before running — branch protection changes affect everyone on the repo.

8. Report, and close on what they still owe

Tell the user, concretely: the workflow path, the settings you chose, whether the secret and required check are in place, and the result of the test run. If any step was skipped (no gh, protection not applied), say which.

End the message with their outstanding actions as copy-pasteable commands — not prose describing them. Anything you could not do yourself belongs here, and the API key is almost always on the list because you are not allowed to do it:

! gh secret set ORCAROUTER_API_KEY --repo <owner/name>

Re-check with gh secret list before claiming it is done. Do not report the install as complete while the secret is missing: the workflow is in place but every run will fail on auth, and "installed" would be a lie the user only finds out about on their next PR.

Reconfigure

Read the existing .github/workflows/orca-code-review.yml first, then check whether settings: "false" is set.

If the dashboard owns settings (settings absent or "true") — most knobs are not in the file. Review mode, models, exhaustive mode, quiet mode, rubric, and the fix-first/block-on tuning all live at OrcaRouter → Apps → OrcaCode Review. Send the user there rather than editing YAML, and explain the precedence rule: an input written in the file only wins if it differs from its documented default.

If the file is authoritative (settings: "false") — edit it. Ask with AskUserQuestion which knobs to change, offering only what is relevant:

  • Merge policy (block-on), exhaustive early-stop (fix-first), and which severities post inline (Report severities, dashboard-only).
  • Diff limits (max-diff-kb, max-diff-files) and on-oversized-diff.
  • Precision filter (precision-filter, judge-model, judge-threshold).
  • Run reporting (report) and token metering (meter).

references/inputs.md has every input, its default, and what it actually controls. Read it before answering a question about behavior — do not guess a default.

State the before → after for each value you change, and note that the new settings take effect on the next push to any open PR.

Troubleshoot

Gather evidence before theorizing:

bash
gh run list --workflow orca-code-review.yml --limit 5
gh run view <run-id> --log-failed

references/troubleshooting.md maps each symptom to its cause and fix. The four that account for most reports:

  • No run at all — the PR is a draft and trigger is ready_for_review, the author is outside auto-review-authors, or the app is off in the dashboard.
  • Run fails immediately, auth error — ORCAROUTER_API_KEY is missing, misnamed, or scoped to an environment the job cannot read.
  • "Diff too large" notice and a red check — expected behavior with on-oversized-diff: "fail". Split the PR, or raise max-diff-kb / max-diff-files.
  • Reviews work but the console's Settings/Analytics tabs are empty — @v1 points at a commit older than scripts/settings.mjs / scripts/report.mjs. There is no error for this; verify with git ls-tree v1 scripts/ against the action repo.

Report the actual failing output, not a paraphrase of it.

Uninstall

Confirm with the user first, then in this order:

  1. Drop the required check — remove review from branch protection before deleting the workflow. A required check whose workflow no longer exists never reports, and every PR blocks forever with no way to clear it.
  2. Delete the workflow — rm .github/workflows/orca-code-review.yml, commit, push.
  3. Leave the secret — say that ORCAROUTER_API_KEY is harmless to keep and is worth keeping if they may reinstall. Delete it only if they ask.
  4. Mention the dashboard — turning the app off at OrcaRouter → Apps → OrcaCode Review stops any remaining billing.

Do not delete old review comments. They are part of the PR history.

© Continuum-AI-Corp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references, assets) in skills/orca-review-action of Continuum-AI-Corp/Orca-Code-Review.

  • SKILL.md
  • assets/workflow.yml
  • references/inputs.md
  • references/troubleshooting.md

Open the folder on GitHubat commit a49ffb5

Compare with similar skills

Orca Review Action next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Orca Review Action compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Orca Review Action this skillContinuum-AI-Corp/Orca-Code-Review175—~2.9kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0
PR Finalize Reviewmicrosoft/garnet12k—~3.1kAutomated safety check: PassMIT
Fastlane Pull Request Reviewfastlane/fastlane42k—~550Automated safety check: PassMIT

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • PR Finalize Review

    microsoft/garnet

    Official

    Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.

    12k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Reviews a fastlane pull request against its linked issue and the project guides, separating blocking from non-blocking findings and handling vulnerabilities privately.

    42k GitHub stars~550 tokensUpdated today
    DevelopmentAuto-check passed
  • Pull Request Babysitter

    thedotmack/claude-mem

    Keeps watching a pull request, fixing real review and CI problems and resolving stale threads, until it is clean and ready to merge.

    99k GitHub stars~1.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from Continuum-AI-Corp/Orca-Code-Review

  • Orca Review

    Continuum-AI-Corp/Orca-Code-Review

    Review code changes yourself, locally, with OrcaCode Review's severity contract and merge gate — no GitHub Action, no OrcaRouter account, no API key.

    175 GitHub stars~3.5k tokensUpdated 20 days ago
    Auto-check passed

Works with

Categories

Questions about Orca Review Action

What does Orca Review Action do?

Set up, reconfigure, troubleshoot, or remove OrcaCode Review — AI pull-request review powered by OrcaRouter — in a GitHub repository. Orca Review Action is an agent skill from Continuum-AI-Corp/Orca-Code-Review. Set up, reconfigure, troubleshoot, or remove OrcaCode Review — AI pull-request review powered by OrcaRouter — in a GitHub repository.

When should I use Orca Review Action?

Orca Review Action fits situations like: the user mentions OrcaCode Review; orcaRouter code review; @orcarouter code review; /orcacode-review.

How do I install Orca Review Action in Claude Code?

Run `npx skills add Continuum-AI-Corp/Orca-Code-Review --skill orca-review-action -a claude-code`. Or copy the skill folder (skills/orca-review-action in Continuum-AI-Corp/Orca-Code-Review) into .claude/skills/orca-review-action in your project. Claude Code loads it when a task matches its description.

How do I install Orca Review Action in Codex?

Run `npx skills add Continuum-AI-Corp/Orca-Code-Review --skill orca-review-action -a codex`. Or copy the skill folder (skills/orca-review-action in Continuum-AI-Corp/Orca-Code-Review) into .agents/skills/orca-review-action in your project. Codex loads it when a task matches its description.

Can I use Orca Review Action in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Continuum-AI-Corp/Orca-Code-Review --skill orca-review-action -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/orca-review-action, .gemini/skills/orca-review-action, .github/skills/orca-review-action and .opencode/skills/orca-review-action in your project.

What does Orca Review Action need to run?

Going by SKILL.md and its folder, Orca Review Action needs the command-line tools its instructions call (gh and git) and credentials named ORCAROUTER_API_KEY. Our summary lists: A credential in ORCAROUTER_API_KEY.

Does Orca Review Action access the network?

SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: orcarouter.ai. This is read from the text; nothing was executed.

Is Orca Review Action safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Orca Review Action use?

Orca Review Action is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Orca Review Action use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Orca Review Action?

Skills that share tags, products or a category with Orca Review Action: PR Babysitter (openinterpreter/openinterpreter, 69k stars), GitHub Review Iteration (prisma/orm, 48k stars), PR Review State Fetch (prisma/orm, 48k stars) and PR Finalize Review (microsoft/garnet, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Orca Review Action?

Continuum-AI-Corp (a GitHub organization) maintains it in Continuum-AI-Corp/Orca-Code-Review, which has 175 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 21, 2026.

Source: Continuum-AI-Corp/Orca-Code-Review on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.