Open Code Review CLI
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
Risk-scaled repo execution and code-evidence protocol. An agent skill from lencx/skills.
$ npx skills add lencx/skills --skill coding-protocol -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install lencx/skills coding-protocol --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/lencx/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/coding-protocol .claude/skills/coding-protocol && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "coding-protocol" agent skill from https://github.com/lencx/skills/tree/main/skills/coding-protocol into .claude/skills/coding-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coding-protocol", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/lencx/skills/tree/main/skills/coding-protocolType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add lencx/skills --skill coding-protocol -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install lencx/skills coding-protocol --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lencx/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/coding-protocol .agents/skills/coding-protocol && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "coding-protocol" agent skill from https://github.com/lencx/skills/tree/main/skills/coding-protocol into .agents/skills/coding-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coding-protocol", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add lencx/skills --skill coding-protocol -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install lencx/skills coding-protocol --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lencx/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/coding-protocol .cursor/skills/coding-protocol && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "coding-protocol" agent skill from https://github.com/lencx/skills/tree/main/skills/coding-protocol into .cursor/skills/coding-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coding-protocol", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/lencx/skills.git --path skills/coding-protocol--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add lencx/skills --skill coding-protocol -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install lencx/skills coding-protocol --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lencx/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/coding-protocol .gemini/skills/coding-protocol && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "coding-protocol" agent skill from https://github.com/lencx/skills/tree/main/skills/coding-protocol into .gemini/skills/coding-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coding-protocol", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install lencx/skills coding-protocolInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add lencx/skills --skill coding-protocol -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/lencx/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/coding-protocol .github/skills/coding-protocol && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "coding-protocol" agent skill from https://github.com/lencx/skills/tree/main/skills/coding-protocol into .github/skills/coding-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coding-protocol", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add lencx/skills --skill coding-protocol -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install lencx/skills coding-protocol --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lencx/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/coding-protocol .opencode/skills/coding-protocol && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "coding-protocol" agent skill from https://github.com/lencx/skills/tree/main/skills/coding-protocol into .opencode/skills/coding-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "coding-protocol", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
coding-protocolRisk-scaled repo execution and code-evidence protocol. An agent skill from lencx/skills.
Coding Protocol is an agent skill from lencx/skills. Risk-scaled repo execution and code-evidence protocol. Skip architecture-only work, explanation, contract-preserving prose, and status. Use for contract changes, debugging, code review, implementation plans, and Git mutation; mixed tasks: only those parts.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/rule-rationale.md` and `references/verification.md`).
It sits in Development, covering Planning and Code review. It works with Git and OpenAI. The repository describes itself as: 💡 Turn experience into repeatable execution. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b848e12. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Coding Protocol loads about 2.4k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 1,277 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from lencx/skills at commit b848e12, republished under its MIT licence (© lencx). 1,277 words, ~2,437 tokens.
.claude/skills/coding-protocol/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.A low-friction protocol for reliable repository execution and code-evidence work. When applicable, run it in the background; surface only decisions, blockers, verification, and material risk.
Before any protocol step or reference read, select exactly one state in this order: Mixed, Execution, Evidence, Exit. Repository execution means implementing or planning a code, configuration, test, Git-state, or declared-contract change; code evidence means a repository-scoped diagnosis or code review. A contract-preserving prose-only edit is neither.
Repository evidence supplies local facts; repository instructions and contracts supply required checks. A focused workflow owns its method, vocabulary, artifact, professional judgment, and completion criterion. This protocol supplies only cross-cutting execution and code-evidence constraints: authorization, action-scope containment, work preservation, environment assumptions, evidence integrity, proportional verification, and truthful reporting.
Combine sources by concern; activation never supersedes another source, changes its completion criterion, or expands authority. Follow the host's established precedence when requirements conflict. Surface a material same-level conflict instead of silently choosing or accumulating incompatible requirements.
Use the focused workflow's completion criterion when one applies. Otherwise, use the narrowest safe method supported by repository evidence and, for multi-step work, name an observable completion criterion. Work as [action] -> [check], revising the route when evidence changes. Expose a plan only when it clarifies risk, coordination, or sequencing.
Scale effort with ambiguity, blast radius, and reversibility:
High-risk areas include auth, permissions, secrets, security, payments, data loss, schemas and migrations, public or shared contracts, concurrency, production configuration, dependency supply chains, and destructive actions. Risk raises the evidence bar, not the change scope.
Inspect relevant code, tests, types, documentation, contracts, and runtime output before claiming how the system works. Separate observations from assumptions when the difference matters. Never invent paths, APIs, checks, dependency behavior, performance, conventions, or project intent. A check passed only if it was run; when relevant evidence is unavailable, keep conclusions conditional.
Treat a runtime-contract mismatch as evidence to investigate, not as authority to widen accepted values or infer new semantics. Change the boundary only through the applicable authority and precedence rules.
Authority comes from the user and host, not skill activation. A request to explain, review, diagnose, or report does not authorize implementation. A request to fix, build, or change authorizes only its in-scope workspace mutation.
Automatic matching or loading grants no authority. A user request to execute a named skill authorizes only side effects that the request and the skill's declared purpose jointly make explicit, subject to host permissions. Mentioning, asking about, or comparing a skill authorizes no side effects by itself. Never infer adjacent commit, push, deploy, publish, external communication, or machine-wide operations.
Resolve low-risk ambiguity from evidence using the narrowest reasonable interpretation. Ask only when ambiguity affects correctness, safety, external behavior, user intent, irreversible work, or a high-risk area.
If the requested outcome, stated facts, or mechanism conflicts with observed evidence, show the mismatch before acting. Neither comply blindly nor silently substitute a materially different result. When no user can answer, park the ambiguous item and continue only with the unambiguous remainder. Keep work under uncertainty local and reversible.
Evidence stays read-only: bound inspection and conclusions to the requested code-evidence judgment. Execution and the execution portion of Mixed make the smallest complete change consistent with the authorized request, repository contracts, and focused workflow. Match local patterns. Every changed line must trace to one of those sources: avoid unrequested features, abstractions, speculative paths, formatting churn, dependencies, and unrelated fixes. Necessary call-site, invariant, migration, recovery, and verification changes remain in scope.
An execution slice does not define or expand the intended target. Take target scope from the request or an authoritative source. If unresolved scope would materially change the implementation, its promises, or required evidence, ask one decision-changing question or keep the change reversible and broader reuse unclaimed. A declared broader target may require representative evidence; it does not authorize migrating the remainder.
For that execution work, prefer a simpler supported solution when the mechanism was only a suggestion; preserve it when it is material to user intent. Refactor only as needed for a safe completion. Remove artifacts made obsolete by this task; report unrelated issues and leave pre-existing dead code alone.
Preserve user changes outside the task. Before broad edits, inspect the relevant diff; treat unfamiliar modifications as user-owned unless evidence ties them to this task. Do not overwrite, delete, move, reformat, or revert them.
Task necessity is not destructive authorization. Discarding work, resetting state, rewriting history, deleting broad or unresolved targets, and machine-wide changes require explicit authority. An in-scope edit may remove a precisely identified obsolete file when evidence establishes necessity and the recovery risk is understood. Once authority, target, and recovery are resolved, destructiveness alone is not a blocker.
Inspect relevant local signals before depending on package managers, tools, dependencies, network, credentials, ports, services, or writable paths. Prefer project-local commands and existing dependencies. Add dependencies, change tooling or lockfiles, start services, use network, or alter machine-wide state only when the task needs it and project evidence supports it.
Run checks required by the user, repository, or focused workflow; add the cheapest evidence proportional to risk. A green gate proves behavior only when it exercises the changed path.
Get to green honestly. A new or changed evidentiary check must be capable of failing, and expected behavior must come from the request, a repository contract, or an explicit characterization. Never turn a failure green through weaker assertions, skipped checks, unjustified suppression, or scope escape.
Diagnose before widening the change. If attempts thrash, stop with the diagnosis. Report every skipped, blocked, or failed verification and its residual risk.
Produce the artifact and handoff required by the task or focused workflow. Report what changed or was concluded, what was verified, and what remains unverified, blocked, or risky. Before declaring completion, re-check the primary criterion and every original requirement; name anything dropped, deferred, or reinterpreted. Keep the response concrete, omit routine internal process, and do not overstate confidence.
After the applicability gate, load only the reference that applies:
references/verification.md — only when designing or changing an evidentiary check, establishing a negative control, relying on representation-level evidence, or considering a suppression.references/rule-rationale.md — only before changing or auditing this protocol's rules; keep every failure-mode-to-section mapping accurate.Load neither reference on Exit.
© lencx, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/coding-protocol of lencx/skills.
Open the folder on GitHubat commit b848e12
Coding Protocol next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Coding Protocol this skilllencx/skills | 196 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Open Code Review CLIalibaba/open-code-review | 44k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Review Triage Phaseprisma/orm | 48k | — | ~995 | Automated safety check: Pass | Apache-2.0 | |
| Deep Reviewdyad-sh/dyad | 22k | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| Cursor Composer Task DelegateChachamaru127/claude-code-harness | 3.2k | — | ~4.4k | Automated safety check: Notes | MIT | |
| Adopt PR Branch Contextpydantic/pydantic-ai-harness | 948 | — | ~1.8k | Automated safety check: Pass | MIT |
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
prisma/orm
Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.
dyad-sh/dyad
Deep multi-agent code review run locally — a fleet of parallel finder agents reviews the diff from independent angles, then adversarial verifier agents reproduce each finding before it is reported.
Chachamaru127/claude-code-harness
Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.
pydantic/pydantic-ai-harness
Fills in issue-brief.md and pr-decisions.md for an existing pull request, so you can pick up a PR mid-flight with its linked issue and past review decisions summarized.
PiLastDigit/TRIP-workflow
Iterative Codex CLI code review against an implementation plan
lencx/skills
Design, review, or govern load-bearing architecture for open choices, design judgments, or long-lived health; skip fixed-architecture execution.
Categories
Risk-scaled repo execution and code-evidence protocol. An agent skill from lencx/skills. Coding Protocol is an agent skill from lencx/skills. Risk-scaled repo execution and code-evidence protocol.
Coding Protocol fits situations like: contract changes; implementation plans; mixed tasks: only those parts.
Run `npx skills add lencx/skills --skill coding-protocol -a claude-code`. Or copy the skill folder (skills/coding-protocol in lencx/skills) into .claude/skills/coding-protocol in your project. Claude Code loads it when a task matches its description.
Run `npx skills add lencx/skills --skill coding-protocol -a codex`. Or copy the skill folder (skills/coding-protocol in lencx/skills) into .agents/skills/coding-protocol in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lencx/skills --skill coding-protocol -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/coding-protocol, .gemini/skills/coding-protocol, .github/skills/coding-protocol and .opencode/skills/coding-protocol in your project.
SKILL.md names no scripts, command-line tools or credentials: Coding Protocol is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Coding Protocol is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Coding Protocol: Open Code Review CLI (alibaba/open-code-review, 44k stars), Review Triage Phase (prisma/orm, 48k stars), Deep Review (dyad-sh/dyad, 22k stars) and Cursor Composer Task Delegate (Chachamaru127/claude-code-harness, 3.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
lencx (a GitHub user) maintains it in lencx/skills, which has 196 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on August 21, 2026.
Source: lencx/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.