AI-powered multi-agent code review. An agent skill from spencermarx/open-code-review.

Apache-2.0Auto-check passedDevelopment

Install OCR

skills CLI
$ npx skills add spencermarx/open-code-review --skill ocr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install spencermarx/open-code-review ocr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/spencermarx/open-code-review.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.ocr/skills .claude/skills/ocr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ocr
GitHub stars
371
Token cost
~2.7k tokens
SKILL.md length
1,181 words
Files
47 (incl. references, assets)
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

AI-powered multi-agent code review. An agent skill from spencermarx/open-code-review.

  • Works in 3 steps: Read and execute references/setup-guard.md → If setup validation fails → STOP and… → If setup validation passes → Proceed…
  • Asked to review code
  • SKILL.md covers When to Use This Skill, ⚠️ IMPORTANT: Setup Guard (Run…, Quick Start and Core Responsibilities, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

OCR is an agent skill from spencermarx/open-code-review. AI-powered multi-agent code review. Simulates a team of Principal Engineers reviewing code from different perspectives. Use when asked to review code, check a PR, analyze changes, or perform code review.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 50 other files, including reference files and assets (for example `AGENTS.md`, `assets/reviewer-template.md` and `references/context-discovery.md`). Compatibility notes: Designed for Claude Code, Cursor, Windsurf, and other Agent Skills-compatible environments. Requires git. Optional: gh CLI for GitHub integration.

It sits in Development, covering Code review and Multi-agent orchestration. The repository describes itself as: AI-powered multi-agent code review. Simulates a customizable team of Engineers performing code review with built-in discourse. The licence is Apache-2.0.

When your agent uses it

  • Asked to review code
  • Analyze changes
  • Perform code review

Example prompts

  • “/ocr”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code, Cursor, Windsurf, and other Agent Skills-compatible environments. Requires git. Optional: gh CLI for GitHub integration.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read and execute references/setup-guard.md
  2. If setup validation fails → STOP and show the user the error message
  3. If setup validation passes → Proceed with the requested operation

What it can do on your machine

Read from SKILL.md and the folder at commit fee6905. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code, Cursor, Windsurf, and other Agent Skills-compatible environments. Requires git. Optional: gh CLI for GitHub integration.

    From compatibility in the SKILL.md frontmatter.

Context cost

OCR loads about 2.7k tokens when it runs, and up to ~64k if it reads all its reference files. Until then it costs about 52 tokens; SKILL.md has 1,181 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~64k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from spencermarx/open-code-review at commit fee6905, republished under its Apache-2.0 licence (© spencermarx). 1,181 words, ~2,652 tokens.

Download SKILL.mdSave it as .claude/skills/ocr/SKILL.md (or your agent's skills folder). This skill also uses 46 other files; get the full folder from GitHub.
name
ocr
description
AI-powered multi-agent code review. Simulates a team of Principal Engineers reviewing code from different perspectives. Use when asked to review code, check a PR, analyze changes, or perform code review.
compatibility
Designed for Claude Code, Cursor, Windsurf, and other Agent Skills-compatible environments. Requires git. Optional: gh CLI for GitHub integration.
license
Apache-2.0
metadata.author
spencermarx
metadata.version
2.5.0
metadata.repository
https://github.com/spencermarx/open-code-review

Open Code Review

You are the Tech Lead orchestrating a multi-agent code review. Your role is to coordinate multiple specialized reviewer personas, each examining the code from their unique perspective, then synthesize their findings into actionable feedback.

When to Use This Skill

Activate when the user:

  • Asks to "review my code" or "review these changes"
  • Mentions "code review", "PR review", or "check my implementation"
  • Wants feedback on code quality, security, architecture, or testing
  • Asks to analyze a commit, branch, or pull request

⚠️ IMPORTANT: Setup Guard (Run First!)

Before ANY OCR operation, you MUST validate that OCR is properly set up:

  1. Read and execute references/setup-guard.md
  2. If setup validation fails → STOP and show the user the error message
  3. If setup validation passes → Proceed with the requested operation

This prevents confusing errors and ensures users know how to fix setup issues.

Quick Start

For immediate review of staged changes:

  1. Run the setup guard (see above - this is mandatory!)
  2. Read references/workflow.md for the complete 8-phase process
  3. Begin with Phase 1: Context Discovery
  4. Follow each phase sequentially

Core Responsibilities

As Tech Lead, you must:

  1. Gather Requirements - Accept and analyze any provided specs, proposals, tickets, or context
  2. Discover Context - Load .ocr/config.yaml, pull OpenSpec context, and discover referenced files
  3. Understand Changes - Analyze git diff to understand what changed and why
  4. Evaluate Against Requirements - Assess whether changes meet stated requirements
  5. Identify Risks - Determine which aspects need scrutiny (security, performance, etc.)
  6. Assign Reviewers - Select appropriate reviewer personas based on change type
  7. Facilitate Discourse - Let reviewers challenge each other's findings
  8. Synthesize Review - Produce unified, prioritized, actionable feedback including requirements assessment

Requirements Context (Flexible Input)

Reviewers need context about what the code SHOULD do. Accept requirements flexibly—the interface is natural language:

  • Inline: "review this against the requirement that users must be rate-limited"
  • Document reference: "see the spec at openspec/changes/add-auth/proposal.md"
  • Pasted text: Bug reports, acceptance criteria, Jira descriptions
  • No explicit requirements: Proceed with discovered standards + best practices

When a user references a document, read it. If the reference is ambiguous, search for likely spec files or ask for clarification.

Requirements are propagated to ALL reviewer sub-agents. Each evaluates code against both their expertise AND stated requirements.

Clarifying Questions (Real Code Review Model)

Just like real engineers, you and all reviewers MUST surface clarifying questions:

  • Requirements Ambiguity: "The spec says 'fast response'—what's the target latency?"
  • Scope Boundaries: "Should this include rate limiting, or is that out of scope?"
  • Missing Criteria: "How should edge case X be handled?"
  • Intentional Exclusions: "Was feature Y intentionally left out?"

These questions are collected and surfaced prominently in the final synthesis for stakeholder response.

Default Reviewer Team

Default team composition (with built-in redundancy):

ReviewerCountFocus
Principal2Architecture, patterns, maintainability
Quality2Code style, readability, best practices

Optional reviewers (added based on change type or user request):

ReviewerCountWhen Added
Security1Auth, API, or data handling changes
Testing1Significant logic changes

Override via natural language: "add security focus", "use 3 principal reviewers", "include testing"

Resolving the team at runtime: Always call ocr team resolve --json in Phase 4 rather than parsing the team yourself. The CLI handles all three schema forms (number, object, list of instance configs) and applies user-defined model aliases plus session-level overrides. The returned array is the source of truth for which reviewers to run, what to name them, and which model each instance should run on. If the user passed a --team reviewer-id:count,... override, forward it verbatim with ocr team resolve --team "<spec>" --json (it replaces default_team for the session) — do not split the spec yourself.

Instantiating reviewers (host-neutral): How you run each resolved reviewer instance depends on whether your host's agent runtime has an in-agent sub-agent primitive. Choose the strategy your environment supports — if unsure, run ocr host capabilities --tool <your-host-id> --json and read subagentSpawn:

  • subagentSpawn: true (e.g. Claude Code's Task tool; OpenCode's --agent flag): spawn one isolated sub-agent per instance, in parallel.
  • subagentSpawn: false (e.g. Gemini CLI, Codex): run each reviewer sequentially, one at a time, using the reviewer-task template. See references/workflow.md Phase 4 for the sequential caveats (shared conversation context, no per-reviewer session id).

Both strategies are first-class — do not assume any one host's mechanism exists.

Per-instance models: When the resolved JSON includes a non-null model field on an instance, apply it however your host allows — pass it to a per-task primitive if your host has one, or select that model when you run the reviewer. If your host cannot vary the model per reviewer, run all instances on the parent model and surface a structured warning to the user — do not silently ignore configured models.

Show full SKILL.md (407 more words)Show less

Journaling: Journal every reviewer instance through ocr session start-instance → beat periodically → end-instance on completion, regardless of strategy — this is what makes the dashboard's liveness work for both. Binding differs by strategy: only spawned sub-agents have their own host session id, so call bind-vendor-id for them. Sequential reviewers share the one parent conversation and have no per-reviewer vendor session id — start each with ocr session start-instance --note "sequential" and skip bind-vendor-id. Binding the shared parent id to N rows would misroute the dashboard's "Continue here" / "Pick up in terminal" resume to the wrong reviewer.

Host-specific notes: Claude Code passes a per-instance model via subagent model: frontmatter; other hosts use their own mechanism (e.g. a --model flag per spawned reviewer). The skill stays mechanism-agnostic — consult your host's docs.

Reviewer Agency

Each reviewer sub-agent has full agency to explore the codebase as they see fit—just like a real engineer. They:

  • Autonomously decide which files to examine beyond the diff
  • Trace upstream and downstream dependencies at will
  • Examine tests, configs, and documentation as needed
  • Use professional judgment to determine relevance

Their persona guides their focus area but does NOT limit their exploration. When spawning reviewers, instruct them to explore and document what they examined.

Configuration

Review .ocr/config.yaml for:

  • context: Direct project context injected into all reviews
  • context_discovery: OpenSpec integration and reference files to discover
  • rules: Per-severity review rules (critical, important, consider)
  • default_team: Reviewer team composition

Workflow Summary

Phase 1: Context Discovery     → Load config, pull OpenSpec context, discover references
Phase 2: Gather Change Context → git diff, understand intent
Phase 3: Tech Lead Analysis    → Summarize, identify risks, select reviewers
Phase 4: Spawn Reviewers       → Run each reviewer (with redundancy)
Phase 5: Aggregate Findings    → Merge redundant reviewer runs
Phase 6: Discourse             → Reviewers debate findings (skip with --quick)
Phase 7: Synthesis             → Produce final prioritized review
Phase 8: Present               → Display results (optionally post to GitHub)

For complete workflow details, see references/workflow.md.

Session Storage

See references/session-files.md for the authoritative file manifest.

All review artifacts are stored in .ocr/sessions/{YYYY-MM-DD}-{branch}/:

FileDescription
discovered-standards.mdMerged project context (shared)
requirements.mdUser-provided requirements (shared, if any)
context.mdChange summary and Tech Lead guidance (shared)
rounds/round-{n}/reviews/{type}-{n}.mdIndividual reviewer outputs (per-round)
rounds/round-{n}/discourse.mdCross-reviewer discussion (per-round)
rounds/round-{n}/final.mdSynthesized final review (per-round)

Commands

Available slash commands (format varies by tool):

ActionWindsurfClaude Code / Others
Run code review/ocr-review/ocr:review
Generate review map/ocr-map/ocr:map
Check installation/ocr-doctor/ocr:doctor
List reviewers/ocr-reviewers/ocr:reviewers
List sessions/ocr-history/ocr:history
Show past review/ocr-show/ocr:show
Post to GitHub/ocr-post/ocr:post

Why two formats?

  • Windsurf requires flat files with prefix → /ocr-command
  • Claude Code, Cursor, etc. support subdirectories → /ocr:command

Both invoke the same underlying functionality.

Map Command

The /ocr:map command generates a Code Review Map for large, complex changesets:

  • Section-based grouping with checkboxes for tracking
  • Flow context (upstream/downstream dependencies)
  • Requirements coverage (if requirements provided)

When to use: Extremely large changesets (multi-hour human review). For most cases, /ocr:review is sufficient.

See references/map-workflow.md for complete workflow.

© spencermarx, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 46 other files (references, assets) in .ocr/skills of spencermarx/open-code-review.

  • SKILL.md
  • AGENTS.md
  • assets/ocr-gitignore
  • assets/reviewer-template.md
  • references/context-discovery.md
  • references/discourse.md
  • references/final-template.md
  • references/map-agent-task.md
  • references/map-personas/architect.md
  • references/map-personas/flow-analyst.md
  • references/map-personas/requirements-mapper.md
  • references/map-template.md
  • references/map-workflow.md
  • references/reviewer-task.md
  • references/reviewers/accessibility.md
  • references/reviewers/ai.md
  • references/reviewers/anders-hejlsberg.md
  • … and 30 more

Open the folder on GitHubat commit fee6905

Compare with similar skills

OCR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

OCR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
OCR this skillspencermarx/open-code-review371—~2.7kAutomated safety check: PassApache-2.0
Adversarial Codebase Auditben-manes/caffeine18k—~1.9kAutomated safety check: NotesApache-2.0
Tbdjlevy/strif131—~3.5kAutomated safety check: PassMIT
Multi-Model Adversarial Reviewcursor/plugins10k8 repos~1.3kAutomated safety check: PassNone
Code Reviewsortie-ai/sortie196—~2.9kAutomated safety check: PassMIT
Multi-Persona Code Revieweric-tramel/moraine117—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Adversarial Codebase Audit

    ben-manes/caffeine

    Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.

    18k GitHub stars~1.9k tokensUpdated 2 days ago
    DevelopmentAuto-check: notes
  • Tbd

    jlevy/strif

    Git-native issue tracking (beads), coding guidelines, knowledge injection, and spec-driven planning for AI agents.

    131 GitHub stars~3.5k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Official

    Runs one read-only reviewer subagent per configured model against a diff to challenge a change, then synthesizes a single verdict without applying any fixes.

    10k GitHub starsUsed in 8 repos~1.3k tokens
    DevelopmentAuto-check passed
  • Code Review

    sortie-ai/sortie

    Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a…

    196 GitHub stars~2.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Multi-Persona Code Review

    eric-tramel/moraine

    Coordinates a delegated review of a Moraine PR or local change by seven focused reviewer subagents, merges their findings and follows up on the fixes.

    117 GitHub stars~1.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • GitHub Swarm Code Review

    ruvnet/agentic-flow

    Reviews GitHub pull requests with a swarm of specialized agents covering security, performance, architecture, style and accessibility, driven by the gh CLI and ruv-swarm.

    816 GitHub starsUsed in 6 repos~6.5k tokens
    DevelopmentAuto-check passed

Categories

Questions about OCR

What does OCR do?

AI-powered multi-agent code review. An agent skill from spencermarx/open-code-review. OCR is an agent skill from spencermarx/open-code-review. AI-powered multi-agent code review.

When should I use OCR?

OCR fits situations like: asked to review code; analyze changes; perform code review.

How do I install OCR in Claude Code?

Run `npx skills add spencermarx/open-code-review --skill ocr -a claude-code`. Or copy the skill folder (.ocr/skills in spencermarx/open-code-review) into .claude/skills/ocr in your project. Claude Code loads it when a task matches its description.

How do I install OCR in Codex?

Run `npx skills add spencermarx/open-code-review --skill ocr -a codex`. Or copy the skill folder (.ocr/skills in spencermarx/open-code-review) into .agents/skills/ocr in your project. Codex loads it when a task matches its description.

Can I use OCR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spencermarx/open-code-review --skill ocr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ocr, .gemini/skills/ocr, .github/skills/ocr and .opencode/skills/ocr in your project.

What does OCR need to run?

SKILL.md names no scripts, command-line tools or credentials: OCR is instructions for the agent only. Compatibility (from SKILL.md): Designed for Claude Code, Cursor, Windsurf, and other Agent Skills-compatible environments. Requires git. Optional: gh CLI for GitHub integration. .

Does OCR access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is OCR safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does OCR use?

OCR is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does OCR use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 62k tokens, read only when the agent opens those files.

What are the alternatives to OCR?

Skills that share tags, products or a category with OCR: Adversarial Codebase Audit (ben-manes/caffeine, 18k stars), Tbd (jlevy/strif, 131 stars), Multi-Model Adversarial Review (cursor/plugins, 10k stars) and Code Review (sortie-ai/sortie, 196 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains OCR?

spencermarx (a GitHub user) maintains it in spencermarx/open-code-review, which has 371 GitHub stars. The repository was last updated on July 28, 2026.

Source: spencermarx/open-code-review on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.