Creator · alibaba
Last updated · Sep 4, 2026
Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in fine-tuned ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
Creator · alibaba
Last updated · Sep 4, 2026
Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in fine-tuned ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
Creator · alibaba
Last updated · Sep 4, 2026
Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in fine-tuned ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
Creator · alibaba
Last updated · Sep 4, 2026
Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in fine-tuned ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
Do not auto-install
Install targets
Codex install prompt
Install the "Open Code Review" agent skill from https://github.com/alibaba/open-code-review/tree/main/skills/open-code-review. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in fine-tuned ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"alibaba-open-code-review","task":"Install Open Code Review","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + OpenAI Agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add alibaba/open-code-review
Maintenance
fresh
11d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
22K
100/100 Quality · 84/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
22K GitHub stars
Repo activity
22K stars, 1.6K forks
Maintenance
11d since push
License
Apache-2.0
Install
npx skills add alibaba/open-code-review
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add alibaba/open-code-reviewDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/alibaba-open-code-review/install
Agent should check
Copy prompt
Task: Use Open Code Review in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alibaba-open-code-review/install
Install command: npx skills add alibaba/open-code-review
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/alibaba-open-code-review/install
LLM text format
/api/skills/alibaba-open-code-review/install?format=text
Find alternatives
/api/skills/search?q=Open%20Code%20Review&limit=3
Agent prompt
Use Open Code Review for this task. Review https://www.openagentskill.com/api/skills/alibaba-open-code-review/install, then install with: npx skills add alibaba/open-code-reviewRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/alibaba-open-code-review
LLM text
/api/registry/manifest/alibaba-open-code-review?format=text
Install alias
/api/registry/install/alibaba-open-code-review
Recommend
/api/registry/recommend?task=Use%20Open%20Code%20Review%20in%20an%20agent%20workflow&limit=3
Agent fit
GitHub automation
Use-case tags
Platforms
Go, Code Review, Claude Code, OpenAI Agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
GitHub automation
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
PASS22K GitHub stars
Stars/forks activity
PASS22K stars, 1.6K forks; issue activity unavailable in current metadata
Recent maintenance
PASS11d since push
License clarity
PASSApache-2.0
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow fit
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Alternative shortlist
Similar skills that may fit this task.
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
A tool that converts codebases, SQL schemas, and other files into queryable knowledge graphs for AI coding assistants.
Pre-indexed code knowledge graph for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, and Hermes Agent — fewer tokens, fewer tool calls, 100% local
--- name: open-code-review description: > Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns. license: Apache-2.0 compatibility: > Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Requires a configured LLM (Anthropic or OpenAI-compatible) before first run. metadata: author: alibaba homepage: https://github.com/alibaba/open-code-review version: "1.0.0" ---
# Open Code Review
A skill for invoking [open-code-review](https://github.com/alibaba/open-code-review) (`ocr`) — an open-source AI code review CLI that reads Git diffs and generates structured, line-level review comments.
## Workflow
### Step 1: Gather Business Context
Analyze the review target (commits, branch, or changes) to extract concise business context. Pass this context via `--background` to improve review quality.
### Step 2: Run Code Review
Run the OCR command with appropriate flags. **Always pass business context via `--background`** when available:
```bash ocr review --audience agent --background "business context here" [user-args] ```
**Argument handling:**
- **Background context** (RECOMMENDED): use `--background "context"` or `-b "context"` to provide business context for better review quality - **Default** (no user arguments): reviews staged, unstaged, and untracked changes (workspace mode) - **Specific commit**: use `--commit` or `-c` to review a single commit against its parent - **Branch comparison**: use `--from <ref>` and `--to <ref>` to review diff between two refs - **Timeout**: default timeout is 15 minutes per file; adjust with `--timeout <minutes>` - **Concurrency**: default concurrency is 8 file workers; reduce with `--concurrency <n>` if rate limits are hit - **Preview mode**: use `--preview` or `-p` to preview which files will be reviewed without running the LLM - **Installation**: if `ocr` command is not found, install it by running `npm i -g @alibaba-group/open-code-review`
**Common invocation patterns:**
| User says | Command to run | |-----------|---------------| | "review my changes" / "review the working copy" | `ocr review --audience agent -b "context"` | | "review this PR" / "review feature branch" | `ocr review --audience agent -b "context" --from main --to <branch>` | | "review commit abc123" | `ocr review --audience agent -b "context" --commit abc123` | | "what would be reviewed?" (dry-run) | `ocr review --preview` |
**Output mode:**
- Always use `--audience agent` to suppress progress UI and emit only the final summary - **Prevent output truncation**: For large reviews or restricted tool environments, redirect output to a temporary file (`ocr review --audience agent ... > /tmp/ocr_out.txt 2>&1`) and inspect it in full via a file reading tool instead of piping through `tail` or `head`, which drops earlier review comments.
**On failure:** If `ocr review` exits non-zero (e.g. an LLM connection error), do not retry blindly — consult the Troubleshooting section below for the matching fix before re-running.
### Step 3: Report
OCR output includes structured `severity` (critical / high / medium / low) and `category` (bug / security / performance / maintainability / test / style / documentation / other) on each comment. Present results grouped by severity, discarding `low` severity items that are likely false positives or nitpicks.
### Step 4: Fix
Before applying fixes, check whether the user requested automatic fixes:
- If the user explicitly requested "review and fix" or similar, proceed with automatic fixes - If the user only requested "review" without fix intent, ask for permission before applying any changes
When fixing issues and suggestions:
- Focus on critical, high, and medium severity items - Apply fixes directly to the code when safe and well-defined - For complex fixes requiring manual intervention, clearly describe what needs to be done - Always verify fixes with the user before committing
## Output Format
Each comment in OCR's output contains:
- `path`: File path - `content`: Review comment text - `start_line` / `end_line`: Line range (both 0 means positioning failed) - `category`: Issue category (bug, security, performance, maintainability, test, style, documentation, other) - `severity`: Issue severity (critical, high, medium, low) - `suggestion_code`: Optional fix suggestion - `existing_code`: Optional original code snippet - `thinking`: Optional LLM reasoning process
Present results grouped by severity using this template:
```markdown ## Code Review Results
**Files reviewed**: N **Issues found**: X critical, Y high, Z medium
### Critical
- **`path/to/file.java:42`** [bug] — Brief description > Recommendation: How to fix
### High
- **`path/to/file.java:26`** [bug] — Brief description > Recommendation: How to fix
### Medium
- **`path/to/file.ts:88`** [performance] — Brief description > Recommendation: How to fix (if applicable) ```
If no critical, high, or medium severity issues remain after filtering, state: "Review complete — no critical, high, or medium issues found in N files."
**Handling mispositioned comments:**
When `start_line` and `end_line` are both `0`, the comment failed to locate the exact position in the file. In such cases:
1. Read the comment content to understand the issue 2. Examine the target file mentioned in the comment 3. Identify the relevant code section based on the comment's context 4. Apply the fix or suggestion to the correct location
## Custom Review Rules
If the user wants project-specific rules, OCR resolves them in this priority order:
1. `--rule <path>` flag (highest) 2. `<repo>/.opencodereview/rule.json` 3. `~/.opencodereview/rule.json` 4. Built-in system defaults (lowest)
By default, the first matching user rule replaces the built-in system rule. Set `merge_system_rule: true` on a rule entry when the matched system rule and user rule should both be included.
Rule file format:
```json { "rules": [ { "path": "**/*.java", "rule": "All new methods must validate required parameters for null", "merge_system_rule": true }, { "path": "**/*mapper*.xml", "rule": "Check SQL for injection risks and missing closing tags" } ] } ```
To preview which rule applies to a file before reviewing:
```bash ocr rules check src/main/java/com/example/Foo.java ```
## Gotchas
- **LLM must be configured first** — `ocr review` will fail loudly if no LLM is reachable. See the Troubleshooting section below if this happens. - **Working directory matters** — `ocr review` operates on the Git repo at the current directory. Use `--repo /path/to/repo` to run from elsewhere. - **Untracked files are reviewed in workspace mode** — running bare `ocr review` includes staged, unstaged, *and* untracked changes. Stage selectively if you want narrower scope. - **Large diffs may hit token limits** — files with very large diffs may be truncated. The default `MAX_TOKENS` is 58888 per request. - **Plan phase triggers at 50 lines** — diffs exceeding 50 changed lines run an extra risk-analysis phase before main review. This adds latency but improves quality. - **Don't pass `--audience human`** — it streams progress UI that pollutes output. Always use `--audience agent`. - **Comment language follows config** — set `language` config to `English` or `Chinese` (default: Chinese) to control review comment language. - **Avoid output truncation** — Large review runs produce verbose output. Never pipe command output to `tail` or `head` as it drops review comments from earlier sections. Redirect output to a file and read it in full.
## Validation
After the review completes, verify success by checking:
1. The command exited with code 0 2. Comments were generated (or "No comments generated" message appears) 3. Warnings (if any) are displayed in stderr
If errors occurred, check the stderr warnings for details about which files failed and why.
## Troubleshooting
**`ocr: command not found`**
Install the CLI:
```bash npm install -g @alibaba-group/open-code-review ```
**`ocr review` fails with LLM connection error**
Prompt the user to configure an LLM provider.
Interactive setup (recommended):
```bash ocr config provider ```
Manual setup (alternative):
```bash ocr config set llm.url https://api.anthropic.com/v1/messages ocr config set llm.auth_token <api-key> ocr config set llm.model claude-opus-4-6 ocr config set llm.use_anthropic true ```
Verify connectivity with `ocr llm test`. Stop here and ask the user to provide credentials — never invent or hardcode API keys.
## References
- Full docs: https://github.com/alibaba/open-code-review - NPM package: https://www.npmjs.com/package/@alibaba-group/open-code-review - Issue tracker: https://github.com/alibaba/open-code-review/issues
Frameworks & tools
Decision snapshot
21,505 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
Early agent signal: 1 outcome, 0% success, Agent Proven Score 7/100.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Open Code Review, ready for a manual X post.
Open Code Review: Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool:... 21.5K stars https://www.openagentskill.com/skills/alibaba-open-code-review?ref=x
Listing + install path for Open Code Review: https://www.openagentskill.com/skills/alibaba-open-code-review?ref=x Install: npx skills add alibaba/open-code-review
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Community indexed listing is attributed to alibaba but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alibaba-open-code-review/audit)
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)alibaba✓
@alibaba
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
Andrej Karpathy Skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
175.2K StarsCaveman
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
97.4K StarsGraphify
A tool that converts codebases, SQL schemas, and other files into queryable knowledge graphs for AI coding assistants.
92.0K StarsCodegraph
Pre-indexed code knowledge graph for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, and Hermes Agent — fewer tokens, fewer tool calls, 100% local
54.2K StarsDo not auto-install
Install targets
Codex install prompt
Install the "Open Code Review" agent skill from https://github.com/alibaba/open-code-review/tree/main/skills/open-code-review. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in fine-tuned ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"alibaba-open-code-review","task":"Install Open Code Review","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + OpenAI Agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add alibaba/open-code-review
Maintenance
fresh
11d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
22K
100/100 Quality · 84/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
22K GitHub stars
Repo activity
22K stars, 1.6K forks
Maintenance
11d since push
License
Apache-2.0
Install
npx skills add alibaba/open-code-review
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add alibaba/open-code-reviewDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/alibaba-open-code-review/install
Agent should check
Copy prompt
Task: Use Open Code Review in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alibaba-open-code-review/install
Install command: npx skills add alibaba/open-code-review
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/alibaba-open-code-review/install
LLM text format
/api/skills/alibaba-open-code-review/install?format=text
Find alternatives
/api/skills/search?q=Open%20Code%20Review&limit=3
Agent prompt
Use Open Code Review for this task. Review https://www.openagentskill.com/api/skills/alibaba-open-code-review/install, then install with: npx skills add alibaba/open-code-reviewRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/alibaba-open-code-review
LLM text
/api/registry/manifest/alibaba-open-code-review?format=text
Install alias
/api/registry/install/alibaba-open-code-review
Recommend
/api/registry/recommend?task=Use%20Open%20Code%20Review%20in%20an%20agent%20workflow&limit=3
Agent fit
GitHub automation
Use-case tags
Platforms
Go, Code Review, Claude Code, OpenAI Agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
GitHub automation
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
PASS22K GitHub stars
Stars/forks activity
PASS22K stars, 1.6K forks; issue activity unavailable in current metadata
Recent maintenance
PASS11d since push
License clarity
PASSApache-2.0
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow fit
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Alternative shortlist
Similar skills that may fit this task.
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
A tool that converts codebases, SQL schemas, and other files into queryable knowledge graphs for AI coding assistants.
Pre-indexed code knowledge graph for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, and Hermes Agent — fewer tokens, fewer tool calls, 100% local
--- name: open-code-review description: > Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns. license: Apache-2.0 compatibility: > Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Requires a configured LLM (Anthropic or OpenAI-compatible) before first run. metadata: author: alibaba homepage: https://github.com/alibaba/open-code-review version: "1.0.0" ---
# Open Code Review
A skill for invoking [open-code-review](https://github.com/alibaba/open-code-review) (`ocr`) — an open-source AI code review CLI that reads Git diffs and generates structured, line-level review comments.
## Workflow
### Step 1: Gather Business Context
Analyze the review target (commits, branch, or changes) to extract concise business context. Pass this context via `--background` to improve review quality.
### Step 2: Run Code Review
Run the OCR command with appropriate flags. **Always pass business context via `--background`** when available:
```bash ocr review --audience agent --background "business context here" [user-args] ```
**Argument handling:**
- **Background context** (RECOMMENDED): use `--background "context"` or `-b "context"` to provide business context for better review quality - **Default** (no user arguments): reviews staged, unstaged, and untracked changes (workspace mode) - **Specific commit**: use `--commit` or `-c` to review a single commit against its parent - **Branch comparison**: use `--from <ref>` and `--to <ref>` to review diff between two refs - **Timeout**: default timeout is 15 minutes per file; adjust with `--timeout <minutes>` - **Concurrency**: default concurrency is 8 file workers; reduce with `--concurrency <n>` if rate limits are hit - **Preview mode**: use `--preview` or `-p` to preview which files will be reviewed without running the LLM - **Installation**: if `ocr` command is not found, install it by running `npm i -g @alibaba-group/open-code-review`
**Common invocation patterns:**
| User says | Command to run | |-----------|---------------| | "review my changes" / "review the working copy" | `ocr review --audience agent -b "context"` | | "review this PR" / "review feature branch" | `ocr review --audience agent -b "context" --from main --to <branch>` | | "review commit abc123" | `ocr review --audience agent -b "context" --commit abc123` | | "what would be reviewed?" (dry-run) | `ocr review --preview` |
**Output mode:**
- Always use `--audience agent` to suppress progress UI and emit only the final summary - **Prevent output truncation**: For large reviews or restricted tool environments, redirect output to a temporary file (`ocr review --audience agent ... > /tmp/ocr_out.txt 2>&1`) and inspect it in full via a file reading tool instead of piping through `tail` or `head`, which drops earlier review comments.
**On failure:** If `ocr review` exits non-zero (e.g. an LLM connection error), do not retry blindly — consult the Troubleshooting section below for the matching fix before re-running.
### Step 3: Report
OCR output includes structured `severity` (critical / high / medium / low) and `category` (bug / security / performance / maintainability / test / style / documentation / other) on each comment. Present results grouped by severity, discarding `low` severity items that are likely false positives or nitpicks.
### Step 4: Fix
Before applying fixes, check whether the user requested automatic fixes:
- If the user explicitly requested "review and fix" or similar, proceed with automatic fixes - If the user only requested "review" without fix intent, ask for permission before applying any changes
When fixing issues and suggestions:
- Focus on critical, high, and medium severity items - Apply fixes directly to the code when safe and well-defined - For complex fixes requiring manual intervention, clearly describe what needs to be done - Always verify fixes with the user before committing
## Output Format
Each comment in OCR's output contains:
- `path`: File path - `content`: Review comment text - `start_line` / `end_line`: Line range (both 0 means positioning failed) - `category`: Issue category (bug, security, performance, maintainability, test, style, documentation, other) - `severity`: Issue severity (critical, high, medium, low) - `suggestion_code`: Optional fix suggestion - `existing_code`: Optional original code snippet - `thinking`: Optional LLM reasoning process
Present results grouped by severity using this template:
```markdown ## Code Review Results
**Files reviewed**: N **Issues found**: X critical, Y high, Z medium
### Critical
- **`path/to/file.java:42`** [bug] — Brief description > Recommendation: How to fix
### High
- **`path/to/file.java:26`** [bug] — Brief description > Recommendation: How to fix
### Medium
- **`path/to/file.ts:88`** [performance] — Brief description > Recommendation: How to fix (if applicable) ```
If no critical, high, or medium severity issues remain after filtering, state: "Review complete — no critical, high, or medium issues found in N files."
**Handling mispositioned comments:**
When `start_line` and `end_line` are both `0`, the comment failed to locate the exact position in the file. In such cases:
1. Read the comment content to understand the issue 2. Examine the target file mentioned in the comment 3. Identify the relevant code section based on the comment's context 4. Apply the fix or suggestion to the correct location
## Custom Review Rules
If the user wants project-specific rules, OCR resolves them in this priority order:
1. `--rule <path>` flag (highest) 2. `<repo>/.opencodereview/rule.json` 3. `~/.opencodereview/rule.json` 4. Built-in system defaults (lowest)
By default, the first matching user rule replaces the built-in system rule. Set `merge_system_rule: true` on a rule entry when the matched system rule and user rule should both be included.
Rule file format:
```json { "rules": [ { "path": "**/*.java", "rule": "All new methods must validate required parameters for null", "merge_system_rule": true }, { "path": "**/*mapper*.xml", "rule": "Check SQL for injection risks and missing closing tags" } ] } ```
To preview which rule applies to a file before reviewing:
```bash ocr rules check src/main/java/com/example/Foo.java ```
## Gotchas
- **LLM must be configured first** — `ocr review` will fail loudly if no LLM is reachable. See the Troubleshooting section below if this happens. - **Working directory matters** — `ocr review` operates on the Git repo at the current directory. Use `--repo /path/to/repo` to run from elsewhere. - **Untracked files are reviewed in workspace mode** — running bare `ocr review` includes staged, unstaged, *and* untracked changes. Stage selectively if you want narrower scope. - **Large diffs may hit token limits** — files with very large diffs may be truncated. The default `MAX_TOKENS` is 58888 per request. - **Plan phase triggers at 50 lines** — diffs exceeding 50 changed lines run an extra risk-analysis phase before main review. This adds latency but improves quality. - **Don't pass `--audience human`** — it streams progress UI that pollutes output. Always use `--audience agent`. - **Comment language follows config** — set `language` config to `English` or `Chinese` (default: Chinese) to control review comment language. - **Avoid output truncation** — Large review runs produce verbose output. Never pipe command output to `tail` or `head` as it drops review comments from earlier sections. Redirect output to a file and read it in full.
## Validation
After the review completes, verify success by checking:
1. The command exited with code 0 2. Comments were generated (or "No comments generated" message appears) 3. Warnings (if any) are displayed in stderr
If errors occurred, check the stderr warnings for details about which files failed and why.
## Troubleshooting
**`ocr: command not found`**
Install the CLI:
```bash npm install -g @alibaba-group/open-code-review ```
**`ocr review` fails with LLM connection error**
Prompt the user to configure an LLM provider.
Interactive setup (recommended):
```bash ocr config provider ```
Manual setup (alternative):
```bash ocr config set llm.url https://api.anthropic.com/v1/messages ocr config set llm.auth_token <api-key> ocr config set llm.model claude-opus-4-6 ocr config set llm.use_anthropic true ```
Verify connectivity with `ocr llm test`. Stop here and ask the user to provide credentials — never invent or hardcode API keys.
## References
- Full docs: https://github.com/alibaba/open-code-review - NPM package: https://www.npmjs.com/package/@alibaba-group/open-code-review - Issue tracker: https://github.com/alibaba/open-code-review/issues
Frameworks & tools
Decision snapshot
21,505 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
Early agent signal: 1 outcome, 0% success, Agent Proven Score 7/100.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Open Code Review, ready for a manual X post.
Open Code Review: Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool:... 21.5K stars https://www.openagentskill.com/skills/alibaba-open-code-review?ref=x
Listing + install path for Open Code Review: https://www.openagentskill.com/skills/alibaba-open-code-review?ref=x Install: npx skills add alibaba/open-code-review
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Community indexed listing is attributed to alibaba but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alibaba-open-code-review/audit)
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)alibaba✓
@alibaba
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
Andrej Karpathy Skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
175.2K StarsCaveman
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
97.4K StarsGraphify
A tool that converts codebases, SQL schemas, and other files into queryable knowledge graphs for AI coding assistants.
92.0K StarsCodegraph
Pre-indexed code knowledge graph for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, and Hermes Agent — fewer tokens, fewer tool calls, 100% local
54.2K StarsDo not auto-install
Install targets
Codex install prompt
Install the "Open Code Review" agent skill from https://github.com/alibaba/open-code-review/tree/main/skills/open-code-review. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in fine-tuned ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"alibaba-open-code-review","task":"Install Open Code Review","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + OpenAI Agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add alibaba/open-code-review
Maintenance
fresh
11d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
22K
100/100 Quality · 84/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
22K GitHub stars
Repo activity
22K stars, 1.6K forks
Maintenance
11d since push
License
Apache-2.0
Install
npx skills add alibaba/open-code-review
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add alibaba/open-code-reviewDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/alibaba-open-code-review/install
Agent should check
Copy prompt
Task: Use Open Code Review in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alibaba-open-code-review/install
Install command: npx skills add alibaba/open-code-review
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/alibaba-open-code-review/install
LLM text format
/api/skills/alibaba-open-code-review/install?format=text
Find alternatives
/api/skills/search?q=Open%20Code%20Review&limit=3
Agent prompt
Use Open Code Review for this task. Review https://www.openagentskill.com/api/skills/alibaba-open-code-review/install, then install with: npx skills add alibaba/open-code-reviewRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/alibaba-open-code-review
LLM text
/api/registry/manifest/alibaba-open-code-review?format=text
Install alias
/api/registry/install/alibaba-open-code-review
Recommend
/api/registry/recommend?task=Use%20Open%20Code%20Review%20in%20an%20agent%20workflow&limit=3
Agent fit
GitHub automation
Use-case tags
Platforms
Go, Code Review, Claude Code, OpenAI Agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
GitHub automation
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
PASS22K GitHub stars
Stars/forks activity
PASS22K stars, 1.6K forks; issue activity unavailable in current metadata
Recent maintenance
PASS11d since push
License clarity
PASSApache-2.0
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow fit
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Alternative shortlist
Similar skills that may fit this task.
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
A tool that converts codebases, SQL schemas, and other files into queryable knowledge graphs for AI coding assistants.
Pre-indexed code knowledge graph for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, and Hermes Agent — fewer tokens, fewer tool calls, 100% local
--- name: open-code-review description: > Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns. license: Apache-2.0 compatibility: > Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Requires a configured LLM (Anthropic or OpenAI-compatible) before first run. metadata: author: alibaba homepage: https://github.com/alibaba/open-code-review version: "1.0.0" ---
# Open Code Review
A skill for invoking [open-code-review](https://github.com/alibaba/open-code-review) (`ocr`) — an open-source AI code review CLI that reads Git diffs and generates structured, line-level review comments.
## Workflow
### Step 1: Gather Business Context
Analyze the review target (commits, branch, or changes) to extract concise business context. Pass this context via `--background` to improve review quality.
### Step 2: Run Code Review
Run the OCR command with appropriate flags. **Always pass business context via `--background`** when available:
```bash ocr review --audience agent --background "business context here" [user-args] ```
**Argument handling:**
- **Background context** (RECOMMENDED): use `--background "context"` or `-b "context"` to provide business context for better review quality - **Default** (no user arguments): reviews staged, unstaged, and untracked changes (workspace mode) - **Specific commit**: use `--commit` or `-c` to review a single commit against its parent - **Branch comparison**: use `--from <ref>` and `--to <ref>` to review diff between two refs - **Timeout**: default timeout is 15 minutes per file; adjust with `--timeout <minutes>` - **Concurrency**: default concurrency is 8 file workers; reduce with `--concurrency <n>` if rate limits are hit - **Preview mode**: use `--preview` or `-p` to preview which files will be reviewed without running the LLM - **Installation**: if `ocr` command is not found, install it by running `npm i -g @alibaba-group/open-code-review`
**Common invocation patterns:**
| User says | Command to run | |-----------|---------------| | "review my changes" / "review the working copy" | `ocr review --audience agent -b "context"` | | "review this PR" / "review feature branch" | `ocr review --audience agent -b "context" --from main --to <branch>` | | "review commit abc123" | `ocr review --audience agent -b "context" --commit abc123` | | "what would be reviewed?" (dry-run) | `ocr review --preview` |
**Output mode:**
- Always use `--audience agent` to suppress progress UI and emit only the final summary - **Prevent output truncation**: For large reviews or restricted tool environments, redirect output to a temporary file (`ocr review --audience agent ... > /tmp/ocr_out.txt 2>&1`) and inspect it in full via a file reading tool instead of piping through `tail` or `head`, which drops earlier review comments.
**On failure:** If `ocr review` exits non-zero (e.g. an LLM connection error), do not retry blindly — consult the Troubleshooting section below for the matching fix before re-running.
### Step 3: Report
OCR output includes structured `severity` (critical / high / medium / low) and `category` (bug / security / performance / maintainability / test / style / documentation / other) on each comment. Present results grouped by severity, discarding `low` severity items that are likely false positives or nitpicks.
### Step 4: Fix
Before applying fixes, check whether the user requested automatic fixes:
- If the user explicitly requested "review and fix" or similar, proceed with automatic fixes - If the user only requested "review" without fix intent, ask for permission before applying any changes
When fixing issues and suggestions:
- Focus on critical, high, and medium severity items - Apply fixes directly to the code when safe and well-defined - For complex fixes requiring manual intervention, clearly describe what needs to be done - Always verify fixes with the user before committing
## Output Format
Each comment in OCR's output contains:
- `path`: File path - `content`: Review comment text - `start_line` / `end_line`: Line range (both 0 means positioning failed) - `category`: Issue category (bug, security, performance, maintainability, test, style, documentation, other) - `severity`: Issue severity (critical, high, medium, low) - `suggestion_code`: Optional fix suggestion - `existing_code`: Optional original code snippet - `thinking`: Optional LLM reasoning process
Present results grouped by severity using this template:
```markdown ## Code Review Results
**Files reviewed**: N **Issues found**: X critical, Y high, Z medium
### Critical
- **`path/to/file.java:42`** [bug] — Brief description > Recommendation: How to fix
### High
- **`path/to/file.java:26`** [bug] — Brief description > Recommendation: How to fix
### Medium
- **`path/to/file.ts:88`** [performance] — Brief description > Recommendation: How to fix (if applicable) ```
If no critical, high, or medium severity issues remain after filtering, state: "Review complete — no critical, high, or medium issues found in N files."
**Handling mispositioned comments:**
When `start_line` and `end_line` are both `0`, the comment failed to locate the exact position in the file. In such cases:
1. Read the comment content to understand the issue 2. Examine the target file mentioned in the comment 3. Identify the relevant code section based on the comment's context 4. Apply the fix or suggestion to the correct location
## Custom Review Rules
If the user wants project-specific rules, OCR resolves them in this priority order:
1. `--rule <path>` flag (highest) 2. `<repo>/.opencodereview/rule.json` 3. `~/.opencodereview/rule.json` 4. Built-in system defaults (lowest)
By default, the first matching user rule replaces the built-in system rule. Set `merge_system_rule: true` on a rule entry when the matched system rule and user rule should both be included.
Rule file format:
```json { "rules": [ { "path": "**/*.java", "rule": "All new methods must validate required parameters for null", "merge_system_rule": true }, { "path": "**/*mapper*.xml", "rule": "Check SQL for injection risks and missing closing tags" } ] } ```
To preview which rule applies to a file before reviewing:
```bash ocr rules check src/main/java/com/example/Foo.java ```
## Gotchas
- **LLM must be configured first** — `ocr review` will fail loudly if no LLM is reachable. See the Troubleshooting section below if this happens. - **Working directory matters** — `ocr review` operates on the Git repo at the current directory. Use `--repo /path/to/repo` to run from elsewhere. - **Untracked files are reviewed in workspace mode** — running bare `ocr review` includes staged, unstaged, *and* untracked changes. Stage selectively if you want narrower scope. - **Large diffs may hit token limits** — files with very large diffs may be truncated. The default `MAX_TOKENS` is 58888 per request. - **Plan phase triggers at 50 lines** — diffs exceeding 50 changed lines run an extra risk-analysis phase before main review. This adds latency but improves quality. - **Don't pass `--audience human`** — it streams progress UI that pollutes output. Always use `--audience agent`. - **Comment language follows config** — set `language` config to `English` or `Chinese` (default: Chinese) to control review comment language. - **Avoid output truncation** — Large review runs produce verbose output. Never pipe command output to `tail` or `head` as it drops review comments from earlier sections. Redirect output to a file and read it in full.
## Validation
After the review completes, verify success by checking:
1. The command exited with code 0 2. Comments were generated (or "No comments generated" message appears) 3. Warnings (if any) are displayed in stderr
If errors occurred, check the stderr warnings for details about which files failed and why.
## Troubleshooting
**`ocr: command not found`**
Install the CLI:
```bash npm install -g @alibaba-group/open-code-review ```
**`ocr review` fails with LLM connection error**
Prompt the user to configure an LLM provider.
Interactive setup (recommended):
```bash ocr config provider ```
Manual setup (alternative):
```bash ocr config set llm.url https://api.anthropic.com/v1/messages ocr config set llm.auth_token <api-key> ocr config set llm.model claude-opus-4-6 ocr config set llm.use_anthropic true ```
Verify connectivity with `ocr llm test`. Stop here and ask the user to provide credentials — never invent or hardcode API keys.
## References
- Full docs: https://github.com/alibaba/open-code-review - NPM package: https://www.npmjs.com/package/@alibaba-group/open-code-review - Issue tracker: https://github.com/alibaba/open-code-review/issues
Frameworks & tools
Decision snapshot
21,505 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
Early agent signal: 1 outcome, 0% success, Agent Proven Score 7/100.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Open Code Review, ready for a manual X post.
Open Code Review: Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool:... 21.5K stars https://www.openagentskill.com/skills/alibaba-open-code-review?ref=x
Listing + install path for Open Code Review: https://www.openagentskill.com/skills/alibaba-open-code-review?ref=x Install: npx skills add alibaba/open-code-review
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Community indexed listing is attributed to alibaba but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alibaba-open-code-review/audit)
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)alibaba✓
@alibaba
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
Andrej Karpathy Skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
175.2K StarsCaveman
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
97.4K StarsGraphify
A tool that converts codebases, SQL schemas, and other files into queryable knowledge graphs for AI coding assistants.
92.0K StarsCodegraph
Pre-indexed code knowledge graph for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, and Hermes Agent — fewer tokens, fewer tool calls, 100% local
54.2K StarsDo not auto-install
Install targets
Codex install prompt
Install the "Open Code Review" agent skill from https://github.com/alibaba/open-code-review/tree/main/skills/open-code-review. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in fine-tuned ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"alibaba-open-code-review","task":"Install Open Code Review","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + OpenAI Agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add alibaba/open-code-review
Maintenance
fresh
11d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
22K
100/100 Quality · 84/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
22K GitHub stars
Repo activity
22K stars, 1.6K forks
Maintenance
11d since push
License
Apache-2.0
Install
npx skills add alibaba/open-code-review
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add alibaba/open-code-reviewDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/alibaba-open-code-review/install
Agent should check
Copy prompt
Task: Use Open Code Review in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Open%20Code%20Review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alibaba-open-code-review/install
Install command: npx skills add alibaba/open-code-review
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/alibaba-open-code-review/install
LLM text format
/api/skills/alibaba-open-code-review/install?format=text
Find alternatives
/api/skills/search?q=Open%20Code%20Review&limit=3
Agent prompt
Use Open Code Review for this task. Review https://www.openagentskill.com/api/skills/alibaba-open-code-review/install, then install with: npx skills add alibaba/open-code-reviewRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/alibaba-open-code-review
LLM text
/api/registry/manifest/alibaba-open-code-review?format=text
Install alias
/api/registry/install/alibaba-open-code-review
Recommend
/api/registry/recommend?task=Use%20Open%20Code%20Review%20in%20an%20agent%20workflow&limit=3
Agent fit
GitHub automation
Use-case tags
Platforms
Go, Code Review, Claude Code, OpenAI Agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
GitHub automation
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
PASS22K GitHub stars
Stars/forks activity
PASS22K stars, 1.6K forks; issue activity unavailable in current metadata
Recent maintenance
PASS11d since push
License clarity
PASSApache-2.0
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow fit
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Alternative shortlist
Similar skills that may fit this task.
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
A tool that converts codebases, SQL schemas, and other files into queryable knowledge graphs for AI coding assistants.
Pre-indexed code knowledge graph for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, and Hermes Agent — fewer tokens, fewer tool calls, 100% local
--- name: open-code-review description: > Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns. license: Apache-2.0 compatibility: > Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Requires a configured LLM (Anthropic or OpenAI-compatible) before first run. metadata: author: alibaba homepage: https://github.com/alibaba/open-code-review version: "1.0.0" ---
# Open Code Review
A skill for invoking [open-code-review](https://github.com/alibaba/open-code-review) (`ocr`) — an open-source AI code review CLI that reads Git diffs and generates structured, line-level review comments.
## Workflow
### Step 1: Gather Business Context
Analyze the review target (commits, branch, or changes) to extract concise business context. Pass this context via `--background` to improve review quality.
### Step 2: Run Code Review
Run the OCR command with appropriate flags. **Always pass business context via `--background`** when available:
```bash ocr review --audience agent --background "business context here" [user-args] ```
**Argument handling:**
- **Background context** (RECOMMENDED): use `--background "context"` or `-b "context"` to provide business context for better review quality - **Default** (no user arguments): reviews staged, unstaged, and untracked changes (workspace mode) - **Specific commit**: use `--commit` or `-c` to review a single commit against its parent - **Branch comparison**: use `--from <ref>` and `--to <ref>` to review diff between two refs - **Timeout**: default timeout is 15 minutes per file; adjust with `--timeout <minutes>` - **Concurrency**: default concurrency is 8 file workers; reduce with `--concurrency <n>` if rate limits are hit - **Preview mode**: use `--preview` or `-p` to preview which files will be reviewed without running the LLM - **Installation**: if `ocr` command is not found, install it by running `npm i -g @alibaba-group/open-code-review`
**Common invocation patterns:**
| User says | Command to run | |-----------|---------------| | "review my changes" / "review the working copy" | `ocr review --audience agent -b "context"` | | "review this PR" / "review feature branch" | `ocr review --audience agent -b "context" --from main --to <branch>` | | "review commit abc123" | `ocr review --audience agent -b "context" --commit abc123` | | "what would be reviewed?" (dry-run) | `ocr review --preview` |
**Output mode:**
- Always use `--audience agent` to suppress progress UI and emit only the final summary - **Prevent output truncation**: For large reviews or restricted tool environments, redirect output to a temporary file (`ocr review --audience agent ... > /tmp/ocr_out.txt 2>&1`) and inspect it in full via a file reading tool instead of piping through `tail` or `head`, which drops earlier review comments.
**On failure:** If `ocr review` exits non-zero (e.g. an LLM connection error), do not retry blindly — consult the Troubleshooting section below for the matching fix before re-running.
### Step 3: Report
OCR output includes structured `severity` (critical / high / medium / low) and `category` (bug / security / performance / maintainability / test / style / documentation / other) on each comment. Present results grouped by severity, discarding `low` severity items that are likely false positives or nitpicks.
### Step 4: Fix
Before applying fixes, check whether the user requested automatic fixes:
- If the user explicitly requested "review and fix" or similar, proceed with automatic fixes - If the user only requested "review" without fix intent, ask for permission before applying any changes
When fixing issues and suggestions:
- Focus on critical, high, and medium severity items - Apply fixes directly to the code when safe and well-defined - For complex fixes requiring manual intervention, clearly describe what needs to be done - Always verify fixes with the user before committing
## Output Format
Each comment in OCR's output contains:
- `path`: File path - `content`: Review comment text - `start_line` / `end_line`: Line range (both 0 means positioning failed) - `category`: Issue category (bug, security, performance, maintainability, test, style, documentation, other) - `severity`: Issue severity (critical, high, medium, low) - `suggestion_code`: Optional fix suggestion - `existing_code`: Optional original code snippet - `thinking`: Optional LLM reasoning process
Present results grouped by severity using this template:
```markdown ## Code Review Results
**Files reviewed**: N **Issues found**: X critical, Y high, Z medium
### Critical
- **`path/to/file.java:42`** [bug] — Brief description > Recommendation: How to fix
### High
- **`path/to/file.java:26`** [bug] — Brief description > Recommendation: How to fix
### Medium
- **`path/to/file.ts:88`** [performance] — Brief description > Recommendation: How to fix (if applicable) ```
If no critical, high, or medium severity issues remain after filtering, state: "Review complete — no critical, high, or medium issues found in N files."
**Handling mispositioned comments:**
When `start_line` and `end_line` are both `0`, the comment failed to locate the exact position in the file. In such cases:
1. Read the comment content to understand the issue 2. Examine the target file mentioned in the comment 3. Identify the relevant code section based on the comment's context 4. Apply the fix or suggestion to the correct location
## Custom Review Rules
If the user wants project-specific rules, OCR resolves them in this priority order:
1. `--rule <path>` flag (highest) 2. `<repo>/.opencodereview/rule.json` 3. `~/.opencodereview/rule.json` 4. Built-in system defaults (lowest)
By default, the first matching user rule replaces the built-in system rule. Set `merge_system_rule: true` on a rule entry when the matched system rule and user rule should both be included.
Rule file format:
```json { "rules": [ { "path": "**/*.java", "rule": "All new methods must validate required parameters for null", "merge_system_rule": true }, { "path": "**/*mapper*.xml", "rule": "Check SQL for injection risks and missing closing tags" } ] } ```
To preview which rule applies to a file before reviewing:
```bash ocr rules check src/main/java/com/example/Foo.java ```
## Gotchas
- **LLM must be configured first** — `ocr review` will fail loudly if no LLM is reachable. See the Troubleshooting section below if this happens. - **Working directory matters** — `ocr review` operates on the Git repo at the current directory. Use `--repo /path/to/repo` to run from elsewhere. - **Untracked files are reviewed in workspace mode** — running bare `ocr review` includes staged, unstaged, *and* untracked changes. Stage selectively if you want narrower scope. - **Large diffs may hit token limits** — files with very large diffs may be truncated. The default `MAX_TOKENS` is 58888 per request. - **Plan phase triggers at 50 lines** — diffs exceeding 50 changed lines run an extra risk-analysis phase before main review. This adds latency but improves quality. - **Don't pass `--audience human`** — it streams progress UI that pollutes output. Always use `--audience agent`. - **Comment language follows config** — set `language` config to `English` or `Chinese` (default: Chinese) to control review comment language. - **Avoid output truncation** — Large review runs produce verbose output. Never pipe command output to `tail` or `head` as it drops review comments from earlier sections. Redirect output to a file and read it in full.
## Validation
After the review completes, verify success by checking:
1. The command exited with code 0 2. Comments were generated (or "No comments generated" message appears) 3. Warnings (if any) are displayed in stderr
If errors occurred, check the stderr warnings for details about which files failed and why.
## Troubleshooting
**`ocr: command not found`**
Install the CLI:
```bash npm install -g @alibaba-group/open-code-review ```
**`ocr review` fails with LLM connection error**
Prompt the user to configure an LLM provider.
Interactive setup (recommended):
```bash ocr config provider ```
Manual setup (alternative):
```bash ocr config set llm.url https://api.anthropic.com/v1/messages ocr config set llm.auth_token <api-key> ocr config set llm.model claude-opus-4-6 ocr config set llm.use_anthropic true ```
Verify connectivity with `ocr llm test`. Stop here and ask the user to provide credentials — never invent or hardcode API keys.
## References
- Full docs: https://github.com/alibaba/open-code-review - NPM package: https://www.npmjs.com/package/@alibaba-group/open-code-review - Issue tracker: https://github.com/alibaba/open-code-review/issues
Frameworks & tools
Decision snapshot
21,505 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
Early agent signal: 1 outcome, 0% success, Agent Proven Score 7/100.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Open Code Review, ready for a manual X post.
Open Code Review: Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool:... 21.5K stars https://www.openagentskill.com/skills/alibaba-open-code-review?ref=x
Listing + install path for Open Code Review: https://www.openagentskill.com/skills/alibaba-open-code-review?ref=x Install: npx skills add alibaba/open-code-review
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Community indexed listing is attributed to alibaba but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/alibaba-open-code-review/audit)
[](https://www.openagentskill.com/skills/alibaba-open-code-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)alibaba✓
@alibaba
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
Andrej Karpathy Skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
175.2K StarsCaveman
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
97.4K StarsGraphify
A tool that converts codebases, SQL schemas, and other files into queryable knowledge graphs for AI coding assistants.
92.0K StarsCodegraph
Pre-indexed code knowledge graph for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, and Hermes Agent — fewer tokens, fewer tool calls, 100% local
54.2K Starsstandard package or runtime install path
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
Early agent signal: 0% success from 1 agent outcomes
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
standard package or runtime install path
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
Early agent signal: 0% success from 1 agent outcomes
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
standard package or runtime install path
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
Early agent signal: 0% success from 1 agent outcomes
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
standard package or runtime install path
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
Early agent signal: 0% success from 1 agent outcomes
Docs
Strong README/SKILL.md context
Risk summary
Install readiness