@alibaba

Ersteller · alibaba

Letzte Aktualisierung · 24. Aug. 2026

open-code-review-delegate

Prüfen · 67Im Registry indexiert

Delegation mode for open-code-review (OCR). Instead of OCR calling an LLM endpoint, this skill instructs the host agent to perform the code review itself, using OCR only for deterministic engineering: file selection and rule resolution. Use when the host agent should drive the re

OpenAgentSkill Trust Score
67/100

Nur Sandbox

Qualität91/100
Audit85/100
Stars21.3K
Verified installs0

Installationsziele

Codex-Installationsprompt

Install the "open-code-review-delegate" agent skill from https://github.com/alibaba/open-code-review/tree/main/skills/open-code-review-delegate. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Delegation mode for open-code-review (OCR). Instead of OCR calling an LLM endpoint, this skill instructs the host agent to perform the code review itself, using OCR only for deterministic engineering: file selection and rule resolution. Use when the host agent should drive the review with its own LLM capabilities. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"alibaba-open-code-review-delegate","task":"Install open-code-review-delegate","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.

Asset-Profil

Coding- und Entwickler-Agents

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Bereich ansehen

Szenario

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Agent-Fit

Claude Code + CLI + Codex

Geeignet für Codex, Claude Code, Cursor, CLI oder benutzerdefinierte Agents.

Installieren

Bereit

npx skills add alibaba/open-code-review --skill open-code-review-delegate

Wartung

Aktuell

Heute gepusht

Risiko

Prüfung nötig

Dependency or permission surface needs review

GitHub-Qualität

21K

91/100 Qualität · 75/100 Vertrauen

Abdeckungs-Tags

CodingGitHub automationCoding-Agentsagent-skill

Review-Notizen

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent-Adoptionskarte

Vertrauen, Audit und Installationsbereitschaft auf einen Blick

Diese Werte kombinieren öffentliche Repository-Metadaten, OpenAgentSkill-Reviewsignale, Wartungsaktualität und Installationsbereitschaft. Sie helfen bei der Vorauswahl, ersetzen aber keine menschliche Prüfung.

Qualität

Ausgezeichnet
91

High-confidence pick with strong adoption and healthy maintenance signals.

Vertrauen

Nur Sandbox
67

Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.

Audit

Prüfung nötig
85

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

OpenAgentSkill Trust Score v5

Menschliche Prüfung vor Installation

Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

21K GitHub-Stars

Repository-Aktivität

21K Stars und 1.6K Forks

Wartung

Heute gepusht

Lizenz

Apache-2.0

Installieren

npx skills add alibaba/open-code-review --skill open-code-review-delegate

Installationssicherheit

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsfläche

shell or command execution, filesystem or document access

Agent-Ergebnisse

Noch keine Agent-Ergebnisdaten

Dokumentation

Starker README/SKILL.md-Kontext

Risikoübersicht

Vor Produktion prüfen

  • The SKILL.md excerpt is truncated at the end, but the provided content is clear and complete for the described workflow.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • Dependency/runtime risk: command execution surface, external package install surface

Installationsbereitschaft

Installationspfad verfügbar

  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Lizenz ist angegeben
  • Noch keine Agent-Proven-Ergebnisbelege

Agent-lesbare Metadaten

Maschinenlesbare Entscheidungsdaten für diesen Skill.

Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.

View technical data+

Geeignete Aufgaben

  • GitHub automation-Workflows
  • Claude-Code-Teams
  • Teams, die GitHub-Adoptionssignale schätzen
  • Inspect repository metadata

Geeignete Agents

CodexClaude CodeCursorOpenAgentSkill CLICLI

Installationsentscheidung

Befehl
npx skills add alibaba/open-code-review --skill open-code-review-delegate
Richtlinie
Prüfen
Menschliche Prüfung
Ja

Vertrauen und Risiko

Vertrauen
67/100
Audit
85/100
Risikoebene
Prüfung nötig

Ergebnis-Loop

Endpoint
/api/agent/outcome
Event-ID
resolve
Ergebnisse
5

Installationsbefehl

npx skills add alibaba/open-code-review --skill open-code-review-delegate

Nicht verwenden, wenn

  • Teams, die ein vom Anbieter unterstütztes SLA benötigen
  • production agents without a repository review
  • The SKILL.md excerpt is truncated at the end, but the provided content is clear and complete for the described workflow.
  • No OpenAgentSkill engagement data yet
  • Hinweise auf Hochrisiko-Berechtigungen: Shell- oder Befehlsausführung

Agent-Sicherheit v2

57/100 · Vor Installation prüfen

ExperimentellPrüfen

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Per API auflösen

Hoch

Shell- oder Befehlsausführung

Die Skill-Metadaten verweisen auf Terminal-, CLI-, Shell-, Subprozess- oder Befehlsausführungs-Workflows.

Mittel

Netzwerkzugriff

Die Skill ruft wahrscheinlich Remote-Seiten, APIs, Repositories oder externe Dienste ab.

Mittel

Dateisystemzugriff

Die Skill kann Projektdateien, Dokumente, generierte Artefakte oder den lokalen Arbeitsbereich lesen oder schreiben.

  • Hinweise auf Hochrisiko-Berechtigungen: Shell- oder Befehlsausführung
  • Dependency or permission surface needs review

Agent-Auflösungsplan

Lass einen Agent die Eignung vor der Installation prüfen.

Die Resolve API liefert die beste Skill, Alternativen, Sicherheitsrichtlinien, Auditnotizen, Installationsziel und einen direkt nutzbaren Prompt.

Textplan öffnen

Agent sollte prüfen

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Prompt kopieren

Task: Use open-code-review-delegate in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20open-code-review-delegate%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/alibaba-open-code-review-delegate/install
Install command: npx skills add alibaba/open-code-review --skill open-code-review-delegate
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent-Übergabe

Gib dem Agent den Installationspfad, nicht noch ein Verzeichnis.

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

Installations-API öffnen

Agent-Prompt

Use open-code-review-delegate for this task. Review https://www.openagentskill.com/api/skills/alibaba-open-code-review-delegate/install, then install with: npx skills add alibaba/open-code-review --skill open-code-review-delegate

Registry-Metadaten

Agent-lesbares Profil für die automatische Skill-Auswahl.

Die Registry API stellt Entscheidungs-, Vertrauens-, Audit-, Use-Case- und Installationssignale ohne UI-Scraping bereit.

Manifest öffnen

Agent-Fit

100/100

GitHub automation

Plattformen

Claude Code

Audit-Bericht

Prüfung nötig · 85/100

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

Audit-Bericht ansehenEval-Bericht ansehen

Agent-Entscheidungspanel

Primäre Wahl für GitHub automation

Use this as a leading candidate, then validate the README and install path in your own agent stack.

100
Bereitschaft
Übernehmen
Phase

Rolle im Stack

Primäre Wahl

Primäre Eignung

GitHub automation

Vertrauenslabel

Produktionsbereit

Installationspfad

Befehl bereit

Verwenden wenn

  • GitHub automation-Workflows
  • Claude-Code-Teams
  • Teams, die GitHub-Adoptionssignale schätzen

Evidenz

  • 21,306 GitHub-Stars
  • recent repository activity
  • install command or GitHub repo available
  • Qualitätsprofil 91/100

zuerst prüfen

  • The SKILL.md excerpt is truncated at the end, but the provided content is clear and complete for the described workflow.
  • No OpenAgentSkill engagement data yet

Implementierungspfad

  1. 1Installieren Sie es in einem Sandbox-Agent und führen Sie eine GitHub automation-Aufgabe vollständig aus.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Vertrauensprofil

Nur Sandbox

Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.

67
OpenAgentSkill Trust Score

GitHub-Akzeptanz

Bestanden

21K GitHub-Stars

Star-/Fork-Aktivität

Bestanden

21K Stars und 1.6K Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Aktuelle Wartung

Bestanden

Heute gepusht

Lizenzklarheit

Bestanden

Apache-2.0

Positive Signale

  • KI-Prüfung genehmigt
  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Kürzlich gewartetes Repository
  • Large GitHub adoption signal
  • Der Installationsbefehl weist kein offensichtliches Hochrisikomuster auf
  • Ergebniszyklus ist bereit, benötigt aber den ersten echten Agent-Lauf

Vor Installation prüfen

  • The SKILL.md excerpt is truncated at the end, but the provided content is clear and complete for the described workflow.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • Dependency/runtime risk: command execution surface, external package install surface
  • Permission surface: shell or command execution, filesystem or document access
  • Noch keine echten Agent-Ergebnisberichte
  • Vor unbeaufsichtigter Installation ist menschliche Prüfung erforderlich

Empfohlene Aktion

Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.

Qualitätsprofil

Ausgezeichnet Kandidat für Agent-Workflows

High-confidence pick with strong adoption and healthy maintenance signals.

91
GitHub-Stars
21K
Aktualität
Heute
Installationsbereit
Ja
Lizenz
Apache-2.0
Vor Installation prüfen: The SKILL.md excerpt is truncated at the end, but the provided content is clear and complete for the described workflow.

Workflow-Eignung

Diese Skill in diesen Szenarien nutzen

Workflow-Eignung

Zum vollständigen Workflow hinzufügen

Alternativen-Shortlist

Vor Installation vergleichen

Similar skills that may fit this task.

Alle vergleichen

Übersicht

--- name: open-code-review-delegate description: > Delegation mode for open-code-review (OCR). Instead of OCR calling an LLM endpoint, this skill instructs the host agent to perform the code review itself, using OCR only for deterministic engineering: file selection and rule resolution. Use when the host agent should drive the review with its own LLM capabilities. license: Apache-2.0 compatibility: > Requires the `ocr` CLI installed (via `npm install -g @alibaba-group/open-code-review` or GitHub release binary). Does NOT require a configured LLM endpoint — delegation mode is LLM-free on the OCR side. metadata: author: alibaba homepage: https://github.com/alibaba/open-code-review version: "1.0.0" ---

# Open Code Review — Delegation Mode

A skill for performing AI code review where OCR provides deterministic engineering (file filtering, rule resolution) and the host agent performs the actual review using its own intelligence and tools.

## Prerequisites

```bash which ocr || echo "NOT INSTALLED" ```

If `ocr` is not installed:

```bash npm install -g @alibaba-group/open-code-review ```

No LLM configuration is needed for delegation mode.

## Workflow

### Step 1: Preview — Determine What to Review

```bash ocr delegate preview --format json [--from <ref> --to <ref>] [--commit <hash>] [--exclude <patterns>] ```

This outputs: - **mode** (workspace / range / commit) - **from / to / commit / merge_base** — ref metadata for constructing git commands - **Reviewable file list** — paths, status, insertions/deletions - **Excluded files** — with exclusion reason

**Common invocations:**

| Scenario | Command | |----------|---------| | Workspace changes | `ocr delegate preview` | | Branch comparison | `ocr delegate preview --from main --to feature` | | Single commit | `ocr delegate preview -c abc123` |

### Step 2: Get Rules for Files

```bash ocr delegate rule --format json <path1> <path2> ... ```

Pass the reviewable file paths from Step 1. Output is grouped by rule content — files sharing the same rule appear under one group, avoiding repetition.

### Step 3: Get Diffs

Use git directly based on the mode/ref info from Step 1:

**Range mode** (merge_base provided in preview output): ```bash git diff <merge_base>..<to> -- <path> ```

**Commit mode**: ```bash git show <commit> -- <path> ```

**Workspace mode**: ```bash # Tracked files git diff HEAD -- <path> # New untracked files — read directly (entire file is new code) cat <path> ```

### Step 4: Review Each File

Create a checklist containing every `reviewable_files` entry. For each reviewable file:

Use `(path, status)` as the checklist identity. Workspace mode can report the same path twice when a staged deletion is followed by an untracked recreation.

1. Get its diff (Step 3) 2. Consult its Rule Group (from Step 2) for the review checklist 3. Conduct a thorough review, using appropriate context tools as needed 4. Mark the file `reviewed`, or `skipped` with a concrete reason

For large changes, review in bounded batches grouped by shared rules and diff size. Do not stop after finding the first high-severity issue.

### Step 5: Format Output

Each comment must follow this structure:

| Field | Type | Required | Description | |-------|------|----------|-------------| | path | string | yes | Relative file path | | content | string | yes | Review comment describing the issue | | start_line | integer | no | Start line in the new file | | end_line | integer | no | End line in the new file | | category | enum | no | bug, security, performance, maintainability, test, style, documentation, other | | severity | enum | no | critical, high, medium, low |

### Step 6: Classify and Report

Before reporting, verify that every previewed file is accounted for. Include `total_files`, `reviewed_files`, `skipped_files`, and `coverage_rate` in the summary. A skipped file must include its reason.

Group findings by severity:

- **Critical/High**: Bugs, security issues, data loss risks — always report - **Medium**: Performance concerns, error handling gaps, maintainability issues — report with context - **Low**: Style nits, minor suggestions — report only if clearly valuable

Discard likely false positives silently.

### Step 7: Fix (Optional)

If the user requested "review and fix": - Apply High/Critical fixes directly - Describe Medium fixes that require manual intervention - Skip Low-priority items unless trivial

## Sub-commands Reference

| Command | Purpose | |---------|---------| | `ocr delegate preview` | Which files to review + mode/ref metadata | | `ocr delegate rule <path...>` | Review rules grouped by content |

## Shared Flags

| Flag | Description | |------|-------------| | `--from <ref>` | Source ref for range mode | | `--to <ref>` | Target ref for range mode | | `-c, --commit <hash>` | Single commit mode | | `--repo <path>` | Repository root (default: cwd) | | `--rule <path>` | Custom rule.json path | | `--exclude <patterns>` | Comma-separated exclude patterns | | `-b, --background <text>` | Business context | | `-B, --background-file <path>` | Business context from Markdown file (takes precedence over `-b`) | | `-f, --format <text\|json>` | Output format; use `json` for agent integrations |

## Gotchas

- **No LLM needed on OCR side** — delegation mode never calls an LLM. All intelligence comes from the host agent. - **Rules are grouped** — Files sharing the same rule are grouped together in the output. You can pass any number of paths per call; for large changes, fetch rules per-batch as you review. - **Working directory matters** — `ocr delegate` operates on the Git repo at the current directory. Use `--repo /path` to override. - **Untracked files in workspace mode** — `preview` includes untracked files. For these, read the file directly instead of using `git diff`. - **Background context** — pass `--background` to `preview` when you have requirement context; it appears in the output for your reference during review. - **Coverage is mandatory** — every `reviewable_files` entry must end as reviewed or explicitly skipped; do not silently omit files.

Technische Details

Version
1.0.0
Lizenz
Apache-2.0
Letzte Aktualisierung
24. Aug. 2026
Veröffentlicht
24. Aug. 2026

Entscheidungsübersicht

Primäre Wahl

100
Bereit
Übernehmen
Phase

21,306 GitHub-Stars

Audit

Installationsprüfung

Installations- und Adoptionsprüfung

85
Prüfung nötig
Sicherheit
75/100
Wartung
100/100
Installieren
92/100
Vollständiges Audit öffnenEval-Bericht ansehen

Von Agent belegte Evidenz

Von Agent belegte Evidenz

Ergebnisberichte nach Resolve, Prüfung, Installation und einem begrenzten Lauf.

0
Belegt
Needs first agent runAuto-Installation: zuerst prüfenLetzter: Unbekannt
Erfolgsrate
Letzter Fehler
Ergebnisse
0
Ausgabequalität
Fehlgeschlagen
0
Nicht relevant
0
Installationen
0
Durch Risiko blockiert
0
Einrichtung erforderlich
0
Produktion
0

Noch keine Agent-Ergebnisdaten. Der erste Lauf kann Erfolg, Einrichtungsbedarf, Risikoblockaden, Fehler oder Irrelevanz über /api/agent/outcome melden.

Installieren

Zum Agent-Workflow hinzufügen

Kostenlos und Open Source. Bericht vor der Installation in Produktions-Agents prüfen.

Wachstums-Loop

Share-Kit

X

Szenariobasierter Entwurf für open-code-review-delegate, bereit für einen manuellen X-Post.

Kuratorenhinweis
open-code-review-delegate: Delegation mode for open-code-review (OCR). Instead of OCR calling an LLM endpoint, this skil...

21.3K stars

https://www.openagentskill.com/skills/alibaba-open-code-review-delegate?ref=x
X-Entwurf öffnen
Optionale Antwort mit Installationsbefehl
Listing + install path for open-code-review-delegate:
https://www.openagentskill.com/skills/alibaba-open-code-review-delegate?ref=x

Install: npx skills add alibaba/open-code-review --skill open-code-review-delegate
Antwortentwurf öffnen

Quelle des Eintrags

Registry-indexiert

Beanspruchbar

Dieser Eintrag wurde aus öffentlichen Quellen indexiert und ist erst nach Genehmigung eines Maintainer-Anspruchs offiziell.

Ersteller
alibaba
Indexiert von
OpenAgentSkill Community-Index

Die Zuordnung verlinkt auf das öffentliche Repository oder Creator-Profil. Creator können den Eintrag beanspruchen, um Eigentümersignale zu aktualisieren.

Diesen Skill beanspruchen

Eigentümeranspruch

Diesen Skill-Eintrag beanspruchen

Dieser Registry-indexiert-Eintrag wird alibaba zugeschrieben, ist aber noch nicht offiziell markiert. Beanspruche ihn, um ein verifiziertes Eigentümersignal hinzuzufügen und künftige Launch-, Installations- und Audit-Updates vertrauenswürdiger zu machen.

Creator-Backlink-Kit

Evidenz-Badges in deine README einfügen

Zeige den kanonischen Eintrag, aktuelle Vertrauens- und Audit-Signale sowie echte Agent-Proven-Evidenz dort, wo Entwickler das Repository bewerten.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/alibaba-open-code-review-delegate?metric=listed&label=Listed)](https://www.openagentskill.com/skills/alibaba-open-code-review-delegate)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/alibaba-open-code-review-delegate?metric=trust&label=Trust)](https://www.openagentskill.com/skills/alibaba-open-code-review-delegate)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/alibaba-open-code-review-delegate?metric=audit&label=Audit)](https://www.openagentskill.com/skills/alibaba-open-code-review-delegate/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/alibaba-open-code-review-delegate?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/alibaba-open-code-review-delegate)

Autor

A

alibaba

@alibaba

Plattform-Fit

Gesundheitssignale

GitHub-Stars
21.3K
Qualitätswert
54/100
Letzter GitHub-Push
24. Aug. 2026
Framework-Hinweise
Unbekannt
OpenAgentSkill-Aufrufe
0
Installationskopien
0
Externe Klicks
0

Community-Signal

Teile mit, ob dieser Skill für deinen Agent-Workflow nützlich ist. Zusammengefasstes Feedback verbessert das Ranking im Laufe der Zeit.

Vertrauen & Sicherheit

Nur Sandbox

67
  • GitHub-Akzeptanz21K GitHub-StarsBestanden
  • Star-/Fork-Aktivität21K Stars und 1.6K Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbarBestanden
  • Aktuelle WartungHeute gepushtBestanden
  • LizenzklarheitApache-2.0Bestanden
  • README/SKILL.md-VollständigkeitMetadaten enthalten ausreichend Nutzungs- und Workflow-KontextBestanden
  • Abhängigkeits-/Laufzeitrisikocommand execution surface, external package install surfacePrüfen