open-code-review
A code-review CLI and plugin for agents: reads a git diff and writes line-level comments with context
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads project code and sends diffs to an external LLM
- Can apply edits to files on request
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/open-code-reviewDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
npm install -g @alibaba-group/open-code-reviewInstall the CLI: npm install -g @alibaba-group/open-code-review, then configure an LLM provider. In Claude Code you can add the plugin: /plugin marketplace add alibaba/open-code-review and /plugin install open-code-review@open-code-review. Run ocr against the change range you need.
Other ways from the author
npm install -g @alibaba-group/open-code-reviewInstalls the ocr command globally. Configure an LLM provider before the first run.
This is third-party code. Review the repository files before installing.
What it does
open-code-review ships the ocr command, which reads git changes and produces structured line-level comments. A hybrid design combines deterministic checks with a built-in ruleset (NPE, thread safety, XSS, SQL injection) and LLM analysis of the diff with access to the surrounding code. It handles workspace changes, branch ranges and single commits, and can apply fixes on request. It comes as a CLI and as a plugin and skill for Claude Code, Codex and Cursor.
Who it is for. For developers and QA who want automated review of changes before merge.
Good fit when
- You want to check changes or a pull request before human review
- You need line-level comments flagging possible bugs and vulnerabilities
- You want to embed code review into an agent in the terminal
Not a fit when
- You have no access to a supported LLM provider
- You need a full static analyzer rather than diff review
Example request
Review my uncommitted changes and give line-level comments, and fix the important onesLimitations
Before the first run you configure an LLM provider: the supported protocols are Anthropic, OpenAI Chat Completions, OpenAI Responses and AWS Bedrock. Review and auto-fixes call an external model, and quality depends on it and on the configured rules.
How to disable. Uninstall the CLI (npm uninstall -g @alibaba-group/open-code-review) and remove the open-code-review plugin via /plugin.
Security check
- Reads project code and sends diffs to an external LLM
- Can apply edits to files on request
README in short
The README presents open-code-review as a code-review tool with a hybrid architecture: deterministic pipelines plus an LLM agent, line-level comments and a built-in multi-language ruleset. It installs as the ocr CLI via npm or a release binary and works with Anthropic and OpenAI-compatible providers. The repo ships plugins and skills for Claude Code, Codex, Cursor and Kimi, plus a built-in MCP. Apache-2.0 licensed.
FAQ
Which LLMs are supported?
Providers speaking Anthropic, OpenAI Chat Completions, OpenAI Responses and AWS Bedrock protocols.
Can it fix code itself?
Yes, on request ocr can apply fixes rather than only report comments.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything