PluginBench
Skill
Pass
Audit score 90

open-code-review-delegate

alibaba/open-code-review

Delegate code review to your agent using OCR for file filtering and rules.

What is open-code-review-delegate?

A skill that integrates open-code-review (OCR) in delegation mode, where OCR handles deterministic tasks like file selection and rule resolution, while your host agent performs the actual code review using its own intelligence. Use this when you want your agent to drive reviews with full control over analysis and findings.

  • Preview reviewable files and metadata (mode, refs, insertions/deletions, exclusions)
  • Fetch review rules grouped by content to avoid repetition
  • Conduct thorough code reviews using your agent's own capabilities
  • Report findings grouped by severity with line-level annotations
  • Support workspace, branch, and single-commit review modes
  • Handle untracked files and staged changes in workspace mode

How to install open-code-review-delegate

npx skills add https://github.com/alibaba/open-code-review --skill open-code-review-delegate
Prerequisites
  • Install ocr CLI: npm install -g @alibaba-group/open-code-review or use GitHub release binary
  • No LLM endpoint configuration needed (delegation mode is LLM-free on OCR side)
Claude Code
Cursor
Windsurf
Cline

How to use open-code-review-delegate

  1. 1.Run ocr delegate preview to list reviewable files and get mode/ref metadata
  2. 2.Pass file paths to ocr delegate rule to fetch review rules grouped by content
  3. 3.Use git diff or cat (for untracked files) to retrieve diffs based on mode from step 1
  4. 4.Review each file against its rule group; mark as reviewed or skipped with reason
  5. 5.Format findings as JSON with path, content, line numbers, category, and severity
  6. 6.Verify all previewed files are accounted for; report summary with coverage rate
  7. 7.Optionally apply high/critical fixes directly or describe medium fixes for manual intervention

Use cases

Good for
  • Review pull request changes before merge by comparing branches
  • Audit a single commit for bugs, security, or style issues
  • Scan workspace changes (staged and unstaged) for quality gates
  • Apply high/critical fixes automatically while describing medium-priority improvements
  • Review with business context by passing requirement or constraint information
Who it's for
  • AI agents (Claude Code, Cursor) performing code review
  • Development teams automating pre-commit or pre-merge checks
  • Engineers who want agent-driven review with deterministic rule application

open-code-review-delegate FAQ

Do I need to configure an LLM endpoint for this skill?

No. Delegation mode is LLM-free on the OCR side. OCR only handles file filtering and rule resolution; your host agent provides all intelligence.

How do I handle untracked files in workspace mode?

Read them directly with cat instead of using git diff, since the entire file is new code.

What if my background context exceeds the size limits?

Summarize the original material while preserving requirements and review-critical details, then pass the summary as a shell-safe argument without --background-file.

What should I do if ocr delegate preview fails with 'unknown flag: --format'?

Rerun without --format and parse text output instead. Verify CLI version with ocr --version and upgrade if needed for JSON support.

How are review rules organized in the output?

Rules are grouped by content—files sharing the same rule appear under one group to avoid repetition. You can pass any number of paths per call.

Full instructions (SKILL.md)

Source of truth, from alibaba/open-code-review.


name: open-code-review-delegate description: > Delegation mode for open-code-review (OCR). Instead of OCR calling an LLM endpoint, this skill instructs the host agent to perform the code review itself, using OCR only for deterministic engineering: file selection and rule resolution. Use when the host agent should drive the review with its own LLM capabilities. license: Apache-2.0 compatibility: > Requires the ocr CLI installed (via npm install -g @alibaba-group/open-code-review or GitHub release binary). Does NOT require a configured LLM endpoint — delegation mode is LLM-free on the OCR side. metadata: author: alibaba homepage: https://github.com/alibaba/open-code-review version: "1.0.0"

Open Code Review — Delegation Mode

A skill for performing AI code review where OCR provides deterministic engineering (file filtering, rule resolution) and the host agent performs the actual review using its own intelligence and tools.

Workflow

Step 1: Preview — Determine What to Review

ocr delegate preview --format json [--from <ref> --to <ref>] [--commit <hash>] [--exclude <patterns>]

This outputs:

  • mode (workspace / range / commit)
  • from / to / commit / merge_base — ref metadata for constructing git commands
  • Reviewable file list — paths, status, insertions/deletions
  • Excluded files — with exclusion reason

Common invocations:

ScenarioCommand
Workspace changesocr delegate preview
Branch comparisonocr delegate preview --from main --to feature
Single commitocr delegate preview -c abc123

Step 2: Get Rules for Files

ocr delegate rule --format json <path1> <path2> ...

Pass the reviewable file paths from Step 1. Output is grouped by rule content — files sharing the same rule appear under one group, avoiding repetition.

Step 3: Get Diffs

Use git directly based on the mode/ref info from Step 1:

Range mode (merge_base provided in preview output):

git diff <merge_base>..<to> -- <path>

Commit mode:

git show <commit> -- <path>

Workspace mode:

# Tracked files
git diff HEAD -- <path>
# New untracked files — read directly (entire file is new code)
cat <path>

Step 4: Review Each File

Create a checklist containing every reviewable_files entry. For each reviewable file:

Use (path, status) as the checklist identity. Workspace mode can report the same path twice when a staged deletion is followed by an untracked recreation.

  1. Get its diff (Step 3)
  2. Consult its Rule Group (from Step 2) for the review checklist
  3. Conduct a thorough review, using appropriate context tools as needed
  4. Mark the file reviewed, or skipped with a concrete reason

For large changes, review in bounded batches grouped by shared rules and diff size. Do not stop after finding the first high-severity issue.

Step 5: Format Output

Each comment must follow this structure:

FieldTypeRequiredDescription
pathstringyesRelative file path
contentstringyesReview comment describing the issue
start_lineintegernoStart line in the new file
end_lineintegernoEnd line in the new file
categoryenumnobug, security, performance, maintainability, test, style, documentation, other
severityenumnocritical, high, medium, low

Step 6: Classify and Report

Before reporting, verify that every previewed file is accounted for. Include total_files, reviewed_files, skipped_files, and coverage_rate in the summary. A skipped file must include its reason.

Group findings by severity:

  • Critical/High: Bugs, security issues, data loss risks — always report
  • Medium: Performance concerns, error handling gaps, maintainability issues — report with context
  • Low: Style nits, minor suggestions — report only if clearly valuable

Discard likely false positives silently.

Step 7: Fix (Optional)

If the user requested "review and fix":

  • Apply High/Critical fixes directly
  • Describe Medium fixes that require manual intervention
  • Skip Low-priority items unless trivial

Sub-commands Reference

CommandPurpose
ocr delegate previewWhich files to review + mode/ref metadata
ocr delegate rule <path...>Review rules grouped by content

Shared Flags

FlagDescription
--from <ref>Source ref for range mode
--to <ref>Target ref for range mode
-c, --commit <hash>Single commit mode
--repo <path>Repository root (default: cwd)
--rule <path>Custom rule.json path
--exclude <patterns>Comma-separated exclude patterns
-b, --background <text>Business context
-B, --background-file <path>Business context from Markdown file (takes precedence over -b)
-f, --format <text|json>Output format; use json for agent integrations

Gotchas

  • No LLM needed on OCR side — delegation mode never calls an LLM. All intelligence comes from the host agent.
  • Rules are grouped — Files sharing the same rule are grouped together in the output. You can pass any number of paths per call; for large changes, fetch rules per-batch as you review.
  • Working directory matters — ocr delegate operates on the Git repo at the current directory. Use --repo /path to override.
  • Untracked files in workspace mode — preview includes untracked files. For these, read the file directly instead of using git diff.
  • Background context — pass --background to preview when you have requirement context; it appears in the output for your reference during review.
  • Coverage is mandatory — every reviewable_files entry must end as reviewed or explicitly skipped; do not silently omit files.

Recovering Oversized Background Context

--background-file has two independent limits. The raw file must not exceed 1 MiB, and the sanitized content must not exceed 8000 characters. Either condition aborts the command. When the command reports either limit:

  1. Do not silently truncate the source file.
  2. Summarize the original material while preserving its requirements, constraints, acceptance criteria, and other review-critical details.
  3. Retry the affected command by passing the summary as one shell-safe argument (for example, use a quoted/escaped argument produced by the host shell, or write it to a new size-bounded file and pass that file). Do not place untrusted summary text directly in a double-quoted shell template; $(), backticks, quotes, and variable references can still be evaluated. Omit the original --background-file so the CLI does not reload the same oversized file and fail again.
  4. If a faithful summary is not possible, omit the OCR background entirely and read the original material directly during the review.

Troubleshooting CLI Version Compatibility

The --format flag is available in ocr v1.9.0 and later. The Skill and the installed CLI can be updated independently. If a requested preview or rule command with --format json fails specifically with unknown flag: --format, rerun it without the flag and use text output for the rest of the delegation run. Preserve the explicit mode, ref, file, and rule information from that output; do not parse text output as JSON or invent missing schema fields. Do not retry without the flag for any other error; report it and stop the affected workflow.

The host-agent Skill may consume the equivalent text output to complete its review checklist. Programmatic integrations that require schema_version or other JSON fields must require a JSON-capable CLI instead: verify with ocr --version and upgrade when necessary:

npm install -g @alibaba-group/open-code-review