open-code-review-delegate skill
Delegation mode for open-code-review (OCR). Instead of OCR calling an LLM endpoint, this skill instructs the host agent to perform the code review itself, using OCR only for deterministic engineering: file selection and rule resolution. Use when the host agent should drive the review with its own LLM capabilities.
Is the open-code-review-delegate skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the open-code-review-delegate skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/alibaba/open-code-review.git /tmp/open-code-review mkdir -p ~/.claude/skills cp -r /tmp/open-code-review/skills/open-code-review-delegate ~/.claude/skills/open-code-review-delegate
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Open Code Review — Delegation Mode
A skill for performing AI code review where OCR provides deterministic engineering (file filtering, rule resolution) and the host agent performs the actual review using its own intelligence and tools.
Workflow
Step 1: Preview — Determine What to Review
ocr delegate preview --format json [--from <ref> --to <ref>] [--commit <hash>] [--exclude <patterns>]This outputs:
- mode (workspace / range / commit)
- from / to / commit / mergebase** — ref metadata for constructing git commands
- Reviewable file list — paths, status, insertions/deletions
- Excluded files — with exclusion reason
Common invocations:
Step 2: Get Rules for Files
ocr delegate rule --format json <path1> <path2> ...Pass the reviewable file paths from Step 1. Output is grouped by rule content — files sharing the same rule appear under one group, avoiding repetition.
Step 3: Get Diffs
Use git directly based on the mode/ref info from Step 1:
Range mode (merge_base provided in preview output):
git diff <merge_base>..<to> -- <path>Commit mode:
git show <commit> -- <path>Workspace mode:
# Tracked files
git diff HEAD -- <path>
# New untracked files — read directly (entire file is new code)
cat <path>Step 4: Review Each File
Create a checklist containing every reviewable_files entry. For each reviewable file:
Use (path, status) as the checklist identity. Workspace mode can report the same path twice when a staged deletion is followed by an untracked recreation.
- Get its diff (Step 3)
- Consult its Rule Group (from Step 2) for the review checklist
- Conduct a thorough review, using appropriate context tools as needed
- Mark the file reviewed, or skipped with a concrete reason
For large changes, review in bounded batches grouped by shared rules and diff size. Do not stop after finding the first high-severity issue.
Step 5: Format Output
Each comment must follow this structure:
Step 6: Classify and Report
Before reporting, verify that every previewed file is accounted for. Include totalfiles, reviewedfiles, skippedfiles, and coveragerate in the summary. A skipped file must include its reason.
Group findings by severity:
- Critical/High: Bugs, security issues, data loss risks — always report
- Medium: Performance concerns, error handling gaps, maintainability issues — report with context
- Low: Style nits, minor suggestions — report only if clearly valuable
Discard likely false positives silently.
Step 7: Fix (Optional)
If the user requested "review and fix":
- Apply High/Critical fixes directly
- Describe Medium fixes that require manual intervention
- Skip Low-priority items unless trivial
Sub-commands Reference
Shared Flags
Gotchas
- No LLM needed on OCR side — delegation mode never calls an LLM. All intelligence comes from the host agent.
- Rules are grouped — Files sharing the same rule are grouped together in the output. You can pass any number of paths per call; for large changes, fetch rules per-batch as you review.
- Working directory matters — ocr delegate operates on the Git repo at the current directory. Use --repo /path to override.
- Untracked files in workspace mode — preview includes untracked files. For these, read the file directly instead of using git diff.
- Background context — pass --background to preview when you have requirement context; it appears in the output for your reference during review.
- Coverage is mandatory — every reviewable_files entry must end as reviewed or explicitly skipped; do not silently omit files.
Recovering Oversized Background Context
--background-file has two independent limits. The raw file must not exceed 1 MiB, and the sanitized content must not exceed 8000 characters. Either condition aborts the command. When the command reports either limit:
constraints, acceptance criteria, and other review-critical details.
- Do not silently truncate the source file.
- Summarize the original material while preserving its requirements,
argument (for example, use a quoted/escaped argument produced by the host shell, or write it to a new size-bounded file and pass that file). Do not place untrusted summary text directly in a double-quoted shell template; $(), backticks, quotes, and variable references can still be evaluated. Omit the original --background-file so the CLI does not reload the same oversized file and fail again.
- Retry the affected command by passing the summary as one shell-safe
read the original material directly during the review.
- If a faithful summary is not possible, omit the OCR background entirely and
Troubleshooting CLI Version Compatibility
The --format flag is available in ocr v1.9.0 and later. The Skill and the installed CLI can be updated independently. If a requested preview or rule command with --format json fails specifically with unknown flag: --format, rerun it without the flag and use text output for the rest of the delegation run. Preserve the explicit mode, ref, file, and rule information from that output; do not parse text output as JSON or invent missing schema fields. Do not retry without the flag for any other error; report it and stop the affected workflow.
The host-agent Skill may consume the equivalent text output to complete its review checklist. Programmatic integrations that require schema_version or other JSON fields must require a JSON-capable CLI instead: verify with ocr --version and upgrade when necessary:
npm install -g @alibaba-group/open-code-reviewMore skills from alibaba/open-code-review
- Aopen-code-reviewPerforms AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.
- Aopen-code-reviewPerforms AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.
- Aopen-code-review-delegateDelegation mode for open-code-review (OCR). Instead of OCR calling an LLM endpoint, this skill instructs the host agent to perform the code review itself, using OCR only for deterministic engineering: file selection and rule resolution. Use when the host agent should drive the review with its own LLM capabilities.