open-code-review
Fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
OpenCodeReview is an AI-powered code review tool available as a Claude Code plugin that combines deterministic engineering with agent-based analysis. Battle-tested at Alibaba scale across tens of thousands of developers, it generates precise line-level code review comments by leveraging a hybrid architecture: hard-coded pipelines ensure complete file coverage and accurate positioning, while an LLM agent performs dynamic decision-making and context retrieval. The plugin includes built-in multi-language rulesets for common defects (null pointer exceptions, thread-safety issues, XSS, SQL injection) and works with OpenAI and Anthropic models, consuming approximately 1/9 the tokens of general-purpose agents while maintaining higher precision.
Key Features
Use Cases
- 01Reviewing pull requests with precise, actionable feedback before merge
- 02Scanning entire unfamiliar codebases or directories for security vulnerabilities and quality issues
- 03Integrating automated code review into CI/CD pipelines (GitHub Actions, GitLab CI, Gerrit)
- 04Auditing legacy code for thread-safety issues and injection vulnerabilities
- 05Reviewing feature branch changes against main branch with merge-base detection
- 06Resuming interrupted reviews on very large changesets without re-processing completed files
Related Plugins
View moreandrej-karpathy-skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
claude-mem
Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Understand-Anything
Graphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
rtk
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
open-code-review — FAQ
What is the OpenCodeReview Claude Code plugin?+
It's an AI-powered code review plugin for Claude Code that uses a hybrid architecture combining deterministic pipelines with LLM agents to generate precise, line-level code review comments. Originally developed at Alibaba and battle-tested with tens of thousands of developers, it identifies security issues, code defects, and quality problems across multiple programming languages.
How do I install the OpenCodeReview plugin for Claude Code?+
First install the CLI globally with 'npm install -g @alibaba-group/open-code-review'. Then in Claude Code, use '/plugin marketplace add alibaba/open-code-review' followed by '/plugin install open-code-review'. Finally, configure an LLM provider with 'ocr config provider' and 'ocr config model'.
Do I need an API key to use OpenCodeReview?+
For default mode, yes—you need an API key for OpenAI, Anthropic, or another compatible LLM provider, configured via 'ocr config provider'. However, delegation mode lets your coding agent perform reviews using its own LLM, requiring no separate API key configuration.
Which AI clients does OpenCodeReview work with?+
The plugin officially supports Claude Code, Codex, and Cursor as documented integrations. It also provides a portable agent skill format compatible with other skill-based agents, plus an MCP server mode for extending the review agent with external tools.
Is OpenCodeReview free to use?+
Yes, OpenCodeReview is open source under the Apache-2.0 license and free to use. However, you'll incur API costs from your chosen LLM provider (OpenAI, Anthropic, etc.) when running reviews in default mode.
What are the prerequisites for using OpenCodeReview?+
You need Git version 2.41 or higher installed, as the tool relies on Git for diff generation, code search, and repository operations. You'll also need Node.js/npm for CLI installation, and an LLM API key unless using delegation mode.
How do I install open-code-review?+
Open the source repository on GitHub and follow its README. open-code-review is a plugin — MCP Agents Market links you directly to the official repo.
Is open-code-review free?+
open-code-review is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.