Open Code Review: AI Code Review CLI from Alibaba
What Open Code Review is
Open Code Review is an AI-powered code review command-line tool published by Alibaba under the Apache-2.0 license. According to its README, it started life as Alibaba Group's internal AI code review assistant, which the project says has served tens of thousands of developers over two years and identified millions of code defects before being released as open source. The binary is called ocr, and the only hard requirement beyond the tool itself is a model endpoint: you point it at an LLM provider, and it reviews your changes.
The core job is narrow and well defined. It reads Git diffs, sends the changed files to a configurable LLM through an agent that can call tools, and produces structured review comments anchored to specific lines. The agent is not limited to the diff hunk: it can read full file contents, search the codebase, and look at the other files changed in the same change set to build context. For code that has no meaningful diff, such as an unfamiliar repository you are auditing, a separate ocr scan command reviews whole files instead.
The target audience is developers and teams who want automated first-pass review on local changes, branches, individual commits, or CI pipelines, and who have found general-purpose coding agents too inconsistent for that specific task.
Why it exists: the problem with general-purpose agents
The README is direct about the motivation. It lists three failure modes it has observed when general-purpose agents (it names Claude Code with Skills) are used for code review:
- Incomplete coverage: on larger change sets, agents tend to review only some files and skip others.
- Position drift: reported issues do not line up with the actual code location, with line numbers or file references drifting.
- Unstable quality: skills driven purely by natural language are hard to debug, and output quality shifts with small prompt changes.
The project's diagnosis is that a purely language-driven architecture has no hard constraints on the review process. Its answer is a hybrid design.
How it works: deterministic engineering plus an agent
Open Code Review splits the review pipeline into steps that must not go wrong, which are handled by ordinary code, and steps that benefit from dynamic judgment, which are handled by the agent.
Deterministic side
- Precise file selection: engineering logic decides exactly which files need review and which should be filtered out, so changes are not silently skipped.
- Smart file bundling: related files are grouped into one review unit. The README's example is
message_en.propertiesandmessage_zh.propertiesbeing reviewed together. Each bundle runs as a sub-agent with its own isolated context, which keeps large change sets stable and lets bundles be reviewed concurrently. - Fine-grained rule matching: review rules are matched to each file's characteristics through a template engine rather than through prompt instructions, which the project says is more stable and predictable.
- Positioning and reflection modules: separate modules check where a comment should be anchored and whether its content holds up, aimed at both location accuracy and content accuracy.
Agent side
- Scenario-tuned prompts: prompt templates optimized specifically for code review, with reduced token use as a stated goal.
- Scenario-tuned toolset: a purpose-built set of tools derived, per the README, from analysis of tool-call traces in production data, including call frequency, repetition rates, and the effect of adding new tools on the overall call chain.
Key features
- Multiple review targets: workspace mode (staged, unstaged, and untracked changes), branch ranges using merge-base, single commits, and full-file scans of a repository or path.
- Resumable sessions: interrupted range, commit, and scan reviews can be resumed by session ID.
- JSON output:
--format json --outputwrites results to a file, which the README recommends when an AI host agent is consuming the results. - Delegation mode: Open Code Review handles file selection and rule resolution while your existing coding agent performs the review with its own model, so no separate LLM configuration or API key is needed.
- Coding agent integrations: plugins or skills for Claude Code, Codex, Cursor, Kimi Code, OpenCode, QCA Forward, and other skill-compatible agents.
- CI/CD integration: documented setups for GitHub Actions, GitLab CI, GitFlic CI, and Gerrit.
- Custom review rules: rules with path filtering and targeting.
- MCP server support: the review agent can be extended with external tools.
- Session viewer: a browser view to replay review sessions and mark comments as fixed or ignored.
- OpenTelemetry integration: telemetry hooks for observability.
Getting started
The README lists Git 2.41 or later as a prerequisite, since the tool relies on Git for diff generation, code search, and repository operations. Install via npm:
npm install -g @alibaba-group/open-code-reviewOther methods (install script, GitHub Release binary, building from source) are covered in the installation docs. Next, configure a model unless you plan to use delegation mode:
ocr config provider # Select a built-in provider or add a custom one
ocr config model # Pick a model for the active providerThe interactive setup walks through provider selection, API key entry, and model choice, then tests connectivity. Then run a review from inside a project:
cd your-project
# Workspace mode — review all staged, unstaged, and untracked changes
ocr review
# Branch range — reviews feature-branch's changes since it diverged from main (merge-base mode)
ocr review --from main --to feature-branch
# Single commit
ocr review --commit abc123
# Full-file scan — review whole files instead of a diff (no git history needed)
ocr scan # scan the entire repository
ocr scan --path internal/agent # scan a directory or specific files
# Save results to a file (recommended for AI host agents)
ocr review --format json --output result.json
# Delegation mode — let your AI coding agent perform the review itself
# OCR handles file selection and rule resolution; no LLM configuration needed
ocr delegate preview
ocr delegate rule src/main.go src/handler.goInterrupted reviews can be listed with ocr session list and resumed with --resume <session-id>.
Use cases
- Pre-commit self-review: run
ocr reviewin workspace mode before pushing to catch defects in uncommitted work. - Pull request gating in CI: run a branch-range review against
mainin GitHub Actions, GitLab CI, or Gerrit and surface line-level comments on the change. - Auditing an inherited codebase: use
ocr scanon a directory that has no useful diff history to get a first pass of findings. - Adding structure to an existing coding agent: use delegation mode or the Claude Code, Cursor, or Codex plugins so the agent you already pay for does the review, while Open Code Review controls which files are covered and which rules apply.
- Large change sets: bundle-level sub-agents are designed to keep coverage complete on big diffs where a single agent context tends to cut corners.
How it compares
The comparison the README itself makes is against general-purpose agents, specifically Claude Code. It publishes results on AACR-Bench, a benchmark the project built from 50 open-source repositories, 200 real pull requests, and 10 programming languages, with 1,505 ground-truth issues annotated and cross-validated by more than 80 senior engineers; the dataset is published on Hugging Face. The README claims that, with the same underlying model, Open Code Review achieves significantly higher precision and F1 than Claude Code while using roughly one ninth of the tokens and finishing faster. It also states plainly that recall is lower than general-purpose agents, describing this as a deliberate trade-off that favors fewer false alarms over catching every issue. Since the benchmark was built by the same team, it is worth running your own comparison on a representative set of your pull requests before drawing conclusions.
Things to know before adopting
- You bring the model: outside delegation mode, every review calls an LLM provider you configure, so cost and data handling depend on that provider. Source code is sent to whatever endpoint you choose.
- Precision over recall: by the project's own account it reports fewer issues than a general agent would. That suits teams tired of noisy review bots, less so teams that want exhaustive coverage.
- Git version: Git 2.41 or newer is required.
- Platform support: the README badges list Windows, macOS, and Linux.
- Telemetry: the docs describe an OpenTelemetry integration for observability; check the telemetry page for what is exported and how it is configured in your environment.
- Age of the open-source project: the public repository was created in May 2026, so the open-source release is young even though the tool has a longer internal history at Alibaba.
- License: Apache-2.0, which permits commercial use and modification with attribution and patent-grant terms.
Project activity
As of October 2026 the repository has roughly 43,000 stars. It was created on May 18, 2026, is written primarily in Go, and is distributed under the Apache-2.0 license. The source is at github.com/alibaba/open-code-review, and documentation lives on the project site at open-codereview.ai. The README also links translated versions in Simplified Chinese, Japanese, Korean, and Russian, and a contributor guide in CONTRIBUTING.md.
Enjoying this project?
Discover more amazing open-source projects on TechLogHub. We curate the best developer tools and projects.
Repository:https://github.com/alibaba/open-code-review
GitHub - alibaba/open-code-review: Open Code Review: AI Code Review CLI from Alibaba
Open Code Review is Alibaba's open-source AI code review CLI. It reads Git diffs, runs an LLM agent over bundled changes with deterministic file selection and r...
github - alibaba/open-code-review

