Type to search across all content

    OpenCodeReview (ocr)

    Alibaba's hybrid code-review CLI: deterministic pipelines + LLM agent, precise line-level comments at 1/9 the tokens

    AlibabaOpen sourceSince

    OpenCodeReview (ocr) is Alibaba's open-source AI code-review CLI. It reads git diffs and drives an LLM agent through a hybrid architecture where deterministic pipelines handle file selection, rule matching, and comment positioning while the agent does the reasoning. Built on two years of internal use at Alibaba scale, it ships a multi-language ruleset and consumes roughly 1/9 of the tokens of general-purpose agents.

    +Pros

    • Precision-first review: higher Precision and F1 than general-purpose agents (Claude Code) on AACR-Bench with the same underlying model, so reviewers triage fewer false alarms
    • ~1/9 the token consumption of general-purpose agents — a typical review pass costs a fraction of a cent on cheap models and keeps CI latency low
    • Deterministic pipelines guarantee complete file coverage and stable comment positioning on large changesets, where language-driven agents drift or skip files
    • Fully self-hosted with BYO LLM key (Anthropic, OpenAI, DeepSeek, DashScope, Z.AI or any OpenAI-compatible endpoint) — code never leaves your infrastructure
    • Delegation mode offloads the review to your existing coding agent (Claude Code, Codex, Cursor, Kimi, OpenCode) — OCR handles file selection and rule resolution, no API key required

    −Cons

    • Recall is deliberately lower than general-purpose agents — the precision-first trade-off means some real defects can slip through; pair it with other checks for security-critical code
    • No official hosted/managed offering — you bring the model key and run the CLI or CI integration yourself, so there is no zero-ops option
    • Requires Git >= 2.41 and a working local clone; it is a diff-first tool, so it is less useful for teams that do all review in a web UI

    Pricing

    Free (Open Source)

    $0

    Apache-2.0 licensed CLI, self-hosted. Bring your own LLM API key — Anthropic, OpenAI, DeepSeek, DashScope, Z.AI or any OpenAI-compatible endpoint. No per-seat cost.

    Introduction

    OpenCodeReview (ocr) is Alibaba's AI code-review CLI, open-sourced in May 2026 after two years as the company's internal official review assistant — serving tens of thousands of developers and flagging millions of code defects before it ever shipped publicly. The ocr command reads git diffs, drives a configurable LLM agent, and returns structured review comments pinned to exact lines.

    The architecture is where it departs from the pack. Instead of a purely language-driven agent, it combines deterministic pipelines with an LLM agent: engineering logic handles the steps that must not go wrong — file selection, bundling, rule matching, comment positioning — while the agent handles dynamic context retrieval and reasoning. The result behaves like a battle-tested linter with judgment: complete coverage on large changesets, stable line-level accuracy, and about 1/9 of the token consumption of general-purpose agents on the same model.

    Key Features

    • Line-level review comments — findings are pinned to exact file:line positions via external positioning and reflection modules, eliminating the position drift common with prompt-driven reviewers.
    • Multi-language ruleset — built-in rules cover null-pointer dereferences, thread-safety, XSS, and SQL injection across languages, with template-engine-based rule matching that keeps the model's attention focused.
    • ocr scan full-file audit — reviews entire files rather than diffs, for auditing unfamiliar codebases or directories with no meaningful git history.
    • Delegation mode — ocr delegate preview lets OCR handle file selection and rule resolution while your coding agent (Claude Code, Codex, Cursor, Kimi, OpenCode) runs the review with its own LLM. No OCR API key required.
    • Session resume — interrupted reviews resume with ocr session list and --resume <session-id>, and replay later in the browser-based Session Viewer.
    • MCP server — exposes review capabilities over the Model Context Protocol so external tools can extend the review agent.

    How It Works

    The hybrid design splits responsibilities deliberately. Deterministic engineering imposes hard constraints on the review process: precise file selection decides exactly which files need review and which should be filtered; smart file bundling groups related files (e.g., paired .properties files) into single review units, each run as a sub-agent with isolated context — a divide-and-conquer strategy that stays stable on very large changesets and supports concurrent review. Fine-grained rule matching uses a template engine rather than free-form prompts, and independent positioning/reflection modules fix both the location and the content accuracy of every comment.

    The agent is reserved for what it does best — dynamic decisions and dynamic context retrieval. Its prompt templates and toolset are scenario-tuned for code review, distilled from analysis of tool-call traces in large-scale production data (call frequency, per-tool repetition, impact on the call chain). The result is a purpose-built agent loop that is more stable and predictable for review than a generic agent toolkit.

    Benchmark

    Alibaba published AACR-Bench, a real-world review benchmark built from 50 popular open-source repositories, 200 real pull requests, and 10 programming languages, cross-validated by 80+ senior engineers on 1,505 annotated ground-truth issues (dataset on Hugging Face).

    Compared to general-purpose agents (Claude Code) on the same underlying model, OpenCodeReview reports significantly higher Precision and F1 while consuming ~1/9 of the tokens and completing reviews faster.

    The honest caveat: its Recall is lower — a deliberate trade-off favoring precision over noise. You get fewer false alarms to triage, but some real defects can slip through, so it pairs best with additional checks on security-critical paths.

    Getting Started

    Install with one command (requires Git >= 2.41):

    npm install -g @alibaba-group/open-code-review

    Configure a provider interactively (ocr config provider, ocr config model) — presets ship for Anthropic, OpenAI, DashScope, DeepSeek, and Z.AI, plus any custom OpenAI/Anthropic-compatible endpoint, so code stays on your infrastructure. Then review:

    ocr review                          # review all workspace changes
    ocr review --from main --to feature-branch   # branch range
    ocr review --commit abc123          # single commit
    ocr scan --path internal/agent      # full-file audit
    ocr review --format json --output result.json  # structured output for CI

    Full reference lives at open-codereview.ai/docs.

    Integrations

    OpenCodeReview plugs into the surrounding ecosystem instead of locking you in: CI/CD via GitHub Actions, GitLab CI, GitFlic CI, and Gerrit; coding agent plugins for Claude Code (/open-code-review:review), Codex, Cursor, Kimi Code, OpenCode, and QCA Forward; a portable agent skill (npx skills add alibaba/open-code-review --skill open-code-review); plus OpenTelemetry telemetry for observability.

    Verdict

    OpenCodeReview is the credible open-source challenger to commercial review tools like CodeRabbit: the same frontier models under the hood, but precision-first output at a fraction of the tokens, with complete control over where your code goes. Engineering teams and maintainers who want low-noise, self-hosted AI review — and already pay for an LLM key — should try it. Teams that need exhaustive recall on security-critical changes should treat it as one layer of a broader review stack, not the only one.

    Further Reading

    Version History

    1.12.9

    Session viewer fixes, credential command validation hardening, GitLab multiline comments

    1.12.8

    F# review support; dependency and build-output directories excluded by default

    1.12.7

    Session export to self-contained HTML file

    1.0

    Initial open-source release of Alibaba's internal AI code-review assistant

    Signature Snippet
    After installing via `npm install -g @alibaba-group/open-code-review`, a developer runs `ocr review --from main --to feature-branch` inside the repo. The CLI reads the diff, selects and bundles the changed files, and sends them to the configured LLM. Minutes later it returns structured review comments pinned to exact lines — a null-pointer dereference in a Go handler, a missing SQL-injection guard on a new endpoint — with zero noise on the untouched files.

    Live feed in your inbox

    Track the tools. Lead the shift.

    Tech leaders use Artificialus to stay ahead: editorial picks, agent comparisons, MCP updates, and signal-heavy analysis when it matters.

    No spam. Only tools and shifts worth tracking.