Skip to main content
Glama

Open Code Review

The first open-source CI/CD quality gate built specifically for AI-generated code. Detects hallucinated imports, stale APIs, over-engineering, and security anti-patterns — powered by local LLMs and any OpenAI-compatible provider. Free. Self-hostable. 6 languages.

Open Code Review

npm version npm version npm downloads License: BUSL-1.1 CI GitHub Stars PRs Welcome

Works With

Cursor GitHub Copilot Claude Code Windsurf Codex Augment Code Supermaven Aider

Any AI tool that generates code — if it writes it, OCR reviews it.

Related MCP server: guardvibe

What AI Linters Miss

AI coding assistants (Copilot, Cursor, Claude) generate code with defects that traditional tools miss entirely:

Defect

Example

ESLint / SonarQube

Hallucinated imports

import { x } from 'non-existent-pkg'

❌ Miss

Stale APIs

Using deprecated APIs from training data

❌ Miss

Context window artifacts

Logic contradictions across files

❌ Miss

Over-engineered patterns

Unnecessary abstractions, dead code

❌ Miss

Security anti-patterns

Hardcoded example secrets, eval()

❌ Partial

Open Code Review detects all of them — across 6 languages, for free.

Demo

L2 HTML Report Screenshot

📄 View full interactive HTML report

Quick Preview

$ ocr scan src/ --sla L3

╔══════════════════════════════════════════════════════════════╗
║           Open Code Review — Deep Scan Report               ║
╚══════════════════════════════════════════════════════════════╝

  Project: packages/core/src
  SLA: L3 Deep — Structural + Embedding + LLM Analysis

  112 issues found in 110 files

  Overall Score: 67/100  D
  Threshold: 70  |  Status: FAILED
  Files Scanned: 110  |  Languages: typescript  |  Duration: 12.3s

Deep Scan (L3) — How It Works

L3 combines three analysis layers for maximum coverage:

Layer 1: Structural Detection         Layer 2: Semantic Analysis        Layer 3: LLM Deep Scan
├── Hallucinated imports (npm/PyPI)   ├── Embedding similarity recall   ├── Cross-file coherence check
├── Stale API detection               ├── Risk scoring                  ├── Logic bug detection
├── Security patterns                 ├── Context window artifacts      ├── Confidence scoring
├── Over-engineering metrics          └── Enhanced severity ranking     └── AI-powered fix suggestions
└── A+ → F quality scoring

Powered by local LLMs or any OpenAI-compatible API. Run Ollama for 100% local analysis, or connect to any remote LLM provider — the interface is the same.

# Local analysis (Ollama)
ocr scan src/ --sla L3 --provider ollama --model qwen3-coder

# Any OpenAI-compatible provider
ocr scan src/ --sla L3 --provider openai-compatible \
  --api-base https://your-llm-endpoint/v1 --model your-model --api-key YOUR_KEY

AI Auto-Fix — ocr heal

Let AI automatically fix the issues it finds. Review changes before applying.

# Preview fixes without changing files
ocr heal src/ --dry-run

# Apply fixes + generate IDE rules
ocr heal src/ --provider ollama --model qwen3-coder --setup-ide

# Only generate IDE rules (Cursor, Copilot, Augment)
ocr setup src/

Multi-Language Detection

Language-specific detectors for 6 languages, plus hallucinated package databases (npm, PyPI, Maven, Go modules):

Language

Specific Detectors

TypeScript / JavaScript

Hallucinated imports (npm), stale APIs, over-engineering

Python

Bare except, eval(), mutable default args, hallucinated imports (PyPI)

Java

System.out.println leaks, deprecated Date/Calendar, hallucinated imports (Maven)

Go

Unhandled errors, deprecated ioutil, panic in library code

Kotlin

!! abuse, println leaks, null-safety anti-patterns

How It Compares

Open Code Review

Claude Code Review

CodeRabbit

GitHub Copilot

Price

Free

$15–25/PR

$24/mo/seat

$10–39/mo

Open Source

Self-hosted

Enterprise

AI Hallucination Detection

Stale API Detection

Deep LLM Analysis

AI Auto-Fix

Multi-Language

✅ 6 langs

JS/TS

JS/TS

Registry Verification

✅ npm/PyPI/Maven

Unicode Security Detection

SARIF Output

GitHub + GitLab

✅ Both

GitHub only

Both

GitHub only

Data Privacy

✅ 100% local

❌ Cloud

❌ Cloud

❌ Cloud

Quick Start

# Install
npm install -g @opencodereview/cli

# Fast scan — no AI needed
ocr scan src/

# Deep scan — with local LLM (Ollama)
ocr scan src/ --sla L3 --provider ollama --model qwen3-coder

# Deep scan — with any OpenAI-compatible provider
ocr scan src/ --sla L3 --provider openai-compatible \
  --api-base https://your-provider/v1 --model your-model --api-key YOUR_KEY

CI/CD Integration

GitHub Actions (30 seconds)

name: Code Review
on: [pull_request]

jobs:
  review:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: raye-deng/open-code-review@v1
        with:
          sla: L1
          threshold: 60
          github-token: ${{ secrets.GITHUB_TOKEN }}

GitLab CI

code-review:
  script:
    - npx @opencodereview/cli scan src/ --sla L1 --threshold 60 --format json --output ocr-report.json
  artifacts:
    reports:
      codequality: ocr-report.json

Output Formats

ocr scan src/ --format terminal    # Pretty terminal output
ocr scan src/ --format json        # JSON for CI pipelines
ocr scan src/ --format sarif       # SARIF for GitHub Code Scanning
ocr scan src/ --format html        # Interactive HTML report

Configuration

# .ocrrc.yml
sla: L3
ai:
  embedding:
    provider: ollama
    model: nomic-embed-text
    baseUrl: http://localhost:11434
  llm:
    provider: ollama
    model: qwen3-coder
    endpoint: http://localhost:11434

  # Or use any OpenAI-compatible provider:
  # provider: openai-compatible
  # apiBase: https://your-llm-endpoint/v1
  # model: your-model

MCP Server — Use in Claude Desktop, Cursor, Windsurf

Integrate Open Code Review directly into your AI IDE via the Model Context Protocol:

npx @opencodereview/mcp-server

Claude Desktop (claude_desktop_config.json):

{
  "mcpServers": {
    "open-code-review": {
      "command": "npx",
      "args": ["-y", "@opencodereview/mcp-server"]
    }
  }
}

Cursor / Windsurf / VS Code Copilot: Add the same configuration in your MCP settings.

Available MCP Tools: ocr_scan (quality gate scan), ocr_heal (AI auto-fix), ocr_explain (issue explanation).

💡 Chrome DevTools MCP Compatible: The OCR MCP Server follows the standard Model Context Protocol. Pair it with Google's Chrome DevTools MCP Server for a complete AI-native dev workflow — one inspects your running app, the other inspects your source code.

Project Structure

packages/
  core/              # Detection engine + scoring (@opencodereview/core)
  cli/               # CLI tool — ocr command (@opencodereview/cli)
  mcp-server/        # MCP Server for AI IDEs (@opencodereview/mcp-server)
  github-action/     # GitHub Action wrapper

Who Is This For?

  • Teams using AI coding assistants — Copilot, Cursor, Claude Code, Codex, or any LLM-based tool that generates production code

  • Open-source maintainers — Review AI-generated PRs for hallucinated imports, stale APIs, and security anti-patterns before merging

  • DevOps / Platform engineers — Add a quality gate to CI/CD pipelines without sending code to cloud services

  • Security-conscious teams — Run everything locally (Ollama), keep your code on your machines

  • Solo developers — Free, fast, and works with zero configuration (npx @opencodereview/cli scan src/)

License

BSL-1.1 — Free for personal and non-commercial use. Converts to Apache 2.0 on 2030-03-11. Commercial use requires a Team or Enterprise license.


Star this repo if you find it useful — it helps more than you think!

Available Tools

4 tools
explain_issueC

Explain a code quality issue detected by OCR. Returns detailed explanation, category context, and fix guidance for the AI agent to act on.

ParametersJSON Schema
NameRequiredDescriptionDefault
issueYesThe issue description to explain
fileNoFile path where the issue was found
lineNoLine number
severityNoSeverity: critical/high/medium/low/info
categoryNoIssue category
suggestionNoAuto-generated fix suggestion

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It states the tool returns explanations and guidance, but doesn't describe behavioral traits like whether it's read-only, if it has side effects, rate limits, or authentication needs. For a tool with no annotations, this leaves significant gaps in understanding how it behaves.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise and front-loaded, stating the core purpose in the first clause. It uses two sentences efficiently to cover what the tool does and what it returns. There's no wasted verbiage, though it could be slightly more structured by explicitly separating purpose from output.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's moderate complexity (6 parameters, no output schema, no annotations), the description is minimally adequate. It covers the basic purpose and return types but lacks details on behavioral traits, usage context relative to siblings, and output format specifics. With no output schema, the description should ideally explain return values more thoroughly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The description doesn't add any parameter-specific information beyond what's in the input schema. Since schema description coverage is 100%, the schema already documents all 6 parameters thoroughly. The baseline score of 3 is appropriate as the description doesn't compensate but also doesn't detract from the comprehensive schema documentation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: 'Explain a code quality issue detected by OCR.' It specifies the verb (explain) and resource (code quality issue), and mentions the return content (detailed explanation, category context, fix guidance). However, it doesn't explicitly differentiate from sibling tools like 'heal_code' or 'scan_diff' which might handle similar issues.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides minimal usage guidance. It implies this tool should be used when an AI agent needs to understand and act on a code quality issue, but it doesn't specify when to use this versus alternatives like 'heal_code' (which might fix issues) or 'scan_diff' (which might detect them). No explicit when/when-not instructions or prerequisites are mentioned.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

heal_codeC

Load a file's source code and prepare a repair prompt for the AI agent. The agent (you) should then apply the fix based on the issue description and suggestion. Returns the file content along with the repair context.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesFile path to heal
issueYesIssue description to fix
suggestionNoSuggested fix from OCR scan

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden. It discloses that the tool loads code and prepares a repair prompt, but lacks details on behavioral traits such as permissions needed, whether it modifies the file (implied by 'heal' but not confirmed), error handling, rate limits, or what 'repair context' entails. This leaves significant gaps for a tool with potential mutation implications.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise and front-loaded, stating the core action in the first sentence. Both sentences earn their place by explaining the tool's function and the agent's role. However, it could be slightly more structured by explicitly separating tool behavior from agent instructions.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no annotations and no output schema, the description is incomplete. It mentions returns 'file content along with the repair context' but doesn't detail the output format or behavioral aspects like side effects. For a tool named 'heal_code' with potential mutations, more context on safety, response structure, and error cases is needed.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema fully documents parameters (path, issue, suggestion). The description adds marginal value by implying parameters are used to 'prepare a repair prompt' and 'apply the fix,' but doesn't provide additional syntax, format, or usage details beyond what the schema already specifies. Baseline 3 is appropriate here.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: 'Load a file's source code and prepare a repair prompt for the AI agent.' It specifies the verb ('load' and 'prepare'), resource ('file's source code'), and outcome ('repair prompt'). However, it doesn't explicitly differentiate from sibling tools like 'explain_issue' or 'scan_diff', which might also involve code analysis or repair contexts.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides minimal guidance on when to use this tool. It mentions the agent should 'apply the fix based on the issue description and suggestion,' implying usage for code repair scenarios, but offers no explicit when-to-use vs. alternatives, prerequisites, or exclusions compared to siblings like 'scan_directory' or 'explain_issue'.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

scan_diffA

Scan git diff between two branches for code quality issues. Ideal for PR/MR review — only analyzes changed files and lines.

ParametersJSON Schema
NameRequiredDescriptionDefault
baseYesBase branch (e.g. 'origin/main')
headYesHead branch (e.g. 'HEAD')
pathYesRepository path
levelNoSLA levelL1

TDQS

A3.9/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden. It discloses that the tool 'only analyzes changed files and lines,' which is useful behavioral context about its scope. However, it doesn't mention performance characteristics (e.g., speed, resource usage), error handling, or what constitutes 'code quality issues,' leaving gaps in behavioral understanding.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two concise sentences with zero waste. The first sentence states the core purpose, and the second adds crucial context about scope and ideal use case. Every word earns its place, and information is front-loaded effectively.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no annotations and no output schema, the description provides adequate purpose and usage context but lacks details on what the tool returns (e.g., issue list format, severity levels) or behavioral traits like error conditions. For a tool with 4 parameters and no structured output documentation, this leaves room for improvement in completeness.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all parameters thoroughly. The description adds no additional parameter semantics beyond what's in the schema (e.g., it doesn't explain what 'SLA level' means or provide examples for 'path'). Baseline 3 is appropriate when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose with a specific verb ('scan'), resource ('git diff between two branches'), and target ('for code quality issues'). It distinguishes from sibling tools like 'scan_directory' by specifying it only analyzes changed files and lines, making it ideal for PR/MR review contexts.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear context for when to use this tool ('Ideal for PR/MR review') and specifies it 'only analyzes changed files and lines,' which implicitly differentiates it from 'scan_directory' that likely scans entire directories. However, it doesn't explicitly state when not to use it or name alternatives like 'explain_issue' or 'heal_code' for related tasks.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

scan_directoryB

Scan a directory for AI-generated code quality issues. Detects hallucinated imports, phantom packages, stale APIs, security anti-patterns, and more. Supports TypeScript, JavaScript, Python, Java, Go, and Kotlin.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesDirectory path to scan
levelNoSLA level: L1 (fast structural), L2 (standard + local AI), L3 (deep + remote AI)L1
languagesNoComma-separated languages (e.g. 'typescript,python'). Auto-detect if omitted.

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries full burden but only partially discloses behavioral traits. It mentions detection capabilities and language support, but omits critical details like whether the scan is read-only, its performance impact, error handling, or output format. For a tool with no annotations, this leaves significant gaps in understanding its behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is appropriately sized and front-loaded, starting with the core action and key detection categories. Both sentences earn their place by specifying scope and capabilities, though it could be slightly more structured by separating usage notes from feature lists.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (scanning for multiple issue types across languages) and lack of annotations and output schema, the description is incomplete. It doesn't explain what the scan returns, how results are formatted, or any behavioral constraints like rate limits or permissions needed, making it inadequate for full contextual understanding.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all parameters well. The description adds minimal value beyond the schema by mentioning language support, which aligns with the 'languages' parameter, but doesn't provide additional syntax or format details. This meets the baseline for high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose with specific verbs ('scan', 'detects') and resources ('directory', 'AI-generated code quality issues'), listing concrete detection categories like hallucinated imports and security anti-patterns. It distinguishes from sibling tools by focusing on scanning rather than explaining or healing issues.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for scanning directories in supported languages, but lacks explicit guidance on when to use this tool versus alternatives like 'scan_diff' or when not to use it. No prerequisites or exclusions are mentioned, leaving usage context somewhat vague.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 4 tool updatesv1.0.0
    • First observedexplain_issue
    • First observedheal_code
    • First observedscan_diff
    • First observedscan_directory

TDQS

A3.5/5.0
Disambiguation5/5

Each tool has a clearly distinct purpose with no overlap: explain_issue provides explanations, heal_code prepares repair prompts, scan_diff analyzes git diffs, and scan_directory scans directories. The descriptions clearly differentiate their functions, making misselection unlikely.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern (explain_issue, heal_code, scan_diff, scan_directory) with clear, descriptive verbs that match their actions. There are no deviations in naming conventions.

Tool Count4/5

Four tools are reasonable for a code review server, covering explanation, repair, diff scanning, and directory scanning. It's slightly lean but well-scoped, as each tool serves a distinct function without redundancy.

Completeness4/5

The tool set covers key code review workflows: scanning (diff and directory), explaining issues, and preparing repairs. Minor gaps might include tools for applying fixes directly or managing review states, but the core functionality is well-covered for the domain.

Maintenance

ActivityInactive
ResponsivenessWithin a week

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    D
    quality
    A
    maintenance
    Skylos MCP server exposes static analysis as tools for AI coding agents — scan any Python, TypeScript, or Go codebase for dead code, security vulnerabilities, and quality issues directly from Claude, Cursor, or any MCP-compatible client. Returns findings with file paths, line numbers, and severity so agents can auto-fix issues in context.
    12
    591
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    Security MCP server with 300+ rules for AI-generated code. Scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL and 20+ modules. Zero config, runs locally.
    39
    393
    5
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI-powered, zero-trust code review with multiple models, supporting single files, git diffs, and multiple files, with security, performance, and architecture checks across 10+ languages.
    13
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/raye-deng/open-code-review'

If you have feedback or need assistance with the MCP directory API, please join our Discord server