open-code-review
Provides automated pull request reviews and security scanning for GitHub repositories, including SARIF output for GitHub Code Scanning.
Offers a dedicated GitHub Action to implement a CI/CD quality gate for detecting defects in AI-generated code.
Acts as a quality gate for code generated by GitHub Copilot to detect hallucinations and stale APIs that traditional linters miss.
Integrates with GitLab CI pipelines to provide automated code quality reports and security analysis.
Features specialized detectors for JavaScript to identify hallucinated imports, stale APIs, and over-engineering.
Detects Kotlin-specific anti-patterns such as null-safety abuse and println leaks during automated code reviews.
Verifies JavaScript and TypeScript package imports against the npm registry to detect hallucinated dependencies.
Enables 100% local, privacy-focused code analysis and deep scanning using local LLM models via Ollama.
Utilizes OpenAI-compatible APIs for deep LLM analysis, cross-file coherence checks, and logic bug detection.
Cross-references Python imports with the PyPI database to identify hallucinated or non-existent package declarations.
Includes dedicated scanners for Python to detect bare excepts, eval usage, and hallucinated imports.
Provides deep structural and semantic analysis for TypeScript codebases, including hallucinated npm import detection.
Performs security scanning to detect potential vulnerabilities and anti-patterns related to Unicode usage in source code.
Supports YAML-based configuration for defining quality gate thresholds, SLA levels, and AI provider settings.
Open Code Review
The first open-source CI/CD quality gate built specifically for AI-generated code. Detects hallucinated imports, stale APIs, over-engineering, and security anti-patterns — powered by local LLMs and any OpenAI-compatible provider. Free. Self-hostable. 6 languages.

Works With
Any AI tool that generates code — if it writes it, OCR reviews it.
Related MCP server: guardvibe
What AI Linters Miss
AI coding assistants (Copilot, Cursor, Claude) generate code with defects that traditional tools miss entirely:
Defect | Example | ESLint / SonarQube |
Hallucinated imports |
| ❌ Miss |
Stale APIs | Using deprecated APIs from training data | ❌ Miss |
Context window artifacts | Logic contradictions across files | ❌ Miss |
Over-engineered patterns | Unnecessary abstractions, dead code | ❌ Miss |
Security anti-patterns | Hardcoded example secrets, | ❌ Partial |
Open Code Review detects all of them — across 6 languages, for free.
Demo

📄 View full interactive HTML report
Quick Preview
$ ocr scan src/ --sla L3
╔══════════════════════════════════════════════════════════════╗
║ Open Code Review — Deep Scan Report ║
╚══════════════════════════════════════════════════════════════╝
Project: packages/core/src
SLA: L3 Deep — Structural + Embedding + LLM Analysis
112 issues found in 110 files
Overall Score: 67/100 D
Threshold: 70 | Status: FAILED
Files Scanned: 110 | Languages: typescript | Duration: 12.3sDeep Scan (L3) — How It Works
L3 combines three analysis layers for maximum coverage:
Layer 1: Structural Detection Layer 2: Semantic Analysis Layer 3: LLM Deep Scan
├── Hallucinated imports (npm/PyPI) ├── Embedding similarity recall ├── Cross-file coherence check
├── Stale API detection ├── Risk scoring ├── Logic bug detection
├── Security patterns ├── Context window artifacts ├── Confidence scoring
├── Over-engineering metrics └── Enhanced severity ranking └── AI-powered fix suggestions
└── A+ → F quality scoringPowered by local LLMs or any OpenAI-compatible API. Run Ollama for 100% local analysis, or connect to any remote LLM provider — the interface is the same.
# Local analysis (Ollama)
ocr scan src/ --sla L3 --provider ollama --model qwen3-coder
# Any OpenAI-compatible provider
ocr scan src/ --sla L3 --provider openai-compatible \
--api-base https://your-llm-endpoint/v1 --model your-model --api-key YOUR_KEYAI Auto-Fix — ocr heal
Let AI automatically fix the issues it finds. Review changes before applying.
# Preview fixes without changing files
ocr heal src/ --dry-run
# Apply fixes + generate IDE rules
ocr heal src/ --provider ollama --model qwen3-coder --setup-ide
# Only generate IDE rules (Cursor, Copilot, Augment)
ocr setup src/Multi-Language Detection
Language-specific detectors for 6 languages, plus hallucinated package databases (npm, PyPI, Maven, Go modules):
Language | Specific Detectors |
TypeScript / JavaScript | Hallucinated imports (npm), stale APIs, over-engineering |
Python | Bare |
Java |
|
Go | Unhandled errors, deprecated |
Kotlin |
|
How It Compares
Open Code Review | Claude Code Review | CodeRabbit | GitHub Copilot | |
Price | Free | $15–25/PR | $24/mo/seat | $10–39/mo |
Open Source | ✅ | ❌ | ❌ | ❌ |
Self-hosted | ✅ | ❌ | Enterprise | ❌ |
AI Hallucination Detection | ✅ | ❌ | ❌ | ❌ |
Stale API Detection | ✅ | ❌ | ❌ | ❌ |
Deep LLM Analysis | ✅ | ❌ | ❌ | ❌ |
AI Auto-Fix | ✅ | ❌ | ❌ | ❌ |
Multi-Language | ✅ 6 langs | ❌ | JS/TS | JS/TS |
Registry Verification | ✅ npm/PyPI/Maven | ❌ | ❌ | ❌ |
Unicode Security Detection | ✅ | ❌ | ❌ | ❌ |
SARIF Output | ✅ | ❌ | ❌ | ❌ |
GitHub + GitLab | ✅ Both | GitHub only | Both | GitHub only |
Data Privacy | ✅ 100% local | ❌ Cloud | ❌ Cloud | ❌ Cloud |
Quick Start
# Install
npm install -g @opencodereview/cli
# Fast scan — no AI needed
ocr scan src/
# Deep scan — with local LLM (Ollama)
ocr scan src/ --sla L3 --provider ollama --model qwen3-coder
# Deep scan — with any OpenAI-compatible provider
ocr scan src/ --sla L3 --provider openai-compatible \
--api-base https://your-provider/v1 --model your-model --api-key YOUR_KEYCI/CD Integration
GitHub Actions (30 seconds)
name: Code Review
on: [pull_request]
jobs:
review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: raye-deng/open-code-review@v1
with:
sla: L1
threshold: 60
github-token: ${{ secrets.GITHUB_TOKEN }}GitLab CI
code-review:
script:
- npx @opencodereview/cli scan src/ --sla L1 --threshold 60 --format json --output ocr-report.json
artifacts:
reports:
codequality: ocr-report.jsonOutput Formats
ocr scan src/ --format terminal # Pretty terminal output
ocr scan src/ --format json # JSON for CI pipelines
ocr scan src/ --format sarif # SARIF for GitHub Code Scanning
ocr scan src/ --format html # Interactive HTML reportConfiguration
# .ocrrc.yml
sla: L3
ai:
embedding:
provider: ollama
model: nomic-embed-text
baseUrl: http://localhost:11434
llm:
provider: ollama
model: qwen3-coder
endpoint: http://localhost:11434
# Or use any OpenAI-compatible provider:
# provider: openai-compatible
# apiBase: https://your-llm-endpoint/v1
# model: your-modelMCP Server — Use in Claude Desktop, Cursor, Windsurf
Integrate Open Code Review directly into your AI IDE via the Model Context Protocol:
npx @opencodereview/mcp-serverClaude Desktop (claude_desktop_config.json):
{
"mcpServers": {
"open-code-review": {
"command": "npx",
"args": ["-y", "@opencodereview/mcp-server"]
}
}
}Cursor / Windsurf / VS Code Copilot: Add the same configuration in your MCP settings.
Available MCP Tools: ocr_scan (quality gate scan), ocr_heal (AI auto-fix), ocr_explain (issue explanation).
💡 Chrome DevTools MCP Compatible: The OCR MCP Server follows the standard Model Context Protocol. Pair it with Google's Chrome DevTools MCP Server for a complete AI-native dev workflow — one inspects your running app, the other inspects your source code.
Project Structure
packages/
core/ # Detection engine + scoring (@opencodereview/core)
cli/ # CLI tool — ocr command (@opencodereview/cli)
mcp-server/ # MCP Server for AI IDEs (@opencodereview/mcp-server)
github-action/ # GitHub Action wrapperWho Is This For?
Teams using AI coding assistants — Copilot, Cursor, Claude Code, Codex, or any LLM-based tool that generates production code
Open-source maintainers — Review AI-generated PRs for hallucinated imports, stale APIs, and security anti-patterns before merging
DevOps / Platform engineers — Add a quality gate to CI/CD pipelines without sending code to cloud services
Security-conscious teams — Run everything locally (Ollama), keep your code on your machines
Solo developers — Free, fast, and works with zero configuration (
npx @opencodereview/cli scan src/)
Featured On
License
BSL-1.1 — Free for personal and non-commercial use. Converts to Apache 2.0 on 2030-03-11. Commercial use requires a Team or Enterprise license.
Star this repo if you find it useful — it helps more than you think!
Available Tools
4 toolsexplain_issueC
Explain a code quality issue detected by OCR. Returns detailed explanation, category context, and fix guidance for the AI agent to act on.
| Name | Required | Description | Default |
|---|---|---|---|
| issue | Yes | The issue description to explain | |
| file | No | File path where the issue was found | |
| line | No | Line number | |
| severity | No | Severity: critical/high/medium/low/info | |
| category | No | Issue category | |
| suggestion | No | Auto-generated fix suggestion |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It states the tool returns explanations and guidance, but doesn't describe behavioral traits like whether it's read-only, if it has side effects, rate limits, or authentication needs. For a tool with no annotations, this leaves significant gaps in understanding how it behaves.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise and front-loaded, stating the core purpose in the first clause. It uses two sentences efficiently to cover what the tool does and what it returns. There's no wasted verbiage, though it could be slightly more structured by explicitly separating purpose from output.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity (6 parameters, no output schema, no annotations), the description is minimally adequate. It covers the basic purpose and return types but lacks details on behavioral traits, usage context relative to siblings, and output format specifics. With no output schema, the description should ideally explain return values more thoroughly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description doesn't add any parameter-specific information beyond what's in the input schema. Since schema description coverage is 100%, the schema already documents all 6 parameters thoroughly. The baseline score of 3 is appropriate as the description doesn't compensate but also doesn't detract from the comprehensive schema documentation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Explain a code quality issue detected by OCR.' It specifies the verb (explain) and resource (code quality issue), and mentions the return content (detailed explanation, category context, fix guidance). However, it doesn't explicitly differentiate from sibling tools like 'heal_code' or 'scan_diff' which might handle similar issues.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides minimal usage guidance. It implies this tool should be used when an AI agent needs to understand and act on a code quality issue, but it doesn't specify when to use this versus alternatives like 'heal_code' (which might fix issues) or 'scan_diff' (which might detect them). No explicit when/when-not instructions or prerequisites are mentioned.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
heal_codeC
Load a file's source code and prepare a repair prompt for the AI agent. The agent (you) should then apply the fix based on the issue description and suggestion. Returns the file content along with the repair context.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | File path to heal | |
| issue | Yes | Issue description to fix | |
| suggestion | No | Suggested fix from OCR scan |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden. It discloses that the tool loads code and prepares a repair prompt, but lacks details on behavioral traits such as permissions needed, whether it modifies the file (implied by 'heal' but not confirmed), error handling, rate limits, or what 'repair context' entails. This leaves significant gaps for a tool with potential mutation implications.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise and front-loaded, stating the core action in the first sentence. Both sentences earn their place by explaining the tool's function and the agent's role. However, it could be slightly more structured by explicitly separating tool behavior from agent instructions.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no annotations and no output schema, the description is incomplete. It mentions returns 'file content along with the repair context' but doesn't detail the output format or behavioral aspects like side effects. For a tool named 'heal_code' with potential mutations, more context on safety, response structure, and error cases is needed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema fully documents parameters (path, issue, suggestion). The description adds marginal value by implying parameters are used to 'prepare a repair prompt' and 'apply the fix,' but doesn't provide additional syntax, format, or usage details beyond what the schema already specifies. Baseline 3 is appropriate here.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Load a file's source code and prepare a repair prompt for the AI agent.' It specifies the verb ('load' and 'prepare'), resource ('file's source code'), and outcome ('repair prompt'). However, it doesn't explicitly differentiate from sibling tools like 'explain_issue' or 'scan_diff', which might also involve code analysis or repair contexts.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides minimal guidance on when to use this tool. It mentions the agent should 'apply the fix based on the issue description and suggestion,' implying usage for code repair scenarios, but offers no explicit when-to-use vs. alternatives, prerequisites, or exclusions compared to siblings like 'scan_directory' or 'explain_issue'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
scan_diffA
Scan git diff between two branches for code quality issues. Ideal for PR/MR review — only analyzes changed files and lines.
| Name | Required | Description | Default |
|---|---|---|---|
| base | Yes | Base branch (e.g. 'origin/main') | |
| head | Yes | Head branch (e.g. 'HEAD') | |
| path | Yes | Repository path | |
| level | No | SLA level | L1 |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It discloses that the tool 'only analyzes changed files and lines,' which is useful behavioral context about its scope. However, it doesn't mention performance characteristics (e.g., speed, resource usage), error handling, or what constitutes 'code quality issues,' leaving gaps in behavioral understanding.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two concise sentences with zero waste. The first sentence states the core purpose, and the second adds crucial context about scope and ideal use case. Every word earns its place, and information is front-loaded effectively.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no annotations and no output schema, the description provides adequate purpose and usage context but lacks details on what the tool returns (e.g., issue list format, severity levels) or behavioral traits like error conditions. For a tool with 4 parameters and no structured output documentation, this leaves room for improvement in completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all parameters thoroughly. The description adds no additional parameter semantics beyond what's in the schema (e.g., it doesn't explain what 'SLA level' means or provide examples for 'path'). Baseline 3 is appropriate when the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with a specific verb ('scan'), resource ('git diff between two branches'), and target ('for code quality issues'). It distinguishes from sibling tools like 'scan_directory' by specifying it only analyzes changed files and lines, making it ideal for PR/MR review contexts.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context for when to use this tool ('Ideal for PR/MR review') and specifies it 'only analyzes changed files and lines,' which implicitly differentiates it from 'scan_directory' that likely scans entire directories. However, it doesn't explicitly state when not to use it or name alternatives like 'explain_issue' or 'heal_code' for related tasks.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
scan_directoryB
Scan a directory for AI-generated code quality issues. Detects hallucinated imports, phantom packages, stale APIs, security anti-patterns, and more. Supports TypeScript, JavaScript, Python, Java, Go, and Kotlin.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Directory path to scan | |
| level | No | SLA level: L1 (fast structural), L2 (standard + local AI), L3 (deep + remote AI) | L1 |
| languages | No | Comma-separated languages (e.g. 'typescript,python'). Auto-detect if omitted. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden but only partially discloses behavioral traits. It mentions detection capabilities and language support, but omits critical details like whether the scan is read-only, its performance impact, error handling, or output format. For a tool with no annotations, this leaves significant gaps in understanding its behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is appropriately sized and front-loaded, starting with the core action and key detection categories. Both sentences earn their place by specifying scope and capabilities, though it could be slightly more structured by separating usage notes from feature lists.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (scanning for multiple issue types across languages) and lack of annotations and output schema, the description is incomplete. It doesn't explain what the scan returns, how results are formatted, or any behavioral constraints like rate limits or permissions needed, making it inadequate for full contextual understanding.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all parameters well. The description adds minimal value beyond the schema by mentioning language support, which aligns with the 'languages' parameter, but doesn't provide additional syntax or format details. This meets the baseline for high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with specific verbs ('scan', 'detects') and resources ('directory', 'AI-generated code quality issues'), listing concrete detection categories like hallucinated imports and security anti-patterns. It distinguishes from sibling tools by focusing on scanning rather than explaining or healing issues.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for scanning directories in supported languages, but lacks explicit guidance on when to use this tool versus alternatives like 'scan_diff' or when not to use it. No prerequisites or exclusions are mentioned, leaving usage context somewhat vague.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
4 tool updates
v1.0.0- First observed
explain_issue - First observed
heal_code - First observed
scan_diff - First observed
scan_directory
TDQS
Each tool has a clearly distinct purpose with no overlap: explain_issue provides explanations, heal_code prepares repair prompts, scan_diff analyzes git diffs, and scan_directory scans directories. The descriptions clearly differentiate their functions, making misselection unlikely.
All tool names follow a consistent verb_noun pattern (explain_issue, heal_code, scan_diff, scan_directory) with clear, descriptive verbs that match their actions. There are no deviations in naming conventions.
Four tools are reasonable for a code review server, covering explanation, repair, diff scanning, and directory scanning. It's slightly lean but well-scoped, as each tool serves a distinct function without redundancy.
The tool set covers key code review workflows: scanning (diff and directory), explaining issues, and preparing repairs. Minor gaps might include tools for applying fixes directly or managing review states, but the core functionality is well-covered for the domain.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
AI-native git hosting — repos, PRs, issues, CI gates, and AI code review over MCP (60 tools).
AI-powered codebase analysis — call graphs, security, dead code, complexity. 150+ tools.
Code intelligence platform for AI agents. 20 tools for architecture, security & impact analysis.
Related MCP Servers
- AlicenseDqualityAmaintenanceSkylos MCP server exposes static analysis as tools for AI coding agents — scan any Python, TypeScript, or Go codebase for dead code, security vulnerabilities, and quality issues directly from Claude, Cursor, or any MCP-compatible client. Returns findings with file paths, line numbers, and severity so agents can auto-fix issues in context.12591Apache 2.0
- AlicenseAqualityAmaintenanceSecurity MCP server with 300+ rules for AI-generated code. Scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL and 20+ modules. Zero config, runs locally.393935Apache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables AI-powered, zero-trust code review with multiple models, supporting single files, git diffs, and multiple files, with security, performance, and architecture checks across 10+ languages.13MIT
- AlicenseNot gradedqualityCmaintenanceOpen-source AI code review MCP server for local git diff auditing with deterministic security rules and AI-powered analysis using any OpenAI-compatible model.4MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/raye-deng/open-code-review'
If you have feedback or need assistance with the MCP directory API, please join our Discord server