Open Code Review — AI Code Quality Scanner
Scan codebases for AI-specific defects that traditional linters (ESLint, SonarQube, Checkstyle) cannot detect.
What It Detects
| Category |
Example |
Severity |
| Hallucinated packages |
import { parseJson } from 'fast-json-utils' (package doesn't exist on npm) |
🔴 Critical |
| Stale APIs |
response.json().then() with v2 API that was removed in v4 |
🟡 Warning |
| Context breaks |
Two files reference the same function name with different signatures |
🟡 Warning |
| Security anti-patterns |
Hardcoded secrets, deprecated crypto, insecure defaults |
🔴 Critical |
| Over-engineering |
Unnecessary abstraction layers, dead code, excessive indirection |
🔵 Info |
Quick Start
# Install
npx @opencodereview/cli scan ./src --sla L1
# With AI-powered deep scan (requires Ollama or API key)
npx @opencodereview/cli scan ./src --sla L2
# Diff mode for CI/CD
npx @opencodereview/cli scan ./src --diff --base origin/main --head HEAD
# SARIF output for GitHub Actions
npx @opencodereview/cli scan ./src --format sarif --output results.sarif
Three Scan Levels
- L1 — Structural analysis (AST, ~3 seconds, no AI needed)
- L2 — L1 + Embedding recall (detects hallucinated packages via vector similarity)
- L3 — L2 + LLM deep scan (understands context, semantics, business logic)
GitHub Action
- uses: raye-deng/open-code-review@v1
with:
scan-path: src/
sla-level: L1
diff-mode: true
MCP Server
Available on Smithery, Cursor Directory, and npm:
{
"mcpServers": {
"open-code-review": {
"url": "https://open-code-review-mcp.v2ray-seins.workers.dev/mcp"
}
}
}
Or via stdio:
{
"mcpServers": {
"open-code-review": {
"command": "npx",
"args": ["-y", "@opencodereview/mcp-server"]
}
}
}
Supported Languages
TypeScript, JavaScript, Python, Java, Go, Kotlin
When to Use This Skill
- A PR contains AI-generated code (Copilot, Cursor, Claude, GPT)
- You want to catch defects that pass all unit tests but will fail in production
- Pre-merge quality gate for AI-assisted development workflows
- Scanning third-party AI-generated code before integration
When NOT to Use
- Basic linting (use ESLint, Ruff, Checkstyle instead)
- Code formatting (use Prettier, gofmt)
- General code review guidance (use the built-in code-review skill)
Links
1---2name: open-code-review3description: Scan AI-generated code for hallucinated packages, stale APIs, security anti-patterns, and over-engineering. Use when: (1) reviewing PRs with AI-generated code, (2) running pre-merge quality gates, (3) scanning repos for AI-specific defects that traditional linters miss. NOT for: basic linting, formatting, or general code review guidance.4---56# Open Code Review — AI Code Quality Scanner78Scan codebases for **AI-specific defects** that traditional linters (ESLint, SonarQube, Checkstyle) cannot detect.910## What It Detects1112| Category | Example | Severity |13|----------|---------|----------|14| **Hallucinated packages** | `import { parseJson } from 'fast-json-utils'` (package doesn't exist on npm) | 🔴 Critical |15| **Stale APIs** | `response.json().then()` with v2 API that was removed in v4 | 🟡 Warning |16| **Context breaks** | Two files reference the same function name with different signatures | 🟡 Warning |17| **Security anti-patterns** | Hardcoded secrets, deprecated crypto, insecure defaults | 🔴 Critical |18| **Over-engineering** | Unnecessary abstraction layers, dead code, excessive indirection | 🔵 Info |1920## Quick Start2122```bash23# Install24npx @opencodereview/cli scan ./src --sla L12526# With AI-powered deep scan (requires Ollama or API key)27npx @opencodereview/cli scan ./src --sla L22829# Diff mode for CI/CD30npx @opencodereview/cli scan ./src --diff --base origin/main --head HEAD3132# SARIF output for GitHub Actions33npx @opencodereview/cli scan ./src --format sarif --output results.sarif34```3536## Three Scan Levels3738- **L1** — Structural analysis (AST, ~3 seconds, no AI needed)39- **L2** — L1 + Embedding recall (detects hallucinated packages via vector similarity)40- **L3** — L2 + LLM deep scan (understands context, semantics, business logic)4142## GitHub Action4344```yaml45- uses: raye-deng/open-code-review@v146 with:47 scan-path: src/48 sla-level: L149 diff-mode: true50```5152## MCP Server5354Available on Smithery, Cursor Directory, and npm:5556```json57{58 "mcpServers": {59 "open-code-review": {60 "url": "https://open-code-review-mcp.v2ray-seins.workers.dev/mcp"61 }62 }63}64```6566Or via stdio:67```json68{69 "mcpServers": {70 "open-code-review": {71 "command": "npx",72 "args": ["-y", "@opencodereview/mcp-server"]73 }74 }75}76```7778## Supported Languages7980TypeScript, JavaScript, Python, Java, Go, Kotlin8182## When to Use This Skill8384- A PR contains AI-generated code (Copilot, Cursor, Claude, GPT)85- You want to catch defects that pass all unit tests but will fail in production86- Pre-merge quality gate for AI-assisted development workflows87- Scanning third-party AI-generated code before integration8889## When NOT to Use9091- Basic linting (use ESLint, Ruff, Checkstyle instead)92- Code formatting (use Prettier, gofmt)93- General code review guidance (use the built-in code-review skill)9495## Links9697- **GitHub**: https://github.com/raye-deng/open-code-review98- **Portal**: https://codes.evallab.ai99- **npm CLI**: `@opencodereview/cli`100- **npm MCP**: `@opencodereview/mcp-server`101- **License**: BSL 1.1 (free for individuals, commercial subscription for teams)