alibaba/open-code-review
Secure, fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), Ope
ARCHETYPE
Minimalist
Lean instructions, few tools, tiny context tax. Lets the model think.
Copy this rig
# review before running: this installs third-party code
$ npx degit alibaba/open-code-review/.claude ./rig-open-code-review # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit alibaba/open-code-review/plugins/open-code-review/skills/open-code-review-delegate .claude/skills/open-code-review-delegate $ npx degit alibaba/open-code-review/plugins/open-code-review/skills/open-code-review .claude/skills/open-code-review
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 6,413 rigs:
{
"permissions": {
"deny": [
"Read(~/.ssh/**)",
"Read(**/.env)",
"Bash(rm -rf *)",
"Read(./.env)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(**/*.pem)",
"Bash(rm -rf /*)",
"Read(~/.aws/**)",
"Bash(rm -rf:*)",
"Read(.env)",
"Bash(git push --force*)",
"Read(**/*.key)",
"Read(./.env.*)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(gh pr merge *)",
"Bash(chown *)",
"Bash(docker *)"
]
}
} Skills (2)
Slash commands (2)
/commit/tag
Similar rigs
yuanw/nix-home
My Nix dotfiles on MacOS/NixOS
Pragmatist 181 tok ·
gdm257/dotfiles
—
Skill Collector 5.2k tok ·
multica-ai/andrej-karpathy-skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
Minimalist 723 tok ·
shareAI-lab/learn-claude-code
Bash is all you need - A nano claude code–like 「agent harness」, built from 0 to 1
Minimalist 156 tok ·