{"_id":"@orcarouter/code-review","_rev":"29-beb627ed2af19636c9570391d7815520","name":"@orcarouter/code-review","dist-tags":{"latest":"2.1.0"},"versions":{"2.0.0":{"name":"@orcarouter/code-review","version":"2.0.0","keywords":["code-review","ai","github-actions","pull-request","orcarouter","claude-code","skill"],"author":{"name":"Continuum-AI-Corp"},"license":"MIT","_id":"@orcarouter/code-review@2.0.0","maintainers":[{"name":"kaifeng.an","email":"kaifeng.an@myflashcloud.com"},{"name":"fengya.tian","email":"fengya.tian@continuum01.ai"}],"homepage":"https://www.orcarouter.ai/code-review","bugs":{"url":"https://github.com/Continuum-AI-Corp/orca-code-review/issues"},"bin":{"orcacode-review":"bin/orcacode-review.mjs"},"dist":{"shasum":"ac4e29e1e7613d42af4458526aadd6b41dcb3083","tarball":"https://registry.npmjs.org/@orcarouter/code-review/-/code-review-2.0.0.tgz","fileCount":14,"integrity":"sha512-JCTV+FL4L0lJUyYwc8bnhnj11UumZf2VqMO+HmhEdTh6x+YrJondbjD26ggRD1UYPMKPYLBSUXLL+84RBUOL8g==","signatures":[{"sig":"MEUCIQCaflAn3R4gQmYPbAt1b7XeE8ZEyNwO01Oh/U7whVWQ5AIgcwa4dzaNRqQ10WnG7jZWI3Z4qJsOlEV9bTL6LQzFqGw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDk7TCB3y+lZLrCmsD3dfEvLC5SpD19tyM544CV1X1jlAIhANHn7/OyipaieiyfN8RJiubrglPPmGv7EaqNEi/lRPT5","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@orcarouter%2fcode-review@2.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":159772},"type":"module","engines":{"node":">=18.17"},"gitHead":"60eeeecfff5a2dde46e5e72cce2079e5e0a37e09","scripts":{"test":"node --test scripts/*.test.mjs"},"_npmUser":{"name":"kaifeng.an","email":"kaifeng.an@myflashcloud.com"},"repository":{"url":"git+https://github.com/Continuum-AI-Corp/orca-code-review.git","type":"git"},"_npmVersion":"10.8.2","description":"One-command installer for OrcaCode Review — AI pull-request review powered by OrcaRouter.","directories":{},"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/code-review_2.0.0_1787751422337_0.8864605140951425","host":"s3://npm-registry-packages-npm-production"}},"2.1.0":{"_id":"@orcarouter/code-review@2.1.0","bin":{"orcacode-review":"bin/orcacode-review.mjs"},"bugs":{"url":"https://github.com/Continuum-AI-Corp/orca-code-review/issues"},"dist":{"shasum":"60343d6a80af2f2b1bf1b888bc32ed0c7b20f766","tarball":"https://registry.npmjs.org/@orcarouter/code-review/-/code-review-2.1.0.tgz","fileCount":80,"integrity":"sha512-Za9UXnxP2DxRY3WVckTh+MuW//AFpO9J4qmG0WYnpzg7dB5AG/K/bopXdFPnp4/0l6ZqgvfAke+0VjzbBWt1sA==","signatures":[{"sig":"MEUCIQDuUfFrhlJ3Kk9GGJwFvJwN5xKDcRzfuq6sKHGQOv4jEwIgKtvFqcS5P1ARCyZd79AyDrj59zPnWFXZfvTXKQaW5/o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDBTXprRBiPzNxIigl2duuzRBGgvCKyigAHavjD/RGoSwIgOtbM2eIOXWxuhovhoUd22uDh950LRwcV2KCtojpa65I="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@orcarouter%2fcode-review@2.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":564812},"name":"@orcarouter/code-review","type":"module","author":{"name":"Continuum-AI-Corp"},"engines":{"node":">=18.17"},"gitHead":"5dae0d66b51d64b5174e27459a66e0c34a85e464","license":"MIT","scripts":{"test":"node --test scripts/*.test.mjs"},"version":"2.1.0","_npmUser":{"name":"kaifeng.an","email":"kaifeng.an@myflashcloud.com"},"homepage":"https://www.orcarouter.ai/code-review","keywords":["code-review","ai","github-actions","pull-request","orcarouter","claude-code","skill"],"repository":{"url":"git+https://github.com/Continuum-AI-Corp/orca-code-review.git","type":"git"},"_npmVersion":"10.8.2","description":"One-command installer for OrcaCode Review — AI pull-request review powered by OrcaRouter.","directories":{},"maintainers":[{"name":"kaifeng.an","email":"kaifeng.an@myflashcloud.com"},{"name":"fengya.tian","email":"fengya.tian@continuum01.ai"}],"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/code-review_2.1.0_1788402711316_0.402333546392162"}}},"time":{"created":"2026-08-25T09:23:37.877Z","modified":"2026-09-03T02:31:51.798Z","1.0.2":"2026-08-25T09:23:38.270Z","1.1.0":"2026-08-25T09:47:47.917Z","1.2.0":"2026-08-25T10:11:01.042Z","1.2.1":"2026-08-25T12:20:53.859Z","1.3.0":"2026-08-26T06:55:07.840Z","1.3.1":"2026-08-26T07:24:00.404Z","1.3.2":"2026-08-26T07:31:52.667Z","1.4.0":"2026-08-26T08:30:47.696Z","1.5.0":"2026-08-26T11:57:52.449Z","2.0.0":"2026-08-26T13:37:02.432Z","2.1.0":"2026-09-03T02:31:51.407Z"},"bugs":{"url":"https://github.com/Continuum-AI-Corp/orca-code-review/issues"},"author":{"name":"Continuum-AI-Corp"},"license":"MIT","homepage":"https://www.orcarouter.ai/code-review","keywords":["code-review","ai","github-actions","pull-request","orcarouter","claude-code","skill"],"repository":{"url":"git+https://github.com/Continuum-AI-Corp/orca-code-review.git","type":"git"},"description":"One-command installer for OrcaCode Review — AI pull-request review powered by OrcaRouter.","maintainers":[{"name":"kaifeng.an","email":"kaifeng.an@myflashcloud.com"},{"name":"fengya.tian","email":"fengya.tian@continuum01.ai"}],"readme":"# OrcaCode Review\n\n**[AI code review](https://www.orcarouter.ai/code-review) that catches serious issues before they merge — powered by ****[OrcaRouter](https://www.orcarouter.ai/)****.**\n\nAutomatically review every pull request, post findings directly on the affected lines, and block serious issues from merging.\n\n**P0/P1 → ❌ Block** · **Findings → 💬 Comment** · **Clean → ✅ Pass**\n\n---\n\n<p align=\"center\">\n  <img src=\"docs/demo-install.gif\" alt=\"npx @orcarouter/code-review: pick how you will use it, where to install, which agents — done\" width=\"900\">\n</p>\n\n---\n\n## How it works\n\n```text\nPR → Review → Merge Gate\n        │\n     P0/P1?\n        ↓\n      BLOCK\n```\n\nEvery push gets one review. Findings post on the affected lines, and P0/P1 blocks the merge.\n\n**You choose the model in OrcaRouter. OrcaCode handles the review.**\n\n### What you get\n\n* 🔍 Automatic review on every PR\n* 💬 Inline findings on the affected lines\n* 🛑 Merge gate for serious issues\n* 🧠 Choose your own review model\n* 🎯 Precision filtering to reduce false positives\n* 🔒 OrcaRouter guardrails + security policies\n* 🔄 Re-run anytime with `/orcacode-review`\n\n---\n\n## Install\n\nOne command teaches your AI what OrcaCode Review is. Everything after that, you just ask for.\n\n```bash\nnpx @orcarouter/code-review\n```\n\nIt asks how you will use it — local review, the GitHub Action, or both — detects which coding agents you use, installs the matching skills, and stops. Then:\n\n> **you:** set up OrcaCode Review in this repo\n\nYour agent writes the workflow, walks you through the API key, and sets the merge gate — asking only the questions that are actually yours to answer.\n\n<p align=\"center\">\n  <img src=\"docs/demo-setup.gif\" alt=\"Claude Code with the orca-review-action skill: asks the merge-gate decisions, writes the workflow, hands the API key step to you\" width=\"900\">\n</p>\n\nThe same goes for everything else:\n\n| Say | It does |\n| --- | --- |\n| *\"review my changes\"* | Reviews them **locally**, itself — see [below](#review-locally-your-agent-is-the-engine) |\n| *\"why didn't the review run?\"* | Diagnoses the secret, the trigger, the base branch, the gate |\n| *\"make OrcaCode Review block P0 only\"* | Retunes the merge policy |\n| *\"remove OrcaCode Review from this repo\"* | Drops the required check first, then the workflow |\n| *\"what can OrcaCode Review do?\"* | Explains itself |\n\n**Claude Code** can install the skill as a plugin instead, which keeps it updated:\n\n```text\n/plugin marketplace add Continuum-AI-Corp/orca-code-review\n/plugin install orca-code-review\n```\n\n### 36 agent platforms\n\nThe same catalog the [OrcaDub MCP server](https://github.com/Continuum-AI-Corp/orcadub-mcp-server) uses, so IDs and paths match across Orca products. Detected agents are pre-ticked; `/` filters the list. For CI or dotfiles, the same choices are flags (`--mode`, `--scope`, `--platform`, `--yes`) — `--help` lists them.\n\nPrefer to wire it by hand? The manual steps are below.\n\nClaude Code, Cursor, Codex, OpenCode, Windsurf, Cline, RooCode, Continue, GitHub Copilot, Gemini CLI, Amazon Q Developer, Qwen Code, Kilo Code, Auggie, Kimi Code, Kiro, Lingma, Junie, CodeBuddy Code, CoStrict, Crush, Factory Droid, iFlow, Pi, Qoder, Antigravity, Antigravity 2.0, Bob Shell, ForgeCode, Trae, Trae CN, ZCode, MimoCode, Hermes, OpenClaw, Command Code.\n\nTwo skills: `orca-review` for reviewing locally and `orca-review-action` for the GitHub Action. The installer asks which you want, or both. An existing identical skill is left unchanged; an existing **different** one is preserved unless you pass `--force`.\n\n### Language\n\nThe CLI speaks **English, Simplified Chinese, Japanese and Korean**, picked from your locale (`LC_ALL` / `LC_MESSAGES` / `LANG`). The guided flow opens with a language screen; `ORCACODE_LANG=zh` pins it for good.\n\nTraditional Chinese locales (`zh-TW`, `zh-HK`) fall back to English on purpose — the vocabulary diverges enough that serving Simplified reads worse than not translating at all.\n\nMenus are arrow-key driven — `↑↓` to move, `Enter` to pick. Multi-select adds `space` to toggle, `a`/`n` for all/none, and `/` to filter (`ctrl-u` clears it), which is how you find one agent among 36 without scrolling. Terminals without raw mode fall back to typing a number.\n\nOnly prose is translated — flags, platform IDs, workflow inputs, and shell commands stay verbatim, because you still have to type them.\n\n---\n\n## Review locally — your agent is the engine\n\nThe Action pays a model in CI to review every PR. You can also run the **same review, right now, in your terminal**, with no Action, no OrcaRouter account, and no API key — because the model is the one your coding agent already has.\n\n> **you:** review my changes\n\n<p align=\"center\">\n  <img src=\"docs/demo-review.gif\" alt=\"Claude Code with the orca-review skill reviewing a pull request by number: plan, review, submit, verdict\" width=\"900\">\n</p>\n\nClaude Code, Codex, Cursor, or any of the 36 platforms picks up the `orca-review` skill and becomes the reviewer. You say what to review; the skill handles the rest:\n\n| Say | It reviews |\n| --- | --- |\n| *\"review my changes\"* | Uncommitted work if the tree is dirty, otherwise this branch against its base |\n| *\"review this branch\"*, *\"review that commit\"* | The range you named |\n| *\"review PR 556\"* | That pull request — **without checking it out**. It is fetched into a private ref; your work tree stays exactly where it was. Fork PRs included |\n| *\"is this safe to merge?\"* | Same, and the gate answers |\n\nBehind the skill are two CLI commands your agent runs for you: `review plan` decides what is in scope — with the reasons for what is not — and hands the agent the per-language checklists, the P0–P3 rubric, and your repo's own `AGENTS.md`/`CLAUDE.md` conventions; `review submit` verifies every finding is filed on the right line, drops duplicates, applies the merge gate, and prints the report your agent relays to you. Nothing that decides what blocks is left to the model.\n\n**It is the same severity contract the Action enforces** — the same `rules/severity-instruction.md`, the same position check, the same result shape. A P1 you find here is a P1 that would block there. That parity is the point: *\"it passed locally\"* has to mean something.\n\nThe file selection is the engine's, without the engine: the exclusion rules and per-language checklists from [Open Code Review](https://github.com/alibaba/open-code-review) (Apache-2.0) ship inside this package, so a local review filters the same files CI would. Nothing extra to install.\n\nSettings that should stick live in a committed `.orcacode-review.json` — which severities block, which language to report in, paths never to review, extra checklists for parts of the tree. You do not write it by hand: after your first review in a repo the agent offers to save the settings it just used, and later *\"from now on only block on P0 locally\"* or *\"never review docs/\"* edits the right key.\n\nScripting your own harness instead of using an agent? `review plan --json` and `review submit --json` are a stable, versioned contract; [`skills/orca-review/references/contract.md`](skills/orca-review/references/contract.md) is the reference.\n\n---\n\n## Quick Start\n\n### 1. Enable OrcaCode Review\n\nGo to [**OrcaRouter**](https://www.orcarouter.ai/) → **Apps → OrcaCode Review** and turn it on.\n\nConfigure your models, review mode, severity rules, merge policy, and other settings directly from the console.\n\n### 2. Install the GitHub Action\n\n[**Install OrcaCode Review from GitHub Marketplace →**](https://github.com/marketplace/actions/orca-code-review)\n\nAdd the Action to your repository:\n\n```yaml\n- uses: Continuum-AI-Corp/orca-code-review@v1\n  with:\n    orcarouter-api-key: ${{ secrets.ORCAROUTER_API_KEY }}\n```\n\n### 3. Add your API key\n\nCreate or copy a key from [**OrcaRouter → API Keys**](https://www.orcarouter.ai/console/token).\n\nAdd it to your GitHub repository as:\n\n```text\nORCAROUTER_API_KEY\n```\n\nunder **Settings → Secrets and variables → Actions**.\n\n### 4. Open a PR\n\n**That's it.**\n\nOrcaCode automatically reviews new PRs and pushes, posts findings inline, and reports the merge gate.\n\n---\n\n## Severity\n\n| Severity | Meaning              | Merge gate | Posted inline          |\n| -------- | -------------------- | ---------- | ---------------------- |\n| **P0**   | Critical / blocker   | ❌ Block    | Always                 |\n| **P1**   | High severity        | ❌ Block    | Always                 |\n| **P2**   | Advisory             | ✅ Pass     | Per Report severities  |\n| **P3**   | Nit / style          | ✅ Pass     | Per Report severities  |\n\nTwo independent settings, and the defaults above are the shipped ones:\n\n* **Merge policy** decides what blocks.\n* **Report severities** decides what gets posted on the diff.\n\nA severity that blocks is always posted, whatever Report severities says — a\nfailing check with nothing on the diff explaining it is worse than a noisy one.\nNarrowing Report severities never changes the gate, and the PR summary always\ncounts every finding, so a muted P2 still shows up there.\n\nCustomize the rubric and both policies from **OrcaRouter → Apps → OrcaCode Review**.\n\n---\n\n## Configure without touching YAML\n\nManage OrcaCode from **OrcaRouter → Apps → OrcaCode Review**:\n\n* **Model** — choose your reviewer\n* **Review mode** — every push, ready for review, or on demand\n* **Merge policy** — choose which severities block\n* **Report severities** — choose which severities post on the diff\n* **Exhaustive review** — run additional passes over the same diff\n* **Quiet mode** — keep P2 findings in the summary\n* **Custom rubric** — define your own review rules\n* **Guardrails** — add security and policy checks\n\n**Change your review strategy anytime. No GitHub workflow edits required.**\n\n---\n\n## Re-run a review\n\nComment on any PR:\n\n```text\n/orcacode-review\n```\n\nto request another review.\n\n---\n\n## Block merges\n\nTo make P0/P1 findings actually prevent merging:\n\n**GitHub → Settings → Branches / Rulesets → Require status checks to pass**\n\nAdd the **`review`** check as required.\n\n---\n\n## Security & Privacy\n\nOrcaCode reads the PR diff and repository files required for review. **It does not execute PR code.**\n\nOptional run reporting sends only review metadata — repository, PR, commit SHA, tier, severity counts, gate result, and engine version.\n\n**No source code, diff, or finding text is included in run reports.**\n\nOrcaRouter guardrails can add secret detection, PII detection, prompt-injection protection, code-security rules, and external security scanners.\n\nSee [`SECURITY.md`](./SECURITY.md) for details.\n\n---\n\n## Under the hood\n\nOrcaCode Review uses [Open Code Review](https://github.com/alibaba/open-code-review) as its review engine and **OrcaRouter for model routing, policy, and control**.\n\n**OrcaCode decides how to review. OrcaRouter decides what model runs it.**\n\n## License\n\n[MIT](./LICENSE) © Continuum-AI-Corp.\n\nOpen Code Review is Apache-2.0. Attribution is preserved in [`NOTICE`](./NOTICE).\n","readmeFilename":"README.md"}