Code review and CI
Official Code Review, Ultrareview, Ultraplan, GitHub Actions, GitLab CI/CD, local review and Passion8 integration boundaries.
Claude Code can review or automate changes locally, on PRs, in the cloud or in CI/CD. First identify where model requests originate and where code/commands execute.
For Ultrareview, Ultraplan, Agent View, /goal, routines and scheduled tasks together, see advanced workflows and cloud capabilities.
| Entry | Runs in | Use | Passion8 boundary |
|---|---|---|---|
/code-review | Local session | Review the current diff | Uses local Passion8 configuration |
/review <pr> | Local session | Review a GitHub PR | Local execution with GitHub access |
| Official Code Review | Anthropic GitHub App/check run | Automatic PR review | Usually official cloud and billing |
/code-review ultra / /ultrareview | Official cloud sandbox | Deep multi-agent review before merge | Separate cloud context/cache |
| GitHub Actions / GitLab CI | CI runner | Fixes, comments and MR/PR creation | Explicit Passion8 environment injection |
/ultraplan | Cloud planning, then chosen execution | Plan complex tasks | Local execution can use Passion8 after return |
#Severity standards
| Label | Meaning | Local policy |
|---|---|---|
| Important | Bug, security issue or regression to fix before merge | Block merge or require a fix |
| Nit | Minor issue, not necessarily blocking | Limit noise |
| Pre-existing | Not introduced by this PR | Track separately instead of mixing into the PR |
Define Important explicitly. Payments, authentication, access control, data loss, migrations and production configuration generally warrant stricter checks.
#Local review workflow
/code-review current diff, focus on correctness, security, migration risk, and missing tests. Treat style-only comments as nit.- Run tests/static checks and provide failures.
- Review only the current diff rather than reading the entire repository.
- Specify severity and excluded findings.
- Require file names and line numbers for important issues.
- Review the same diff again after fixes.
Local review uses the session's model, effort, tools and gateway configuration. Model/effort switches or fallbacks can cause cache misses on the next turn.
#Official Code Review
The GitHub integration can post check runs and comments for shared team review. Configure:
| Item | Purpose |
|---|---|
| GitHub App | Access to the target organization/repository |
| Spend cap | Review budget |
CLAUDE.md | Project rules and context |
REVIEW.md | Severity, exclusions and required checks |
| Feedback | Developers mark findings useful or unhelpful |
For Passion8-only model traffic, use local /code-review or headless CLI in a CI runner. Do not assume official cloud review uses your local gateway.
#What to put in REVIEW.md
# Review instructions
## Important
Report issues that can cause auth bypass, data loss, payment error, privilege escalation, silent corruption, failed migration, or production outage.
## Nit
Limit nit comments to concrete maintainability problems. Do not report formatting already covered by linters.
## Always check
- Permission boundaries
- Error handling and retries
- Database migrations and rollback
- Tests for changed behavior#Ultrareview
Deep cloud multi-agent review is suitable for high-confidence pre-merge checks, rather than every small edit.
| Property | /code-review | /review <pr> | /code-review ultra |
|---|---|---|---|
| Target | Working-tree diff | GitHub PR | Diff or PR |
| Execution | Local session | Local session | Cloud sandbox |
| Depth | Quick to moderate | Moderate | Independent multi-agent verification |
| Duration | Seconds to minutes | Minutes | Typically 5–10 minutes |
| Cost | Normal usage | Normal usage | Usage credits after free allowance |
| Cache | Local session | Local session | Separate cloud cache |
Noninteractive runs can request JSON for scripts or CI.
#Ultraplan
Cloud planning can continue on the web or return a plan to the terminal.
| Stage | Behavior |
|---|---|
| CLI start | Sends the task and context |
| Cloud research | Web session investigates and drafts a plan |
| Browser confirmation | Add constraints or approve the plan |
| Execution choice | Continue on the web or return locally |
Prefer local execution for internal systems, uncommitted files or gateway-specific work.
#GitHub Actions
Respond to issues, PR comments, failed tests or manual workflow dispatches. Inject gateway variables explicitly:
env:
ANTHROPIC_BASE_URL: https://passion8.cc
ANTHROPIC_AUTH_TOKEN: ${{ secrets.PASSION8_API_KEY }}| Item | Recommendation |
|---|---|
| Token | Least-privilege secret |
| Fork PRs | Do not expose write access or secrets to untrusted forks |
| Logs | Do not print keys, customer data or full production logs |
| Prompt | Include diff, failure logs and objective, rather than the entire repository |
| Tools | Restrict tools through claude_args or settings |
| Cost | Fix the model and max turns to avoid unlimited loops |
#GitLab CI/CD
Also check runner permissions, MR permissions and protected variables:
claude:
variables:
ANTHROPIC_BASE_URL: "https://passion8.cc"
ANTHROPIC_AUTH_TOKEN: "$PASSION8_API_KEY"
script:
- claude -p "Review this merge request and summarize important correctness issues."- Permit writes only on protected branches or trusted MRs.
- Use read-only review for external contributors.
- Keep cloud OIDC/Bedrock/Vertex credentials separate from Passion8 keys.
- Use least-privilege tokens for MR comments and pushes.
- Do not save complete transcripts in CI caches/artifacts.
#Caching and cost
| Action | Five-minute/one-hour behavior |
|---|---|
| Repeated local review | Stable prefixes can refresh TTL |
| Multiple repair turns in one CI job | May reuse a warm cache within five minutes |
| New container per job | Different prompts, paths or variables can cause cold starts |
| Official Code Review | Cloud context does not share local gateway caches |
| Ultrareview | Multi-agent cloud caching with more aggregate tokens |
| Ultraplan returned locally | Reassess using the local provider/session |
#Official references
#Related pages
Support
Need help?
For setup, billing, or model issues, email us. Check the status page for uptime.
WeChat / QQ support is available at the bottom right.

