Claude Code

Code review and CI

Official Code Review, Ultrareview, Ultraplan, GitHub Actions, GitLab CI/CD, local review and Passion8 integration boundaries.

Claude Code can review or automate changes locally, on PRs, in the cloud or in CI/CD. First identify where model requests originate and where code/commands execute.

For Ultrareview, Ultraplan, Agent View, /goal, routines and scheduled tasks together, see advanced workflows and cloud capabilities.

EntryRuns inUsePassion8 boundary
/code-reviewLocal sessionReview the current diffUses local Passion8 configuration
/review <pr>Local sessionReview a GitHub PRLocal execution with GitHub access
Official Code ReviewAnthropic GitHub App/check runAutomatic PR reviewUsually official cloud and billing
/code-review ultra / /ultrareviewOfficial cloud sandboxDeep multi-agent review before mergeSeparate cloud context/cache
GitHub Actions / GitLab CICI runnerFixes, comments and MR/PR creationExplicit Passion8 environment injection
/ultraplanCloud planning, then chosen executionPlan complex tasksLocal execution can use Passion8 after return

#Severity standards

LabelMeaningLocal policy
ImportantBug, security issue or regression to fix before mergeBlock merge or require a fix
NitMinor issue, not necessarily blockingLimit noise
Pre-existingNot introduced by this PRTrack separately instead of mixing into the PR

Define Important explicitly. Payments, authentication, access control, data loss, migrations and production configuration generally warrant stricter checks.

#Local review workflow

/code-review current diff, focus on correctness, security, migration risk, and missing tests. Treat style-only comments as nit.
  1. Run tests/static checks and provide failures.
  2. Review only the current diff rather than reading the entire repository.
  3. Specify severity and excluded findings.
  4. Require file names and line numbers for important issues.
  5. Review the same diff again after fixes.

Local review uses the session's model, effort, tools and gateway configuration. Model/effort switches or fallbacks can cause cache misses on the next turn.

#Official Code Review

The GitHub integration can post check runs and comments for shared team review. Configure:

ItemPurpose
GitHub AppAccess to the target organization/repository
Spend capReview budget
CLAUDE.mdProject rules and context
REVIEW.mdSeverity, exclusions and required checks
FeedbackDevelopers mark findings useful or unhelpful

For Passion8-only model traffic, use local /code-review or headless CLI in a CI runner. Do not assume official cloud review uses your local gateway.

#What to put in REVIEW.md

REVIEW.md
# Review instructions

## Important

Report issues that can cause auth bypass, data loss, payment error, privilege escalation, silent corruption, failed migration, or production outage.

## Nit

Limit nit comments to concrete maintainability problems. Do not report formatting already covered by linters.

## Always check

- Permission boundaries
- Error handling and retries
- Database migrations and rollback
- Tests for changed behavior

#Ultrareview

Deep cloud multi-agent review is suitable for high-confidence pre-merge checks, rather than every small edit.

Property/code-review/review <pr>/code-review ultra
TargetWorking-tree diffGitHub PRDiff or PR
ExecutionLocal sessionLocal sessionCloud sandbox
DepthQuick to moderateModerateIndependent multi-agent verification
DurationSeconds to minutesMinutesTypically 5–10 minutes
CostNormal usageNormal usageUsage credits after free allowance
CacheLocal sessionLocal sessionSeparate cloud cache

Noninteractive runs can request JSON for scripts or CI.

#Ultraplan

Cloud planning can continue on the web or return a plan to the terminal.

StageBehavior
CLI startSends the task and context
Cloud researchWeb session investigates and drafts a plan
Browser confirmationAdd constraints or approve the plan
Execution choiceContinue on the web or return locally

Prefer local execution for internal systems, uncommitted files or gateway-specific work.

#GitHub Actions

Respond to issues, PR comments, failed tests or manual workflow dispatches. Inject gateway variables explicitly:

.github/workflows/claude.yml
env:
  ANTHROPIC_BASE_URL: https://passion8.cc
  ANTHROPIC_AUTH_TOKEN: ${{ secrets.PASSION8_API_KEY }}
ItemRecommendation
TokenLeast-privilege secret
Fork PRsDo not expose write access or secrets to untrusted forks
LogsDo not print keys, customer data or full production logs
PromptInclude diff, failure logs and objective, rather than the entire repository
ToolsRestrict tools through claude_args or settings
CostFix the model and max turns to avoid unlimited loops

#GitLab CI/CD

Also check runner permissions, MR permissions and protected variables:

.gitlab-ci.yml
claude:
  variables:
    ANTHROPIC_BASE_URL: "https://passion8.cc"
    ANTHROPIC_AUTH_TOKEN: "$PASSION8_API_KEY"
  script:
    - claude -p "Review this merge request and summarize important correctness issues."
  1. Permit writes only on protected branches or trusted MRs.
  2. Use read-only review for external contributors.
  3. Keep cloud OIDC/Bedrock/Vertex credentials separate from Passion8 keys.
  4. Use least-privilege tokens for MR comments and pushes.
  5. Do not save complete transcripts in CI caches/artifacts.

#Caching and cost

ActionFive-minute/one-hour behavior
Repeated local reviewStable prefixes can refresh TTL
Multiple repair turns in one CI jobMay reuse a warm cache within five minutes
New container per jobDifferent prompts, paths or variables can cause cold starts
Official Code ReviewCloud context does not share local gateway caches
UltrareviewMulti-agent cloud caching with more aggregate tokens
Ultraplan returned locallyReassess using the local provider/session

See command cache effects.

#Official references

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.