affaan-m/ECC
64.5
Adequate · 25 September 2026
144.7k
lines of production code
JavaScript
with Rust, Python
5
measurements over time
What this system is
This system is an agentic IDE control plane and orchestration framework that manages multiple AI coding agents across diverse development environments. It provides a unified infrastructure for session management, inter-agent communication, and conflict resolution, enabling coordinated work across isolated Git worktrees. The platform integrates with various IDEs and LLM providers while enforcing security, quality gates, and self-improving skill evolution through automated hooks and observability dashboards.
Features
Add CodeBuddy IDE integration with install and uninstall scripts
Users can now install and manage Everything Claude Code (ECC) workflows within the CodeBuddy IDE. This change introduces cross-platform Node.js and Bash scripts (install.js, install.sh, uninstall.js, uninstall.sh) that copy commands, agents, skills, and rules into a project's .codebuddy directory. The installation tracks managed files via a manifest (.ecc-manifest) to enable safe, selective uninstallation that avoids removing user-added content, and includes security checks to prevent path traversal during removal.
.codebuddy · high confidence
Add Kiro IDE formatting and quality gate scripts
New shell scripts have been added to the .kiro/scripts directory to support the Kiro IDE integration. The format.sh script automatically detects and runs code formatting using either Biome or Prettier based on project configuration files. The quality-gate.sh script performs a comprehensive project health check by sequentially running build, type checking, linting, and test suites, detecting the appropriate package manager and tooling (such as pnpm, yarn, npm, Biome, ESLint, Ruff, or golangci-lint) to provide a unified pass/fail status for project quality.
.kiro/scripts · high confidence
Add eval-harness example demonstrating static inspection and offline verification
The eval-harness example now provides a complete offline workflow for evaluating code variants without executing them. It demonstrates that candidate execution is refused without a verified OS backend, performs static inspection to detect syntactic warnings (such as hidden network calls or checker probes), replays locally declared fixtures, and builds/verifies offline capsule receipts. The example includes a taskset, baseline, candidate, and reward-hack variant fixtures to illustrate these capabilities.
examples/eval-harness · high confidence
Add read-only coordination inventory example with declared goals and sessions support
The \examples/coordination-inventory\ directory now includes a new read-only inventory tool that generates local JSON reports by joining declared task IDs, parent IDs, heartbeat age, OS RAM, resource leases, and import warnings. This update extends the inventory's manifest contract (v1) to support optional \goals\ and \sessions\ collections, allowing users to observe declared intent (active/complete goals, open/closed sessions) alongside task data. The example includes synthetic fixtures (\manifest.json\, \goals.json\) and scripts (\evaluate.js\, \benchmark.js\) to characterize overlap detection accuracy and performance, demonstrating how declared goals and sessions are tracked without triggering automatic coordination actions.
examples/coordination-inventory · high confidence
Added codemap generator script for architectural documentation
A new \scripts/codemaps/generate.ts\ script has been added to automatically generate architectural documentation. When executed, it recursively scans the source directory (skipping build artifacts and dependencies), classifies files into five categories (frontend, backend, database, integrations, and workers), and outputs structured Markdown files under \docs/CODEMAPS/\. This includes an index file and individual area files listing entry points, directories, and file counts, providing a quick overview of the project structure for developers.
scripts/codemaps · high confidence
Added example MCP server configuration for Kiro IDE
The .kiro/settings directory now includes an example configuration file (mcp.json.example) that defines four Model Context Protocol (MCP) servers: bedrock-agentcore-mcp-server, strands-agents, awslabs.cdk-mcp-server, and react-docs. This file serves as a template for users to configure their Kiro IDE environment with specific tool integrations, including auto-approval settings for certain documentation search and fetch actions.
.kiro/settings · high confidence
Agent proximity detection with collision avoidance and 2D visualization
Added a new agent-proximity library that monitors multiple agents editing the same codebase to prevent merge conflicts. The system calculates a collision risk score based on three channels: direct line-range overlap, dependency coupling (where one agent's changes break another's imports), and directory tree proximity. When risk exceeds defined thresholds, it triggers a 'Traffic Advisory' to prompt agents to share intent, or a 'Resolution Advisory' to force one agent to steer away. The library also provides 3D embedding of agent positions for visualization and a 2D PCA projection for the control-plane view.
scripts/lib/agent-proximity · high confidence
Cursor integration harness with security and workflow hooks
This change introduces a new set of Node.js hooks in \.cursor/hooks\ that bridge Cursor AI events to the project's existing Claude Code hook infrastructure. The adapter translates Cursor's JSON input into the expected format and delegates to local scripts, enabling several new capabilities: it blocks file reads of sensitive files (env, keys, PEM) in the tab, warns about potential secrets in prompts, and prevents running dev servers outside of tmux on non-Windows platforms. It also adds logging for MCP and subagent activity, tracks build and PR creation events, and enforces a local, position-aware \block-no-verify\ script to avoid false positives with git commit messages.
.cursor/hooks · high confidence
Initial release of the LLM abstraction package
The \src/llm\ package is introduced as a provider-agnostic interface for multiple LLM backends. It exposes core types (LLMInput, LLMOutput, Message, ToolCall, ToolDefinition, ToolResult) and components (LLMProvider, ToolExecutor, ToolRegistry, get\_provider, interactive\select) via the public API. A CLI entry point is added via \\\main\\.py\ and a \gui()\ function in \\\init\\_.py\ that delegates to the selector's main routine, enabling users to run the tool from the command line or invoke the interactive selector programmatically.
src/llm · high confidence
Interactive LLM provider and model selector added
The CLI now includes an interactive selector that allows users to choose their preferred LLM provider (such as Claude, OpenAI, or Ollama) and specific model from a menu. This tool saves the selection to a \.llm.env\ configuration file and displays environment variable export commands to apply the settings to the current session. It also provides a notice for self-hosted Ollama users regarding Itô compute sponsorship.
src/llm/cli · high confidence
Introduce .trae directory with install and uninstall scripts for Trae IDE
Adds a new .trae directory containing install.sh and uninstall.sh scripts, along with documentation, to deploy Everything Claude Code (ECC) workflows into Trae projects. Users can now install commands, agents, skills, and rules locally or globally (to the home directory) using the install script, which supports a CN environment via the TRAE\_ENV variable. The uninstall script safely removes only ECC-managed files tracked in a manifest, preserving user-added content.
.trae · high confidence
Introduce ECC 2.0 agentic IDE control plane with session management and inter-agent communication
This change scaffolds the ECC 2.0 core in \ecc2/src\, establishing a new agentic IDE control plane. It introduces a structured inter-agent messaging system (\comms\) supporting task handoffs, queries, and conflict detection with priority levels. The new CLI (\main\) provides commands to start, delegate, and assign agent sessions, launch orchestration templates, and manage worktree policies. It also includes a bounded harness evaluation framework (\harness\_eval\) for deterministic configuration testing and a notification system (\notifications\) for desktop alerts, webhooks, and quiet hours.
ecc2/src · high confidence
Introduce ECC 2.0 session management and observability infrastructure
This change introduces the core ECC 2.0 session management layer, including a background daemon for session lifecycle, heartbeat monitoring, and automatic recovery of crashed sessions. It adds a new observability module that tracks tool calls, computes risk scores based on file sensitivity and blast radius, and suggests actions (Allow, Review, Require Confirmation, Block). The session manager now supports creating sessions with profiles and grouping, handling remote dispatch, and managing worktree auto-merge and auto-prune. A new output store buffers and broadcasts session output lines for real-time dashboard streaming. The harness detection system is expanded to support multiple IDE agents (Claude, Codex, Gemini, Cursor, etc.) and detects them via project markers. State persistence is handled via a new SQLite-based state store with comprehensive session, worktree, and daemon activity tracking.
ecc2/src/session · high confidence
Introduce ECC 2.0 terminal UI dashboard
The ECC 2.0 terminal UI is now available, providing a comprehensive dashboard for managing agent sessions, worktrees, and team coordination. Users can monitor session states, view real-time output, and manage budgets via token and cost meters with configurable alert thresholds. The interface supports interactive pane navigation, split-diff viewing for worktree changes, and direct controls for session lifecycle actions like spawning, stopping, resuming, and deleting. It also includes features for auto-dispatch, worktree merging, and conflict resolution, all accessible through a configurable keybinding system.
ecc2/src/tui · high confidence
Introduce ECC 2.0 worktree management and Git integration layer
This change introduces the core worktree management module for the ECC 2.0 agentic IDE control plane. It adds the ability to create and remove isolated Git worktrees for agent sessions, enforcing configurable branch prefixes and sharing dependency caches across worktrees. The module also provides a comprehensive Git status and patch view, exposing merge readiness checks, conflict previews, and structured data for staged/unstaged changes, file previews, and hunk-level actions to support the new UI controls and diff viewer.
ecc2/src/worktree · high confidence
Introduce ECC plugin hooks for OpenCode integration
Added a new plugin system in .opencode/plugins that bridges ECC hooks to OpenCode's event model, enabling features like auto-formatting on file edits and tracking changed files. The implementation includes a new ecc-hooks.ts file that maps OpenCode events (such as file.edited) to ECC actions, with resilience improvements to prevent session crashes if optional libraries are missing, and supports configurable hook profiles (minimal, standard, strict) via environment variables.
.opencode/plugins · high confidence
Introduce ECC2 Control Pane with live agent proximity visualization and JIT board management
This change adds a new local web-based Control Pane for ECC2, providing operators with a live view of agent activity and collision risk. The pane features a 2D PCA projection of agent pairs and a 3D 'airspace' visualization that highlights convergence risks using traffic and resolution advisories. It also includes an interactive JIT board where agents and humans can claim and move work items, alongside a set of backend actions for syncing knowledge and backfilling the ECC2 graph. The server is designed for local loopback use with strict host/origin gating and a strict Content Security Policy.
scripts/lib/control-pane · high confidence
Introduce GitHub-native epic coordination scripts
Added a new set of scripts in \scripts/lib/github-coordination\ to manage epic lifecycle and state synchronization directly within GitHub issues. This includes logic for claiming, syncing, validating, and publishing epics, with support for policy-driven label management, dependency verification, and review gating. The implementation uses the GitHub CLI (\gh\) for API interactions and persists coordination state in a local store, enabling automated tracking of epic progress and status.
scripts/lib/github-coordination · high confidence
Introduce Kiro IDE support with installation scripts and documentation
Adds the \.kiro/\ directory structure to support the Kiro IDE, including an \install.sh\ script that copies agents, skills, steering files, hooks, and settings into a target project, along with a \README.md\ documenting the components and usage.
.kiro · high confidence
Introduce OpenCode plugin support with migration guide and configuration
The .opencode directory now provides a complete integration for the OpenCode CLI, including an opencode.json configuration file that defines agents, commands, and skills, alongside a TypeScript plugin module (index.ts) that exports hooks and custom tools. A new MIGRATION.md guide helps users transition from Claude Code by mapping hooks to OpenCode's plugin events, and a .npmignore file ensures clean package distribution. This change adds the necessary configuration and plugin infrastructure to run ECC features within the OpenCode environment.
.opencode · high confidence
Introduce Pi Coding Agent adapter for ECC integration
Adds a new \.pi\ directory containing a thin adapter that connects the Pi coding agent to ECC's canonical skills, commands, and engineering rules. The adapter mounts ECC's skills and commands directly without duplication, injects portable engineering rules into the system prompt, and maps Pi's session lifecycle events to ECC's existing hook runner (honoring \ECC\_HOOK\_PROFILE\ and \ECC\_DISABLED\_HOOKS\). It includes a \/ecc-doctor\ diagnostic command to verify the integration and handles hook execution safely via \execFile\ with isolated timeouts and output limits.
.pi · high confidence
Introduce Plan Canvas for browser-based plan review
Plan Canvas is a new browser review interface for plan artifacts. It renders .plan.md files to HTML with a secure, minimal Markdown subset (including task lists, links, and Mermaid diagrams) and provides a local loopback server to manage review sessions. Users can annotate specific elements of the rendered plan, send chat feedback, and approve or request changes, with all interactions persisted to a local state directory.
scripts/lib/plan-canvas · high confidence
Introduce layered TOML configuration system for ECC 2.0
The ECC 2.0 control plane now supports a structured, layered configuration system loaded from TOML files. This change introduces a comprehensive set of configuration modules that allow users to define and customize agent profiles (including model selection, tool permissions, and budget limits), orchestration templates for multi-step workflows, and various memory connectors (supporting JSONL and Markdown formats for files and directories, as well as Dotenv integration). Additionally, the configuration layer enables fine-grained control over session behaviors, including configurable budget thresholds with alert levels, risk scoring thresholds for tool actions, conflict resolution strategies, worktree management policies, and notification settings for desktop, webhook, and completion summaries.
ecc2/src/config · high confidence
Introduce modular prompt building and template management
The prompt handling logic has been reorganized into a dedicated module with a new \PromptBuilder\ class that normalizes messages and tools for different providers (e.g., Claude, OpenAI, Ollama) using configurable templates. A separate template registry allows users to register, retrieve, and clear named prompt templates, providing a structured way to manage provider-specific formatting and system instructions.
src/llm/prompt · high confidence
Introduce self-improving skills loop with observation, health, and amendment capabilities
Added a new skill-improvement library that enables a self-improving loop for skills. The \observations.js\ module records skill execution telemetry (success/failure, errors, feedback) to a local JSONL file. The \health.js\ module analyzes these records to generate a health report, identifying recurring errors, tasks, and feedback, and classifying skills as healthy, watching, or failing. The \amendify.js\ module uses this health data to propose specific, additive markdown patches to fix recurring issues. Finally, \evaluate.js\ compares baseline and amended run outcomes to recommend whether to promote an amendment or keep the baseline, ensuring improvements are data-driven.
scripts/lib/skill-improvement · high confidence
Introduce skill evolution foundation with health tracking and dashboard
This change adds the core library for tracking and visualizing skill evolution. It introduces a tracker that records skill execution outcomes (success, failure, partial) to a local JSONL file with retention limits, a health module that calculates success rates and trends over 7 and 30-day windows, a versioning system for managing skill snapshots and evolution logs, and a dashboard module that renders these metrics as text-based panels (including sparklines and trend arrows) for immediate visibility into skill performance.
scripts/lib/skill-evolution · high confidence
Introduces a unified LLM provider abstraction layer with new provider support
This change establishes a new core abstraction for Large Language Model interactions, defining a standard interface (LLMProvider) and shared data types (LLMInput, LLMOutput, ToolDefinition) that decouple the application logic from specific backend implementations. It adds dedicated provider adapters for OpenAI, Anthropic Claude, Ollama, Atlas Cloud, and Astraflow, enabling users to switch between these backends via a central resolver. The implementation includes specific behavioral adjustments, such as mapping max\_tokens to Ollama's num\_predict, attaching cache\_control to the Claude system block, and enforcing minimum token limits for Atlas reasoning models.
src/llm/providers · high confidence
Native 'orch-review' workflow pilot for autonomous code review
This change introduces a pilot native Claude Code workflow (\orch-review.workflow.js\) that ports the autonomous, fan-out-heavy review segment of the existing orchestration pipeline to the native engine. The workflow runs multi-dimensional code reviews (quality, language-specific, and conditional security) in parallel, deduplicates findings, and adversarially verifies all CRITICAL and HIGH issues before returning a verdict. It is invoked via the \/orch-review\ command, which gathers diffs and passes them to the workflow, ensuring that the review process benefits from barrier-free pipelining, automatic concurrency capping, and structured-output validation while maintaining a 'fail-closed' security posture for unverified or failed dimensions.
workflows · high confidence
New CI validation and supply-chain security tooling
This change introduces a suite of new Node.js scripts in the \scripts/ci\ directory to enforce documentation integrity, validate configuration schemas, and scan for supply-chain risks. The \catalog.js\ script ensures that agent, command, and skill counts in README files (including Chinese translations) match the actual files on disk. Schema validators (\validate-agents.js\, \validate-commands.js\, \validate-hooks.js\, \check-hooks-schema-keys.js\) enforce strict frontmatter requirements, cross-reference integrity, and loader-specific key constraints for hooks. Additionally, \check-unicode-safety.js\ sanitizes invisible characters to prevent prompt injection, while \scan-supply-chain-iocs.js\ and \supply-chain-advisory-sources.js\ actively detect compromised packages and track security advisories.
scripts/ci · high confidence
New CLI scripts for installation, diagnostics, and agent interaction
The scripts directory now includes a suite of new Node.js utilities to enhance the ECC user experience. \auto-update.js\ allows users to pull the latest repository changes and reinstall managed targets while preserving original install-state requests, with strict validation to prevent execution from untrusted repositories. \catalog.js\ and \consult.js\ provide new ways to discover and recommend install components and profiles based on natural language queries or specific filters. \doctor.js\ helps diagnose drift and missing managed files in the current context. Additionally, \claw.js\ introduces a new session-aware REPL for interacting with the Claude agent, and \control-pane.js\ launches a local web-based operator interface for managing ECC2 state.
scripts · high confidence
New Codex integration and validation scripts
Added a suite of shell and Node.js scripts under scripts/codex to manage, validate, and repair the Codex integration. check-codex-global-state.sh performs a regression sanity check on the global \~/.codex state, verifying config.toml, AGENTS.md, skills, and prompts, and specifically flags legacy \[mcp\_servers.exa\] entries that use a rejected url key. check-plugin-cache.js validates that the installed Codex plugin cache can resolve every file path referenced by its manifest. install-global-git-hooks.sh safely installs ECC git hooks globally via core.hooksPath, including a security check to prevent silently displacing another tool's hooks. merge-codex-config.js and merge-mcp-config.js handle the add-only merging of the Codex baseline and recommended MCP servers (currently chrome-devtools) into config.toml, with merge-mcp-config.js also repairing the legacy invalid exa url entry. legacy-sync-state.js provides a CLI interface for the legacy sync state management functions.
scripts/codex · high confidence
New Discord bot and automated release announcement delivery
This change introduces a new dependency-free Discord bot (ecc-bot.mjs) that provides slash commands for looking up skills, searching documentation, and checking the latest release, alongside a new announcement delivery system (release-announce.mjs) that automatically posts release notes to a scoped Discord webhook or channel. The system ensures reliable delivery by tracking receipts via GitHub Discussion comments and includes security hardening against SSRF, log injection, and resource exhaustion by validating interaction tokens, clamping heartbeat intervals, and sanitizing user-supplied strings.
scripts/discord · high confidence
New Kiro IDE hooks for automated code quality and safety checks
The \.kiro/hooks\ directory now includes a set of pre-configured IDE hooks that automatically trigger agent actions based on file changes and tool usage. These hooks provide immediate feedback for TypeScript/JavaScript formatting, type checking, and console.log cleanup; Python linting; Rust compilation checks; and security reviews for sensitive directories. Additional hooks enforce TDD practices, prevent unnecessary documentation, review git push operations, and generate session summaries or lessons-learned patterns upon agent completion. A manual quality gate hook is also available to run build, lint, and test scripts on demand.
.kiro/hooks · high confidence
New OpenCode tools for testing, linting, formatting, and security auditing
The .opencode/tools directory now includes a suite of custom OpenCode tools that extend the IDE's capabilities. Users can now run tests with automatic package manager and framework detection (run-tests), check test coverage against thresholds (check-coverage), and view changed files as a navigable tree with change indicators (changed-files). Code quality is supported via lint detection and command generation for linters like Biome, ESLint, and Ruff (lint-check), as well as formatter detection and command generation for Biome, Prettier, Black, and others (format-code). Dependency management is enhanced with a dependency analyzer that identifies outdated or vulnerable packages (dependency-analyzer), and security is improved with a security audit tool that scans for dependency vulnerabilities, hardcoded secrets, and code anti-patterns (security-audit). Additionally, a git summary tool provides branch status, recent commits, and diff stats (git-summary). These tools are exported via a central index and are designed to be robust, with lazy loading to prevent session crashes if plugin dependencies are missing.
.opencode/tools · high confidence
New agent compression, data persistence, and installation libraries
This change introduces a suite of new utility modules in scripts/lib to support agent lifecycle management and installation. agent-compress.js provides logic to parse agent markdown files and compress them into catalog or summary entries to reduce token usage. agent-data-home.js establishes a cross-harness mechanism for resolving agent data persistence paths, supporting both Cursor and Claude environments. agent-tools.js adds robust parsing for agent frontmatter tool lists. Additionally, atomic-write.js implements safe, race-free file writing, claude-commit-attribution.js handles Claude Code co-author settings, claude-dry-run-sandbox.js creates isolated environments for safe command execution, and claude-plugin-setup.js along with its associated migration and legacy sync modules manage the installation, configuration, and scope migration of the ECC plugin for Claude and Codex.
scripts/lib · high confidence
New and consolidated hook scripts for dev server automation, config protection, and design quality
The scripts/hooks directory now includes several new hook implementations: auto-tmux-dev.js automatically runs dev servers (npm/pnpm/yarn/bun dev) in a detached tmux session on Unix or a new cmd window on Windows to prevent blocking; config-protection.js blocks modifications to linter/formatter config files (e.g., .eslintrc, biome.json) to prevent agents from weakening rules instead of fixing code; design-quality-check.js warns against generic frontend patterns like 'Get Started' CTAs or uniform grids; check-console-log.js warns about leftover console.log statements in modified JS/TS files; doc-file-warning.js warns on ad-hoc documentation filenames (e.g., NOTES.md) outside structured directories; and bash-hook-dispatcher.js consolidates pre/post-bash hook execution. Existing hooks like block-no-verify.js, cost-tracker.js, and ecc-context-monitor.js are also present with updated logic for stdin handling, cost calculation, and context warnings.
scripts/hooks · high confidence
New install targets for Adal, Gemini, Zed, CodeBuddy, JoyCode, Hermes, OpenClaw, and Qwen
The installer now supports a broader range of AI coding assistants. New project-scoped adapters have been added for Adal, Gemini, Zed, CodeBuddy, JoyCode, and Kimi, while home-scoped adapters have been added for Hermes, OpenClaw, Qwen, and Codex. The system also introduces a dedicated \claude-project\ adapter for per-project Claude Code installations, distinct from the existing \claude-home\ adapter. These additions are managed by a new registry in \scripts/lib/install-targets/registry.js\ and rely on updated helper logic in \helpers.js\ to handle platform-specific path isolation and operation planning.
scripts/lib/install-targets · high confidence
New opt-in AURA trust-check adapter for agent reputation
The \integrations/aura\ module introduces a zero-dependency, read-only adapter that queries the AURA Open Protocol to assess the counterparty reputation of an agent before sensitive actions like settlement or delegation. It provides an \aura\_verdict\ function for inspection and a \before\_settle\ gate that raises \AuraUntrusted\ by default for agents with no history (\new\) or poor track records (\high\_risk\), while allowing \trusted\ and \caution\ agents to proceed. The adapter is off by default, requires no authentication, and includes a threat model and offline tests to ensure safe integration.
integrations · high confidence
New pre-commit and pre-push Git hooks for secret scanning and verification
Added new \pre-commit\ and \pre-push\ hooks in \scripts/codex-git-hooks\ to enforce security and code quality. The pre-commit hook scans staged files for high-signal secrets (such as AWS keys, GitHub tokens, and private keys) and blocks commits if found, replacing previous file-based disable mechanisms with an environment-variable bypass. The pre-push hook performs lightweight verification, including running Node.js lint/test/build scripts and Go/Python tests, but requires explicit opt-in via \ECC\_PREPUSH\_RUN\_CHECKS=1\ to prevent arbitrary code execution from untrusted repositories. It also includes logic to correctly resolve virtualenv paths for pytest and skips checks on branch deletion pushes.
scripts/codex-git-hooks · high confidence
New session adapters for Claude, Codex, and OpenCode with canonical snapshots
The session-adapters library now includes dedicated adapters for Claude local history, Codex worktree rollouts, and OpenCode sessions, alongside the existing dmux-tmux orchestration support. These adapters allow the system to open and inspect session data from these specific sources, normalizing them into a unified canonical snapshot format (ecc.session.v1) that includes worker health status and structured source targets. A central registry automatically routes session targets to the correct adapter based on their type (e.g., 'claude-history', 'codex-worktree', 'opencode'), enabling consistent handling of diverse session origins.
scripts/lib/session-adapters · high confidence
New skills for accessibility auditing, agent evaluation, and self-debugging
Added new skill definitions for accessibility (WCAG 2.2 compliance across Web, iOS, and Android), agent architecture auditing, head-to-head coding agent evaluation, agent harness construction, and structured agent introspection debugging. These skills provide structured workflows and best practices for ensuring inclusive design, diagnosing agent failures, and comparing agent performance.
skills · high confidence
New tool execution and ReAct agent framework
This change introduces a new \src/llm/tools\ module providing a structured abstraction for LLM tool calling. It includes a \ToolRegistry\ for managing available functions, a \ToolExecutor\ that safely handles both synchronous and asynchronous tool execution while masking internal errors from the model, and a \ReActAgent\ class that orchestrates the iterative loop of generating tool calls, executing them, and feeding results back to the provider until a final answer is reached or the iteration limit is hit.
src/llm/tools · high confidence
New unified memory conformance example validates CLI and MCP evidence integrity
A new example in examples/unified-memory validates that the ECC CLI and local stdio MCP server handle memory records consistently and securely. The conformance runner (conformance.cjs) creates disposable synthetic vaults to verify that scoped queries return identical ordered records, scores, and provenance across CLI and MCP handoffs, while enforcing strict access controls such as rejecting client identity overrides, target-filter spoofing, and unauthorized trust promotion. It also introduces a new evidence verification module (evidence.cjs) that validates the integrity of memory bodies against a host-owned in-memory catalog, ensuring source-content matching and rejecting tampered, missing, or foreign-context evidence. The example includes dedicated boundary tests (evidence.test.cjs) for schema validation, digest integrity, and control character rejection, all running without external services or network dependencies.
examples/unified-memory · high confidence
New workflow for ECC Pro security roadmap planning
A new workflow file has been added to automate the quarterly planning process for ECC Pro and AgentShield security. This workflow guides the agent through a three-phase process: surveying current capabilities and triaging open issues, researching external threats and competitor gaps, and synthesizing a prioritized, revenue-biased security roadmap. It includes specific schemas and guardrails to ensure the output focuses on monetizable features and addresses critical trust issues like false positives.
.claude/workflows · high confidence
Security
Repository foundation and security hardening for ECC 2.2.2
This release establishes the canonical repository baseline for ECC 2.2.2 by adding essential configuration and documentation files, including \.coderabbit.yaml\ for automated security-focused code reviews, \.env.example\ for environment variable management, and \AGENTS.md\ defining the 68-agent orchestration model. It also introduces \SECURITY.md\ and prompt defense guidelines in \CLAUDE.md\ to enforce input validation and secret management. On the dependency front, it patches two critical vulnerabilities: \lru\ (RUSTSEC-2026-0253) and \js-yaml\ ([GHSA redacted]), ensuring the runtime surface is secure against known supply-chain and parsing risks.
(repo-wide) · high confidence
Behavioural changes
Cursor-specific memory isolation via ECC\_AGENT\_DATA\_HOME
The scaffolds now include Cursor-specific configuration files that isolate ECC memory data from Claude Code's default storage. A new \ecc-agent-data.json\ sets the default data root to \\~/.cursor/ecc\, while \hooks.json\ registers a session-start hook to automatically set the \ECC\_AGENT\_DATA\_HOME\ environment variable. Additionally, a rule file (\ecc-agent-data-home.mdc\) documents this boundary, ensuring session summaries and learned skills are persisted in the Cursor-specific directory rather than \\~/.claude\, preventing data overlap when both tools are used.
scaffolds · high confidence
Updated brand assets and documentation imagery for ECC v2.0.0
The repository's visual identity has been refreshed with new SVG assets: a new \ecc-icon.svg\ replaces the previous brand mark, and a redesigned \hero.svg\ banner now displays the ECC v2.0.0 branding, updated taglines, and a catalog of supported agents and skills. Additionally, \star-history-data.tsv\ has been added to provide the underlying data for GitHub star history visualizations in the documentation.
assets · high confidence
Fixes
Fixes data directory resolution logic for continuous learning
The continuous learning scripts now correctly resolve the data directory by validating that environment variables (CLV2\_HOMUNCULUS\_DIR, XDG\_DATA\_HOME) and HOME are absolute paths, falling back to a default location only when necessary, which prevents errors caused by relative path configurations.
skills/continuous-learning-v2/scripts · high confidence
Installer hardening and legacy migration support
The installation process now includes robust safeguards and migration paths for existing setups. It introduces a file-locking mechanism for Claude settings to prevent concurrent modifications and validates hook configurations against a strict schema. The installer can now detect and migrate legacy Antigravity and Claude skill installations, adapting agent frontmatter and flattening skill directories to match current standards. Additionally, it preserves user-edited Codex configuration files and reconciles previously installed files that are now excluded by the target adapter, ensuring a cleaner upgrade path without data loss.
scripts/lib/install · high confidence
Test coverage
Added integration tests for hooks and Plan Canvas; Added test coverage for agent compression, data home, proximity, and installation modules; Added test coverage for hook scripts in tests/hooks; Added test coverage for installation, build, and operational scripts; Added test coverage for skills, Docker harness, and agreement builder; Added test coverage for the eval-harness library components; Added test fixtures for guided installer and TasteForge video contract validation; Added tests for command frontmatter, plan command behavior, and skill discovery generation; Added tests for the Pi coding agent adapter and hook runtime; Expanded CI test coverage for skills, agents, and configuration surfaces; Hardened CLI test harness for plugin setup; New test suite for configuration, plugins, and LLM providers.
Dependencies
Initial dependency manifests for ECC 2.2.2 across Node, Rust, and Python
This change introduces the initial dependency lockfiles and manifests for the ECC 2.2.2 release, establishing the baseline for the project's three main runtime environments. For the Node.js harness, it adds \package.json\ and \package-lock.json\ (root and \.opencode/\) pinning \typescript\ to 5.9.3/6.0.3, \@opencode-ai/plugin\ to 1.4.3/1.18.25, and \ajv\ to 8.20.0, alongside dev tools like \eslint\ 10.9.1 and \c8\ 11.0.0. For the Rust TUI control plane (\ecc2\), it adds \Cargo.toml\ and \Cargo.lock\, specifying \ratatui\ 0.30, \crossterm\ 0.29, \rusqlite\ 0.40, and \git2\ 0.21. For the Python LLM abstraction layer, it adds \pyproject.toml\ requiring \anthropic\>=0.120.2\ and \openai\>=2.34.0\, along with test dependencies like \pytest\>=9.1.1\ and \mypy\>=2.3.0\. It also includes initial \requirements.txt\ files for media skills (e.g., \taste-application\) and a test fixture \package.json\.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 64.
Lenses
- Code Health 51
- Architecture 92
- Maturity 82
- Readiness 71
- Security 82
- Event Sourcing 100
- Accessibility 74
Changes since last survey
- 300 commits — 133 feature/other, 167 fixes
By area
- (repo) — 71 commits
- scripts/hooks — 31 commits
- scripts/lib — 26 commits
- (root) — 24 commits
- tests/hooks — 18 commits
- tests/scripts — 16 commits
- scripts/codex-git-hooks — 10 commits
- tests/lib — 8 commits
- skills/skill-stocktake — 5 commits
- tests/gan-harness.test.js — 5 commits
- .github/workflows — 4 commits
- docs/ja-JP — 4 commits
- docs/releases — 4 commits
- skills/skill-comply — 4 commits
- tests/ci — 4 commits
- .opencode/plugins — 3 commits
- docs/es — 3 commits
- ecc2/Cargo.lock — 3 commits
- rules/common — 3 commits
- scripts/memory-mcp.mjs — 3 commits
Notable commits
- fix: Fix/control plane canvas size (#3192)
- fix: Fix/proximity a11y risk cues (#3193)
- fix: Fix/rails patterns followups
- fix: Merge Windows-safe Claude settings race regression fixtures
- fix: Merge branch 'main' into fix/3116-home-install-exclusions
- fix: Merge branch 'main' into fix/3136-gateguard-batch-consistency
- fix: Merge branch 'main' into fix/agent-location-and-namespacing
- fix: Merge branch 'main' into fix/agent-location-docs
- fix: Merge branch 'main' into fix/issue-2886-heredoc-gateguard
- fix: Merge branch 'main' into fix/ollama-generation-token-limit
- fix: Merge branch 'main' into fix/prepush-venv-pytest
- fix: Merge branch 'main' into fix/readme-badges-star-history-20260918
- fix: Merge pull request #2 from VarunGore36/fix/claw-windows-exec-regression
- fix: Merge pull request #2380 from chs0813/fix/plugin-hook-bootstrap-no-echo
- fix: Merge pull request #2633 from Juanpacol/fix/harness-optimizer-eval-harness-reference
- fix: Merge pull request #2693 from andrest/fix/stale-model-rates-cost-estimate-and-skill
- fix: Merge pull request #2873 from actus7/consolidate/remaining-fixes-v3
- fix: Merge pull request #2899 from haelyra/fix/plugin-bootstrap-prefix-classification
- fix: Merge pull request #2912 from affaan-m/fix/packed-install-hook-consent
- fix: Merge pull request #2913 from affaan-m/fix/opencode-hook-consent
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
affaan-m/ECC was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e482e579415fde18357cafce70f177ae19fd7f03 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.