Ecc GuideSAFE
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
Overview
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
bd656e3e97c4OBSERVED · 2026-09-20Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned | |
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: ecc-guide description: ECC の現在のエージェント、スキル、コマンド、フック、ルール、インストールプロファイル、およびプロジェクトオンボーディングをガイドしています。ライブリポジトリサーフェスを読んでから回答するようユーザーをガイドします。 origin: community --- # ECC Guide Use this skill when a user needs help understanding, navigating, installing, or choosing parts of Everything Claude Code. ## When To Use Use this skill when the user: - asks what ECC includes - wants help finding a skill, command, agent, hook, rule, or install profile - is new to the repository and needs a guided path - asks "how do I do X with ECC?" - asks which ECC components fit a project - needs a lightweight explanation of how commands, skills, agents, hooks, and rules relate - is confused by install paths, duplicate installs, reset/uninstall, or selective install options ## Core Principle Answer from current files, not memory. ECC changes quickly, so hard-coded catalog counts, feature lists, and install instructions go stale. When the ECC repository is available, inspect the relevant files before giving a concrete answer: ```bash node scripts/ci/catalog.js --json find skills -maxdepth 2 -name SKILL.md | sort find commands -maxdepth 1 -name '*.md' | sort find agents -maxdepth 1 -name '*.md' | sort node scripts/install-plan.js --list-profiles node scripts/install-plan.js --list-components --json ``` Use the smallest set of reads needed for the user's question. ## Repository Map - `README.md`: install paths, uninstall/reset guidance, public positioning, FAQs - `AGENTS.md`: contributor guidance and project structure - `agent.yaml`: exported gitagent surface and command list - `commands/`: maintained slash-command compatibility shims - `skills/*/SKILL.md`: reusable workflows and domain playbooks - `agents/*.md`: delegated subagent role prompts - `rules/`: language and harness rules - `hooks/README.md`, `hooks/hooks.json`, `scripts/hooks/`: hook behavior and safety gates - `manifests/install-*.json`: selective install modules, components, profiles, and target support - `docs/`: harness guides, architecture notes, translated docs, release docs ## Response Style Lead with the answer, then give the next action. Most users do not need a full catalog dump. Good first response shape: 1. what to use 2. why it fits 3. exact file or command to inspect 4. one next command or question Avoid: - listing every skill or command by default - repeating large README sections - recommending retired command shims when a skill-first path exists - claiming a component exists without checking the filesystem - replacing install guidance with manual copy commands when the managed installer supports the target ## Common Tasks ### New User Onboarding Give a short menu: - install or reset ECC - pick skills for a project - understand commands vs skills - inspect hooks and safety behavior - run a harness audit - find a specific workflow Point to `README.md` for install/reset and `/project-init` for project-specific onboarding. ### Feature Discovery For "what should I use for X?": 1. Search `skills/`, `commands/`, and `agents/`. 2. Prefer skills as the primary workflow surface. 3. Use commands only when they are a maintained compatibility shim or a user explicitly wants slash-command behavior. 4. Mention agents when delegation is useful. Useful searches: ```bash rg -n "<query>" skills commands agents docs find skills -maxdepth 2 -name SKILL.md | sort ``` ### Install Guidance Use managed install paths: ```bash node scripts/install-plan.js --list-profiles node scripts/install-plan.js --profile minimal --target claude --json node scripts/install-apply.js --profile minimal --target claude --dry-run ``` For specific skill installs: ```bash node scripts/install-plan.js --skills <skill-id> --target claude --json node scripts/install-apply.js --skills <skill-id> --target claude --dry-run ``` Warn users not to stack plugin installs and full manual/profile installs unless they intentionally want duplicate surfaces. ### Project Onboarding Use `/project-init` when the user wants ECC configured for a target repo. The expected sequence is: 1. detect the stack from project files 2. resolve a dry-run install plan 3. inspect existing `CLAUDE.md` and settings files 4. ask before applying changes 5. keep generated guidance minimal and repo-specific ### Troubleshooting Ask for the target harness and install path first, then inspect: - plugin install metadata - `.claude/`, `.cursor/`, `.codex/`, `.gemini/`, `.opencode/`, `.codebuddy/`, `.joycode/`, or `.qwen/` - `hooks/hooks.json` - install-state files - relevant command/skill files For repo health, suggest: ```bash npm run harness:audit -- --format text npm run observability:ready npm test ``` ## Output Templates ### Short Recommendation ```text Use <skill-or-command>. It fits because <reason>. Canonical file: <path> Verify with: <command> Next: <one concrete action> ``` ### Search Results ```text Best matches: - <path>: <why it matters> - <path>: <why it matters> Recommendation: <which one to use first and why> ``` ### Install Plan Summary ```text Detected: <stack evidence> Target: <harness> Plan: <profile/modules/skills> Dry run: <command> Would change: <paths> Needs approval before apply: <yes/no> ``` ## Related Surfaces - `/project-init`: stack-aware onboarding plan for a target repo - `/harness-audit`: deterministic readiness scorecard - `/skill-health`: skill quality review - `/skill-create`: generate a new skill from local git history - `/security-scan`: inspect Claude/OpenCode configuration security
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
bd656e3e97c4full audit observations/trust-audit/skill/affaan-m__ecc-guide.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-20 | bd656e3e97c4 | SAFE | B | 89 | first audit |
Questions
What does the Ecc Guide skill do?
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
Is Ecc Guide safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Ecc Guide access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Ecc Guide work with?
Its documentation mentions claude-code, codex and cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (bd656e3e97c4), read on 2026-09-20. The repository is watched, and a new audit runs when it changes — this is the first audit.