ECC Deep Technical Analysis: The 207K Star Agent Operating System, a Full Dissection of 63 Agents × 251 Skills × 7 Platforms
Core proposition: ECC (Everything Claude Code) positions itself as a "Harness-native Agent operating system": 207K Stars, 190 contributors, 63 Agents, 251 Skills, and support for all 7 AI platforms. Just how strong is it? What can it bring to our tech stack? Methodology: clone and install → directory traversal → source-level dissection → point-by-point risk assessment via the skill-analysis six-step method → adoption decision matrix
1. Project Overview
ECC is currently the most-watched AI Agent infrastructure project on GitHub. It is not an Agent, but an operating system that lets multiple Agent platforms work in concert.
| Dimension | Data |
|---|---|
| Stars | 207,883 |
| Forks | 31,901 |
| Contributors | 190 |
| License | MIT |
| Tech stack | JavaScript (60.8%) + Rust (29.6%) + Python (5.3%) |
| Total size | 84MB |
| Last updated | 2026-06-04 |
Core Numbers
63 Agents : 16 Language Reviews + 12 Build Fixes + 5 Planning + 6 Operations + Other
251 Skills : Security → Deep Research → Frontend → Medical Compliance
79 Commands : Slash command legacy compatibility layer
31 Hooks : 8 Lifecycle Nodes Fully Covered
20 Rules : 19 Languages + Common Global Rules
7 Harnesses : Claude Code, Codex, Cursor, OpenCode, Gemini, Kiro, Zed
2. Architecture Panorama
2.1 Directory Design
ECC/
├── agents/ (63 files) # Specialized Agent Markdown definitions
├── skills/ (251 dirs) # Workflow skill library
├── commands/ (79 files) # Slash command compatibility layer
├── rules/ (19 dirs) # Global rules categorized by language
├── hooks/ # 8 lifecycle × 31 Hooks
├── scripts/ # Node.js automation
├── contexts/ # dev / research / review three-mode switching
├── mcp-configs/ # 14 MCP Server configurations
├── schemas/ # JSON Schema validation layer
├── .claude/ .codex/ .cursor/ # 7 cross-platform adaptation layers
├── ecc2/ # Rust control plane (alpha)
└── docs/ # 12+ language documentation
2.2 Core Design Philosophy
ECC's design revolves around the Agent-First principle:
- An Agent is a file: one Markdown file per Agent, containing the role description, trigger conditions, and tool permissions
- Skill-First workflow: Commands have been demoted to shims; Skills are the single authoritative execution source
- Hook-driven automation: 31 Hooks cover 8 lifecycle points: PreToolUse, PostToolUse, Stop, SessionStart, SessionEnd, PreCompact, Notification, External
- Cross-platform abstraction: core Skills/Rules are shared, while each Harness's adaptation layer is independent
3. The Agent System: 63 Specialized Agents
ECC's Agents are not simple prompt variants; each Agent is a complete role definition:
| Type | Count | Examples |
|---|---|---|
| Language review | 16 | cpp-reviewer, python-reviewer, csharp-reviewer |
| Build repair | 12 | build-error-resolver, cpp-build-resolver, django-build-resolver |
| Planning and analysis | 5 | architect, code-architect, chief-of-staff |
| Operations support | 6 | code-explorer, doc-updater, docs-lookup |
| Security testing | 4 | repo-security-review, e2e-runner, conversation-analyzer |
| Other | 20 | a11y-architect, code-simplifier, comment-analyzer |
Key design features:
- One
.mdfile per Agent, so the AI can directly understand the task boundary agent.yamlprovides structured routing mappings- AGENTS.md (250+ lines) defines the dispatch rules for "automatically selecting an Agent based on task type"
4. The Skill System: An Ecosystem of 251 Skills
4.1 Categories
| Category | Representative Skill |
|---|---|
| 🔒 Security | security-review (including an OWASP checklist + secrets detection) |
| 🔬 Research | deep-research (a multi-round in-depth research workflow) |
| 🏗️ Architecture | architecture-decision-records, agent-architecture-audit |
| 🎨 Frontend | angular-developer, accessibility |
| 🧪 Testing | ai-regression-testing, agent-eval |
| 🤖 Self-improvement | autonomous-loops, self-improving-agent, agentic-os |
4.2 Standard Skill Structure
Every Skill follows a uniform SKILL.md format. Taking security-review as an example:
---
name: security-review
origin: ECC
description: Use when adding authentication, handling user input...
---
# Security Review Skill
## When to Activate
## Security Checklist
### 1. Secrets Management
### 2. Input Validation
...
Key features:
- An
originmarker: every Skill records its source (origin: ECC), which makes tracing and merging easy - Uniform frontmatter: the three fields name + description + origin
- Structured trigger conditions: the "When to Activate" section makes the boundary explicit
5. Hook Lifecycle: A Fully Covered Automation Layer
ECC's 31 Hooks cover 8 lifecycle points of an Agent, and this is where our biggest gap lies:
| Lifecycle Point | ECC Hook Count | UltraClaw Status |
|---|---|---|
| PreToolUse | 8 | ❌ None |
| PostToolUse | 6 | ❌ None |
| Stop | 3 | ❌ None |
| SessionStart | 4 | before_agent_start (1) |
| SessionEnd | 3 | ❌ None |
| PreCompact | 3 | ❌ None |
| Notification | 2 | ❌ None |
| External | 2 | ❌ None |
The most valuable Hooks:
- memory-persistence: loads memory at SessionStart and saves memory at SessionEnd
- secret-detection: checks tool arguments for leaked keys at PreToolUse
- session-summary: automatically generates a session summary at the Stop stage
- compact-guard: controls the context compaction strategy at the PreCompact stage
6. Security Architecture: 5 Layers of Defense in Depth
ECC's security design is not a patch applied after the fact; it was embedded from day one:
Layer 1: Prompt Defense : security baseline in system prompt
Layer 2: Hook Validation : PreToolUse detects dangerous operations
Layer 3: CI Audit : GitHub Actions automated security scanning
Layer 4: MCP Scope : MCP Server fine-grained permission control
Layer 5: Security Policy : Global security policy (the-security-guide.md, 82KB)
The accompanying security document the-security-guide.md is 82KB long, covering threat modeling, OWASP Top 10 mapping, secrets management, prompt injection defense, and more.
7. Source-Level Technical Point Extraction (with Risk Assessment)
Dissecting them one by one using the skill-analysis six-step method:
| # | Technical Point | Source Evidence | Risk | Level |
|---|---|---|---|---|
| 1 | Agent definition as a file | agents/*.md (63), each file independently defining role/triggers/permissions | No structured schema validation | 🟡 |
| 2 | Full Hook lifecycle coverage | hooks/hooks.json (31 hooks, 8 lifecycle points) | Cascade failure: any single hook failing interrupts the session | 🟠 |
| 3 | Skill origin marker | The origin: ECC frontmatter in skills/*/SKILL.md | No conflict resolution strategy | 🟡 |
| 4 | AGENTS.md routing | AGENTS.md (8KB) natural-language dispatch table | LLM routing is non-deterministic | 🟡 |
| 5 | Cross-platform directory mirroring | The 7 directories .claude/ .codex/ .cursor/ etc. | Risk of maintenance explosion | 🟠 |
| 6 | memory-persistence hook | hooks/memory-persistence/ | Sensitive data saved automatically | 🔴 |
| 7 | 5-layer security depth | SECURITY.md + the-security-guide.md (82KB) | Configuration complexity | 🟡 |
| 8 | ecc2 Rust control plane | ecc2/src/ (main.rs + 8 modules) | Unstable at the alpha stage | 🟠 |
8. Adoption Decision Matrix
| # | Technical Point | Decision | Reason | Priority |
|---|---|---|---|---|
| 1 | Skill origin marker | ✅ Adopt | One line of frontmatter, zero cost | P0 |
| 2 | Automatic memory loading | ✅ Adopt | Load 48h vector memory at SessionStart | P0 |
| 3 | Hook lifecycle | ✅ Adopt (with changes) | Add isolation + timeout protection | P1 |
| 4 | 5-layer security depth | ✅ Adopt (gradually) | Start with Layers 1-2 | P1 |
| 5 | Port 10 high-value Skills | ✅ Adopt | deep-research / security-review / architecture-review, etc. | P1 |
| 6 | Agent definition as a file | ✅ Adopt | More human-friendly than raw JSON | P2 |
| 7 | Structured routing table | ✅ Adopt (with changes) | Keywords + LLM assistance | P2 |
| 8 | Cross-platform directories | ❌ Do not adopt | We only have OpenClaw, no need | - |
| 9 | ecc2 Rust control plane | ⏸️ Wait and see | Wait for beta | P3 |
9. Concrete Porting Roadmap
P0: Execute This Week
- Skill origin marker: add
origin: ultraclawfrontmatter to every SKILL.md underskills/ - Automatic memory loading: add a SessionStart preload step to HEARTBEAT.md
P1: Execute This Month
- Port 10 high-value Skills: deep-research → security-review → architecture-review → agent-eval → autonomous-loops → code-reviewer → doc-updater → api-design → database-review → article-writing
- Hook system upgrade: PreToolUse (pre-tool checks) + SessionEnd (automatic memory saving)
- Security baseline: Prompt Defense + OWASP checklist + secrets detection
P2: Execute This Quarter
- Dedicated Agent Markdown definitions: create a description file for each Agent
- Commands → Skills migration: standardize slash commands as Skill entry points
- Structured routing table: upgrade from keyword matching to matrix routing
10. Core Takeaways
- An Agent operating system is its own product category: ECC proves this is not merely "prompt engineering"
- Hooks are the "operating system kernel" of an Agent: an Agent without lifecycle hooks is like an OS without interrupt handling
- Skills need an origin marker: in a large-scale Skill ecosystem, tracing the source is a hard requirement
- Security must be embedded from day one: ECC's 5-layer security depth validates Defense in Depth
- Cross-platform is a double-edged sword: supporting multiple platforms brings ecosystem advantages, but maintenance cost grows exponentially
This report is based on the ECC v2.0.0-rc.1 source repository (84MB, GitHub: affaan-m/ECC), with a technical dissection completed using the skill-analysis six-step method. Analysis methodology: repository scoping → source breakdown → technical point extraction → risk analysis → applicability assessment → report production.
More in Evidence
- A Reality Check on Decision Models: Why They Seem Miraculous Online but We Measured Only 54%: A Full Comparison of JEV / LAYA / KEV / CLM-8B and a Deployment Formula
- The "Non-Text-Generating Model": Jev and the New System One Category, and How Agent Architecture Changes When AI Only Answers Multiple Choice
- WeChat Open Source WeMM-Embedding Deep Dive: The Multimodal Embedding Model Topping MMEB-v2, Can It Run on Your Mac?
- A Source-Level Architectural Dissection of DeepSeek Harness: How an Everything-Is-a-Plugin Agent Framework Is Built