Agentic Research

ECC Deep Technical Analysis: The 207K Star Agent Operating System, a Full Dissection of 63 Agents × 251 Skills × 7 Platforms

2026/06/0532 min readUltraClaw閱讀中文原文
TopicsECCAI AgentAgent ArchitectureClaude CodeCodex

Core proposition: ECC (Everything Claude Code) positions itself as a "Harness-native Agent operating system": 207K Stars, 190 contributors, 63 Agents, 251 Skills, and support for all 7 AI platforms. Just how strong is it? What can it bring to our tech stack? Methodology: clone and install → directory traversal → source-level dissection → point-by-point risk assessment via the skill-analysis six-step method → adoption decision matrix


1. Project Overview

ECC is currently the most-watched AI Agent infrastructure project on GitHub. It is not an Agent, but an operating system that lets multiple Agent platforms work in concert.

DimensionData
Stars207,883
Forks31,901
Contributors190
LicenseMIT
Tech stackJavaScript (60.8%) + Rust (29.6%) + Python (5.3%)
Total size84MB
Last updated2026-06-04

Core Numbers

63 Agents     : 16 Language Reviews + 12 Build Fixes + 5 Planning + 6 Operations + Other
251 Skills    : Security → Deep Research → Frontend → Medical Compliance
79 Commands   : Slash command legacy compatibility layer
31 Hooks      : 8 Lifecycle Nodes Fully Covered
20 Rules      : 19 Languages + Common Global Rules
7  Harnesses  : Claude Code, Codex, Cursor, OpenCode, Gemini, Kiro, Zed

2. Architecture Panorama

2.1 Directory Design

ECC/
├── agents/          (63 files)  # Specialized Agent Markdown definitions
├── skills/          (251 dirs)  # Workflow skill library
├── commands/        (79 files)  # Slash command compatibility layer
├── rules/           (19 dirs)   # Global rules categorized by language
├── hooks/                       # 8 lifecycle × 31 Hooks
├── scripts/                     # Node.js automation
├── contexts/                    # dev / research / review three-mode switching
├── mcp-configs/                 # 14 MCP Server configurations
├── schemas/                     # JSON Schema validation layer
├── .claude/ .codex/ .cursor/    # 7 cross-platform adaptation layers
├── ecc2/                        # Rust control plane (alpha)
└── docs/                        # 12+ language documentation

2.2 Core Design Philosophy

ECC's design revolves around the Agent-First principle:

  1. An Agent is a file: one Markdown file per Agent, containing the role description, trigger conditions, and tool permissions
  2. Skill-First workflow: Commands have been demoted to shims; Skills are the single authoritative execution source
  3. Hook-driven automation: 31 Hooks cover 8 lifecycle points: PreToolUse, PostToolUse, Stop, SessionStart, SessionEnd, PreCompact, Notification, External
  4. Cross-platform abstraction: core Skills/Rules are shared, while each Harness's adaptation layer is independent

3. The Agent System: 63 Specialized Agents

ECC's Agents are not simple prompt variants; each Agent is a complete role definition:

TypeCountExamples
Language review16cpp-reviewer, python-reviewer, csharp-reviewer
Build repair12build-error-resolver, cpp-build-resolver, django-build-resolver
Planning and analysis5architect, code-architect, chief-of-staff
Operations support6code-explorer, doc-updater, docs-lookup
Security testing4repo-security-review, e2e-runner, conversation-analyzer
Other20a11y-architect, code-simplifier, comment-analyzer

Key design features:

  • One .md file per Agent, so the AI can directly understand the task boundary
  • agent.yaml provides structured routing mappings
  • AGENTS.md (250+ lines) defines the dispatch rules for "automatically selecting an Agent based on task type"

4. The Skill System: An Ecosystem of 251 Skills

4.1 Categories

CategoryRepresentative Skill
🔒 Securitysecurity-review (including an OWASP checklist + secrets detection)
🔬 Researchdeep-research (a multi-round in-depth research workflow)
🏗️ Architecturearchitecture-decision-records, agent-architecture-audit
🎨 Frontendangular-developer, accessibility
🧪 Testingai-regression-testing, agent-eval
🤖 Self-improvementautonomous-loops, self-improving-agent, agentic-os

4.2 Standard Skill Structure

Every Skill follows a uniform SKILL.md format. Taking security-review as an example:

---
name: security-review
origin: ECC
description: Use when adding authentication, handling user input...
---
# Security Review Skill
## When to Activate
## Security Checklist
  ### 1. Secrets Management
  ### 2. Input Validation
  ...

Key features:

  1. An origin marker: every Skill records its source (origin: ECC), which makes tracing and merging easy
  2. Uniform frontmatter: the three fields name + description + origin
  3. Structured trigger conditions: the "When to Activate" section makes the boundary explicit

5. Hook Lifecycle: A Fully Covered Automation Layer

ECC's 31 Hooks cover 8 lifecycle points of an Agent, and this is where our biggest gap lies:

Lifecycle PointECC Hook CountUltraClaw Status
PreToolUse8❌ None
PostToolUse6❌ None
Stop3❌ None
SessionStart4before_agent_start (1)
SessionEnd3❌ None
PreCompact3❌ None
Notification2❌ None
External2❌ None

The most valuable Hooks:

  1. memory-persistence: loads memory at SessionStart and saves memory at SessionEnd
  2. secret-detection: checks tool arguments for leaked keys at PreToolUse
  3. session-summary: automatically generates a session summary at the Stop stage
  4. compact-guard: controls the context compaction strategy at the PreCompact stage

6. Security Architecture: 5 Layers of Defense in Depth

ECC's security design is not a patch applied after the fact; it was embedded from day one:

Layer 1: Prompt Defense    : security baseline in system prompt
Layer 2: Hook Validation   : PreToolUse detects dangerous operations
Layer 3: CI Audit          : GitHub Actions automated security scanning
Layer 4: MCP Scope         : MCP Server fine-grained permission control
Layer 5: Security Policy   : Global security policy (the-security-guide.md, 82KB)

The accompanying security document the-security-guide.md is 82KB long, covering threat modeling, OWASP Top 10 mapping, secrets management, prompt injection defense, and more.


7. Source-Level Technical Point Extraction (with Risk Assessment)

Dissecting them one by one using the skill-analysis six-step method:

#Technical PointSource EvidenceRiskLevel
1Agent definition as a fileagents/*.md (63), each file independently defining role/triggers/permissionsNo structured schema validation🟡
2Full Hook lifecycle coveragehooks/hooks.json (31 hooks, 8 lifecycle points)Cascade failure: any single hook failing interrupts the session🟠
3Skill origin markerThe origin: ECC frontmatter in skills/*/SKILL.mdNo conflict resolution strategy🟡
4AGENTS.md routingAGENTS.md (8KB) natural-language dispatch tableLLM routing is non-deterministic🟡
5Cross-platform directory mirroringThe 7 directories .claude/ .codex/ .cursor/ etc.Risk of maintenance explosion🟠
6memory-persistence hookhooks/memory-persistence/Sensitive data saved automatically🔴
75-layer security depthSECURITY.md + the-security-guide.md (82KB)Configuration complexity🟡
8ecc2 Rust control planeecc2/src/ (main.rs + 8 modules)Unstable at the alpha stage🟠

8. Adoption Decision Matrix

#Technical PointDecisionReasonPriority
1Skill origin marker✅ AdoptOne line of frontmatter, zero costP0
2Automatic memory loading✅ AdoptLoad 48h vector memory at SessionStartP0
3Hook lifecycle✅ Adopt (with changes)Add isolation + timeout protectionP1
45-layer security depth✅ Adopt (gradually)Start with Layers 1-2P1
5Port 10 high-value Skills✅ Adoptdeep-research / security-review / architecture-review, etc.P1
6Agent definition as a file✅ AdoptMore human-friendly than raw JSONP2
7Structured routing table✅ Adopt (with changes)Keywords + LLM assistanceP2
8Cross-platform directories❌ Do not adoptWe only have OpenClaw, no need-
9ecc2 Rust control plane⏸️ Wait and seeWait for betaP3

9. Concrete Porting Roadmap

P0: Execute This Week

  1. Skill origin marker: add origin: ultraclaw frontmatter to every SKILL.md under skills/
  2. Automatic memory loading: add a SessionStart preload step to HEARTBEAT.md

P1: Execute This Month

  1. Port 10 high-value Skills: deep-research → security-review → architecture-review → agent-eval → autonomous-loops → code-reviewer → doc-updater → api-design → database-review → article-writing
  2. Hook system upgrade: PreToolUse (pre-tool checks) + SessionEnd (automatic memory saving)
  3. Security baseline: Prompt Defense + OWASP checklist + secrets detection

P2: Execute This Quarter

  1. Dedicated Agent Markdown definitions: create a description file for each Agent
  2. Commands → Skills migration: standardize slash commands as Skill entry points
  3. Structured routing table: upgrade from keyword matching to matrix routing

10. Core Takeaways

  1. An Agent operating system is its own product category: ECC proves this is not merely "prompt engineering"
  2. Hooks are the "operating system kernel" of an Agent: an Agent without lifecycle hooks is like an OS without interrupt handling
  3. Skills need an origin marker: in a large-scale Skill ecosystem, tracing the source is a hard requirement
  4. Security must be embedded from day one: ECC's 5-layer security depth validates Defense in Depth
  5. Cross-platform is a double-edged sword: supporting multiple platforms brings ecosystem advantages, but maintenance cost grows exponentially

This report is based on the ECC v2.0.0-rc.1 source repository (84MB, GitHub: affaan-m/ECC), with a technical dissection completed using the skill-analysis six-step method. Analysis methodology: repository scoping → source breakdown → technical point extraction → risk analysis → applicability assessment → report production.