Skip to content

Everything Claude Code: the largest bundle, used for real

Everything Claude Code (ECC, repository affaan-m/ECC) is an open-source harness bundle for coding agents and the largest measured plugin: 68 subagents, 386 skills and commands, seven hook events and a Chrome DevTools MCP entry. It works best in Claude Code, also installs in Codex and Cursor, and adds about 41,500 always-on tokens to every Claude Code session.

You saw the star count, ran two install commands, and now your agent has more slash commands than your team has conventions. Your /context reading jumped, a Stop hook runs a type check you did not ask for, and nobody can say which of the 386 entries is doing useful work. This page is for the developer who wants ECC’s best parts on a real feature without carrying the rest.

What you get from running ECC on one feature

Section titled “What you get from running ECC on one feature”
  • The install line for Claude Code, Codex and Cursor, and the one mistake per tool that doubles everything.
  • An inventory of what the plugin actually puts in your session, with the measured context cost next to lighter frameworks.
  • A worked run on one feature (login rate limiting): plan, test-first build, fresh-context review, security pass, session save.
  • A keep-and-prune table and a slim install that keeps ten components instead of 454 skills and agents.
  • The traps: command-name collisions, a version pin that does not resolve, cost advice that contradicts the tool defaults, and look-alike repositories.

ECC describes itself as a loop: plan, test, implement, review, verify, remember, improve. It ships that loop as five kinds of component. The README and Claude Code count them differently, so this table shows both.

ComponentREADME count (2.2.2)What claude plugin details reportsWhat it does in your session
Subagents68 agents68 agentsScoped workers such as planner, tdd-guide, code-reviewer, security-reviewer, build-error-resolver, e2e-runner, and per-language reviewers
Skills292 skills386 skills (equals 292 skills plus 94 commands)Workflows such as tdd-workflow, security-review, verification-loop, search-first, e2e-testing, strategic-compact, context-budget
Commands94 commandscounted as skillsEntry points such as /ecc:plan, /ecc:code-review, /ecc:build-fix, /ecc:save-session
Hooks“Runtime”7 hook eventsSessionStart, PreToolUse, PostToolUse, PostToolUseFailure, PreCompact, Stop, SessionEnd; Stop alone has seven hook IDs, among them stop:format-typecheck and stop:check-console-log on the standard and strict profiles
MCPone default connector1 (chrome-devtools)Browser debugging; the README says plugin installs do not auto-enable ECC’s bundled MCP definitions, so check /mcp
Rules“Selective”not in the pluginAlways-loaded standards (rules/common plus language packs) that you copy by hand, because Claude Code plugins cannot distribute rules

Two consequences matter before you install. First, ECC is a plugin, so it installs as one unit; the README points to its own installer, not the plugin, when you want to choose components. Second, hooks are code that runs outside the permission prompt, so treat the hook runtime as something you review, the way hooks automation describes.

The single most useful number about ECC is not its star count. Claude Code 2.1.283 projects about 41,515 always-on tokens for ecc@ecc: the skill and agent descriptions that ride along in every session. That is before the SessionStart hook adds its own context, which ECC caps at 8,000 characters by default (ECC_SESSION_START_MAX_CHARS).

Plugin (Claude Code 2.1.283, 2026-09-26)SkillsAgentsAlways-on tokens
superpowers@claude-plugins-official150~838
mattpocock-skills@claude-plugins-official250~1,609
agent-skills@addy-agent-skills344~3,620
gsd-core@gsd-core14464~10,700
ecc@ecc38668~41,515

Source: measured with claude plugin details <plugin> on Claude Code 2.1.283, 2026-09-26. These are Claude Code’s own projections, not billing data.

On Claude Opus 5.5, the Claude Code default from v2.1.280 on the latest channel, with a 1M-token window (see the models hub), 41,500 tokens is about 4% of the window. The window is not the real cost. Those tokens are billed as input on every request, and several hundred similar skill descriptions give the model more ways to pick the wrong one. The cost per context page shows how to turn a token count into money for your own traffic.

Measure it on your machine before and after, from the terminal and inside a session:

Terminal window
claude plugin details ecc@ecc # terminal: always-on tokens, skills, agents, hooks, MCP
/context

Run /context in a fresh session without ECC, then again with it, and keep both numbers in the pull request that adds ECC to a team setup.

Install ECC in Claude Code, Codex or Cursor

Section titled “Install ECC in Claude Code, Codex or Cursor”

ECC’s README says the same thing for every tool: pick one install method per tool and never stack two. A plugin install plus a manual install duplicates skills, commands and hooks, and duplicated hooks fire twice.

Inside a Claude Code session (needs Claude Code 2.1 or later, Git and Node.js 18 or later):

/plugin marketplace add https://github.com/affaan-m/ECC
/plugin install ecc@ecc

Then start a new session, run /plugin list, and confirm that ecc@ecc is enabled. From a terminal, claude plugin list shows the same.

In our install on 2026-09-26 it printed “2 userConfig options not yet set”. Run /ecc:configure-ecc to set them and choose a hook profile; the default profile (ECC_HOOK_PROFILE) is standard.

Rules do not come with the plugin. Copy the common pack and one language pack into this repository only (project scope keeps them out of your other projects):

Terminal window
git clone https://github.com/affaan-m/ECC.git ~/src/ECC
mkdir -p .claude/rules/ecc
cp -R ~/src/ECC/rules/common .claude/rules/ecc/
cp -R ~/src/ECC/rules/typescript .claude/rules/ecc/ # your stack, not all of them

Build one feature with ECC: login rate limiting

Section titled “Build one feature with ECC: login rate limiting”

The feature: an Express and TypeScript service where POST /api/auth/login must return 429 with a Retry-After header after five failed attempts for one account in 15 minutes, while a correct password still resets the counter. It is small enough to finish in one session and security-sensitive enough to need review. The commands are the Claude Code plugin forms; the README maps each one to the subagent it uses. In Codex, invoke the same skills with $ (for example $tdd-workflow, as the README does with $configure-ecc); in Cursor, the adapter installs the agents as .cursor/agents/ecc-*.md, which you reference by name.

  1. Plan with /ecc:plan. The planner subagent writes an implementation blueprint. Read it for three things: where the counter lives (in memory breaks with more than one instance), what the key is (account, IP, or both), and which tests prove the behaviour.

  2. Build test-first with tdd-workflow. Run the tdd-workflow skill (or call the tdd-guide subagent by name): interfaces, failing tests (red), minimal code (green), refactor. Check the transcript for a red test run before any implementation. A test that never failed proves nothing. The skill’s own bar is 80% coverage; your CI threshold wins if it differs.

  3. Review from a fresh context with /ecc:code-review. The code-reviewer subagent reads the diff without the implementation conversation in its context. Type the namespaced form: a bare /code-review runs Claude Code’s bundled review skill instead.

  4. Run a security pass with ecc:security-review. Rate limiting is an authentication control, so ask for the attacks, not a style review. Name the namespaced skill: a bare /security-review runs Claude Code’s bundled review of the pending branch changes, not ECC’s checklist. To hand the pass to the security-reviewer subagent instead, ask for it by name.

  5. Repair the build if it breaks with /ecc:build-fix. The build-error-resolver subagent works on compiler and test-runner output. Use it on a red build, not as a routine step.

  6. Save the session with /ecc:save-session before you close the terminal, so /ecc:resume-session can pick the work up with the plan and decisions intact.

When the agent stops, ECC runs several Stop hooks, among them stop:format-typecheck (300-second timeout in hooks/hooks.json) and stop:check-console-log on the standard and strict profiles. Treat them as a local early warning. They are not your merge gate.

How do you verify ECC’s output without reading every line?

Section titled “How do you verify ECC’s output without reading every line?”

ECC makes the agent test first and review itself, but a self-review by the same vendor’s model is weak evidence. The proof for this feature is:

  • Acceptance tests you wrote into the plan, seen failing and then passing. Check the red run in the transcript, then run the suite yourself: npm test -- tests/auth/login-rate-limit.test.ts.
  • CI gates that run with or without ECC: type check, lint, the full test suite, and the coverage threshold your team already enforces.
  • A second reviewer from a different model, for example codex review or a review bot from AI code review bots, on the pull request.
  • A human sign-off on the plan and the tests, not the diff. You approve that the acceptance tests describe the behaviour you want; the gates prove the code meets them.

If any of those is missing, ECC has made the agent faster without making the result safer.

Most teams use a small slice of ECC. The README itself says “Start with the workflow you need, not the full catalog”. This split follows the loop in the worked example.

KeepWhyPruneWhy
/ecc:plan and the planner subagentA written plan before code, reviewable in two minutesLanguage reviewers and resolvers for stacks you do not use (Go, Python, F#, HarmonyOS/ArkTS and others)Each one adds a description to every session
tdd-workflow with tdd-guideThe test-first loop is where the quality comes frommulti-* commandsNeed an external runtime ECC does not bundle
/ecc:code-review with code-reviewerFresh-context review before your ownDomain capabilities you do not work in (for example capability:machine-learning)The installer offers them as opt-in --with modules for a reason
ecc:security-reviewAttack-oriented pass on sensitive routesRule packs beyond common plus one languageRules are always loaded, so every pack costs context
verification-loop, search-firstCheck before claiming done; look before writingRetired command shims (legacy-command-shims/)Old names that collide with built-ins such as /plan
/ecc:build-fix, context-budgetRed builds and context pressureThe hook runtime, until you have read itCode that runs on every tool call and stop

With the plugin, use the /ecc: commands. With the slim install, call the planner, code-reviewer and build-error-resolver subagents by name, and ask for the security pass in a prompt (“Use the security-review skill…”), never as the /security-review command, which stays Claude Code’s built-in.

To get the “keep” column without the rest, uninstall the plugin (claude plugin uninstall ecc@ecc in a terminal, Claude Code 2.1.283) and install the pieces from a clone you have reviewed. ECC’s installer takes explicit skills, and agents are plain Markdown files you copy:

Terminal window
# Terminal, in the ECC clone
cd ~/src/ECC
node scripts/ecc.js consult "security reviews" --target claude # which components match a job
# installs the skills at user scope (~/.claude/skills), per the README
./install.sh --target claude --skills tdd-workflow,security-review,verification-loop,search-first,context-budget
node scripts/ecc.js list-installed # what ECC now owns
# Terminal, in your service's repository: five subagents, project scope only
mkdir -p .claude/agents
cp ~/src/ECC/agents/{planner,tdd-guide,code-reviewer,security-reviewer,build-error-resolver}.md .claude/agents/

That is ten components instead of 454 skills and agents, with no hook runtime. Note the split scope: the five skills land in your user directory and apply to every project, while the five subagents live in this repository only. Leave commands/ behind: copied by hand, plan.md and code-review.md become /plan and /code-review and collide with Claude Code’s own commands. Call the subagents by name instead (“Use the planner subagent to…”). At the plugin’s average of about 90 always-on tokens per entry (41,515 across 454), ten components list for roughly 900 tokens; run /context again to confirm on your setup.

If you want the whole loop with fewer moving parts, the README’s ./install.sh --profile minimal --target claude installs rules, agents, commands and core workflows without the hook runtime. Add hooks later with --modules hooks-runtime --enable-hooks only after you have read them. If you keep the plugin, ECC_DISABLED_HOOKS takes a comma-separated list of hook IDs, and ECC_SESSION_START_CONTEXT=off turns off the SessionStart injection.

Everything appears twice. You installed the plugin and then ran ./install.sh --profile full, or you synced into Codex and also added the Codex plugin. Recovery: run claude plugin uninstall ecc@ecc, then run node scripts/ecc.js uninstall --dry-run from the ECC clone, read the list, run it without --dry-run, and reinstall with one method.

The wrong command runs. /code-review, /plan and /security-review are Claude Code built-ins (the review skill, plan mode and the bundled security review). The plugin’s versions are /ecc:code-review, /ecc:plan and the ecc:security-review skill. Manual installs expose short names and a retired /tdd shim that shadow or collide with built-ins. Recovery: use the namespaced forms, and do not copy legacy-command-shims/.

The agent picks the wrong skill. With hundreds of descriptions in context, a generic prompt such as “review this” can trigger a language reviewer for the wrong stack. Recovery: name the skill in the prompt, as the prompts above do, and prune the packs you do not use.

The Stop hook hangs or fails the session. stop:format-typecheck runs your formatter and type checker, with a 300-second timeout, so on a large monorepo every stop can wait minutes for it. Recovery: add its ID to ECC_DISABLED_HOOKS and keep the type check in CI, where it belongs.

Costs go up after you follow the README’s cost advice. ECC’s token-optimization section recommends "model": "sonnet", a MAX_THINKING_TOKENS cap and a Haiku subagent model, and states savings with no source. That runs against how current models are tuned: from v2.1.280 (the latest channel) Claude Code defaults to Claude Opus 5.5 at medium effort. Tune effort with /effort before you switch model, and switch only when your own evals say so. Recovery: remove those settings and follow the models hub.

A look-alike package or repository. Search results surface re-uploads. Recovery: install only from the names in the traps box, and scan your agent configuration with ECC’s AgentShield (agentshield scan --path ., npm ecc-agentshield 1.6.0 on 2026-09-26) or the checks in skill supply-chain security.

Choose ECC when you want one opinionated harness and are prepared to prune it. Choose something smaller when you need one practice: Superpowers costs about 838 always-on tokens for a complete design-plan-TDD-review loop, and the discipline packs page compares ECC with Matt Pocock’s skills, gstack, agent-skills and Ponytail. For a spec trail that product owners approve, use a spec-driven framework instead.