Everything Claude Code: the largest bundle, used for real
Everything Claude Code (ECC, repository affaan-m/ECC) is an open-source harness bundle for coding agents and the largest measured plugin: 68 subagents, 386 skills and commands, seven hook events and a Chrome DevTools MCP entry. It works best in Claude Code, also installs in Codex and Cursor, and adds about 41,500 always-on tokens to every Claude Code session.
You saw the star count, ran two install commands, and now your agent has more slash commands than your team has conventions. Your /context reading jumped, a Stop hook runs a type check you did not ask for, and nobody can say which of the 386 entries is doing useful work. This page is for the developer who wants ECC’s best parts on a real feature without carrying the rest.
What you get from running ECC on one feature
Section titled “What you get from running ECC on one feature”- The install line for Claude Code, Codex and Cursor, and the one mistake per tool that doubles everything.
- An inventory of what the plugin actually puts in your session, with the measured context cost next to lighter frameworks.
- A worked run on one feature (login rate limiting): plan, test-first build, fresh-context review, security pass, session save.
- A keep-and-prune table and a slim install that keeps ten components instead of 454 skills and agents.
- The traps: command-name collisions, a version pin that does not resolve, cost advice that contradicts the tool defaults, and look-alike repositories.
What does Everything Claude Code install?
Section titled “What does Everything Claude Code install?”ECC describes itself as a loop: plan, test, implement, review, verify, remember, improve. It ships that loop as five kinds of component. The README and Claude Code count them differently, so this table shows both.
| Component | README count (2.2.2) | What claude plugin details reports | What it does in your session |
|---|---|---|---|
| Subagents | 68 agents | 68 agents | Scoped workers such as planner, tdd-guide, code-reviewer, security-reviewer, build-error-resolver, e2e-runner, and per-language reviewers |
| Skills | 292 skills | 386 skills (equals 292 skills plus 94 commands) | Workflows such as tdd-workflow, security-review, verification-loop, search-first, e2e-testing, strategic-compact, context-budget |
| Commands | 94 commands | counted as skills | Entry points such as /ecc:plan, /ecc:code-review, /ecc:build-fix, /ecc:save-session |
| Hooks | “Runtime” | 7 hook events | SessionStart, PreToolUse, PostToolUse, PostToolUseFailure, PreCompact, Stop, SessionEnd; Stop alone has seven hook IDs, among them stop:format-typecheck and stop:check-console-log on the standard and strict profiles |
| MCP | one default connector | 1 (chrome-devtools) | Browser debugging; the README says plugin installs do not auto-enable ECC’s bundled MCP definitions, so check /mcp |
| Rules | “Selective” | not in the plugin | Always-loaded standards (rules/common plus language packs) that you copy by hand, because Claude Code plugins cannot distribute rules |
Two consequences matter before you install. First, ECC is a plugin, so it installs as one unit; the README points to its own installer, not the plugin, when you want to choose components. Second, hooks are code that runs outside the permission prompt, so treat the hook runtime as something you review, the way hooks automation describes.
What does ECC cost in context?
Section titled “What does ECC cost in context?”The single most useful number about ECC is not its star count. Claude Code 2.1.283 projects about 41,515 always-on tokens for ecc@ecc: the skill and agent descriptions that ride along in every session. That is before the SessionStart hook adds its own context, which ECC caps at 8,000 characters by default (ECC_SESSION_START_MAX_CHARS).
| Plugin (Claude Code 2.1.283, 2026-09-26) | Skills | Agents | Always-on tokens |
|---|---|---|---|
superpowers@claude-plugins-official | 15 | 0 | ~838 |
mattpocock-skills@claude-plugins-official | 25 | 0 | ~1,609 |
agent-skills@addy-agent-skills | 34 | 4 | ~3,620 |
gsd-core@gsd-core | 144 | 64 | ~10,700 |
ecc@ecc | 386 | 68 | ~41,515 |
Source: measured with claude plugin details <plugin> on Claude Code 2.1.283, 2026-09-26. These are Claude Code’s own projections, not billing data.
On Claude Opus 5.5, the Claude Code default from v2.1.280 on the latest channel, with a 1M-token window (see the models hub), 41,500 tokens is about 4% of the window. The window is not the real cost. Those tokens are billed as input on every request, and several hundred similar skill descriptions give the model more ways to pick the wrong one. The cost per context page shows how to turn a token count into money for your own traffic.
Measure it on your machine before and after, from the terminal and inside a session:
claude plugin details ecc@ecc # terminal: always-on tokens, skills, agents, hooks, MCP/contextRun /context in a fresh session without ECC, then again with it, and keep both numbers in the pull request that adds ECC to a team setup.
Install ECC in Claude Code, Codex or Cursor
Section titled “Install ECC in Claude Code, Codex or Cursor”ECC’s README says the same thing for every tool: pick one install method per tool and never stack two. A plugin install plus a manual install duplicates skills, commands and hooks, and duplicated hooks fire twice.
Inside a Claude Code session (needs Claude Code 2.1 or later, Git and Node.js 18 or later):
/plugin marketplace add https://github.com/affaan-m/ECC/plugin install ecc@eccThen start a new session, run /plugin list, and confirm that ecc@ecc is enabled. From a terminal, claude plugin list shows the same.
In our install on 2026-09-26 it printed “2 userConfig options not yet set”. Run /ecc:configure-ecc to set them and choose a hook profile; the default profile (ECC_HOOK_PROFILE) is standard.
Rules do not come with the plugin. Copy the common pack and one language pack into this repository only (project scope keeps them out of your other projects):
git clone https://github.com/affaan-m/ECC.git ~/src/ECCmkdir -p .claude/rules/ecccp -R ~/src/ECC/rules/common .claude/rules/ecc/cp -R ~/src/ECC/rules/typescript .claude/rules/ecc/ # your stack, not all of themIn a terminal (codex-cli 0.157.1 has codex plugin marketplace add and codex plugin add; the verb is add, not install):
codex plugin marketplace add affaan-m/ECCcodex plugin add ecc@ecccodex plugin list --jsoncodex plugin list --json confirms the plugin is registered. Restart Codex and run $configure-ecc: it confirms the plugin loads and walks you through setup.
Codex keeps one enabled plugin state per CODEX_HOME, with no user, project or local scopes, and its hooks need an explicit trust decision; ECC’s four Claude hook profiles do not apply. Do not also run ECC’s older scripts/sync-ecc-to-codex.sh path, which the README marks as deprecated.
Codex 0.157.1 has no equivalent of claude plugin details, so the figure above is Claude Code only.
Cursor has no ECC plugin. The README installs a project-local adapter from a clone, in the repository you want to equip:
git clone https://github.com/affaan-m/ECC.git ~/src/ECCcd ~/src/ECC./install.sh --profile minimal --target cursorThe adapter writes under .cursor/, with agent definitions at .cursor/agents/ecc-*.md, and does not install a root AGENTS.md. The README warns that Cursor-native loading “can vary by Cursor build”. We did not run this route; it comes from the README.
Build one feature with ECC: login rate limiting
Section titled “Build one feature with ECC: login rate limiting”The feature: an Express and TypeScript service where POST /api/auth/login must return 429 with a Retry-After header after five failed attempts for one account in 15 minutes, while a correct password still resets the counter. It is small enough to finish in one session and security-sensitive enough to need review. The commands are the Claude Code plugin forms; the README maps each one to the subagent it uses. In Codex, invoke the same skills with $ (for example $tdd-workflow, as the README does with $configure-ecc); in Cursor, the adapter installs the agents as .cursor/agents/ecc-*.md, which you reference by name.
-
Plan with
/ecc:plan. Theplannersubagent writes an implementation blueprint. Read it for three things: where the counter lives (in memory breaks with more than one instance), what the key is (account, IP, or both), and which tests prove the behaviour. -
Build test-first with
tdd-workflow. Run thetdd-workflowskill (or call thetdd-guidesubagent by name): interfaces, failing tests (red), minimal code (green), refactor. Check the transcript for a red test run before any implementation. A test that never failed proves nothing. The skill’s own bar is 80% coverage; your CI threshold wins if it differs. -
Review from a fresh context with
/ecc:code-review. Thecode-reviewersubagent reads the diff without the implementation conversation in its context. Type the namespaced form: a bare/code-reviewruns Claude Code’s bundled review skill instead. -
Run a security pass with
ecc:security-review. Rate limiting is an authentication control, so ask for the attacks, not a style review. Name the namespaced skill: a bare/security-reviewruns Claude Code’s bundled review of the pending branch changes, not ECC’s checklist. To hand the pass to thesecurity-reviewersubagent instead, ask for it by name. -
Repair the build if it breaks with
/ecc:build-fix. Thebuild-error-resolversubagent works on compiler and test-runner output. Use it on a red build, not as a routine step. -
Save the session with
/ecc:save-sessionbefore you close the terminal, so/ecc:resume-sessioncan pick the work up with the plan and decisions intact.
When the agent stops, ECC runs several Stop hooks, among them stop:format-typecheck (300-second timeout in hooks/hooks.json) and stop:check-console-log on the standard and strict profiles. Treat them as a local early warning. They are not your merge gate.
How do you verify ECC’s output without reading every line?
Section titled “How do you verify ECC’s output without reading every line?”ECC makes the agent test first and review itself, but a self-review by the same vendor’s model is weak evidence. The proof for this feature is:
- Acceptance tests you wrote into the plan, seen failing and then passing. Check the red run in the transcript, then run the suite yourself:
npm test -- tests/auth/login-rate-limit.test.ts. - CI gates that run with or without ECC: type check, lint, the full test suite, and the coverage threshold your team already enforces.
- A second reviewer from a different model, for example
codex reviewor a review bot from AI code review bots, on the pull request. - A human sign-off on the plan and the tests, not the diff. You approve that the acceptance tests describe the behaviour you want; the gates prove the code meets them.
If any of those is missing, ECC has made the agent faster without making the result safer.
What to keep and what to prune
Section titled “What to keep and what to prune”Most teams use a small slice of ECC. The README itself says “Start with the workflow you need, not the full catalog”. This split follows the loop in the worked example.
| Keep | Why | Prune | Why |
|---|---|---|---|
/ecc:plan and the planner subagent | A written plan before code, reviewable in two minutes | Language reviewers and resolvers for stacks you do not use (Go, Python, F#, HarmonyOS/ArkTS and others) | Each one adds a description to every session |
tdd-workflow with tdd-guide | The test-first loop is where the quality comes from | multi-* commands | Need an external runtime ECC does not bundle |
/ecc:code-review with code-reviewer | Fresh-context review before your own | Domain capabilities you do not work in (for example capability:machine-learning) | The installer offers them as opt-in --with modules for a reason |
ecc:security-review | Attack-oriented pass on sensitive routes | Rule packs beyond common plus one language | Rules are always loaded, so every pack costs context |
verification-loop, search-first | Check before claiming done; look before writing | Retired command shims (legacy-command-shims/) | Old names that collide with built-ins such as /plan |
/ecc:build-fix, context-budget | Red builds and context pressure | The hook runtime, until you have read it | Code that runs on every tool call and stop |
With the plugin, use the /ecc: commands. With the slim install, call the planner, code-reviewer and build-error-resolver subagents by name, and ask for the security pass in a prompt (“Use the security-review skill…”), never as the /security-review command, which stays Claude Code’s built-in.
To get the “keep” column without the rest, uninstall the plugin (claude plugin uninstall ecc@ecc in a terminal, Claude Code 2.1.283) and install the pieces from a clone you have reviewed. ECC’s installer takes explicit skills, and agents are plain Markdown files you copy:
# Terminal, in the ECC clonecd ~/src/ECCnode scripts/ecc.js consult "security reviews" --target claude # which components match a job# installs the skills at user scope (~/.claude/skills), per the README./install.sh --target claude --skills tdd-workflow,security-review,verification-loop,search-first,context-budgetnode scripts/ecc.js list-installed # what ECC now owns
# Terminal, in your service's repository: five subagents, project scope onlymkdir -p .claude/agentscp ~/src/ECC/agents/{planner,tdd-guide,code-reviewer,security-reviewer,build-error-resolver}.md .claude/agents/That is ten components instead of 454 skills and agents, with no hook runtime. Note the split scope: the five skills land in your user directory and apply to every project, while the five subagents live in this repository only. Leave commands/ behind: copied by hand, plan.md and code-review.md become /plan and /code-review and collide with Claude Code’s own commands. Call the subagents by name instead (“Use the planner subagent to…”). At the plugin’s average of about 90 always-on tokens per entry (41,515 across 454), ten components list for roughly 900 tokens; run /context again to confirm on your setup.
If you want the whole loop with fewer moving parts, the README’s ./install.sh --profile minimal --target claude installs rules, agents, commands and core workflows without the hook runtime. Add hooks later with --modules hooks-runtime --enable-hooks only after you have read them. If you keep the plugin, ECC_DISABLED_HOOKS takes a comma-separated list of hook IDs, and ECC_SESSION_START_CONTEXT=off turns off the SessionStart injection.
What breaks when you run ECC?
Section titled “What breaks when you run ECC?”Everything appears twice. You installed the plugin and then ran ./install.sh --profile full, or you synced into Codex and also added the Codex plugin. Recovery: run claude plugin uninstall ecc@ecc, then run node scripts/ecc.js uninstall --dry-run from the ECC clone, read the list, run it without --dry-run, and reinstall with one method.
The wrong command runs. /code-review, /plan and /security-review are Claude Code built-ins (the review skill, plan mode and the bundled security review). The plugin’s versions are /ecc:code-review, /ecc:plan and the ecc:security-review skill. Manual installs expose short names and a retired /tdd shim that shadow or collide with built-ins. Recovery: use the namespaced forms, and do not copy legacy-command-shims/.
The agent picks the wrong skill. With hundreds of descriptions in context, a generic prompt such as “review this” can trigger a language reviewer for the wrong stack. Recovery: name the skill in the prompt, as the prompts above do, and prune the packs you do not use.
The Stop hook hangs or fails the session. stop:format-typecheck runs your formatter and type checker, with a 300-second timeout, so on a large monorepo every stop can wait minutes for it. Recovery: add its ID to ECC_DISABLED_HOOKS and keep the type check in CI, where it belongs.
Costs go up after you follow the README’s cost advice. ECC’s token-optimization section recommends "model": "sonnet", a MAX_THINKING_TOKENS cap and a Haiku subagent model, and states savings with no source. That runs against how current models are tuned: from v2.1.280 (the latest channel) Claude Code defaults to Claude Opus 5.5 at medium effort. Tune effort with /effort before you switch model, and switch only when your own evals say so. Recovery: remove those settings and follow the models hub.
A look-alike package or repository. Search results surface re-uploads. Recovery: install only from the names in the traps box, and scan your agent configuration with ECC’s AgentShield (agentshield scan --path ., npm ecc-agentshield 1.6.0 on 2026-09-26) or the checks in skill supply-chain security.
When is ECC the wrong choice?
Section titled “When is ECC the wrong choice?”Choose ECC when you want one opinionated harness and are prepared to prune it. Choose something smaller when you need one practice: Superpowers costs about 838 always-on tokens for a complete design-plan-TDD-review loop, and the discipline packs page compares ECC with Matt Pocock’s skills, gstack, agent-skills and Ponytail. For a spec trail that product owners approve, use a spec-driven framework instead.