Skip to content

Commit bf10629

Browse files
committed
Merge remote-tracking branch 'origin/main' into HEAD
2 parents 12ea937 + 74ffba6 commit bf10629

246 files changed

Lines changed: 22959 additions & 2160 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.agents/plugins/marketplace.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@
66
"plugins": [
77
{
88
"name": "ecc",
9-
"version": "2.1.0",
9+
"version": "2.2.0",
1010
"source": {
1111
"source": "local",
12-
"path": "./plugins/ecc"
12+
"path": "./"
1313
},
1414
"policy": {
1515
"installation": "AVAILABLE",

‎.agents/skills/plan-canvas/SKILL.md‎

Lines changed: 50 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -46,12 +46,31 @@ Codex — or just run the `ecc-plan-canvas` commands directly.
4646
# 1. Open the artifact in the user's browser (returns immediately)
4747
ecc-plan-canvas open .claude/plans/feature.plan.md
4848

49-
# 2. Block until the human responds. Leave running; re-run if interrupted —
50-
# queued feedback is never lost. Run in the background if your harness
51-
# time-limits foreground commands.
49+
# 2. Block until the human responds. Leave running; re-run if interrupted:
50+
# queued feedback is never lost.
5251
ecc-plan-canvas await .claude/plans/feature.plan.md
5352
```
5453

54+
### Stay listening, or the human talks to an empty chair
55+
56+
Feedback only reaches you while an `await` is actually parked on the session.
57+
If your turn ends with nothing listening, the message sits in the queue and,
58+
from the human's side of the glass, sending appears to do nothing at all.
59+
60+
So **run `await` as a background task** when your harness supports one (in
61+
Claude Code, a Bash call with `run_in_background: true`). It exits the moment
62+
feedback arrives and the harness hands you the JSON, which keeps the loop alive
63+
across turns instead of dying with the foreground call. A foreground `await`
64+
works too, but only until the harness time-limits it.
65+
66+
Two backstops exist, and neither is an excuse to skip the above:
67+
68+
- `ecc-plan-canvas pending` lists feedback queued with no listener. Check it
69+
whenever you are unsure whether you missed something.
70+
- The `stop:plan-canvas-pending` hook blocks your turn from ending while canvas
71+
feedback is undelivered, and hands you the messages. If you are reading
72+
feedback from that hook, you stopped listening too early.
73+
5574
`await` prints JSON when the human acts:
5675

5776
```json
@@ -73,12 +92,31 @@ ecc-plan-canvas await .claude/plans/feature.plan.md
7392
end the session, and start implementing. `request-changes` means revise the
7493
artifact (the canvas live-reloads it) and keep the loop going.
7594

76-
**3. Respond in the canvas**, then keep listening — one command does both:
95+
**3. Always respond in the canvas**, then keep listening. One command does both:
7796

7897
```bash
79-
ecc-plan-canvas await <file> --reply "Split Phase 2 as requested — take a look."
98+
ecc-plan-canvas await <file> --reply "Split Phase 2 as requested. Take a look."
8099
```
81100

101+
Every human message gets a reply in the canvas, even a one-liner like
102+
"On it, rewriting the risk table now." Silence in the chat panel is
103+
indistinguishable from a broken canvas, which is exactly the failure this loop
104+
exists to prevent. Answer there, not only in the terminal.
105+
106+
While you work, keep the chat honest with the activity indicator:
107+
108+
```bash
109+
# animated "agent is thinking..." bubble; refresh it during long work
110+
ecc-plan-canvas typing <file> --state thinking
111+
# switch to "agent is typing..." just before a reply lands
112+
ecc-plan-canvas typing <file> --state typing
113+
```
114+
115+
`await` sets `thinking` for you the moment it hands you a batch, and `--reply`
116+
clears it. Both states self-expire, so a crashed agent decays to an honest
117+
"queued" instead of leaving the human watching dots forever. Refresh `thinking`
118+
if a revision takes more than a minute.
119+
82120
**4. End** when review concludes: `ecc-plan-canvas end <file>`.
83121

84122
## Diagrams (Mermaid)
@@ -143,8 +181,13 @@ ecc-plan-canvas await <file> --reply "Reworked the risk table."
143181

144182
## Anti-Patterns
145183

146-
- Polling with `--timeout-ms` in a loop — it exists for tests. Leave the
147-
plain `await` running instead.
184+
- Polling with `--timeout-ms` in a loop. It exists for tests. Leave the plain
185+
`await` running instead.
186+
- Ending your turn with no `await` listening while the review is still open.
187+
That is the one failure the human experiences as "I sent a message and
188+
nothing happened".
189+
- Reading the feedback but answering only in the terminal. The human is looking
190+
at the canvas.
148191
- Reopening after a user-initiated end "just to show" something.
149192
- Pasting the whole plan into chat *and* opening a canvas — pick the canvas
150193
and keep the terminal summary to one line.

‎.claude-plugin/marketplace.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@
1111
{
1212
"name": "ecc",
1313
"source": "./",
14-
"description": "Harness-native ECC operator layer - 67 agents, 281 skills, 94 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses",
15-
"version": "2.1.0",
14+
"description": "Harness-native ECC operator layer - 68 agents, 286 skills, 94 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses",
15+
"version": "2.2.0",
1616
"author": {
1717
"name": "Affaan Mustafa",
1818
"email": "me@affaanmustafa.com"

‎.claude-plugin/plugin.json‎

Lines changed: 16 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"name": "ecc",
3-
"version": "2.1.0",
4-
"description": "Harness-native ECC plugin for engineering teams - 67 agents, 281 skills, 94 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses",
3+
"version": "2.2.0",
4+
"description": "Harness-native ECC plugin for engineering teams - 68 agents, 286 skills, 94 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses",
55
"author": {
66
"name": "Affaan Mustafa",
77
"url": "https://x.com/affaanmustafa"
@@ -22,6 +22,20 @@
2222
"automation",
2323
"best-practices"
2424
],
25+
"userConfig": {
26+
"hooks_enabled": {
27+
"type": "boolean",
28+
"title": "Enable ECC hooks",
29+
"description": "Run ECC's local lifecycle, quality, and safety automation. Disable this to keep skills and commands without local hook automation.",
30+
"default": true
31+
},
32+
"hook_profile": {
33+
"type": "string",
34+
"title": "ECC hook profile",
35+
"description": "Choose minimal, standard, or strict. Invalid values safely fall back to standard.",
36+
"default": "standard"
37+
}
38+
},
2539
"mcpServers": {},
2640
"skills": [
2741
"./skills/"

‎.codex-plugin/README.md‎

Lines changed: 62 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -8,35 +8,83 @@ This directory contains the **Codex plugin manifest** for ECC.
88
.codex-plugin/
99
└── plugin.json — Codex plugin manifest (name, version, skills ref, MCP ref)
1010
.mcp.json — MCP server configurations at plugin root (NOT inside .codex-plugin/)
11+
hooks/codex-hooks.json — Codex-compatible lifecycle hook projection
1112
```
1213

1314
## What This Provides
1415

15-
- **249 skills** from `./skills/` — reusable Codex workflows for TDD, security,
16+
- **281 skills** from `./skills/` — reusable Codex workflows for TDD, security,
1617
code review, architecture, and more
17-
- **6 MCP servers** — GitHub, Context7, Exa, Memory, Playwright, Sequential Thinking
18+
- **1 default MCP server** — Chrome DevTools; retired connectors remain opt-in
19+
- **Codex lifecycle hooks** — synchronous command hooks on supported events,
20+
with explicit review and trust in `/hooks`
1821

1922
## Installation
2023

21-
Codex plugin support is marketplace-backed. The repo exposes a repo-scoped
22-
marketplace at `.agents/plugins/marketplace.json`; Codex can add and track that
23-
marketplace source from the CLI:
24+
Codex 0.146.0 and newer use `plugin add`, not `plugin install`. Add ECC's
25+
repository marketplace, install the native plugin, and verify the registration:
2426

2527
```bash
26-
# Add the public repo marketplace
2728
codex plugin marketplace add affaan-m/ECC
29+
codex plugin add ecc@ecc
30+
codex plugin list --json
31+
```
32+
33+
Both add commands are safe to run again. A repeated marketplace add reports
34+
`alreadyAdded: true`, and a repeated plugin add keeps the same enabled plugin
35+
registration. To fetch a newer marketplace snapshot before applying a new ECC
36+
release, run:
37+
38+
```bash
39+
codex plugin marketplace upgrade ecc
40+
codex plugin add ecc@ecc
41+
```
42+
43+
For local development, the same native journey accepts a checkout path:
2844

29-
# Or add a local checkout while developing
45+
```bash
3046
codex plugin marketplace add /absolute/path/to/ECC
47+
codex plugin add ecc@ecc
3148
```
3249

33-
The marketplace entry points at `plugins/ecc/` — Codex does not discover
34-
plugins whose local marketplace `source.path` is the marketplace root (`./`),
35-
so the entry must target a concrete plugin subdirectory (see
36-
[#2128](https://github.com/affaan-m/ECC/issues/2128)). That thin plugin folder
37-
references the root `skills/` and `.mcp.json` so content stays single-sourced.
38-
After adding or updating the marketplace, restart Codex and install or enable
39-
`ecc` from the plugin directory.
50+
ECC's marketplace entry points at the repository root. Codex copies the selected
51+
plugin source into its cache, so the root source keeps `skills/`, `.mcp.json`,
52+
`hooks/`, hook scripts, and presentation assets together. Parent-relative paths
53+
from a thin plugin directory would escape that cache and produce an installed
54+
registration with missing runtime content.
55+
56+
Restart Codex after installation. You can also open `/plugins` in Codex CLI to
57+
inspect, enable, disable, or remove the plugin. The native Codex plugin does not
58+
use Claude's `user`, `project`, or `local` install scopes: its enabled state is
59+
stored once in the active `CODEX_HOME` (normally `~/.codex`) and applies to
60+
Codex sessions using that home.
61+
62+
## Hooks and reconfiguration
63+
64+
The Codex manifest uses the documented `hooks` field to bundle
65+
`./hooks/codex-hooks.json`. This provider-specific projection keeps the
66+
synchronous `SessionStart` bootstrap verified against Codex 0.146. Claude hook
67+
profiles are not Codex hook profiles: handlers that block tools, use unsupported
68+
events, run asynchronously, or fail Codex's hook protocol stay out of the native
69+
bundle. Codex enables hook support by default, but native plugin installation
70+
does not silently authorize commands. Start a new Codex session, open `/hooks`,
71+
then review and trust the ECC hook definition before enabling it.
72+
Codex records trust against each definition's hash, so changed hooks require
73+
review again. Use `/plugins` for plugin enablement and `/hooks` for hook trust;
74+
these are separate controls.
75+
76+
Once the cached skills are available, invoke `$configure-ecc` inside Codex for
77+
ECC's guided configuration. Installing the plugin again is idempotent and does
78+
not create a second scope or duplicate hook registration.
79+
80+
## Native plugin versus legacy managed sync
81+
82+
The commands above are the native Codex plugin path. The legacy managed sync
83+
(`bash scripts/sync-ecc-to-codex.sh`) is a separate compatibility
84+
path that merges files into `~/.codex`. It is not a native plugin install and
85+
does not create a marketplace registration. Prefer the native path on current
86+
Codex; use the legacy managed sync only when you intentionally need its copied
87+
configuration layer.
4088

4189
After install, `codex plugin list` is only a registration check. From an ECC
4290
checkout, run the cache check to verify that the installed manifest can resolve
@@ -46,22 +94,6 @@ its referenced skills, MCP config, and assets:
4694
node scripts/codex/check-plugin-cache.js
4795
```
4896

49-
> **Plugin mode is currently fragile on Codex.** Marketplace discovery and
50-
> install work with this layout, but runtime skill loading from local/repo
51-
> marketplaces is unreliable upstream
52-
> ([openai/codex#26037](https://github.com/openai/codex/issues/26037)) — Codex
53-
> copies only the plugin folder into its install cache, so parent-referenced
54-
> content may not be exposed in a fresh session. The safer, fully supported
55-
> path today is the manual sync flow:
56-
> `npm install && bash scripts/sync-ecc-to-codex.sh`.
57-
58-
Official Plugin Directory publishing is coming soon. For official OpenAI
59-
plugin-directory review, package this repo under the `openai/plugins`
60-
repository shape: `plugins/ecc/.codex-plugin/plugin.json`,
61-
`plugins/ecc/skills/`, and the supporting README/assets. Until that listing is
62-
accepted, treat the public repo marketplace as the supported Codex distribution
63-
path and keep release copy framed as repo-marketplace/manual installation.
64-
6597
The installed plugin registers under the short slug `ecc` so tool and command names
6698
stay below provider length limits.
6799

‎.codex-plugin/plugin.json‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "ecc",
3-
"version": "2.1.0",
3+
"version": "2.2.0",
44
"description": "Harness-native ECC workflows for Codex: shared skills, production-ready MCP configs, and selective-install-aligned conventions for TDD, security scanning, code review, and autonomous development.",
55
"author": {
66
"name": "Affaan Mustafa",
@@ -13,9 +13,10 @@
1313
"keywords": ["codex", "agents", "skills", "tdd", "code-review", "security", "workflow", "automation"],
1414
"skills": "./skills/",
1515
"mcpServers": "./.mcp.json",
16+
"hooks": "./hooks/codex-hooks.json",
1617
"interface": {
1718
"displayName": "ECC",
18-
"shortDescription": "249 ECC skills plus MCP configs for TDD, security, code review, and autonomous development.",
19+
"shortDescription": "281 ECC skills plus MCP configs for TDD, security, code review, and autonomous development.",
1920
"longDescription": "ECC is a harness-native operator system for Codex and adjacent agent harnesses. It packages reusable skills, MCP configs, TDD workflows, security scanning, code review, architecture decisions, operator workflows, and release gates in one installable plugin.",
2021
"developerName": "Affaan Mustafa",
2122
"category": "Coding",

‎.github/ISSUE_TEMPLATE/config.yml‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
blank_issues_enabled: true
2+
contact_links:
3+
- name: ECC questions and setup help
4+
url: https://github.com/affaan-m/ECC/discussions/categories/q-a
5+
about: Ask a public question or get help from the community.
6+
- name: Private security report
7+
url: https://github.com/affaan-m/ECC/security/advisories/new
8+
about: Report vulnerabilities privately. Do not put secrets in a public issue.
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
name: Feature idea
2+
description: Describe the outcome you need and your current workaround.
3+
title: "[Idea] "
4+
labels:
5+
- enhancement
6+
- needs-triage
7+
body:
8+
- type: markdown
9+
attributes:
10+
value: |
11+
This is a public GitHub issue. Do not include secrets, prompts, customer data, private repository details, or unredacted paths.
12+
- type: textarea
13+
id: outcome
14+
attributes:
15+
label: What outcome do you need?
16+
description: Describe the job to be done, not an implementation if you do not have one in mind.
17+
validations:
18+
required: true
19+
- type: textarea
20+
id: workaround
21+
attributes:
22+
label: What do you do today?
23+
description: Optional. A workaround helps us understand urgency and scope.
24+
- type: dropdown
25+
id: harness
26+
attributes:
27+
label: Which harness is affected?
28+
options:
29+
- All harnesses
30+
- Claude Code
31+
- Codex
32+
- Cursor
33+
- OpenCode
34+
- GitHub Copilot
35+
- Another harness
36+
- type: textarea
37+
id: success
38+
attributes:
39+
label: What would success look like?
40+
description: Optional acceptance criteria or a small example.

0 commit comments

Comments
 (0)