Everything Claude Code (ECC): The Agent Harness Operating System for Production Software Engineering Everything Claude Code (ECC): Hệ Điều Hành Agent Harness Cho Kỹ Thuật Phần Mềm Thực Chiến
Architectural deep-dive into Everything Claude Code (ECC): 68 specialized agents, 286 skills, the 7-phase closed engineering loop, AgentShield security auditing, and multi-harness orchestration across Claude Code, Codex, Cursor, and Antigravity. Phân tích kiến trúc Everything Claude Code (ECC): 68 tác tử chuyên biệt, 286 kỹ năng chuẩn hóa, vòng lặp 7 giai đoạn khép kín, lớp bảo mật AgentShield và khả năng điều phối đa nền tảng (Claude Code, Codex, Cursor, Antigravity).
1. 🌟 The Evolution: From Raw Prompts to an Agent Harness OS
The generative AI paradigm for software development has reached an inflection point. While large language models (LLMs) like Claude 3.7 Sonnet, GPT-4.5, and Gemini 2.0 Flash possess exceptional raw reasoning, deploying them directly as unstructured chat interfaces frequently leads to catastrophic drift: hallucinated library imports, forgotten architectural constraints, broken test suites, and unverified diffs.
Everything Claude Code (ECC), created by Affaan Mustafa (affaan-m/ECC), represents a quantum leap in autonomous software engineering. Winner of the Anthropic Hackathon and backed by over 140,000+ GitHub stars, ECC shifts the paradigm from “hoping the model writes good code” to operating an integrated agent engineering harness.
“Your agent can write code, but ECC gives it a coordinated engineering system and toolbox: it plans before it builds, verifies changes with tests, reviews its own work from a fresh context, remembers what matters, and turns repeated wins into reusable skills.” — The ECC Core Philosophy
plan──►test──►implement──►review──►verify──►remember──►improve
Rather than crafting ad-hoc prompts for every single bugfix or feature request, ECC installs a permanent engineering operating system inside the agent’s harness.
2. 🏗️ The 6 Architectural Pillars of ECC
ECC organizes autonomous software engineering into six foundational layers:
flowchart TD
subgraph ECC_Core ["Everything Claude Code (ECC) Ecosystem"]
Agents["🤖 68 Specialized Agents\n(Architect, Reviewer, Debugger, TDD Lead)"]
Skills["⚡ 286 Production Skills\n(TDD, Context Eng, Impeccable UI, ADRs)"]
Rules["📜 Selective Rules Engine\n(rules/common, rules/typescript, rules/go)"]
Hooks["🪝 Runtime Hooks & Memory\n(Context pruning, session recovery, pre-commit)"]
Shield["🛡️ AgentShield Security\n(AST analysis, prompt injection & secret audit)"]
Harnesses["🌐 Multi-Harness Adapters\n(Claude Code, Codex, Cursor, Antigravity)"]
end
Agents --> Skills
Skills --> Rules
Rules --> Hooks
Hooks --> Shield
Shield --> Harnesses
| Layer | Component Count | Primary Responsibility |
|---|---|---|
| 🤖 Specialized Agents | 68 Agents | Autonomous subagents with isolated context windows dedicated to planning, security review, build repair, database design, and frontend architecture. |
| ⚡ Production Skills | 286 Skills | Standardized SKILL.md capability packages (compliant with agentskills.io) covering TDD, doubt-driven review, and telemetry. |
| 📜 Rules Engine | Selective by Stack | Always-loaded project standards (rules/common, rules/typescript, rules/python, rules/rust) that enforce strict conventions. |
| 🪝 Hooks & Memory | Real-time Runtime | Lifecycle interceptors for pre-tool execution, context compaction, session memory persistence, and quality gates. |
| 🛡️ AgentShield | AST & Pattern Audit | Deep security auditing engine scanning prompts, MCP tools, shell executions, and secret leaks. |
| 🌐 Multi-Harness Core | 12+ Platforms | Native interoperability for Claude Code (ecc@ecc), Codex, Cursor, Gemini CLI, Zed, Antigravity, and Qwen. |
3. 🔄 The 7-Phase Closed Engineering Loop
At the heart of ECC is its Closed Engineering Loop. The framework enforces strict phase gates that prevent an agent from writing implementation code until design intent, test boundaries, and architectural trade-offs are empirically locked:
flowchart LR
S1["💡 1. Plan\n(Spec & Socratic)"] --> S2["🧪 2. Test\n(Failing TDD)"]
S2 --> S3["🔨 3. Implement\n(Minimal Code)"]
S3 --> S4["🔍 4. Review\n(Doubt-Driven)"]
S4 --> S5["✅ 5. Verify\n(Live Test Suite)"]
S5 --> S6["🧠 6. Remember\n(Persistent Memory)"]
S6 --> S7["🚀 7. Improve\n(Skill Evolution)"]
The 7 Lifecycle Stages:
- Plan (Spec & Socratic Interview): Through skills like
interview-meandspec-driven-development, the agent clarifies ambiguity, exposes edge cases, and drafts a concrete implementation plan. - Test (Strict TDD): The agent creates isolated test cases before touching application logic, observing explicit test failures.
- Implement (Radical Simplicity): Implements only the minimal code necessary to pass tests, adhering to KISS, DRY, and YAGNI.
- Review (Doubt-Driven Development): Spawns an isolated adversarial reviewer agent with zero prior conversational bias to audit the diff for regressions, race conditions, and security holes.
- Verify (Empirical Evidence): Runs full test suites, linting, and build verification. Assumptions are strictly forbidden.
- Remember (Context & Knowledge Distillation): Captures key architectural decisions into persistent memory docs and ADRs.
- Improve (Skill Genesis): When novel troubleshooting patterns succeed, the agent synthesizes new reusable
SKILL.mdworkflows.
4. 🛡️ AgentShield: Security Hardening for Autonomous Agents
As autonomous agents gain shell execution rights and MCP tool capabilities, prompt injection and supply-chain vulnerabilities pose massive risks. ECC incorporates AgentShield—a specialized static and runtime security engine:
flowchart TD
Command["Agent Command / MCP Execution Request"] --> Inspector{"🛡️ AgentShield Inspector"}
Inspector -->|Check AST & Regex| Rule1["🚫 Secret Leakage Detection\n(Stripe, AWS, Private Keys)"]
Inspector -->|Check Blast Radius| Rule2["⚠️ Destructive Command Blocker\n(rm -rf, dd, format, drop table)"]
Inspector -->|Check MCP Schema| Rule3["🔍 Tool Poisoning / Prompt Injection\n(Hidden XML, Jailbreaks)"]
Rule1 & Rule2 & Rule3 --> Decision{"Policy Evaluation"}
Decision -->|Pass| Exec["✅ Execute Safely in Sandbox"]
Decision -->|Fail| Abort["🛑 Terminate Action & Prompt Developer"]
Key Security Safeguards:
- AST Parsing of Shell Payloads: Prevents obfuscated bash pipelines (
base64 -d | sh) from bypassing string filters. - Sensitive Key Sanitization: Intercepts stdout/stderr streams to redact environment variables, private keys, and session tokens before logging.
- Permission Scoping: Limits subagents to designated workspace branches and read-only tool boundaries when performing audits.
5. 🌐 Multi-Harness Orchestration
While ECC originated around Anthropic’s Claude Code, its universal architecture abstracts agent logic across 12+ leading AI developer harnesses:
| Harness | Integration Mechanism | Configuration Target |
|---|---|---|
| Claude Code | Native Plugin (ecc@ecc) via /plugin | ~/.claude/ & settings.json |
| Codex (CLI & App) | Native Repo Marketplace Plugin | ~/.codex/ & config.toml |
| Cursor | Local Project Agent Adapter | .cursor/agents/ecc-*.md |
| Antigravity (Google) | Native Customization System | .agents/skills/ & Rules Engine |
| OpenCode / Zed / Kimi | Project-scoped CLI Adapters | .kimi-code/, .zed/, .opencode/ |
6. ⚡ Context Hierarchy & The “Zero-Bloat” Strategy
One of the biggest failure modes in AI engineering is Context Window Saturation (loading too many rules, docs, and skills simultaneously, diluting model attention). ECC resolves this with a strict 5-Tier Context Hierarchy:
| Tier | Context Category & Scope | Lifecycle & Token Budget |
|---|---|---|
| Tier 1: Foundation Rules | Project rules (CLAUDE.md, rules/common) | Always active (< 2% token budget) |
| Tier 2: Architectural Specs | Specifications, ADRs, active milestones | Loaded per active feature / session |
| Tier 3: Core Source Code | Targeted implementation files (atomic slices) | Loaded on demand per task |
| Tier 4: Verification Artifacts | Test runner logs, compiler & linter errors | Ephemeral; pruned after iteration |
| Tier 5: Conversational History | Turn-by-turn prompts & tool exchanges | Compacted dynamically by runtime hooks |
By keeping base rules ultra-lean and activating skills on-demand through keyword indexing, ECC keeps the model’s effective context window razor-sharp.
7. 🚀 Quickstart: Installing ECC
For Claude Code:
Run the official plugin commands inside Claude Code:
/plugin marketplace add https://github.com/affaan-m/ECC
/plugin install ecc@ecc
For Universal Package Setup (npm/npx):
npx ecc-universal setup
For Multi-Harness Guided Setup:
npx ecc-universal install --guided
8. 💡 Key Takeaways for AI-Native Engineers
- Discipline Over Token Volume: An agent with a structured 7-phase lifecycle outperforms an unconstrained model running 10x more reasoning tokens.
- Context is Finite: Treat the context window as a precious L1 cache. Keep persistent rules under 100 lines and load deep skills dynamically.
- Adversarial Verification is Essential: Self-verification in the same context fails due to confirmation bias. Spawning a fresh subagent with a skeptical prompt catches 80%+ of subtle logic bugs before merge.
1. 🌟 Sự Tiến Hóa: Từ Chatbot Đến Hệ Điều Hành Agent Harness
Kỷ nguyên ứng dụng AI trong kỹ thuật phần mềm đang bước vào một bước ngoặt mang tính cách mạng. Dù các mô hình ngôn ngữ lớn (LLM) như Claude 3.7 Sonnet, GPT-4.5 hay Gemini 2.0 Flash sở hữu năng lực suy luận vượt trội, việc sử dụng chúng qua các giao diện chat thông thường thường dẫn đến những lỗi nghiêm trọng: trôi dạt kiến trúc, tự bịa thư viện không tồn tại, phá vỡ bộ test sẵn có và sinh mã nguồn thiếu kiểm chứng.
Everything Claude Code (ECC), được sáng lập bởi Affaan Mustafa (affaan-m/ECC), là một bước đột phá lớn trong lập trình tác tử (Agentic Coding). Đạt giải Quán quân Anthropic Hackathon và thu hút hơn 140.000+ ngôi sao trên GitHub, ECC chuyển dịch tư duy từ việc “hy vọng AI viết code chuẩn” sang vận hành một hệ thống kỹ thuật phần mềm chuẩn chỉ bên trong harness của tác tử.
“Agent của bạn có thể viết code, nhưng ECC cung cấp cho nó một hệ thống kỹ thuật và hộp công cụ phối hợp nhịp nhàng: lập kế hoạch trước khi xây dựng, kiểm chứng thay đổi bằng test, tự review lại công việc từ một ngữ cảnh tươi mới, ghi nhớ những điều cốt lõi và biến các bài học thành kỹ năng tái sử dụng.” — Triết lý cốt lõi của ECC
plan──►test──►implement──►review──►verify──►remember──►improve
Thay vì phải viết đi viết lại những prompt dài dòng cho từng bugfix hay tính năng mới, ECC cài đặt sẵn một hệ điều hành kỹ thuật phần mềm thường trực cho AI agent của bạn.
2. 🏗️ 6 Trụ Cột Kiến Trúc Của ECC
ECC tổ chức toàn bộ quy trình phát triển phần mềm tự trị thành 6 tầng kiến trúc chặt chẽ:
flowchart TD
subgraph ECC_Core ["Hệ Sinh Thái Everything Claude Code (ECC)"]
Agents["🤖 68 Tác Tử Chuyên Biệt\n(Architect, Reviewer, Debugger, TDD Lead)"]
Skills["⚡ 286 Kỹ Năng Chuẩn Hóa\n(TDD, Context Eng, Impeccable UI, ADRs)"]
Rules["📜 Bộ Quy Tắc Chọn Lọc\n(rules/common, rules/typescript, rules/go)"]
Hooks["🪝 Runtime Hooks & Bộ Nhớ\n(Nén ngữ cảnh, lưu phiên làm việc, pre-commit)"]
Shield["🛡️ Lớp Bảo Mật AgentShield\n(Phân tích AST, chống prompt injection & lộ secret)"]
Harnesses["🌐 Lớp Điều Phối Đa Nền Tảng\n(Claude Code, Codex, Cursor, Antigravity)"]
end
Agents --> Skills
Skills --> Rules
Rules --> Hooks
Hooks --> Shield
Shield --> Harnesses
| Tầng Kiến Trúc | Quy Mô | Vai Trò & Cơ Chế Hoạt Động |
|---|---|---|
| 🤖 Tác Tử Chuyên Biệt (Agents) | 68 Agents | Các subagent độc lập với context window riêng biệt, chuyên trách về lập kế hoạch, kiểm toán bảo mật, sửa lỗi build, thiết kế database và kiến trúc frontend. |
| ⚡ Kỹ Năng Thực Chiến (Skills) | 286 Skills | Các gói kỹ năng chuẩn hóa theo định dạng SKILL.md (chuẩn agentskills.io) bao gồm TDD, review phản biện và đo lường hệ thống. |
| 📜 Bộ Quy Tắc (Rules Engine) | Chọn lọc theo Stack | Các tiêu chuẩn dự án luôn được tải sẵn (rules/common, rules/typescript, rules/python, rules/rust) nhằm đảm bảo kỷ luật mã nguồn. |
| 🪝 Runtime Hooks & Bộ Nhớ | Thời gian thực | Các hook can thiệp vào vòng đời thực thi: nén context, lưu vết phiên làm việc và thiết lập cổng kiểm soát chất lượng pre-commit. |
| 🛡️ AgentShield | Phân tích AST & Mẫu | Động cơ bảo mật chuyên sâu quét sạch các nguy cơ prompt injection, lệnh phá hoại và lộ lọt token bí mật. |
| 🌐 Điều Phối Đa Nền Tảng | 12+ Môi trường | Hỗ trợ tương thích bản địa trên Claude Code (ecc@ecc), Codex, Cursor, Gemini CLI, Zed, Antigravity và Qwen. |
3. 🔄 Vòng Lặp Kỹ Thuật Khép Kín 7 Giai Đoạn
Trọng tâm sức mạnh của ECC nằm ở Vòng Lặp Kỹ Thuật Khép Kín (Closed Engineering Loop). Quy trình này nghiêm cấm agent viết code ứng dụng khi chưa làm rõ ý đồ thiết kế và khóa chặt các ca kiểm thử:
flowchart LR
S1["💡 1. Lập Kế Hoạch\n(Spec & Socratic)"] --> S2["🧪 2. Viết Test\n(Strict TDD Fail)"]
S2 --> S3["🔨 3. Viết Mã\n(Mã tối giản)"]
S3 --> S4["🔍 4. Phản Biện\n(Doubt-Driven)"]
S4 --> S5["✅ 5. Xác Minh\n(Chạy toàn bộ Test)"]
S5 --> S6["🧠 6. Ghi Nhớ\n(Lưu trữ Bộ nhớ)"]
S6 --> S7["🚀 7. Tiến Hóa\n(Tự Sinh Kỹ Năng)"]
7 Giai đoạn chi tiết:
- Lập kế hoạch (Socratic Interview & Spec): Thông qua các kỹ năng như
interview-mevàspec-driven-development, agent liên tục đặt câu hỏi làm rõ các ca biên và viết tài liệu đặc tả kỹ thuật chi tiết. - Viết test trước (Strict TDD): Tạo các test case cô lập trước khi can thiệp vào mã nguồn logic và chứng kiến test thất bại (Red phase).
- Viết mã tối giản (Radical Simplicity): Chỉ viết lượng mã vừa đủ để vượt qua bộ test, tuân thủ nghiêm ngặt nguyên lý KISS, DRY và YAGNI.
- Phản biện đa chiều (Doubt-Driven Development): Khởi tạo một subagent độc lập hoàn toàn mới với tâm thế nghi ngờ để rà soát toàn bộ diff, tìm kiếm lỗi race condition, bảo mật hoặc hồi quy logic.
- Xác minh thực nghiệm (Empirical Evidence): Chạy test suite, linter và build. Mọi giả định “chắc là chạy được” đều bị loại bỏ.
- Ghi nhớ kiến trúc (Context & Knowledge Distillation): Ghi lại các quyết định thiết kế quan trọng vào tài liệu ADR và bộ nhớ dài hạn.
- Tiến hóa kỹ năng (Skill Genesis): Khi giải quyết thành công một vấn đề kỹ thuật mới, agent tự động đúc kết thành file
SKILL.mdđể tái sử dụng trong tương lai.
4. 🛡️ AgentShield: Lá Chắn Bảo Mật Cho Kỹ Thuật Tác Tử
Khi AI agent được cấp quyền thực thi lệnh Shell và gọi các công cụ MCP, nguy cơ bị tấn công qua Prompt Injection hoặc mã độc chuỗi cung ứng là cực kỳ lớn. ECC trang bị lớp bảo mật AgentShield:
flowchart TD
Command["Yêu cầu chạy Shell / Gọi công cụ MCP"] --> Inspector{"🛡️ Bộ Kiểm Tra AgentShield"}
Inspector -->|Quét AST & Regex| Rule1["🚫 Phát hiện Lộ Lọt Secret\n(Stripe, AWS, Private Keys)"]
Inspector -->|Đánh giá Tầm ảnh hưởng| Rule2["⚠️ Chặn Lệnh Phá Hoại\n(rm -rf, dd, format, drop table)"]
Inspector -->|Quét Schema MCP| Rule3["🔍 Chống Đầu Độc Tool / Prompt Injection\n(XML ẩn, Payload bẻ khóa)"]
Rule1 & Rule2 & Rule3 --> Decision{"Đánh Giá Chính Sách"}
Decision -->|Hợp lệ| Exec["✅ Thực Thi An Toàn Trong Sandbox"]
Decision -->|Vi phạm| Abort["🛑 Hủy Thao Tác & Cảnh Báo Cho Developer"]
Các tính năng bảo vệ nổi bật:
- Phân tích cú pháp AST của dòng lệnh: Ngăn chặn các đoạn mã bash bị mã hóa (
base64 -d | sh) luồn lách qua các bộ lọc từ khóa đơn giản. - Tự động làm sạch dữ liệu nhạy cảm: Chặn và làm mờ các token, khóa API, biến môi trường trong luồng stdout/stderr trước khi lưu vào log.
- Giới hạn phạm vi quyền hạn: Khóa subagent kiểm thử trong các workspace phân nhánh cô lập (worktrees) và giới hạn quyền chỉ đọc khi thực hiện audit.
5. 🌐 Điều Phối Đa Nền Tảng (Multi-Harness)
Dù khởi nguồn từ Claude Code của Anthropic, kiến trúc mở của ECC cho phép nó hoạt động trơn tru trên 12+ môi trường phát triển AI hàng đầu hiện nay:
| Môi trường | Cơ Chế Tích Hợp | Thư Mục Cấu Hình |
|---|---|---|
| Claude Code | Plugin bản địa (ecc@ecc) qua lệnh /plugin | ~/.claude/ & settings.json |
| Codex (CLI & App) | Plugin Native Repo Marketplace | ~/.codex/ & config.toml |
| Cursor | Bộ chuyển đổi Agent cục bộ theo dự án | .cursor/agents/ecc-*.md |
| Antigravity (Google) | Hệ thống Tùy biến Tác tử Bản địa | .agents/skills/ & Rules Engine |
| OpenCode / Zed / Kimi | Bộ điều phối CLI theo dự án | .kimi-code/, .zed/, .opencode/ |
6. ⚡ Phân Cấp Ngữ Cảnh & Chiến Lược “Zero-Bloat”
Một trong những nguyên nhân khiến AI lập trình kém hiệu quả là Quá tải cửa sổ ngữ cảnh (Context Bloating)—khi nạp quá nhiều quy tắc và tài liệu cùng lúc làm loãng sự tập trung của mô hình. ECC giải quyết triệt để bằng Mô hình phân cấp ngữ cảnh 5 tầng:
| Tầng Phân Cấp | Danh Mục & Phạm Vi Ngữ Cảnh | Vòng Đời & Ngân Sách Token |
|---|---|---|
| Tầng 1: Quy Tắc Nền Tảng | Tiêu chuẩn dự án (CLAUDE.md, rules/common) | Luôn nạp sẵn (< 2% dung lượng token) |
| Tầng 2: Tài Liệu Đặc Tả | Tài liệu Spec, ADR, kiến trúc tính năng | Nạp theo từng tính năng đang xử lý |
| Tầng 3: Mã Nguồn Trọng Tâm | Các file code triển khai trực tiếp (atomic slices) | Nạp chính xác theo từng task nhỏ |
| Tầng 4: Nhật Ký Kiểm Thử | Kết quả test suite, thông báo lỗi compiler/linter | Dữ liệu tạm; tự động dọn dẹp sau vòng lặp |
| Tầng 5: Lịch Sử Hội Thoại | Lịch sử trao đổi và kết quả gọi công cụ | Tự động nén và tóm tắt bởi runtime hooks |
Bằng cách giữ các quy tắc nền tảng dưới 100 dòng và chỉ kích hoạt các kỹ năng chuyên sâu khi có yêu cầu, ECC đảm bảo agent luôn duy trì độ sắc bén tối đa.
7. 🚀 Hướng Dẫn Cài Đặt Nhanh ECC
Dành cho Claude Code:
Chạy 2 lệnh plugin chính thức ngay trong Claude Code:
/plugin marketplace add https://github.com/affaan-m/ECC
/plugin install ecc@ecc
Cài đặt toàn diện qua npm/npx:
npx ecc-universal setup
Cài đặt đa nền tảng có hướng dẫn (Multi-Harness):
npx ecc-universal install --guided
8. 💡 Bài Học Thực Chiến Cho Kỹ Sư AI-Native
- Kỷ luật quan trọng hơn số lượng Token: Một agent được trang bị quy trình kỹ thuật 7 giai đoạn khép kín luôn tạo ra sản phẩm chất lượng hơn một mô hình “thả rông” tiêu tốn gấp 10 lần token suy luận.
- Ngữ cảnh là tài nguyên hữu hạn: Hãy xem context window như bộ nhớ đệm L1 Cache. Giữ quy tắc cốt lõi ngắn gọn và nạp kỹ năng động theo ngữ cảnh.
- Luôn kiểm tra chéo bằng tác tử phản biện (Adversarial Review): Tác tử tự kiểm tra code của chính mình trong cùng một context rất dễ bị thiên kiến xác nhận (confirmation bias). Việc spawn một subagent hoàn toàn mới với tâm thế nghi ngờ sẽ bắt được hơn 80% các lỗi logic tiềm ẩn trước khi tạo PR.