AI & Agents AI & Tác Tử ·

Everything Claude Code (ECC): The Agent Harness Operating System for Production Software Engineering Everything Claude Code (ECC): Hệ Điều Hành Agent Harness Cho Kỹ Thuật Phần Mềm Thực Chiến

Architectural deep-dive into Everything Claude Code (ECC): 68 specialized agents, 286 skills, the 7-phase closed engineering loop, AgentShield security auditing, and multi-harness orchestration across Claude Code, Codex, Cursor, and Antigravity. Phân tích kiến trúc Everything Claude Code (ECC): 68 tác tử chuyên biệt, 286 kỹ năng chuẩn hóa, vòng lặp 7 giai đoạn khép kín, lớp bảo mật AgentShield và khả năng điều phối đa nền tảng (Claude Code, Codex, Cursor, Antigravity).

Written by Nguyen Cong Ben Nguyen Cong Ben
Everything Claude Code (ECC): The Agent Harness Operating System for Production Software Engineering

1. 🌟 The Evolution: From Raw Prompts to an Agent Harness OS

The generative AI paradigm for software development has reached an inflection point. While large language models (LLMs) like Claude 3.7 Sonnet, GPT-4.5, and Gemini 2.0 Flash possess exceptional raw reasoning, deploying them directly as unstructured chat interfaces frequently leads to catastrophic drift: hallucinated library imports, forgotten architectural constraints, broken test suites, and unverified diffs.

Everything Claude Code (ECC), created by Affaan Mustafa (affaan-m/ECC), represents a quantum leap in autonomous software engineering. Winner of the Anthropic Hackathon and backed by over 140,000+ GitHub stars, ECC shifts the paradigm from “hoping the model writes good code” to operating an integrated agent engineering harness.

“Your agent can write code, but ECC gives it a coordinated engineering system and toolbox: it plans before it builds, verifies changes with tests, reviews its own work from a fresh context, remembers what matters, and turns repeated wins into reusable skills.”The ECC Core Philosophy

plan ──► test ──► implement ──► review ──► verify ──► remember ──► improve

Rather than crafting ad-hoc prompts for every single bugfix or feature request, ECC installs a permanent engineering operating system inside the agent’s harness.


2. 🏗️ The 6 Architectural Pillars of ECC

ECC organizes autonomous software engineering into six foundational layers:

flowchart TD
    subgraph ECC_Core ["Everything Claude Code (ECC) Ecosystem"]
        Agents["🤖 68 Specialized Agents\n(Architect, Reviewer, Debugger, TDD Lead)"]
        Skills["⚡ 286 Production Skills\n(TDD, Context Eng, Impeccable UI, ADRs)"]
        Rules["📜 Selective Rules Engine\n(rules/common, rules/typescript, rules/go)"]
        Hooks["🪝 Runtime Hooks & Memory\n(Context pruning, session recovery, pre-commit)"]
        Shield["🛡️ AgentShield Security\n(AST analysis, prompt injection & secret audit)"]
        Harnesses["🌐 Multi-Harness Adapters\n(Claude Code, Codex, Cursor, Antigravity)"]
    end

    Agents --> Skills
    Skills --> Rules
    Rules --> Hooks
    Hooks --> Shield
    Shield --> Harnesses
LayerComponent CountPrimary Responsibility
🤖 Specialized Agents68 AgentsAutonomous subagents with isolated context windows dedicated to planning, security review, build repair, database design, and frontend architecture.
⚡ Production Skills286 SkillsStandardized SKILL.md capability packages (compliant with agentskills.io) covering TDD, doubt-driven review, and telemetry.
📜 Rules EngineSelective by StackAlways-loaded project standards (rules/common, rules/typescript, rules/python, rules/rust) that enforce strict conventions.
🪝 Hooks & MemoryReal-time RuntimeLifecycle interceptors for pre-tool execution, context compaction, session memory persistence, and quality gates.
🛡️ AgentShieldAST & Pattern AuditDeep security auditing engine scanning prompts, MCP tools, shell executions, and secret leaks.
🌐 Multi-Harness Core12+ PlatformsNative interoperability for Claude Code (ecc@ecc), Codex, Cursor, Gemini CLI, Zed, Antigravity, and Qwen.

3. 🔄 The 7-Phase Closed Engineering Loop

At the heart of ECC is its Closed Engineering Loop. The framework enforces strict phase gates that prevent an agent from writing implementation code until design intent, test boundaries, and architectural trade-offs are empirically locked:

flowchart LR
    S1["💡 1. Plan\n(Spec & Socratic)"] --> S2["🧪 2. Test\n(Failing TDD)"]
    S2 --> S3["🔨 3. Implement\n(Minimal Code)"]
    S3 --> S4["🔍 4. Review\n(Doubt-Driven)"]
    S4 --> S5["✅ 5. Verify\n(Live Test Suite)"]
    S5 --> S6["🧠 6. Remember\n(Persistent Memory)"]
    S6 --> S7["🚀 7. Improve\n(Skill Evolution)"]

The 7 Lifecycle Stages:

  1. Plan (Spec & Socratic Interview): Through skills like interview-me and spec-driven-development, the agent clarifies ambiguity, exposes edge cases, and drafts a concrete implementation plan.
  2. Test (Strict TDD): The agent creates isolated test cases before touching application logic, observing explicit test failures.
  3. Implement (Radical Simplicity): Implements only the minimal code necessary to pass tests, adhering to KISS, DRY, and YAGNI.
  4. Review (Doubt-Driven Development): Spawns an isolated adversarial reviewer agent with zero prior conversational bias to audit the diff for regressions, race conditions, and security holes.
  5. Verify (Empirical Evidence): Runs full test suites, linting, and build verification. Assumptions are strictly forbidden.
  6. Remember (Context & Knowledge Distillation): Captures key architectural decisions into persistent memory docs and ADRs.
  7. Improve (Skill Genesis): When novel troubleshooting patterns succeed, the agent synthesizes new reusable SKILL.md workflows.

4. 🛡️ AgentShield: Security Hardening for Autonomous Agents

As autonomous agents gain shell execution rights and MCP tool capabilities, prompt injection and supply-chain vulnerabilities pose massive risks. ECC incorporates AgentShield—a specialized static and runtime security engine:

flowchart TD
    Command["Agent Command / MCP Execution Request"] --> Inspector{"🛡️ AgentShield Inspector"}
    
    Inspector -->|Check AST & Regex| Rule1["🚫 Secret Leakage Detection\n(Stripe, AWS, Private Keys)"]
    Inspector -->|Check Blast Radius| Rule2["⚠️ Destructive Command Blocker\n(rm -rf, dd, format, drop table)"]
    Inspector -->|Check MCP Schema| Rule3["🔍 Tool Poisoning / Prompt Injection\n(Hidden XML, Jailbreaks)"]
    
    Rule1 & Rule2 & Rule3 --> Decision{"Policy Evaluation"}
    Decision -->|Pass| Exec["✅ Execute Safely in Sandbox"]
    Decision -->|Fail| Abort["🛑 Terminate Action & Prompt Developer"]

Key Security Safeguards:

  • AST Parsing of Shell Payloads: Prevents obfuscated bash pipelines (base64 -d | sh) from bypassing string filters.
  • Sensitive Key Sanitization: Intercepts stdout/stderr streams to redact environment variables, private keys, and session tokens before logging.
  • Permission Scoping: Limits subagents to designated workspace branches and read-only tool boundaries when performing audits.

5. 🌐 Multi-Harness Orchestration

While ECC originated around Anthropic’s Claude Code, its universal architecture abstracts agent logic across 12+ leading AI developer harnesses:

HarnessIntegration MechanismConfiguration Target
Claude CodeNative Plugin (ecc@ecc) via /plugin~/.claude/ & settings.json
Codex (CLI & App)Native Repo Marketplace Plugin~/.codex/ & config.toml
CursorLocal Project Agent Adapter.cursor/agents/ecc-*.md
Antigravity (Google)Native Customization System.agents/skills/ & Rules Engine
OpenCode / Zed / KimiProject-scoped CLI Adapters.kimi-code/, .zed/, .opencode/

6. ⚡ Context Hierarchy & The “Zero-Bloat” Strategy

One of the biggest failure modes in AI engineering is Context Window Saturation (loading too many rules, docs, and skills simultaneously, diluting model attention). ECC resolves this with a strict 5-Tier Context Hierarchy:

TierContext Category & ScopeLifecycle & Token Budget
Tier 1: Foundation RulesProject rules (CLAUDE.md, rules/common)Always active (< 2% token budget)
Tier 2: Architectural SpecsSpecifications, ADRs, active milestonesLoaded per active feature / session
Tier 3: Core Source CodeTargeted implementation files (atomic slices)Loaded on demand per task
Tier 4: Verification ArtifactsTest runner logs, compiler & linter errorsEphemeral; pruned after iteration
Tier 5: Conversational HistoryTurn-by-turn prompts & tool exchangesCompacted dynamically by runtime hooks

By keeping base rules ultra-lean and activating skills on-demand through keyword indexing, ECC keeps the model’s effective context window razor-sharp.


7. 🚀 Quickstart: Installing ECC

For Claude Code:

Run the official plugin commands inside Claude Code:

/plugin marketplace add https://github.com/affaan-m/ECC
/plugin install ecc@ecc

For Universal Package Setup (npm/npx):

npx ecc-universal setup

For Multi-Harness Guided Setup:

npx ecc-universal install --guided

8. 💡 Key Takeaways for AI-Native Engineers

  1. Discipline Over Token Volume: An agent with a structured 7-phase lifecycle outperforms an unconstrained model running 10x more reasoning tokens.
  2. Context is Finite: Treat the context window as a precious L1 cache. Keep persistent rules under 100 lines and load deep skills dynamically.
  3. Adversarial Verification is Essential: Self-verification in the same context fails due to confirmation bias. Spawning a fresh subagent with a skeptical prompt catches 80%+ of subtle logic bugs before merge.

1. 🌟 Sự Tiến Hóa: Từ Chatbot Đến Hệ Điều Hành Agent Harness

Kỷ nguyên ứng dụng AI trong kỹ thuật phần mềm đang bước vào một bước ngoặt mang tính cách mạng. Dù các mô hình ngôn ngữ lớn (LLM) như Claude 3.7 Sonnet, GPT-4.5 hay Gemini 2.0 Flash sở hữu năng lực suy luận vượt trội, việc sử dụng chúng qua các giao diện chat thông thường thường dẫn đến những lỗi nghiêm trọng: trôi dạt kiến trúc, tự bịa thư viện không tồn tại, phá vỡ bộ test sẵn có và sinh mã nguồn thiếu kiểm chứng.

Everything Claude Code (ECC), được sáng lập bởi Affaan Mustafa (affaan-m/ECC), là một bước đột phá lớn trong lập trình tác tử (Agentic Coding). Đạt giải Quán quân Anthropic Hackathon và thu hút hơn 140.000+ ngôi sao trên GitHub, ECC chuyển dịch tư duy từ việc “hy vọng AI viết code chuẩn” sang vận hành một hệ thống kỹ thuật phần mềm chuẩn chỉ bên trong harness của tác tử.

“Agent của bạn có thể viết code, nhưng ECC cung cấp cho nó một hệ thống kỹ thuật và hộp công cụ phối hợp nhịp nhàng: lập kế hoạch trước khi xây dựng, kiểm chứng thay đổi bằng test, tự review lại công việc từ một ngữ cảnh tươi mới, ghi nhớ những điều cốt lõi và biến các bài học thành kỹ năng tái sử dụng.”Triết lý cốt lõi của ECC

plan ──► test ──► implement ──► review ──► verify ──► remember ──► improve

Thay vì phải viết đi viết lại những prompt dài dòng cho từng bugfix hay tính năng mới, ECC cài đặt sẵn một hệ điều hành kỹ thuật phần mềm thường trực cho AI agent của bạn.


2. 🏗️ 6 Trụ Cột Kiến Trúc Của ECC

ECC tổ chức toàn bộ quy trình phát triển phần mềm tự trị thành 6 tầng kiến trúc chặt chẽ:

flowchart TD
    subgraph ECC_Core ["Hệ Sinh Thái Everything Claude Code (ECC)"]
        Agents["🤖 68 Tác Tử Chuyên Biệt\n(Architect, Reviewer, Debugger, TDD Lead)"]
        Skills["⚡ 286 Kỹ Năng Chuẩn Hóa\n(TDD, Context Eng, Impeccable UI, ADRs)"]
        Rules["📜 Bộ Quy Tắc Chọn Lọc\n(rules/common, rules/typescript, rules/go)"]
        Hooks["🪝 Runtime Hooks & Bộ Nhớ\n(Nén ngữ cảnh, lưu phiên làm việc, pre-commit)"]
        Shield["🛡️ Lớp Bảo Mật AgentShield\n(Phân tích AST, chống prompt injection & lộ secret)"]
        Harnesses["🌐 Lớp Điều Phối Đa Nền Tảng\n(Claude Code, Codex, Cursor, Antigravity)"]
    end

    Agents --> Skills
    Skills --> Rules
    Rules --> Hooks
    Hooks --> Shield
    Shield --> Harnesses
Tầng Kiến TrúcQuy MôVai Trò & Cơ Chế Hoạt Động
🤖 Tác Tử Chuyên Biệt (Agents)68 AgentsCác subagent độc lập với context window riêng biệt, chuyên trách về lập kế hoạch, kiểm toán bảo mật, sửa lỗi build, thiết kế database và kiến trúc frontend.
⚡ Kỹ Năng Thực Chiến (Skills)286 SkillsCác gói kỹ năng chuẩn hóa theo định dạng SKILL.md (chuẩn agentskills.io) bao gồm TDD, review phản biện và đo lường hệ thống.
📜 Bộ Quy Tắc (Rules Engine)Chọn lọc theo StackCác tiêu chuẩn dự án luôn được tải sẵn (rules/common, rules/typescript, rules/python, rules/rust) nhằm đảm bảo kỷ luật mã nguồn.
🪝 Runtime Hooks & Bộ NhớThời gian thựcCác hook can thiệp vào vòng đời thực thi: nén context, lưu vết phiên làm việc và thiết lập cổng kiểm soát chất lượng pre-commit.
🛡️ AgentShieldPhân tích AST & MẫuĐộng cơ bảo mật chuyên sâu quét sạch các nguy cơ prompt injection, lệnh phá hoại và lộ lọt token bí mật.
🌐 Điều Phối Đa Nền Tảng12+ Môi trườngHỗ trợ tương thích bản địa trên Claude Code (ecc@ecc), Codex, Cursor, Gemini CLI, Zed, Antigravity và Qwen.

3. 🔄 Vòng Lặp Kỹ Thuật Khép Kín 7 Giai Đoạn

Trọng tâm sức mạnh của ECC nằm ở Vòng Lặp Kỹ Thuật Khép Kín (Closed Engineering Loop). Quy trình này nghiêm cấm agent viết code ứng dụng khi chưa làm rõ ý đồ thiết kế và khóa chặt các ca kiểm thử:

flowchart LR
    S1["💡 1. Lập Kế Hoạch\n(Spec & Socratic)"] --> S2["🧪 2. Viết Test\n(Strict TDD Fail)"]
    S2 --> S3["🔨 3. Viết Mã\n(Mã tối giản)"]
    S3 --> S4["🔍 4. Phản Biện\n(Doubt-Driven)"]
    S4 --> S5["✅ 5. Xác Minh\n(Chạy toàn bộ Test)"]
    S5 --> S6["🧠 6. Ghi Nhớ\n(Lưu trữ Bộ nhớ)"]
    S6 --> S7["🚀 7. Tiến Hóa\n(Tự Sinh Kỹ Năng)"]

7 Giai đoạn chi tiết:

  1. Lập kế hoạch (Socratic Interview & Spec): Thông qua các kỹ năng như interview-mespec-driven-development, agent liên tục đặt câu hỏi làm rõ các ca biên và viết tài liệu đặc tả kỹ thuật chi tiết.
  2. Viết test trước (Strict TDD): Tạo các test case cô lập trước khi can thiệp vào mã nguồn logic và chứng kiến test thất bại (Red phase).
  3. Viết mã tối giản (Radical Simplicity): Chỉ viết lượng mã vừa đủ để vượt qua bộ test, tuân thủ nghiêm ngặt nguyên lý KISS, DRY và YAGNI.
  4. Phản biện đa chiều (Doubt-Driven Development): Khởi tạo một subagent độc lập hoàn toàn mới với tâm thế nghi ngờ để rà soát toàn bộ diff, tìm kiếm lỗi race condition, bảo mật hoặc hồi quy logic.
  5. Xác minh thực nghiệm (Empirical Evidence): Chạy test suite, linter và build. Mọi giả định “chắc là chạy được” đều bị loại bỏ.
  6. Ghi nhớ kiến trúc (Context & Knowledge Distillation): Ghi lại các quyết định thiết kế quan trọng vào tài liệu ADR và bộ nhớ dài hạn.
  7. Tiến hóa kỹ năng (Skill Genesis): Khi giải quyết thành công một vấn đề kỹ thuật mới, agent tự động đúc kết thành file SKILL.md để tái sử dụng trong tương lai.

4. 🛡️ AgentShield: Lá Chắn Bảo Mật Cho Kỹ Thuật Tác Tử

Khi AI agent được cấp quyền thực thi lệnh Shell và gọi các công cụ MCP, nguy cơ bị tấn công qua Prompt Injection hoặc mã độc chuỗi cung ứng là cực kỳ lớn. ECC trang bị lớp bảo mật AgentShield:

flowchart TD
    Command["Yêu cầu chạy Shell / Gọi công cụ MCP"] --> Inspector{"🛡️ Bộ Kiểm Tra AgentShield"}
    
    Inspector -->|Quét AST & Regex| Rule1["🚫 Phát hiện Lộ Lọt Secret\n(Stripe, AWS, Private Keys)"]
    Inspector -->|Đánh giá Tầm ảnh hưởng| Rule2["⚠️ Chặn Lệnh Phá Hoại\n(rm -rf, dd, format, drop table)"]
    Inspector -->|Quét Schema MCP| Rule3["🔍 Chống Đầu Độc Tool / Prompt Injection\n(XML ẩn, Payload bẻ khóa)"]
    
    Rule1 & Rule2 & Rule3 --> Decision{"Đánh Giá Chính Sách"}
    Decision -->|Hợp lệ| Exec["✅ Thực Thi An Toàn Trong Sandbox"]
    Decision -->|Vi phạm| Abort["🛑 Hủy Thao Tác & Cảnh Báo Cho Developer"]

Các tính năng bảo vệ nổi bật:

  • Phân tích cú pháp AST của dòng lệnh: Ngăn chặn các đoạn mã bash bị mã hóa (base64 -d | sh) luồn lách qua các bộ lọc từ khóa đơn giản.
  • Tự động làm sạch dữ liệu nhạy cảm: Chặn và làm mờ các token, khóa API, biến môi trường trong luồng stdout/stderr trước khi lưu vào log.
  • Giới hạn phạm vi quyền hạn: Khóa subagent kiểm thử trong các workspace phân nhánh cô lập (worktrees) và giới hạn quyền chỉ đọc khi thực hiện audit.

5. 🌐 Điều Phối Đa Nền Tảng (Multi-Harness)

Dù khởi nguồn từ Claude Code của Anthropic, kiến trúc mở của ECC cho phép nó hoạt động trơn tru trên 12+ môi trường phát triển AI hàng đầu hiện nay:

Môi trườngCơ Chế Tích HợpThư Mục Cấu Hình
Claude CodePlugin bản địa (ecc@ecc) qua lệnh /plugin~/.claude/ & settings.json
Codex (CLI & App)Plugin Native Repo Marketplace~/.codex/ & config.toml
CursorBộ chuyển đổi Agent cục bộ theo dự án.cursor/agents/ecc-*.md
Antigravity (Google)Hệ thống Tùy biến Tác tử Bản địa.agents/skills/ & Rules Engine
OpenCode / Zed / KimiBộ điều phối CLI theo dự án.kimi-code/, .zed/, .opencode/

6. ⚡ Phân Cấp Ngữ Cảnh & Chiến Lược “Zero-Bloat”

Một trong những nguyên nhân khiến AI lập trình kém hiệu quả là Quá tải cửa sổ ngữ cảnh (Context Bloating)—khi nạp quá nhiều quy tắc và tài liệu cùng lúc làm loãng sự tập trung của mô hình. ECC giải quyết triệt để bằng Mô hình phân cấp ngữ cảnh 5 tầng:

Tầng Phân CấpDanh Mục & Phạm Vi Ngữ CảnhVòng Đời & Ngân Sách Token
Tầng 1: Quy Tắc Nền TảngTiêu chuẩn dự án (CLAUDE.md, rules/common)Luôn nạp sẵn (< 2% dung lượng token)
Tầng 2: Tài Liệu Đặc TảTài liệu Spec, ADR, kiến trúc tính năngNạp theo từng tính năng đang xử lý
Tầng 3: Mã Nguồn Trọng TâmCác file code triển khai trực tiếp (atomic slices)Nạp chính xác theo từng task nhỏ
Tầng 4: Nhật Ký Kiểm ThửKết quả test suite, thông báo lỗi compiler/linterDữ liệu tạm; tự động dọn dẹp sau vòng lặp
Tầng 5: Lịch Sử Hội ThoạiLịch sử trao đổi và kết quả gọi công cụTự động nén và tóm tắt bởi runtime hooks

Bằng cách giữ các quy tắc nền tảng dưới 100 dòng và chỉ kích hoạt các kỹ năng chuyên sâu khi có yêu cầu, ECC đảm bảo agent luôn duy trì độ sắc bén tối đa.


7. 🚀 Hướng Dẫn Cài Đặt Nhanh ECC

Dành cho Claude Code:

Chạy 2 lệnh plugin chính thức ngay trong Claude Code:

/plugin marketplace add https://github.com/affaan-m/ECC
/plugin install ecc@ecc

Cài đặt toàn diện qua npm/npx:

npx ecc-universal setup

Cài đặt đa nền tảng có hướng dẫn (Multi-Harness):

npx ecc-universal install --guided

8. 💡 Bài Học Thực Chiến Cho Kỹ Sư AI-Native

  1. Kỷ luật quan trọng hơn số lượng Token: Một agent được trang bị quy trình kỹ thuật 7 giai đoạn khép kín luôn tạo ra sản phẩm chất lượng hơn một mô hình “thả rông” tiêu tốn gấp 10 lần token suy luận.
  2. Ngữ cảnh là tài nguyên hữu hạn: Hãy xem context window như bộ nhớ đệm L1 Cache. Giữ quy tắc cốt lõi ngắn gọn và nạp kỹ năng động theo ngữ cảnh.
  3. Luôn kiểm tra chéo bằng tác tử phản biện (Adversarial Review): Tác tử tự kiểm tra code của chính mình trong cùng một context rất dễ bị thiên kiến xác nhận (confirmation bias). Việc spawn một subagent hoàn toàn mới với tâm thế nghi ngờ sẽ bắt được hơn 80% các lỗi logic tiềm ẩn trước khi tạo PR.