ECC

ECC

Open-source security and optimization for Claude Code, Codex, Cursor, and OpenCode

70/100Safe BetFree · from $19/seat/month or $190/seat/yearFreemium

ECC is a serious fit for teams running multiple coding agents who want security and consistency without cloud lock-in. The free OSS layer is generous, but $19/seat for Pro makes sense once private repos and automation matter. Beginners may find setup heavy; single-agent users should first evaluate native harness features. No other toolkit we've seen matches its cross-harness governance and continuous learning loop.

Verified 5d ago · liveness 70/100 · cite: rightaichoice.com/tools/ecc

Best for
  • Teams running multiple coding agents who need cross-harness security and policy enforcement
  • Engineering orgs wanting to automate repo workflows via the GitHub App
  • Enterprises requiring governance, SSO, and audit trails for agent usage
  • Devs who want continuous learning from session history to reduce rework
Not ideal for
  • Beginners seeking a simple plug-and-play agent without configuration
  • Users of non-supported harnesses like GitHub Copilot or Amazon Q Developer
  • Teams preferring a fully managed cloud solution with no local setup
Visit Website

AdvancedFor a solo developer: install the CLI via npm (npm i -g ecc-universal) or use the plugin marketplace, then pick a profile (core or developer) — expect 10-15 minutes to first useful output. For a team: adding the GitHub App and configuring Pro on private repos takes about 30 minutes, including setup and a test run. Enterprise rollout with SSO and policy packs may take a few days with dedicatedWeb · CLI · API · PluginAPI availableVerified 5d ago
Pricing
Free · from $19/seat/month or $190/seat/year
FreemiumFree tier3 plans6 hidden costs
Learning curve
Advanced
For a solo developer: install the CLI via npm (npm i -g ecc-universal) or use the plugin marketplace, then pick a profile (core or developer) — expect 10-15 minutes to first useful output. For a team: adding the GitHub App and configuring Pro on private repos takes about 30 minutes, including setup and a test run. Enterprise rollout with SSO and policy packs may take a few days with dedicated
Runs on
WebCLIAPIPlugin
API available · 5 integrations
Who it's for
Developer on a team using Claude Code and CursorEngineering manager in a mid-size org using multiple agentsSecurity lead at an enterprise using Codex and OpenCode
Live sentiment
Is ECC actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip ECC if you use only one coding agent and don't need cross-harness security, or if you rely on harnesses like GitHub Copilot or Amazon Q Developer that ECC doesn't support.

The 30-second take
Biggest gripe

Pro plans are priced at $19 per seat per month, which can add up if you have a large team, though yearly billing saves ~17%.

Price reality

ECC's freemium model fits OSS maintainers and small teams well: Free covers public repos, Pro at $19/seat/month (or $190/yearly) is competitive for private repos and automation, while Enterprise is custom. Compared to fully managed alternatives like Korl or Aider Pro, ECC offers more control and lower entry cost but requires self-hosting.

In short

ECC — Open-source security and optimization for Claude Code, Codex, Cursor, and OpenCode. Best for Teams running multiple coding agents who need cross-harness security and policy enforcement, Engineering orgs wanting to automate repo workflows via the GitHub App, Enterprises requiring governance, SSO, and audit trails for agent usage. Free to start; paid plans from $19190/user/mo.

What's new in ECC

Checked 3 days ago

Across the latest 7 updates: 3 feature updates, 2 launches, 1 pricing change and 1 changelog entry.

Viability Score

70/100
Safe Bet

How well maintained and how widely used is ECC? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this

Recent activity
90
Traction
not measured
Site health
95
User sentiment
15
What the vendor publishes
60

Last calculated: September 2026

How we score →

Key Features

  • 261 OSS skills for coding agents
  • 64 agents and 84 commands for orchestration
  • AgentShield scans every session
  • 102 security rules catch config vulnerabilities
  • Cross-harness support: Claude Code, Codex, Cursor, OpenCode
  • GitHub App turns repo history into reusable skills
  • /ecc-tools analyze generates reviewable PRs
  • ECC 2.0 control plane with session visibility
  • Token optimization and shared policy context
  • Continuous learning from session history
  • Auto-pruning of idle instincts
  • Central skill registry with versioned checksums
  • Opt-in usage insight with consent scopes
  • Local-first control plane for observability
  • Install profiles: core, developer, security, full

About ECC

FreemiumAdvancedAPI availableWeb · CLI · API · Plugin

ECC is an open-source agent harness system that secures and optimizes AI coding agents across Claude Code, Codex, Cursor, and OpenCode. Designed for developers and engineering teams, the MIT-licensed repository ships 261 skills, 64 agents, 84 commands, and install profiles (core, developer, security, full). The AgentShield scanner audits every session with 102 security rules, catching config vulnerabilities and enforcing policy. The GitHub App converts repo history into reusable skills and defaults, making it the fastest path from OSS to a repo-native workflow. The system works in three layers. The distribution layer is the free OSS repo, MIT-licensed and open for anyone to copy. The protection layer is AgentShield, an open-source scanner that audits agent configs locally and can be extended with policy packs. The control-plane layer is ECC 2.0, a local-first operator surface for session visibility, token optimization, and cross-harness orchestration — shipped with the 2.0.0 stable release. ECC's learning loop goes beyond git diffs. It learns from session history — corrections, failure-to-fix sequences, and repeated workflows — turning them into atomic instincts with confidence scoring. Insight extraction is rule-based and inspectable, not a black box. Idle instincts decay on a schedule and auto-prune with reviewable dry-run plans, keeping the system efficient. A central skill registry lets teams publish and update skills without touching git, with versioned checksums and auto-sync across seats. Opt-in usage insight gives teams control over sharing; nothing is shared by default, and sharing never includes code or transcripts. ECC is freemium: the OSS layer and public-repo analysis are free, Pro costs $19 per seat per month (or $190 per seat per year) and unlocks private repos, PR-triggered audits, and automation. Enterprise offers SSO, custom rules, and dedicated support. Compared to simpler alternatives like Aider or Continue, ECC is a heavier,

Behind the Verdict

ECC is not a simple plugin. It's a layered system — OSS repo, AgentShield scanner, and a control plane — that demands a bit of setup. If you're a solo dev using Claude Code casually, the free OSS layer is worth a look, but you might not need Pro. The real value shows when your team runs multiple harnesses — Claude Code for some, Codex for others, Cursor for the rest — and you want one place to enforce policy and learn from every session. We'd reach for ECC when the coordination burden becomes real: private repos, multiple active developers, and a need for audit trails. The GitHub App pricing reflects that: Free covers public repos with 10 analyses per month and 200 commits per run; Pro at $19/seat adds private-repo analysis, PR-triggered audits, and 50 analyses per seat per month, pooled on the installation. Enterprise adds SSO and unlimited analyses. The learning loop is the standout: it captures session history — corrections, error-to-fix sequences — and turns them into instincts you can inspect and prune. That's a feature you won't find in Aider or Continue, which are simpler and more linear. Where it bites: the free tier's commit cap (200 commits per run) might feel tight on large repos. And the setup is not zero-config — you'll need to install profiles, connect the GitHub App, and learn the command syntax. It's also GitHub-centric; if your organization lives on GitLab, you're out of luck. And the $19/seat cost adds up for big teams — though those teams likely need the governance. Compared to alternatives, ECC is more complex but more powerful. Aider offers a chat-driven coding experience with minimal setup, but no cross-harness security or team learning. Continue focuses on IDE integration but doesn't manage multiple harnesses or enforce security rules. ECC

Researching ECC? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas ECC actually fits — and what changes day-one when you adopt it.

Developer on a team using Claude Code and Cursor

You install the GitHub App on your repo, comment /ecc-tools analyze, and review the generated pull request that extracts reusable skills from your history.

Outcome: Within minutes you have a PR with pattern-based defaults, reducing setup time and aligning both agents.

Engineering manager in a mid-size org using multiple agents

You upgrade to Pro, enable PR-triggered config audits and AgentShield scanning, and auto-trigger on large pushes to enforce security policy.

Outcome: Every pull request gets a config audit automatically, catching vulnerabilities before merge and reducing manual review.

Security lead at an enterprise using Codex and OpenCode

You adopt the Enterprise plan with SSO and custom policy packs, and use the control plane to monitor sessions across harnesses.

Outcome: You gain visibility and governance across all agent sessions, with audit logs and policy enforcement, meeting compliance requirements.

Use Cases

  • Scan code repositories for risky configurations using AgentShield before merging PRs.
  • Convert repository history into reusable skills and defaults for your coding agents.
  • Automate PR-triggered config audits across private repos with the GitHub App.
  • Orchestrate multiple coding agents across Claude Code, Codex, Cursor, and OpenCode from a single control plane.
  • Enforce security policies and governance rules on agent sessions across your team.

Limitations

  • The ECC OSS layer stays free, but the free GitHub App tier is limited to public repos and 10 analyses per month, with 200 commits per run.
  • Pro plans cost $19 per seat per month and include private repo analysis, 50 analyses per seat pooled, and 1,000 commits per run, with metered overage available.
  • Enterprise plans offer unlimited analyses and 5,000 commits per run.
  • ECC currently supports only four agent harnesses: Claude Code, Codex, Cursor, and OpenCode.

as of 2026-08-21

Verification history

We have re-verified ECC 7 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.

  1. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  2. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  3. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  4. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  5. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  6. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it

Showing the 6 most recent of 7 verification passes.

Free to cite with attribution — this page re-verifies continuously.

12-month cost

Project the real annual outlay, including the implied monthly cost when only an annual tier is published.

Annual total
Free
Over 12 months
Effective monthly
Free
Billed monthly

Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.

Plans compared

For each published ECC tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.

Free

$0/month

Ideal for

OSS maintainers and evaluators who want to try ECC on public repos with no credit card and no time limit.

What this tier adds

Starts with public repo analysis, 10 analyses per month, 200 commits per run, and core/developer install profiles.

Pro

$19/seat/month or $190/seat/year

Ideal for

Developers and small teams needing private repo analysis, PR-triggered audits, and AgentShield-backed scanning with billing and priority support.

What this tier adds

Adds private repo analysis, 50 analyses per seat pooled, 1,000 commits per run, auto-triggers, and self-serve billing.

Enterprise

Contact sales

Ideal for

Organizations with procurement and governance needs, requiring SSO, audit logs, custom policy packs, and dedicated support.

What this tier adds

Unlimited analyses, 5,000 commits per run, SSO-ready governance, custom rules, and dedicated onboarding with SLA.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • Pro plans are priced at $19 per seat per month, which can add up if you have a large team, though yearly billing saves ~17%.
  • Pro seats are pooled but capped at 50 analyses per seat; exceeding that incurs metered overage charges.
  • The free tier is limited to public repos and 10 analyses per month, so evaluating on private code requires upgrading to Pro.
  • Enterprise features like SSO, audit logs, and custom policy packs are only available on the contact-sales tier.
  • There is no fully managed cloud option, so you must handle local setup and maintenance yourself, which may require engineering time.
  • If you need integrations beyond GitHub and the four harnesses, you may need to build custom adapters, which is not included in any plan.

Where the pricing makes sense

The company stage and team size where ECC's pricing actually pencils out — and where peers do it cheaper.

ECC's freemium model fits OSS maintainers and small teams well: Free covers public repos, Pro at $19/seat/month (or $190/yearly) is competitive for private repos and automation, while Enterprise is custom. Compared to fully managed alternatives like Korl or Aider Pro, ECC offers more control and lower entry cost but requires self-hosting.

Setup time & first value

How long it actually takes to get something useful out of ECC — broken out by persona, not the marketing-page minute.

For a solo developer: install the CLI via npm (npm i -g ecc-universal) or use the plugin marketplace, then pick a profile (core or developer) — expect 10-15 minutes to first useful output. For a team: adding the GitHub App and configuring Pro on private repos takes about 30 minutes, including setup and a test run. Enterprise rollout with SSO and policy packs may take a few days with dedicated

Switching to or from ECC

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • From Korl: If you're using Korl's agent management, you can move by installing ECC OSS and using the GitHub App to analyze repos, then port any custom skills to the central registry.
  • From Continue: Continue's config can be translated into ECC skills by scanning your repo history and converting repeated patterns into instincts.
  • From Aider: Aider users can transition by using ECC's cross-harness support, pointing ECC at the same repo and letting the learning loop capture session patterns.
Migrating out
  • To Aider: Export any custom skills as markdown files and manually recreate them in Aider's command system.
  • To Korl: You can export ECC's learned instincts as JSON and import them into Korl's automation rules, though cross-harness coverage will be lost.
  • To Continue: Convert ECC skills into Continue's config format, and use the session logs to inform your new setup.

Integrations

Resources & Guides

Tutorials & Learning

Tools that pair well with ECC

Common stack mates teams adopt alongside ECC, with the specific reason each pairing earns its keep.

Featured Head-to-Head Comparisons

Alternatives to ECC

View all
Continue

Continue

Pioneering open-source AI coding agent for VS Code and JetBrains, now archived after Cursor acquisition.

FreeTry
Imbue

Imbue

Open AI toolkit for loyal, auditable coding agents.

FreemiumTry
MarsX

MarsX

Open-source dev platform uniting AI, NoCode, Code, and reusable MicroApps.

FreemiumTry

Frequently Asked Questions

Used ECC? Help shape our editorial sentiment research.