ECC
Open-source security and optimization for Claude Code, Codex, Cursor, and OpenCode
ECC is a serious fit for teams running multiple coding agents who want security and consistency without cloud lock-in. The free OSS layer is generous, but $19/seat for Pro makes sense once private repos and automation matter. Beginners may find setup heavy; single-agent users should first evaluate native harness features. No other toolkit we've seen matches its cross-harness governance and continuous learning loop.
Verified 5d ago · liveness 70/100 · cite: rightaichoice.com/tools/ecc
- Teams running multiple coding agents who need cross-harness security and policy enforcement
- Engineering orgs wanting to automate repo workflows via the GitHub App
- Enterprises requiring governance, SSO, and audit trails for agent usage
- Devs who want continuous learning from session history to reduce rework
- Beginners seeking a simple plug-and-play agent without configuration
- Users of non-supported harnesses like GitHub Copilot or Amazon Q Developer
- Teams preferring a fully managed cloud solution with no local setup
We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.
- Honest verdict, not marketing
- Real pros & cons from real users
- Attributed quotes with receipts
3 free scans · no card needed
Skip ECC if you use only one coding agent and don't need cross-harness security, or if you rely on harnesses like GitHub Copilot or Amazon Q Developer that ECC doesn't support.
Pro plans are priced at $19 per seat per month, which can add up if you have a large team, though yearly billing saves ~17%.
ECC's freemium model fits OSS maintainers and small teams well: Free covers public repos, Pro at $19/seat/month (or $190/yearly) is competitive for private repos and automation, while Enterprise is custom. Compared to fully managed alternatives like Korl or Aider Pro, ECC offers more control and lower entry cost but requires self-hosting.
In short
ECC — Open-source security and optimization for Claude Code, Codex, Cursor, and OpenCode. Best for Teams running multiple coding agents who need cross-harness security and policy enforcement, Engineering orgs wanting to automate repo workflows via the GitHub App, Enterprises requiring governance, SSO, and audit trails for agent usage. Free to start; paid plans from $19190/user/mo.
What's new in ECC
Checked 3 days agoAcross the latest 7 updates: 3 feature updates, 2 launches, 1 pricing change and 1 changelog entry.
Continuous learning, team skill sync, and opt-in usage insight
Session-history learning adds confidence-scored instincts; auto-pruning with dry-run plan. Team skill registry syncs versions at session start. Opt-in telemetry with explicit consent scopes.
Cross-harness and catalog visibility
Selective install profiles and OSS paths clarified for Claude Code, Codex, Cursor, and OpenCode. Verified packaging routes across repo, npm, Marketplace Action, and app paths.
AgentShield cross-harness story clarified
AgentShield remains additive to cross-harness portability, integrated with the ECC 2.0 control plane.
Discord community launch
ECC launches a Discord community for users and contributors.
ECC 2.0.0 stable release
ECC 2.0.0 stable ships with 261 skills, orch-* orchestrator family, control-pane substrate, session adapters, MCP inventory, and worktree-lifecycle service.
GitHub App pricing aligned to commercialization plan
Public repos stay free; Pro uses active-seat billing, pooled usage, and metered overage. Checkout and onboarding aligned for teams and enterprises.
Website repositioned around the full ECC system
Landing, pricing, security, and platforms copy now reflect the real ECC stack. Community proof shows current stars, contributors, npm usage, sponsors, and sourced discussions.
Viability Score
How well maintained and how widely used is ECC? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this
Last calculated: September 2026
How we score →Key Features
- 261 OSS skills for coding agents
- 64 agents and 84 commands for orchestration
- AgentShield scans every session
- 102 security rules catch config vulnerabilities
- Cross-harness support: Claude Code, Codex, Cursor, OpenCode
- GitHub App turns repo history into reusable skills
- /ecc-tools analyze generates reviewable PRs
- ECC 2.0 control plane with session visibility
- Token optimization and shared policy context
- Continuous learning from session history
- Auto-pruning of idle instincts
- Central skill registry with versioned checksums
- Opt-in usage insight with consent scopes
- Local-first control plane for observability
- Install profiles: core, developer, security, full
About ECC
ECC is an open-source agent harness system that secures and optimizes AI coding agents across Claude Code, Codex, Cursor, and OpenCode. Designed for developers and engineering teams, the MIT-licensed repository ships 261 skills, 64 agents, 84 commands, and install profiles (core, developer, security, full). The AgentShield scanner audits every session with 102 security rules, catching config vulnerabilities and enforcing policy. The GitHub App converts repo history into reusable skills and defaults, making it the fastest path from OSS to a repo-native workflow. The system works in three layers. The distribution layer is the free OSS repo, MIT-licensed and open for anyone to copy. The protection layer is AgentShield, an open-source scanner that audits agent configs locally and can be extended with policy packs. The control-plane layer is ECC 2.0, a local-first operator surface for session visibility, token optimization, and cross-harness orchestration — shipped with the 2.0.0 stable release. ECC's learning loop goes beyond git diffs. It learns from session history — corrections, failure-to-fix sequences, and repeated workflows — turning them into atomic instincts with confidence scoring. Insight extraction is rule-based and inspectable, not a black box. Idle instincts decay on a schedule and auto-prune with reviewable dry-run plans, keeping the system efficient. A central skill registry lets teams publish and update skills without touching git, with versioned checksums and auto-sync across seats. Opt-in usage insight gives teams control over sharing; nothing is shared by default, and sharing never includes code or transcripts. ECC is freemium: the OSS layer and public-repo analysis are free, Pro costs $19 per seat per month (or $190 per seat per year) and unlocks private repos, PR-triggered audits, and automation. Enterprise offers SSO, custom rules, and dedicated support. Compared to simpler alternatives like Aider or Continue, ECC is a heavier,
Behind the Verdict
ECC is not a simple plugin. It's a layered system — OSS repo, AgentShield scanner, and a control plane — that demands a bit of setup. If you're a solo dev using Claude Code casually, the free OSS layer is worth a look, but you might not need Pro. The real value shows when your team runs multiple harnesses — Claude Code for some, Codex for others, Cursor for the rest — and you want one place to enforce policy and learn from every session. We'd reach for ECC when the coordination burden becomes real: private repos, multiple active developers, and a need for audit trails. The GitHub App pricing reflects that: Free covers public repos with 10 analyses per month and 200 commits per run; Pro at $19/seat adds private-repo analysis, PR-triggered audits, and 50 analyses per seat per month, pooled on the installation. Enterprise adds SSO and unlimited analyses. The learning loop is the standout: it captures session history — corrections, error-to-fix sequences — and turns them into instincts you can inspect and prune. That's a feature you won't find in Aider or Continue, which are simpler and more linear. Where it bites: the free tier's commit cap (200 commits per run) might feel tight on large repos. And the setup is not zero-config — you'll need to install profiles, connect the GitHub App, and learn the command syntax. It's also GitHub-centric; if your organization lives on GitLab, you're out of luck. And the $19/seat cost adds up for big teams — though those teams likely need the governance. Compared to alternatives, ECC is more complex but more powerful. Aider offers a chat-driven coding experience with minimal setup, but no cross-harness security or team learning. Continue focuses on IDE integration but doesn't manage multiple harnesses or enforce security rules. ECC
Researching ECC? Get your full AI stack in 60 seconds.
Free, no signup — tell us your goal and get tools matched to your budget & existing stack.
Real-world workflow fit
Concrete scenarios for the personas ECC actually fits — and what changes day-one when you adopt it.
You install the GitHub App on your repo, comment /ecc-tools analyze, and review the generated pull request that extracts reusable skills from your history.
Outcome: Within minutes you have a PR with pattern-based defaults, reducing setup time and aligning both agents.
You upgrade to Pro, enable PR-triggered config audits and AgentShield scanning, and auto-trigger on large pushes to enforce security policy.
Outcome: Every pull request gets a config audit automatically, catching vulnerabilities before merge and reducing manual review.
You adopt the Enterprise plan with SSO and custom policy packs, and use the control plane to monitor sessions across harnesses.
Outcome: You gain visibility and governance across all agent sessions, with audit logs and policy enforcement, meeting compliance requirements.
Use Cases
- Scan code repositories for risky configurations using AgentShield before merging PRs.
- Convert repository history into reusable skills and defaults for your coding agents.
- Automate PR-triggered config audits across private repos with the GitHub App.
- Orchestrate multiple coding agents across Claude Code, Codex, Cursor, and OpenCode from a single control plane.
- Enforce security policies and governance rules on agent sessions across your team.
Limitations
- The ECC OSS layer stays free, but the free GitHub App tier is limited to public repos and 10 analyses per month, with 200 commits per run.
- Pro plans cost $19 per seat per month and include private repo analysis, 50 analyses per seat pooled, and 1,000 commits per run, with metered overage available.
- Enterprise plans offer unlimited analyses and 5,000 commits per run.
- ECC currently supports only four agent harnesses: Claude Code, Codex, Cursor, and OpenCode.
as of 2026-08-21
Verification history
We have re-verified ECC 7 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
- — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
Showing the 6 most recent of 7 verification passes.
Free to cite with attribution — this page re-verifies continuously.
12-month cost
Project the real annual outlay, including the implied monthly cost when only an annual tier is published.
Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.
Plans compared
For each published ECC tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.
Free
$0/month
Ideal for
OSS maintainers and evaluators who want to try ECC on public repos with no credit card and no time limit.
What this tier adds
Starts with public repo analysis, 10 analyses per month, 200 commits per run, and core/developer install profiles.
Pro
$19/seat/month or $190/seat/year
Ideal for
Developers and small teams needing private repo analysis, PR-triggered audits, and AgentShield-backed scanning with billing and priority support.
What this tier adds
Adds private repo analysis, 50 analyses per seat pooled, 1,000 commits per run, auto-triggers, and self-serve billing.
Enterprise
Contact sales
Ideal for
Organizations with procurement and governance needs, requiring SSO, audit logs, custom policy packs, and dedicated support.
What this tier adds
Unlimited analyses, 5,000 commits per run, SSO-ready governance, custom rules, and dedicated onboarding with SLA.
Where the pricing makes sense
The company stage and team size where ECC's pricing actually pencils out — and where peers do it cheaper.
ECC's freemium model fits OSS maintainers and small teams well: Free covers public repos, Pro at $19/seat/month (or $190/yearly) is competitive for private repos and automation, while Enterprise is custom. Compared to fully managed alternatives like Korl or Aider Pro, ECC offers more control and lower entry cost but requires self-hosting.
Setup time & first value
How long it actually takes to get something useful out of ECC — broken out by persona, not the marketing-page minute.
For a solo developer: install the CLI via npm (npm i -g ecc-universal) or use the plugin marketplace, then pick a profile (core or developer) — expect 10-15 minutes to first useful output. For a team: adding the GitHub App and configuring Pro on private repos takes about 30 minutes, including setup and a test run. Enterprise rollout with SSO and policy packs may take a few days with dedicated
Switching to or from ECC
How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.
- →From Korl: If you're using Korl's agent management, you can move by installing ECC OSS and using the GitHub App to analyze repos, then port any custom skills to the central registry.
- →From Continue: Continue's config can be translated into ECC skills by scanning your repo history and converting repeated patterns into instincts.
- →From Aider: Aider users can transition by using ECC's cross-harness support, pointing ECC at the same repo and letting the learning loop capture session patterns.
- ↗To Aider: Export any custom skills as markdown files and manually recreate them in Aider's command system.
- ↗To Korl: You can export ECC's learned instincts as JSON and import them into Korl's automation rules, though cross-harness coverage will be lost.
- ↗To Continue: Convert ECC skills into Continue's config format, and use the session logs to inform your new setup.
Integrations
Resources & Guides
Tutorials & Learning
Official links
Tools that pair well with ECC
Common stack mates teams adopt alongside ECC, with the specific reason each pairing earns its keep.
Featured Head-to-Head Comparisons
Ecc vs Presto Voice
Presto Voice and ECC serve entirely different domains – drive-thru automation vs. development agent orchestration. Choose Presto Voice if you run a QSR chain and need proven voice AI to boost revenue and efficiency. Pick ECC if you're a developer or team using Claude Code, Codex, Cursor, or OpenCode and want to govern, optimize, and secure your agent workflows with an open, extensible system.
Ecc vs Locus Robotics
Locus Robotics and ECC serve completely different domains—warehouse automation vs. developer tooling. Choose Locus if you need proven AMRs to boost fulfillment productivity by 2-3x; choose ECC if you orchestrate coding agents and need cross-harness security/skills. No overlap in use cases.
Ecc vs Truleo
Truleo and ECC serve completely different domains—law enforcement intelligence vs. developer agent orchestration. Choose Truleo if you run a police department needing to connect siloed data and automate report writing (40→7 min). Choose ECC if you manage coding agents across Claude Code, Codex, Cursor, or OpenCode and want security, skills, and governance. No overlap in audience or use case.
Alternatives to ECC
View allFrequently Asked Questions
Best-of guides
Used ECC? Help shape our editorial sentiment research.


