mirror of
https://github.com/affaan-m/ECC.git
synced 2026-08-17 21:15:40 +02:00
The `.opencode/commands/*.md` frontmatter referenced agents with the Claude Code plugin namespace (`agent: everything-claude-code:<name>`), but ECC's opencode integration registers its agents unscoped in `opencode.json`'s `agent` map (`code-reviewer`, `planner`, ...), and that file's own `command` section already references them unscoped. The `everything-claude-code:` scope resolves under no opencode config (the opencode plugin package is `ecc-universal`, and inline-config agents are bare), so subtask commands like `/code-review` hard-fail with `Agent not found: everything-claude-code:code-reviewer`. Non-subtask commands fall back to the default agent and appear to work — which is why only some commands failed. Strip the `everything-claude-code:` prefix from all 30 command frontmatter agent ids so they match the registered agents, fix the MIGRATION.md example, and replace the test that enforced the broken scoped invariant with one that asserts each command agent id is a registered opencode agent (fails on the old scoped ids, passes on the fix). Fixes #2477
2.0 KiB
2.0 KiB
description, agent, subtask
| description | agent | subtask |
|---|---|---|
| Run comprehensive security review | security-reviewer | true |
Security Review Command
Conduct a comprehensive security review: $ARGUMENTS
Your Task
Analyze the specified code for security vulnerabilities following OWASP guidelines and security best practices.
Security Checklist
OWASP Top 10
-
Injection (SQL, NoSQL, OS command, LDAP)
- Check for parameterized queries
- Verify input sanitization
- Review dynamic query construction
-
Broken Authentication
- Password storage (bcrypt, argon2)
- Session management
- Multi-factor authentication
- Password reset flows
-
Sensitive Data Exposure
- Encryption at rest and in transit
- Proper key management
- PII handling
-
XML External Entities (XXE)
- Disable DTD processing
- Input validation for XML
-
Broken Access Control
- Authorization checks on every endpoint
- Role-based access control
- Resource ownership validation
-
Security Misconfiguration
- Default credentials removed
- Error handling doesn't leak info
- Security headers configured
-
Cross-Site Scripting (XSS)
- Output encoding
- Content Security Policy
- Input sanitization
-
Insecure Deserialization
- Validate serialized data
- Implement integrity checks
-
Using Components with Known Vulnerabilities
- Run
npm audit - Check for outdated dependencies
- Run
-
Insufficient Logging & Monitoring
- Security events logged
- No sensitive data in logs
- Alerting configured
Additional Checks
- Secrets in code (API keys, passwords)
- Environment variable handling
- CORS configuration
- Rate limiting
- CSRF protection
- Secure cookie flags
Report Format
Critical Issues
[Issues that must be fixed immediately]
High Priority
[Issues that should be fixed before release]
Recommendations
[Security improvements to consider]
IMPORTANT: Security issues are blockers. Do not proceed until critical issues are resolved.