mirror of
https://github.com/affaan-m/ECC.git
synced 2026-08-17 21:15:40 +02:00
* feat(workflows): re-land orch-review workflow + add /orch-review command Re-lands #2363 (reverted by #2393 to unbreak main's lint) and fixes the root cause so it stays green: - Restore workflows/orch-review.workflow.js + workflows/README.md. - eslint.config.js: ignore 'workflows/**/*.workflow.*' and '.claude/workflows/**' per the maintainer's note in #2393. Workflow DSL scripts use both top-level export (ESM) and top-level return (the runtime wraps them in an async fn), which no single eslint sourceType can parse — they must be excluded, not lint-fixed. 'npx eslint .' is green with this ignore. - Add commands/orch-review.md (the /orch-review surface) + regenerate docs/COMMAND-REGISTRY.json. Supersedes #2397 (command-only), which referenced the reverted workflow. * fix(workflows): address orch-review bot review findings - Verifier uncertainty no longer demotes blockers (Greptile P1 + CodeRabbit): isReal=false only refutes when confidence >= 0.8; low-confidence 'false' is treated as uncertain and kept blocking (fail closed). - Treat the diff (and finding text) as untrusted input in both review and verify prompts; ignore embedded directives (prompt-injection hardening). - Validate changedFiles entries are strings, not just that it is an array. - Enforce proof for HIGH/CRITICAL in FINDINGS_SCHEMA, not only in the prompt. - Remove in-place mutation in dimension build + dedup merge (immutable). - /orch-review: extract & validate a numeric PR id before shelling out to gh. - Docs: complete the stats example, soften wording, refresh follow-up list. * style(workflows): apply formatter to orch-review assembly * fix(plan-orchestrate): detect ecc@ecc marketplace + emit ecc: agent prefix (#2316) (#2409) * fix(plan-orchestrate): detect ecc@ecc marketplace + emit ecc: agent prefix (#2316) Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(ci): resync lockfiles with package.json (eslint 10) + migrate yarn.lock to Yarn 4 format package.json requires eslint@^10.6.0 but the committed locks pinned 9.39.2, so npm ci aborted and Yarn 4 hardened mode rejected the stale v1-classic yarn.lock (YN0028). Regenerate package-lock.json and rewrite yarn.lock in Yarn 4 (berry) format so npm ci and immutable yarn installs both pass. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(ci): require clean probe exit for Windows shell/bash detection; add pyyaml dev dep Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: affaan <affaan@itomarkets.com> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) (#2410) * fix(ci): resync lockfiles with package.json (eslint 10) + migrate yarn.lock to Yarn 4 format package.json requires eslint@^10.6.0 but the committed locks pinned 9.39.2, so npm ci aborted and Yarn 4 hardened mode rejected the stale v1-classic yarn.lock (YN0028). Regenerate package-lock.json and rewrite yarn.lock in Yarn 4 (berry) format so npm ci and immutable yarn installs both pass. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(ci): require clean probe exit for Windows shell/bash detection; add pyyaml dev dep Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * refactor: consolidate duplicated hook-root resolver into shared resolveEccRoot() (#2368) The inline node -e resolver blob was duplicated ~60x across hooks.json, command docs, and translations. Each copy inlined the full ~700-char plugin-root search using a spread over nested array literals (p.join(d,'plugins',...s) over [['ecc'],...]), which breaks Windows hook execution due to shell quoting (#2368). Collapse every copy to a 250-char locator that loads the committed resolve-ecc-root module and delegates to resolveEccRoot() — no spread, no nested array literals, no escaped double quotes. The real search logic now lives in one tested module. Also route session-start-bootstrap.js through resolveEccRoot() instead of its own duplicated reimplementation, and fix the auto-update.md 'marketplace' (singular) typo along the way. Guard tests updated: discovery behavior is asserted against resolveEccRoot(); the inline is asserted to delegate and to contain no Windows-fragile constructs. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(resolve-ecc-root): restore full env-unset discovery in inline resolver Address Greptile review on #2410: when CLAUDE_PLUGIN_ROOT is unset the delegating inline could only load the resolver module from ~/.claude, returning ~/.claude without ever reaching the plugin/cache search. Restore the old inline's discovery breadth (exact plugin roots + versioned cache) Windows-safely (no spread, nested arrays, or escaped quotes), then delegate the authoritative decision to resolveEccRoot(). Add regression tests for plugin-subdir and versioned-cache bootstrap with env unset. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: affaan <affaan@itomarkets.com> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix: docs/COMMAND-REGISTRY.json check fails on fresh Windows clone (missing .gitattributes) (#2437) * fix: add .gitattributes to force LF line endings for text files npm run command-registry:check (part of npm test) fails on a fresh clone on Windows with the common core.autocrlf=true setting: git checks out docs/COMMAND-REGISTRY.json with CRLF, but generate-command-registry.js always writes LF, so the strict string comparison in checkRegistry() never matches. Forcing LF via .gitattributes makes checkouts consistent across platforms regardless of a contributor's local autocrlf setting. * fix: normalize CRLF line endings to LF per .gitattributes pyproject.toml, src/llm/__init__.py, src/llm/prompt/builder.py, src/llm/providers/claude.py, and tests/test_builder.py had CRLF line endings committed to the repo, inconsistent with the rest of the codebase. Renormalized via 'git add --renormalize .' now that .gitattributes enforces eol=lf. --------- Co-authored-by: Affaan Mustafa <me@affaanmustafa.com> * chore(catalog): sync command counts (92->93) + register orch-review in agent.yaml surface --------- Co-authored-by: devin-ai-integration[bot] <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: affaan <affaan@itomarkets.com> Co-authored-by: Boube <109886533+Cb2i@users.noreply.github.com> Co-authored-by: Affaan Mustafa <me@affaanmustafa.com>
260 lines
5.0 KiB
YAML
260 lines
5.0 KiB
YAML
spec_version: "0.1.0"
|
|
name: ecc
|
|
version: 2.0.0
|
|
description: "Initial gitagent export surface for ECC's shared skill catalog, governance, and identity. Native agents, commands, and hooks remain authoritative in the repository while manifest coverage expands."
|
|
author: affaan-m
|
|
license: MIT
|
|
model:
|
|
preferred: claude-opus-4-6
|
|
fallback:
|
|
- claude-sonnet-4-6
|
|
skills:
|
|
- agent-architecture-audit
|
|
- agent-eval
|
|
- agent-harness-construction
|
|
- agent-payment-x402
|
|
- agentic-engineering
|
|
- agentic-os
|
|
- ai-first-engineering
|
|
- ai-regression-testing
|
|
- android-clean-architecture
|
|
- api-design
|
|
- architecture-decision-records
|
|
- article-writing
|
|
- autonomous-loops
|
|
- backend-patterns
|
|
- benchmark
|
|
- blueprint
|
|
- browser-qa
|
|
- bun-runtime
|
|
- canary-watch
|
|
- carrier-relationship-management
|
|
- ck
|
|
- claude-devfleet
|
|
- click-path-audit
|
|
- clickhouse-io
|
|
- codebase-onboarding
|
|
- coding-standards
|
|
- compose-multiplatform-patterns
|
|
- configure-ecc
|
|
- content-engine
|
|
- content-hash-cache-pattern
|
|
- context-budget
|
|
- continuous-agent-loop
|
|
- continuous-learning
|
|
- continuous-learning-v2
|
|
- cost-aware-llm-pipeline
|
|
- cpp-coding-standards
|
|
- cpp-testing
|
|
- crosspost
|
|
- customs-trade-compliance
|
|
- data-scraper-agent
|
|
- database-migrations
|
|
- deep-research
|
|
- deployment-patterns
|
|
- design-system
|
|
- django-patterns
|
|
- django-security
|
|
- django-tdd
|
|
- django-verification
|
|
- dmux-workflows
|
|
- docker-patterns
|
|
- documentation-lookup
|
|
- e2e-testing
|
|
- energy-procurement
|
|
- enterprise-agent-ops
|
|
- error-handling
|
|
- eval-harness
|
|
- exa-search
|
|
- fal-ai-media
|
|
- flutter-dart-code-review
|
|
- foundation-models-on-device
|
|
- frontend-patterns
|
|
- frontend-slides
|
|
- fsharp-testing
|
|
- git-workflow
|
|
- golang-patterns
|
|
- golang-testing
|
|
- healthcare-cdss-patterns
|
|
- healthcare-emr-patterns
|
|
- healthcare-eval-harness
|
|
- healthcare-phi-compliance
|
|
- inventory-demand-planning
|
|
- investor-materials
|
|
- investor-outreach
|
|
- iterative-retrieval
|
|
- java-coding-standards
|
|
- jpa-patterns
|
|
- kotlin-coroutines-flows
|
|
- kotlin-exposed-patterns
|
|
- kotlin-ktor-patterns
|
|
- kotlin-patterns
|
|
- kotlin-testing
|
|
- laravel-patterns
|
|
- laravel-plugin-discovery
|
|
- laravel-security
|
|
- laravel-tdd
|
|
- laravel-verification
|
|
- liquid-glass-design
|
|
- logistics-exception-management
|
|
- market-research
|
|
- mcp-server-patterns
|
|
- motion-ui
|
|
- nanoclaw-repl
|
|
- nextjs-turbopack
|
|
- nutrient-document-processing
|
|
- nuxt4-patterns
|
|
- perl-patterns
|
|
- perl-security
|
|
- perl-testing
|
|
- plankton-code-quality
|
|
- plan-orchestrate
|
|
- postgres-patterns
|
|
- product-lens
|
|
- production-scheduling
|
|
- prompt-optimizer
|
|
- python-patterns
|
|
- python-testing
|
|
- pytorch-patterns
|
|
- quality-nonconformance
|
|
- quarkus-patterns
|
|
- quarkus-security
|
|
- quarkus-tdd
|
|
- quarkus-verification
|
|
- ralphinho-rfc-pipeline
|
|
- react-patterns
|
|
- react-performance
|
|
- react-testing
|
|
- regex-vs-llm-structured-text
|
|
- repo-scan
|
|
- returns-reverse-logistics
|
|
- rules-distill
|
|
- rust-patterns
|
|
- rust-testing
|
|
- safety-guard
|
|
- santa-method
|
|
- search-first
|
|
- security-review
|
|
- security-scan
|
|
- skill-comply
|
|
- skill-stocktake
|
|
- springboot-patterns
|
|
- springboot-security
|
|
- springboot-tdd
|
|
- springboot-verification
|
|
- strategic-compact
|
|
- swift-actor-persistence
|
|
- swift-concurrency-6-2
|
|
- swift-protocol-di-testing
|
|
- swiftui-patterns
|
|
- tdd-workflow
|
|
- team-builder
|
|
- token-budget-advisor
|
|
- verification-loop
|
|
- video-editing
|
|
- videodb
|
|
- visa-doc-translate
|
|
- x-api
|
|
commands:
|
|
- aside
|
|
- auto-update
|
|
- build-fix
|
|
- checkpoint
|
|
- code-review
|
|
- cost-report
|
|
- cpp-build
|
|
- cpp-review
|
|
- cpp-test
|
|
- ecc-guide
|
|
- epic-claim
|
|
- epic-decompose
|
|
- epic-publish
|
|
- epic-review
|
|
- epic-sync
|
|
- epic-unblock
|
|
- epic-validate
|
|
- evolve
|
|
- fastapi-review
|
|
- feature-dev
|
|
- flutter-build
|
|
- flutter-review
|
|
- flutter-test
|
|
- gan-build
|
|
- gan-design
|
|
- go-build
|
|
- go-review
|
|
- go-test
|
|
- gradle-build
|
|
- harness-audit
|
|
- hookify
|
|
- hookify-configure
|
|
- hookify-help
|
|
- hookify-list
|
|
- instinct-export
|
|
- instinct-import
|
|
- instinct-status
|
|
- jira
|
|
- kotlin-build
|
|
- kotlin-review
|
|
- kotlin-test
|
|
- learn
|
|
- learn-eval
|
|
- loop-start
|
|
- loop-status
|
|
- marketing-campaign
|
|
- model-route
|
|
- multi-backend
|
|
- multi-execute
|
|
- multi-frontend
|
|
- multi-plan
|
|
- multi-workflow
|
|
- orch-add-feature
|
|
- orch-build-mvp
|
|
- orch-change-feature
|
|
- orch-fix-defect
|
|
- orch-refine-code
|
|
- orch-review
|
|
- plan
|
|
- plan-prd
|
|
- pm2
|
|
- projects
|
|
- promote
|
|
- project-init
|
|
- pr
|
|
- prp-commit
|
|
- prp-implement
|
|
- prp-plan
|
|
- prp-pr
|
|
- prp-prd
|
|
- prune
|
|
- python-review
|
|
- quality-gate
|
|
- react-build
|
|
- react-review
|
|
- react-test
|
|
- refactor-clean
|
|
- resume-session
|
|
- review-pr
|
|
- rust-build
|
|
- rust-review
|
|
- rust-test
|
|
- santa-loop
|
|
- save-session
|
|
- security-scan
|
|
- sessions
|
|
- setup-pm
|
|
- skill-create
|
|
- skill-health
|
|
- test-coverage
|
|
- update-codemaps
|
|
- update-docs
|
|
- vue-review
|
|
tags:
|
|
- agent-harness
|
|
- developer-tools
|
|
- code-review
|
|
- testing
|
|
- security
|
|
- cross-platform
|
|
- gitagent
|