affaan-m/everything-claude-code cursor hook kiro mcp skill
agent workflow
ECC is an agent harness operating system that provides Claude Code and other AI coding agents with a coordinated engineering workflow: planning, testing, implementation, review, verification, and memory. It includes 67 specialized agents, 281 skills across multiple domains, command shims, security scanning via AgentShield, and language-specific rule packs to enforce standards across projects.
Install the Claude Code plugin to equip your agent with planning, testing, and code review workflows Use domain-specific agents for security audits, architecture decisions, build repair, and specialized work Add language-specific rule packs to enforce standards in TypeScript, Python, Java, Go, and other stacks Leverage 281 skills for test-driven development, documentation, frontend, data, ML, and operations tasks Enable AgentShield to scan for security issues in prompts, hooks, MCP configs, and agent files 5 CRITICAL✓ 31 HIGH✓ 148 MEDIUM 47 LOW 16 INFO
✓ CRITICAL/HIGH reflect AI-verified findings (false positives excluded) · MEDIUM/LOW/INFO are unverified scanner output
AI-verified (CRITICAL/HIGH): 14 confirmed (39%) 22 likely real (61%) 25 false positive — excluded from CRITICAL/HIGH count above
Findings by checker · 10 high-signal, 9 mostly false-positive (hidden by default)
CHK-144 15 findings 14 confirmed 1 false positive
7% FP CHK-014 10 findings 6 likely 4 false positive
40% FP CHK-001 3 findings 2 likely 1 false positive
33% FP CHK-008 2 findings 2 likely
0% FP CHK-081 1 finding 1 likely
0% FP CHK-080 1 finding 1 likely
0% FP CHK-068 1 finding 1 likely
0% FP CHK-099 1 finding 1 likely
0% FP CHK-040 1 finding 1 likely
0% FP CHK-083 1 finding 1 likely
0% FP ▼ Show 9 checkers that are mostly false positives (25 findings) 175 findings click to expand
CHK-001 Wildcard PreToolUse hook [pre:mcp-health-check] — fires before EVERY tool call
hooks/hooks.json
AI: likely real likely ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/claw.js
scripts/claw.js
AI: likely real confirmed ▼
CHK-027 Data exfiltration instruction in skill — HTTP POST/PUT/PATCH to external endpoint
skills/nutrient-document-processing/SKILL.md
AI: likely real likely ▼
CHK-001 Wildcard PreToolUse hook [pre:observe:continuous-learning] — fires before EVERY tool call
hooks/hooks.json
AI: likely real likely ▼
CHK-080 Node.js vm module used as sandbox — vm is NOT a security boundary
scripts/ci/validate-hooks.js
AI: likely real confirmed ▼
CHK-068 15 hook events configured — maximum persistence surface
.cursor/hooks.json
AI: likely real possible ▼
CHK-144 'firecrawl' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-144 'browserbase' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-099 Potential IDOR — 'project_id' accessed without ownership check
skills/continuous-learning-v2/scripts/instinct-cli.py
AI: likely real possible ▼
CHK-144 'fal-ai' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-144 'playwright' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-040 AWS Access Key detected in tests/hooks/pre-bash-commit-quality.test.js [test context]
tests/hooks/pre-bash-commit-quality.test.js
AI: likely real likely ▼
CHK-023 Embedded instruction in skill file — instruction override
skills/tdd-workflow/SKILL.md
AI: likely real likely ▼
CHK-144 'filesystem' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-014 'memxus' uses HTTP transport to external URL: https://mcp.memxus.com/mcp
mcp-configs/mcp-servers.json
AI: likely real likely ▼
CHK-144 'codescene' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in scripts/classifier.py
skills/skill-comply/scripts/classifier.py
AI: likely real likely ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in hooks/quality-gate.js
scripts/hooks/quality-gate.js
AI: likely real likely ▼
CHK-119 Kiro steering file references credential path: process.env.DATABASE_PASSWORD
.kiro/steering/typescript-security.md
AI: likely real likely ▼
CHK-014 'parallel-search' uses HTTP transport to external URL: https://search.parallel.ai/mcp
mcp-configs/mcp-servers.json
AI: likely real likely ▼
CHK-014 'laraplugins' uses HTTP transport to external URL: https://laraplugins.io/mcp/plugins
mcp-configs/mcp-servers.json
AI: likely real likely ▼
CHK-014 'clickhouse' uses HTTP transport to external URL: https://mcp.clickhouse.cloud/mcp
mcp-configs/mcp-servers.json
AI: likely real likely ▼
CHK-014 'cloudflare-workers-bindings' uses HTTP transport to external URL: https://bindings.mcp.cloudflare.com/mcp
mcp-configs/mcp-servers.json
AI: likely real likely ▼
CHK-014 'browser-use' uses HTTP transport to external URL: https://api.browser-use.com/mcp
mcp-configs/mcp-servers.json
AI: likely real likely ▼
CHK-144 'exa-web-search' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-144 'github' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-024 Filesystem traversal instruction in skill — recursive grep across filesystem
skills/verification-loop/SKILL.md
AI: likely real likely ▼
CHK-144 'squish' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-083 Potential path traversal — user-controlled path in file operation: skills/frontend-slides/scripts/extract-pptx.py
skills/frontend-slides/scripts/extract-pptx.py
AI: likely real possible ▼
CHK-144 'confluence' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-144 'token-optimizer' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-144 'railway' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-144 'sequential-thinking' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-008 PostToolUse governance hook captures broad tool output
hooks/hooks.json
AI: likely real likely ▼
CHK-008 Stop governance hook captures broad tool output
hooks/hooks.json
AI: likely real likely ▼
CHK-144 'memory' invoked via npx with no version pin — rug pull risk
mcp-configs/mcp-servers.json
AI: confirmed likely ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in lib/tmux-worktree-orchestrator.js
scripts/lib/tmux-worktree-orchestrator.js
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in lib/github-discussions.js
scripts/lib/github-discussions.js
possible ▼
CHK-125a fs.unlinkSync — file deletion — no scope constraint in lib/session-bridge.js
scripts/lib/session-bridge.js
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in lib/agent-data-home.js
scripts/lib/agent-data-home.js
possible ▼
CHK-125a fs.unlinkSync — file deletion — no scope constraint in lib/session-manager.js
scripts/lib/session-manager.js
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in lib/llm-summary.js
scripts/lib/llm-summary.js
possible ▼
CHK-125a fs.unlinkSync — file deletion — no scope constraint in lib/session-aliases.js
scripts/lib/session-aliases.js
possible ▼
CHK-125 child_process module — shell execution — no scope constraint in lib/install-executor.js
scripts/lib/install-executor.js
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in lib/ecc_dashboard_runtime.py
scripts/lib/ecc_dashboard_runtime.py
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in lib/observer-sessions.js
scripts/lib/observer-sessions.js
possible ▼
CHK-125 child_process module — shell execution — no scope constraint in lib/orchestration-session.js
scripts/lib/orchestration-session.js
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in lib/utils.js
scripts/lib/utils.js
possible ▼
CHK-125 child_process module — shell execution — no scope constraint in lib/install-lifecycle.js
scripts/lib/install-lifecycle.js
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in worktree-lifecycle/git.js
scripts/lib/worktree-lifecycle/git.js
possible ▼
CHK-125 child_process module — shell execution — no scope constraint in control-pane/message-sink.js
scripts/lib/control-pane/message-sink.js
possible ▼
CHK-125 child_process module — shell execution — no scope constraint in control-pane/server.js
scripts/lib/control-pane/server.js
possible ▼
CHK-125 child_process module — shell execution — no scope constraint in control-pane/proximity.js
scripts/lib/control-pane/proximity.js
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in github-coordination/gh-api.js
scripts/lib/github-coordination/gh-api.js
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in agent-proximity/graph.js
scripts/lib/agent-proximity/graph.js
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in state-store/index.js
scripts/lib/state-store/index.js
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in state-store/migrations.js
scripts/lib/state-store/migrations.js
possible ▼
CHK-125 child_process module — shell execution — no scope constraint in session-adapters/codex-worktree.js
scripts/lib/session-adapters/codex-worktree.js
possible ▼
CHK-125 child_process module — shell execution — no scope constraint in session-adapters/opencode.js
scripts/lib/session-adapters/opencode.js
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in skill-evolution/versioning.js
scripts/lib/skill-evolution/versioning.js
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in agents/python-reviewer.md
.kiro/agents/python-reviewer.md
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in agents/python-reviewer.json
.kiro/agents/python-reviewer.json
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in agents/typescript-reviewer.md
.kiro/agents/typescript-reviewer.md
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in agents/typescript-reviewer.json
.kiro/agents/typescript-reviewer.json
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in agents/java-reviewer.json
.kiro/agents/java-reviewer.json
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in agents/java-reviewer.md
.kiro/agents/java-reviewer.md
possible ▼
CHK-125 eval() — arbitrary code execution — no scope constraint in pytorch-patterns/SKILL.md
.kiro/skills/pytorch-patterns/SKILL.md
possible ▼
CHK-125 kubectl invocation — cluster command execution — no scope constraint in deployment-patterns/SKILL.md
.kiro/skills/deployment-patterns/SKILL.md
possible ▼
CHK-125b chown — ownership change — no scope constraint in deployment-patterns/SKILL.md
.kiro/skills/deployment-patterns/SKILL.md
possible ▼
CHK-125 eval() — arbitrary code execution — no scope constraint in pytorch-patterns/SKILL.md
skills/pytorch-patterns/SKILL.md
possible ▼
CHK-125 eval() — arbitrary code execution — no scope constraint in security-bounty-hunter/SKILL.md
skills/security-bounty-hunter/SKILL.md
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in plankton-code-quality/SKILL.md
skills/plankton-code-quality/SKILL.md
possible ▼
CHK-125 kubectl invocation — cluster command execution — no scope constraint in deployment-patterns/SKILL.md
skills/deployment-patterns/SKILL.md
possible ▼
CHK-125b chown — ownership change — no scope constraint in deployment-patterns/SKILL.md
skills/deployment-patterns/SKILL.md
possible ▼
CHK-125 kubectl invocation — cluster command execution — no scope constraint in safety-guard/SKILL.md
skills/safety-guard/SKILL.md
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in safety-guard/SKILL.md
skills/safety-guard/SKILL.md
possible ▼
CHK-125 kubectl invocation — cluster command execution — no scope constraint in kubernetes-patterns/SKILL.md
skills/kubernetes-patterns/SKILL.md
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in hookify-rules/SKILL.md
skills/hookify-rules/SKILL.md
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in homelab-wireguard-vpn/SKILL.md
skills/homelab-wireguard-vpn/SKILL.md
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in homelab-wireguard-vpn/SKILL.md
skills/homelab-wireguard-vpn/SKILL.md
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in golang-testing/SKILL.md
skills/golang-testing/SKILL.md
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in scripts/runner.py
skills/skill-comply/scripts/runner.py
possible ▼
CHK-125a shutil.rmtree() — recursive directory deletion — no scope constraint in scripts/runner.py
skills/skill-comply/scripts/runner.py
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in scripts/spec_generator.py
skills/skill-comply/scripts/spec_generator.py
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in scripts/scenario_generator.py
skills/skill-comply/scripts/scenario_generator.py
possible ▼
CHK-125a os.unlink() — file deletion — no scope constraint in scripts/detect-project.sh
skills/continuous-learning-v2/scripts/detect-project.sh
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in hooks/session-start.mjs
skills/ck/hooks/session-start.mjs
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in commands/shared.mjs
skills/ck/commands/shared.mjs
possible ▼
CHK-115 Credential file path referenced in skill content: .env
skills/bun-runtime/SKILL.md
possible ▼
CHK-027 Outbound network call in skill — external network call (verify direction — could be benign API fetch)
skills/python-testing/SKILL.md
possible ▼
CHK-115 Credential file path referenced in skill content: .env`
skills/x-api/SKILL.md
possible ▼
CHK-027 Outbound network call in skill — external network call (verify direction — could be benign API fetch)
skills/docker-patterns/SKILL.md
possible ▼
CHK-115 Credential file path referenced in skill content: .env
skills/docker-patterns/SKILL.md
possible ▼
CHK-115 Credential file path referenced in skill content: .env`
skills/laravel-patterns/SKILL.md
possible ▼
CHK-027 Outbound network call in skill — external network call (verify direction — could be benign API fetch)
skills/videodb/SKILL.md
possible ▼
CHK-115 Credential file path referenced in skill content: .env"
skills/videodb/SKILL.md
possible ▼
CHK-027 Outbound network call in skill — external network call (verify direction — could be benign API fetch)
skills/social-publisher/SKILL.md
possible ▼
CHK-115 Credential file path referenced in skill content: .env`
skills/opensource-pipeline/SKILL.md
possible ▼
CHK-115 Credential file path referenced in skill content: .env.
skills/git-workflow/SKILL.md
possible ▼
CHK-027 Outbound network call in skill — external network call (verify direction — could be benign API fetch)
skills/data-scraper-agent/SKILL.md
possible ▼
▼ Show 25 false positives (13% of this view) Last scanned: Jul 12, 2026
More servers
google-gemini/gemini-cli 85
An open-source AI agent that brings the power of Gemini directly into your terminal.
106k★
skypilot-org/skypilot 85
obra/superpowers 85
Foundational skill pack by Jesse Vincent now in anthropics/claude-plugins-official. Includes ffuf web-fuzzing/pentest skill. Partial analysis done — full hook and plugin inspection pending. tier=T2
191k★
Significant-Gravitas/AutoGPT 85
AutoGPT is the vision of accessible AI for everyone, to use and to build on. Our mission is to provide the tools, so that you can focus on what matters.
186k★
nanocoai/nanoclaw 85
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
30k★
google-gemini/gemini-cli 85
An open-source AI agent that brings the power of Gemini directly into your terminal.
106k★
Scan your entire org's MCP deployment
2,500+ repos pre-scored. 22% carry CRITICAL findings.