AI Guides › Step-by-step guides

Install One Claude Code Plugin Pack, Then Audit What It Added

By Nigel Guy · 5 min read

The usual way to adopt a famous Claude Code setup is to install everything on day one and hope. You end up with hundreds of skills, a pile of hooks and a session that starts with extra context you never asked for, and you cannot tell which part helped or which part broke something. This guide uses the popular open-source "Everything Claude Code" repository, now branded ECC, as the worked example, but the method suits any plugin pack.

The rule: install one path, start with one workflow, and read what the pack added before you trust it.

Before you start

Step 1 — Confirm you have the official source

Install only from github.com/affaan-m/ECC, the npm packages ecc-universal or ecc-agentshield, or the maintainer's own site. The README warns that third-party mirrors may contain malware. Because a pack can run hooks and MCP servers on your machine, a lookalike repo is a real risk, not a theoretical one.

Step 2 — Pick exactly one install path

The README says to pick one path per tool and not stack methods; stacking duplicates skills, hooks and commands. Your options for Claude Code:

Path Command Best for
Guided setup npx ecc-universal@2.2.3 setup Most people; walks you through choices (version number as shown in the README at the time of checking, so check the current one)
Native plugin /plugin marketplace add https://github.com/affaan-m/ECC then /plugin install ecc@ecc Staying inside Claude Code's own plugin system
From source git clone https://github.com/affaan-m/ECC.git, then cd ECC and ./install.sh --profile minimal --target claude Reading the files before anything is installed

For a first run, use the from-source path with the minimal profile. The README describes profiles named minimal, core and full; full --enable-hooks is the everything option and not where to begin.

If you use the plugin route, Claude Code's own docs say /plugin install opens a details pane first. Read the "Will install" list there, then choose a scope. "Install for you, in this repo only" (local scope) is the cautious choice while you test.

Step 3 — Add rules by hand, and only the ones you use

Claude Code plugins cannot bundle rules, so the README has you copy them yourself:

mkdir -p ~/.claude/rules/ecc && cp -R rules/common ~/.claude/rules/ecc/

Add rules/common plus one language pack you actually write in. Rules are always loaded, so every extra pack costs context on every session.

Step 4 — Start with one workflow

The README's advice is to start with the workflow you need, not the whole catalogue. Two entry points it names: /ecc:plan for planning a feature, and the tdd-workflow skill for test-driven development. Pick one, use it on the throwaway project for a few sessions, and ignore the rest.

Step 5 — Scan the setup itself

The "security layer" is AgentShield, a scanner for agent configuration rather than your application code. The README says it checks secrets, permissions, hooks, MCP server risk and agent files. Run it from the project folder:

agentshield scan --path .

Treat the output as a prompt to read, not a certificate. A scanner cannot tell you whether a hook's intent is good.

Step 6 — Measure what it costs you

Two checks, both from official sources:

  1. The ECC README says session start can inject up to 8,000 characters of extra context. You can tune it with ECC_SESSION_START_MAX_CHARS or switch it off with ECC_SESSION_START_CONTEXT=off.
  2. For plugin installs, run claude plugin details <name> in your shell. Claude Code's docs say the Always-on line is the tokens the plugin adds to every session, with a per-component breakdown.

Check it worked

If commands appear twice, you stacked two install methods. The README's fix is npx ecc-universal uninstall, then reinstall using one path.

What to skip

Guardrails

Sources

All 751 AI guides · JulieMango plans from £17/mo