{
  "description": "Curated Pi-native profile for ECC: portable engineering skills and pure prompt workflow commands, regenerated into pi/core/ by scripts/build-pi-core.js.",
  "profile": {
    "dir": "pi/core",
    "packageName": "ecc-pi-core",
    "license": "MIT",
    "keywords": [
      "pi-package",
      "skills"
    ]
  },
  "curationRules": {
    "include": [
      "language/framework skills",
      "testing/TDD",
      "code review",
      "security review (non-offensive)",
      "planning",
      "refactoring",
      "docs",
      "git/PR workflows",
      "prompt commands that are pure prompt workflows"
    ],
    "exclude": [
      "makes network calls, needs API keys, or downloads at runtime (npx, pip install, curl|sh)",
      "wraps third-party SaaS (exa, context7, fal, videodb, x-api, social/marketing/SEO/outreach)",
      "integrates commercial products (ECC Tools, ecc.tools, AgentShield, billing/ops skills)",
      "depends on Claude-Code-only mechanics (hooks, agent rosters/orch-*, continuous-learning, loops, hookify, cost tracking, session save/resume, gateguard)",
      "venture-specific (ito-*, prediction-market-*, hermes-*, nasiko-*, openclaw-*, x402)",
      "niche domain pack (healthcare/HIPAA, supply chain/logistics, homelab, scientific, visa/legal docs) or offensive security (bug bounty)"
    ]
  },
  "skills": {
    "include": [
      "accessibility",
      "agent-architecture-audit",
      "agent-eval",
      "agent-harness-construction",
      "agent-introspection-debugging",
      "agent-self-evaluation",
      "agentic-engineering",
      "ai-first-engineering",
      "android-clean-architecture",
      "angular-developer",
      "api-connector-builder",
      "api-design",
      "architecture-decision-records",
      "backend-patterns",
      "benchmark",
      "benchmark-optimization-loop",
      "blueprint",
      "bun-runtime",
      "click-path-audit",
      "clickhouse-io",
      "code-tour",
      "codebase-onboarding",
      "coding-standards",
      "compose-multiplatform-patterns",
      "content-hash-cache-pattern",
      "contract-first",
      "cost-aware-llm-pipeline",
      "council",
      "cpp-coding-standards",
      "cpp-testing",
      "csharp-testing",
      "dart-flutter-patterns",
      "dashboard-builder",
      "data-throughput-accelerator",
      "database-migrations",
      "deployment-patterns",
      "design-system",
      "dev-team",
      "django-celery",
      "django-patterns",
      "django-security",
      "django-tdd",
      "django-verification",
      "docker-patterns",
      "dotnet-patterns",
      "e2e-testing",
      "error-handling",
      "fastapi-patterns",
      "flutter-dart-code-review",
      "foundation-models-on-device",
      "frontend-a11y",
      "frontend-patterns",
      "fsharp-testing",
      "git-workflow",
      "golang-patterns",
      "golang-testing",
      "hexagonal-architecture",
      "inherit-legacy-style",
      "intent-driven-development",
      "java-coding-standards",
      "jpa-patterns",
      "kotlin-coroutines-flows",
      "kotlin-exposed-patterns",
      "kotlin-ktor-patterns",
      "kotlin-patterns",
      "kotlin-testing",
      "kubernetes-patterns",
      "laravel-patterns",
      "laravel-security",
      "laravel-tdd",
      "laravel-verification",
      "latency-critical-systems",
      "liquid-glass-design",
      "living-docs-governance",
      "make-interfaces-feel-better",
      "mcp-server-patterns",
      "ml-adoption-playbook",
      "mle-workflow",
      "motion-advanced",
      "motion-foundations",
      "motion-patterns",
      "mysql-patterns",
      "nestjs-patterns",
      "nextjs-turbopack",
      "nuxt4-patterns",
      "parallel-execution-optimizer",
      "perl-patterns",
      "perl-security",
      "perl-testing",
      "postgres-patterns",
      "prisma-patterns",
      "product-capability",
      "product-lens",
      "production-audit",
      "python-patterns",
      "python-testing",
      "pytorch-patterns",
      "quarkus-patterns",
      "quarkus-security",
      "quarkus-tdd",
      "quarkus-verification",
      "rails-patterns",
      "react-native-patterns",
      "react-patterns",
      "react-performance",
      "react-testing",
      "redis-patterns",
      "regex-vs-llm-structured-text",
      "rust-patterns",
      "rust-testing",
      "security-review",
      "springboot-patterns",
      "springboot-security",
      "springboot-tdd",
      "springboot-verification",
      "swift-actor-persistence",
      "swift-concurrency-6-2",
      "swift-protocol-di-testing",
      "swiftui-patterns",
      "tdd-workflow",
      "verification-loop",
      "vite-patterns",
      "vue-patterns"
    ],
    "rename": {
      "council": "ecc-council"
    },
    "exclude": {
      "agent-payment-x402": "venture-specific x402 payments; wallet and network runtime",
      "agent-sort": "ECC install planner over the full ECC catalog; not portable",
      "agentic-os": "Claude-Code-only persistent OS mechanics (slash commands, memory, schedules)",
      "ai-regression-testing": "workflow creates Claude Code custom slash commands (.claude/commands)",
      "article-writing": "content/marketing writing, not engineering",
      "automation-audit-ops": "ECC ops audit of hooks/connectors/MCP surfaces",
      "autonomous-agent-harness": "Claude-Code-only autonomous harness (hooks, scheduling, computer use)",
      "autonomous-loops": "Claude-Code-only autonomous loops",
      "benchmark-methodology": "competitive/marketing benchmarking",
      "blender-motion-state-inspection": "niche 3D/Blender domain pack",
      "brand-discovery": "brand/marketing content",
      "brand-voice": "marketing/outreach voice profiling",
      "browser-qa": "requires a browser automation MCP server at runtime",
      "canary-watch": "makes network calls to deployed URLs",
      "carrier-relationship-management": "supply chain/logistics domain pack",
      "cisco-ios-patterns": "network-device ops niche domain",
      "ck": "Claude-Code-only persistent memory commands",
      "claude-devfleet": "multi-agent orchestration via external DevFleet product",
      "codehealth-mcp": "wraps CodeScene MCP SaaS",
      "competitive-platform-analysis": "competitive/marketing analysis",
      "competitive-report-structure": "competitive/marketing reporting",
      "config-gc": "Claude-Code-only config garbage collection (~/.claude)",
      "configure-ecc": "ECC-specific setup wizard",
      "connections-optimizer": "social/outreach (X and LinkedIn)",
      "content-engine": "social/marketing content system",
      "context-budget": "Claude-Code-only context window audit",
      "continuous-agent-loop": "continuous agent loops",
      "continuous-learning": "Claude-Code-only hooks-based continuous learning (deprecated)",
      "continuous-learning-v2": "Claude-Code-only hooks-based continuous learning",
      "cost-tracking": "Claude Code cost tracking",
      "council-multi-model": "requires external Codex CLI at runtime",
      "counterparty-channel-discipline": "agent messaging ops policy",
      "crosspost": "social/marketing distribution",
      "customer-billing-ops": "billing/ops skill over connected billing tools",
      "customs-trade-compliance": "customs/trade niche domain",
      "data-scraper-agent": "scheduled network scraping agent",
      "deep-research": "requires firecrawl and exa SaaS MCP tools",
      "defi-amm-security": "crypto/DeFi niche domain",
      "delivery-gate": "Claude-Code-only stop hook",
      "dmux-workflows": "multi-agent orchestration via dmux",
      "documentation-lookup": "wraps Context7 SaaS MCP",
      "dynamic-workflow-mode": "Claude dynamic workflow mode mechanics",
      "ecc-guide": "ECC repository self-reference",
      "ecc-recipes": "ECC command catalog self-reference",
      "ecc-tools-cost-audit": "ECC Tools commercial billing/ops",
      "email-ops": "mailbox ops skill",
      "energy-procurement": "energy procurement niche domain",
      "enterprise-agent-ops": "agent runtime ops, not portable engineering",
      "esign-field-placement": "niche e-sign browser automation",
      "eval-harness": "reads and writes .claude/evals (Claude-Code-only)",
      "evm-token-decimals": "crypto/EVM niche domain",
      "exa-search": "wraps Exa SaaS",
      "fal-ai-media": "wraps fal.ai SaaS",
      "finance-billing-ops": "billing/ops skill",
      "flox-environments": "runtime installer flow (curl|sh) for Flox",
      "frontend-design-direction": "ECC-specific design direction",
      "frontend-slides": "presentation/content production, not engineering",
      "gan-style-harness": "Claude-Code-only generator/evaluator harness",
      "gateguard": "Claude-Code-only PreToolUse gate",
      "generating-python-installer": "niche Windows installer packaging with runtime downloads",
      "github-ops": "makes GitHub API calls via gh at runtime",
      "google-workspace-ops": "wraps Google Workspace SaaS",
      "growth-log": "ECC learning-log workflow",
      "healthcare-cdss-patterns": "healthcare niche domain pack",
      "healthcare-emr-patterns": "healthcare niche domain pack",
      "healthcare-eval-harness": "healthcare niche domain pack",
      "healthcare-phi-compliance": "healthcare/PHI niche domain pack",
      "hermes-imports": "venture-specific hermes-*",
      "hipaa-compliance": "HIPAA niche domain pack",
      "homelab-network-readiness": "homelab niche domain pack",
      "homelab-network-setup": "homelab niche domain pack",
      "homelab-pihole-dns": "homelab niche domain pack",
      "homelab-vlan-segmentation": "homelab niche domain pack",
      "homelab-wireguard-vpn": "homelab niche domain pack",
      "hookify-rules": "hookify (Claude-Code-only hooks)",
      "i18n-sync": "built around a third-party npm CLI (locakit) with external source links; not self-contained",
      "inventory-demand-planning": "supply chain niche domain",
      "investor-materials": "fundraising/marketing content",
      "investor-outreach": "fundraising outreach",
      "ios-icon-gen": "Iconify API network calls at runtime",
      "iterative-retrieval": "multi-agent subagent context mechanics; links to external social post",
      "ito-baskets": "venture-specific ito-*",
      "ito-compute": "venture-specific ito-*",
      "ito-inference": "venture-specific ito-*",
      "ito-training": "venture-specific ito-*",
      "jira-integration": "wraps Jira SaaS API",
      "knowledge-ops": "ops skill over MCP memory and vector stores",
      "laravel-plugin-discovery": "wraps LaraPlugins.io SaaS MCP",
      "lead-intelligence": "sales outreach pipeline",
      "llm-trading-agent-security": "trading-agent niche domain",
      "logistics-exception-management": "logistics niche domain",
      "loop-design-check": "agent loop design mechanics",
      "mailtrap-email-integration": "wraps Mailtrap SaaS API",
      "manim-video": "niche video production; pip installs at runtime",
      "market-research": "web research over network sources",
      "marketing-campaign": "marketing",
      "master-agreement-generator": "legal docs niche",
      "messages-ops": "messaging ops skill",
      "nanoclaw-repl": "ECC product-specific REPL",
      "nasiko-control-plane": "venture-specific nasiko-*",
      "netmiko-ssh-automation": "network-device ops niche; SSH at runtime",
      "network-bgp-diagnostics": "network ops niche domain",
      "network-config-validation": "network ops niche domain",
      "network-interface-health": "network ops niche domain",
      "nodejs-keccak256": "crypto/EVM niche domain",
      "nutrient-document-processing": "wraps Nutrient DWS SaaS API",
      "openclaw-persona-forge": "venture-specific openclaw-*",
      "opensource-pipeline": "multi-agent roster pipeline",
      "operator-approval-loop": "ECC ops approval contract",
      "orch-add-feature": "Claude-Code-only orch-* orchestration",
      "orch-build-mvp": "Claude-Code-only orch-* orchestration",
      "orch-change-feature": "Claude-Code-only orch-* orchestration",
      "orch-fix-defect": "Claude-Code-only orch-* orchestration",
      "orch-pipeline": "Claude-Code-only orch-* orchestration",
      "orch-refine-code": "Claude-Code-only orch-* orchestration",
      "plan-canvas": "Claude-Code-only plan canvas server",
      "plan-orchestrate": "ECC orchestration prompt generator over the full catalog",
      "plankton-code-quality": "Claude-Code-only write-time hooks",
      "prediction-market-oracle-research": "venture-specific prediction-market-*",
      "prediction-market-risk-review": "venture-specific prediction-market-*",
      "production-scheduling": "manufacturing niche domain",
      "project-flow-ops": "ops over GitHub/Linear SaaS",
      "prompt-optimizer": "ECC command/agent catalog self-reference",
      "quality-nonconformance": "regulated manufacturing niche",
      "ralphinho-rfc-pipeline": "multi-agent DAG orchestration",
      "recsys-pipeline-architect": "installs upstream package via npx skills add",
      "recursive-decision-ledger": "recursive prompting loops",
      "remotion-video-creation": "video/media production niche",
      "repo-scan": "downloads an external skill at runtime",
      "research-ops": "ECC ops research workflow with network enrichment",
      "returns-reverse-logistics": "logistics niche domain",
      "rules-distill": "Claude-Code-only rules distillation mechanics",
      "safety-guard": "Claude-Code-only PreToolUse hooks",
      "santa-method": "multi-agent adversarial review roster",
      "scientific-db-pubmed-database": "scientific niche domain pack",
      "scientific-db-uspto-database": "scientific niche domain pack",
      "scientific-pkg-gget": "scientific niche domain pack",
      "scientific-thinking-literature-review": "scientific niche domain pack",
      "scientific-thinking-scholar-evaluation": "scientific niche domain pack",
      "search-first": "network searches (npm/PyPI/GitHub) at runtime",
      "security-bounty-hunter": "offensive security (bug bounty)",
      "security-scan": "wraps AgentShield commercial product",
      "seo": "SEO/marketing",
      "skill-comply": "runs agent rosters for compliance checks",
      "skill-scout": "network searches of skill marketplaces",
      "skill-stocktake": "subagent-based Claude skill audit",
      "social-graph-ranker": "social graph (X and LinkedIn)",
      "social-publisher": "wraps SocialClaw SaaS",
      "strategic-compact": "Claude Code session compaction mechanics",
      "taste": "media/creative-direction niche pack",
      "taste-application": "media generation via fal.ai SaaS",
      "taste-distillation": "media analysis paired with fal.ai SaaS",
      "tasteforge-video": "media generation workflow over fal.ai SaaS",
      "team-agent-orchestration": "agent squad orchestration",
      "team-builder": "Claude agents roster picker",
      "terminal-opener": "ECC harness utility, not engineering content",
      "terminal-ops": "ECC ops workflow",
      "tinystruct-patterns": "niche single-framework pack",
      "token-budget-advisor": "session/token mechanics",
      "ui-demo": "Playwright video recording with runtime installs",
      "ui-to-vue": "runs an npx converter package at runtime",
      "uncloud": "niche cluster ops",
      "unified-memory": "ECC memory vault (session save/resume family)",
      "unified-notifications-ops": "ECC notifications ops",
      "video-editing": "media production niche",
      "videodb": "wraps VideoDB SaaS",
      "visa-doc-translate": "visa/legal docs niche; OCR network calls",
      "windows-desktop-e2e": "niche Windows desktop automation; pip installs at runtime",
      "workspace-surface-audit": "ECC harness surface audit",
      "x-api": "wraps X/Twitter SaaS API"
    }
  },
  "commands": {
    "include": [
      "aside.md",
      "build-fix.md",
      "code-review.md",
      "cpp-test.md",
      "fastapi-review.md",
      "feature-dev.md",
      "flutter-test.md",
      "go-test.md",
      "gradle-build.md",
      "kotlin-test.md",
      "plan-prd.md",
      "plan.md",
      "pr.md",
      "prp-commit.md",
      "prp-implement.md",
      "prp-plan.md",
      "prp-pr.md",
      "prp-prd.md",
      "react-test.md",
      "refactor-clean.md",
      "rust-test.md",
      "test-coverage.md",
      "update-codemaps.md",
      "update-docs.md"
    ],
    "exclude": {
      "auto-update.md": "ECC self-update/reinstall",
      "checkpoint.md": "writes .claude/checkpoints.log (Claude-Code-only)",
      "cost-report.md": "Claude Code cost tracking",
      "cpp-build.md": "invokes ECC agent roster (cpp-build-resolver)",
      "cpp-review.md": "invokes ECC agent roster (cpp-reviewer)",
      "ecc-guide.md": "ECC repository self-reference",
      "epic-claim.md": "GitHub epic ops over ECC coordination state; network",
      "epic-decompose.md": "GitHub epic ops over ECC coordination state; network",
      "epic-publish.md": "GitHub epic ops over ECC coordination state; network",
      "epic-review.md": "GitHub epic ops over ECC coordination state; network",
      "epic-sync.md": "GitHub epic ops over ECC coordination state; network",
      "epic-unblock.md": "GitHub epic ops over ECC coordination state; network",
      "epic-validate.md": "GitHub epic ops over ECC coordination state; network",
      "evolve.md": "instincts/continuous-learning mechanics",
      "flutter-build.md": "invokes ECC agent roster (dart-build-resolver)",
      "flutter-review.md": "invokes ECC agent roster (flutter-reviewer)",
      "gan-build.md": "GAN generator/evaluator loop harness",
      "gan-design.md": "GAN generator/evaluator loop harness",
      "go-build.md": "invokes ECC agent roster (go-build-resolver)",
      "go-review.md": "invokes ECC agent roster (go-reviewer)",
      "harness-audit.md": "ECC harness audit",
      "hookify-configure.md": "hookify (Claude-Code-only hooks)",
      "hookify-help.md": "hookify (Claude-Code-only hooks)",
      "hookify-list.md": "hookify (Claude-Code-only hooks)",
      "hookify.md": "hookify (Claude-Code-only hooks)",
      "instinct-export.md": "instincts (continuous-learning)",
      "instinct-import.md": "instincts (continuous-learning)",
      "instinct-status.md": "instincts (continuous-learning)",
      "jira.md": "wraps Jira SaaS API",
      "kotlin-build.md": "invokes ECC agent roster (kotlin-build-resolver)",
      "kotlin-review.md": "invokes ECC agent roster (kotlin-reviewer)",
      "learn-eval.md": "continuous-learning session extraction",
      "learn.md": "continuous-learning session extraction",
      "loop-start.md": "autonomous loops",
      "loop-status.md": "autonomous loops",
      "marketing-campaign.md": "marketing",
      "model-route.md": "ECC model routing/cost mechanics",
      "multi-backend.md": "multi-model orchestration",
      "multi-execute.md": "multi-model orchestration",
      "multi-frontend.md": "multi-model orchestration",
      "multi-plan.md": "multi-model orchestration",
      "multi-workflow.md": "multi-model orchestration",
      "orch-add-feature.md": "Claude-Code-only orch-* orchestration",
      "orch-build-mvp.md": "Claude-Code-only orch-* orchestration",
      "orch-change-feature.md": "Claude-Code-only orch-* orchestration",
      "orch-fix-defect.md": "Claude-Code-only orch-* orchestration",
      "orch-refine-code.md": "Claude-Code-only orch-* orchestration",
      "orch-review.md": "Claude-Code-only orch-* orchestration",
      "plan-canvas.md": "Claude-Code-only plan canvas server",
      "pm2.md": "PM2 runtime process manager ops",
      "project-init.md": "ECC install-manifest onboarding plan",
      "projects.md": "instincts (continuous-learning)",
      "promote.md": "instincts (continuous-learning)",
      "prune.md": "instincts (continuous-learning)",
      "python-review.md": "invokes ECC agent roster (python-reviewer)",
      "quality-gate.md": "drives the ECC PostToolUse formatter hook script",
      "react-build.md": "invokes ECC agent roster (react-build-resolver)",
      "react-review.md": "invokes ECC agent roster (react-reviewer)",
      "resume-session.md": "Claude Code session save/resume (~/.claude/session-data)",
      "review-pr.md": "invokes ECC agent roster (specialized review agents)",
      "rust-build.md": "invokes ECC agent roster (rust-build-resolver)",
      "rust-review.md": "invokes ECC agent roster (rust-reviewer)",
      "santa-loop.md": "multi-agent adversarial review loop",
      "save-session.md": "Claude Code session save/resume (~/.claude/session-data)",
      "security-scan.md": "wraps AgentShield commercial product",
      "sessions.md": "Claude Code session management",
      "setup-pm.md": "runs an ECC repo script (scripts/setup-package-manager.js)",
      "skill-create.md": "Claude Code skill authoring plus instincts",
      "skill-health.md": "ECC skill analytics dashboard",
      "vue-review.md": "invokes ECC agent roster (vue-reviewer)"
    }
  },
  "safety": {
    "semantics": "URLs: documentation hosts in urlAllowlistHosts, placeholder hosts (example.com/org/net and subdomains), and non-FQDN internal hostnames (localhost, docker service names) are allowed; everything else fails. Runtime downloads: pipe-to-shell (curl|sh, wget|sh) and fetch-and-run npx forms (-y/--yes, pkg@version, create-*, degit, \"skills add\") fail. Local-first npx <tool> and standard project dependency installation (pip install <dep>) are the reader's own project workflow and are allowed; skills whose own operation downloads tooling are excluded above. Absolute per-user home paths fail; portable tilde references are allowed.",
    "urlAllowlistHosts": [
      "aka.ms",
      "angular.dev",
      "aws.amazon.com",
      "bloclibrary.dev",
      "cli.github.com",
      "developer.android.com",
      "developer.apple.com",
      "developers.cloudflare.com",
      "dart.dev",
      "docs.flutter.dev",
      "external-secrets.io",
      "github.com",
      "isocpp.github.io",
      "kotlinlang.org",
      "modelcontextprotocol.io",
      "nextjs.org",
      "owasp.org",
      "portswigger.net",
      "pub.dev",
      "riverpod.dev",
      "supabase.com",
      "vite.dev",
      "www.cisecurity.org",
      "www.speedscope.app",
      "www.terraform.io",
      "www.w3.org"
    ],
    "defaultAllowedHosts": [
      "localhost",
      "127.0.0.1",
      "[::1]",
      "0.0.0.0",
      "example.com",
      "example.org",
      "example.net"
    ],
    "scanAllowlist": [
      {
        "path": "skills/tdd-workflow/SKILL.md",
        "contains": "curl ... | sh` must be rejected",
        "reason": "anti-pattern warning telling reviewers to reject pipe-to-shell; not an instruction"
      }
    ]
  }
}
