Skip to content

Commit f698e3e

Browse files
committed
docs: add MRR-biased ECC Pro + AgentShield security roadmap
Output of a multi-agent survey + research pass: capability map of AgentShield and ECC Pro, triage of every open PR/issue on both repos, and web research on competitors, unbuilt ideas, and dev-tool demand. 17 items across 4 themes (now/next/later) scored for free-to-paid conversion, each linked to the real PRs/issues that implement it. Includes the reusable workflow script that generated it. Headline: ecc-agentshield is ~30K downloads/month with near-zero monetization bridge, and the agent-proximity moat is computed but never rendered. Roadmap removes trust blockers (FP cluster), makes the moat visible (PR #2320), then productizes local CLI primitives into hosted Pro surfaces.
1 parent 71d22d0 commit f698e3e

2 files changed

Lines changed: 536 additions & 0 deletions

File tree

Lines changed: 189 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,189 @@
1+
export const meta = {
2+
name: 'ecc-pro-security-roadmap',
3+
description: 'Survey + web-research + triage both ECC and AgentShield, then synthesize a prioritized ECC Pro security roadmap',
4+
whenToUse: 'Quarterly product/security planning for ECC Pro and AgentShield',
5+
phases: [
6+
{ title: 'Survey', detail: 'map current AgentShield + ECC Pro capability, triage open PRs/issues on both repos' },
7+
{ title: 'Research', detail: 'recent agentic-security CVEs, competitor gaps, unbuilt ideas, Sentry/code-review feature demand' },
8+
{ title: 'Synthesize', detail: 'merge everything into a prioritized, MRR-biased roadmap' }
9+
]
10+
};
11+
12+
// ----- shared schemas -----
13+
const TRIAGE_SCHEMA = {
14+
type: 'object',
15+
additionalProperties: false,
16+
properties: {
17+
repo: { type: 'string' },
18+
items: {
19+
type: 'array',
20+
items: {
21+
type: 'object',
22+
additionalProperties: false,
23+
properties: {
24+
ref: { type: 'string', description: 'e.g. "PR #103" or "issue #102"' },
25+
title: { type: 'string' },
26+
category: { type: 'string', enum: ['merge', 'close', 'needs-work', 'triage-later', 'security-priority'] },
27+
rationale: { type: 'string' },
28+
proValue: { type: 'string', description: 'how this maps to ECC Pro / MRR, or "none"' }
29+
},
30+
required: ['ref', 'title', 'category', 'rationale', 'proValue']
31+
}
32+
},
33+
summary: { type: 'string' }
34+
},
35+
required: ['repo', 'items', 'summary']
36+
};
37+
38+
const CAPABILITY_SCHEMA = {
39+
type: 'object',
40+
additionalProperties: false,
41+
properties: {
42+
area: { type: 'string' },
43+
haveToday: { type: 'array', items: { type: 'string' } },
44+
gaps: { type: 'array', items: { type: 'string' } },
45+
proLeverage: { type: 'array', items: { type: 'string' }, description: 'what could plausibly be paid/Pro-tier' },
46+
summary: { type: 'string' }
47+
},
48+
required: ['area', 'haveToday', 'gaps', 'proLeverage', 'summary']
49+
};
50+
51+
const RESEARCH_SCHEMA = {
52+
type: 'object',
53+
additionalProperties: false,
54+
properties: {
55+
topic: { type: 'string' },
56+
findings: {
57+
type: 'array',
58+
items: {
59+
type: 'object',
60+
additionalProperties: false,
61+
properties: {
62+
title: { type: 'string' },
63+
detail: { type: 'string' },
64+
source: { type: 'string', description: 'URL, CVE id, or product name' },
65+
gapVsUs: { type: 'string', enum: ['we-have-it', 'partial', 'missing'] },
66+
relevanceToAgentShield: { type: 'string' },
67+
proOpportunity: { type: 'string', description: 'how this could become ECC Pro / paid value' }
68+
},
69+
required: ['title', 'detail', 'source', 'gapVsUs', 'proOpportunity']
70+
}
71+
},
72+
summary: { type: 'string' }
73+
},
74+
required: ['topic', 'findings', 'summary']
75+
};
76+
77+
const ROADMAP_SCHEMA = {
78+
type: 'object',
79+
additionalProperties: false,
80+
properties: {
81+
themes: {
82+
type: 'array',
83+
items: {
84+
type: 'object',
85+
additionalProperties: false,
86+
properties: { name: { type: 'string' }, rationale: { type: 'string' } },
87+
required: ['name', 'rationale']
88+
}
89+
},
90+
items: {
91+
type: 'array',
92+
items: {
93+
type: 'object',
94+
additionalProperties: false,
95+
properties: {
96+
title: { type: 'string' },
97+
area: { type: 'string', enum: ['agentshield', 'ecc-pro', 'ecc-core', 'both'] },
98+
horizon: { type: 'string', enum: ['now', 'next', 'later'] },
99+
effort: { type: 'string', enum: ['S', 'M', 'L', 'XL'] },
100+
impact: { type: 'string', enum: ['low', 'medium', 'high', 'flagship'] },
101+
mrrAngle: { type: 'string' },
102+
description: { type: 'string' },
103+
linkedItems: { type: 'array', items: { type: 'string' } }
104+
},
105+
required: ['title', 'area', 'horizon', 'effort', 'impact', 'mrrAngle', 'description', 'linkedItems']
106+
}
107+
},
108+
top5Now: { type: 'array', items: { type: 'string' } },
109+
summary: { type: 'string' }
110+
},
111+
required: ['themes', 'items', 'top5Now', 'summary']
112+
};
113+
114+
const GUARDRAILS = [
115+
'CONSTRAINTS: research/triage only. Do NOT modify any code, do NOT open/close/merge PRs, do NOT post comments,',
116+
'do NOT send any external message. Return findings as data only.',
117+
'Brand it "ECC" (never "everything claude code"). AgentShield was FEATURED at a hackathon, never say it "won".',
118+
'AgentShield npm package is "ecc-agentshield". Local clone: ~/GitHub/ECC/agentshield. ECC repo: affaan-m/ECC. AgentShield repo: affaan-m/agentshield.',
119+
'You have Bash (gh CLI), Read, Grep, Glob, and web tools (load via ToolSearch: WebSearch / firecrawl / exa).'
120+
].join(' ');
121+
122+
phase('Survey');
123+
124+
const surveyThunks = [
125+
() =>
126+
agent(
127+
`${GUARDRAILS}\n\nSURVEY AgentShield's CURRENT detection capability. Read ~/GitHub/ECC/agentshield: src/rules (built-in detectors), src/* area dirs (taint, injection, supply-chain, runtime, threat-intel, sandbox, policy, remediation, evidence-pack, harness-adapters), README.md, CHANGELOG.md, WORKING-CONTEXT.md. Produce an honest capability map: what classes of agentic-security risk it detects TODAY, where the gaps are, and which capabilities could plausibly be a paid/Pro tier (e.g. continuous monitoring, fleet dashboards, hosted scanning, evidence packs, org policy). area="agentshield-capability".`,
128+
{ label: 'survey:agentshield-capability', phase: 'Survey', agentType: 'general-purpose', schema: CAPABILITY_SCHEMA }
129+
),
130+
() =>
131+
agent(
132+
`${GUARDRAILS}\n\nSURVEY the CURRENT state of ECC Pro / paid surface. Read in ~/GitHub/ECC/everything-claude-code: scripts/lib/control-pane/* (control pane, proximity, viz), scripts/lib/agent-proximity/*, docs/design/agent-proximity.md, README.md, any pricing/Pro/Enterprise mentions. Determine: what is free vs what is positioned as Pro/Enterprise today, what monetizable surfaces exist (control pane, 3D agent-airspace observability, shared knowledge, JIT team workflows, kanban), and where the paid value story is thin. area="ecc-pro-surface".`,
133+
{ label: 'survey:ecc-pro-surface', phase: 'Survey', agentType: 'general-purpose', schema: CAPABILITY_SCHEMA }
134+
),
135+
() =>
136+
agent(
137+
`${GUARDRAILS}\n\nTRIAGE every OPEN PR and ISSUE on the ECC repo (affaan-m/ECC). Use gh: \`gh pr list --repo affaan-m/ECC --state open --limit 80 --json number,title,author,isDraft\` and \`gh issue list --repo affaan-m/ECC --state open --limit 80 --json number,title,labels\`. For the higher-signal ones, peek at the diff/body (\`gh pr view <n> --repo affaan-m/ECC\`). Categorize each: merge / close / needs-work / triage-later / security-priority, with a one-line rationale and any Pro/MRR value. Prioritize identifying security-relevant and Pro-relevant items. repo="affaan-m/ECC".`,
138+
{ label: 'triage:ecc', phase: 'Survey', agentType: 'general-purpose', schema: TRIAGE_SCHEMA }
139+
),
140+
() =>
141+
agent(
142+
`${GUARDRAILS}\n\nTRIAGE every OPEN PR and ISSUE on the AgentShield repo (affaan-m/agentshield). Use gh similarly. Pay special attention to the false-positive cluster (issues #100, #102, #99 "bm", PR #103) where the scanner penalizes its own recommended fix and flags benign strings — these hurt trust and conversion. Also assess #101 (external rule-pack loader --rule-pack) and #97 (FAQ docs). Categorize each: merge / close / needs-work / triage-later / security-priority, with rationale and Pro/MRR value. repo="affaan-m/agentshield".`,
143+
{ label: 'triage:agentshield', phase: 'Survey', agentType: 'general-purpose', schema: TRIAGE_SCHEMA }
144+
)
145+
];
146+
147+
phase('Research');
148+
149+
const researchThunks = [
150+
() =>
151+
agent(
152+
`${GUARDRAILS}\n\nDEEP RESEARCH: recent (2025-2026) CVEs and disclosed vulnerability classes in AGENTIC / LLM / MCP security that a scanner like AgentShield should detect. Use web tools (ToolSearch then WebSearch / firecrawl / exa). Cover: MCP server vulns (tool poisoning, rug-pull tool updates, prompt injection via tool descriptions, confused-deputy), CVEs in popular agent frameworks / MCP servers, npm/PyPI supply-chain attacks targeting AI tooling, prompt-injection-driven RCE, memory/context poisoning, credential exfiltration via agents. For each finding mark gapVsUs (we-have-it / partial / missing) vs AgentShield's current detectors, and the Pro opportunity. topic="agentic-cves-2025-2026".`,
153+
{ label: 'research:cves', phase: 'Research', agentType: 'general-purpose', schema: RESEARCH_SCHEMA }
154+
),
155+
() =>
156+
agent(
157+
`${GUARDRAILS}\n\nDEEP RESEARCH: competitor / adjacent tools in agent + LLM + supply-chain security and what they do that AgentShield does NOT. Use web tools. Cover products like: Protect AI, Lakera, Prompt Security, HiddenLayer, Snyk, Socket.dev, Endor Labs, Semgrep, GitGuardian, Invariant Labs (MCP-scan), Cloudflare/others' MCP security, plus any new entrants. For each, note their headline capability, whether AgentShield has it (gapVsUs), and how a comparable or better capability could be packaged as ECC Pro paid value. Also: pull npm download stats for "ecc-agentshield" to ground the growth story if reachable. topic="competitor-gap-analysis".`,
158+
{ label: 'research:competitors', phase: 'Research', agentType: 'general-purpose', schema: RESEARCH_SCHEMA }
159+
),
160+
() =>
161+
agent(
162+
`${GUARDRAILS}\n\nIDEATION: agentic-security capabilities that have been discussed/considered for AgentShield or ECC but NOT yet built, plus net-new ideas grounded in the threat model. Read ~/GitHub/ECC/agentshield/WORKING-CONTEXT.md and any docs/ for hints of deferred work; read the AgentShield README for the current feature set; then reason about the gaps. Think across the kill chain: discovery/config scan -> PR-time review -> CI gate -> runtime monitor -> incident evidence. Candidate ideas: real-time runtime guardrails, MCP supply-chain provenance/lockfile attestation, taint-tracking across tool calls, behavioral baselining of agents, secret/credential flow tracing, autofix with verification, hosted continuous scanning + dashboards, org policy as code, agent-identity/least-privilege. Mark gapVsUs and proOpportunity for each. topic="unbuilt-ideation".`,
163+
{ label: 'research:ideation', phase: 'Research', agentType: 'general-purpose', schema: RESEARCH_SCHEMA }
164+
),
165+
() =>
166+
agent(
167+
`${GUARDRAILS}\n\nRESEARCH: what developers actually want from existing security + code-review tooling (Sentry, GitHub code scanning / CodeQL, Snyk, Semgrep, SonarQube, Dependabot) and where those tools fall short for AI-agent codebases. Use web tools (look at user complaints, feature requests, comparison posts). Identify the unmet demand AgentShield Pro could capture: e.g. PR-time security review tuned for agent configs, low-false-positive findings, IDE/editor integration, runtime error+security telemetry like Sentry but for agents, autofix, SARIF/GitHub integration, evidence/compliance packs. For each, gapVsUs and proOpportunity. topic="devtool-demand-gaps".`,
168+
{ label: 'research:devtool-demand', phase: 'Research', agentType: 'general-purpose', schema: RESEARCH_SCHEMA }
169+
)
170+
];
171+
172+
// Survey and research have no cross-dependency; run all 8 concurrently (the
173+
// runtime caps concurrency anyway) and barrier here — synthesis needs everything.
174+
const [survey, research] = await Promise.all([parallel(surveyThunks), parallel(researchThunks)]);
175+
176+
const surveyClean = survey.filter(Boolean);
177+
const researchClean = research.filter(Boolean);
178+
log(`survey: ${surveyClean.length}/4 returned, research: ${researchClean.length}/4 returned`);
179+
180+
phase('Synthesize');
181+
182+
const bundle = JSON.stringify({ survey: surveyClean, research: researchClean }, null, 2);
183+
184+
const roadmap = await agent(
185+
`${GUARDRAILS}\n\nYou are the synthesis lead. Below is JSON from 4 survey agents (AgentShield capability, ECC Pro surface, ECC repo triage, AgentShield repo triage) and 4 research agents (CVEs, competitors, unbuilt ideation, devtool demand).\n\nProduce a PRIORITIZED, MRR-BIASED roadmap for ECC Pro (its AgentShield and ECC portions). Rules:\n- Bias hard toward what converts free users to paid and grows MRR. AgentShield is doing ~10k npm downloads/week (~30k/month) on "ecc-agentshield" - that is a huge top-of-funnel; the roadmap must include how to monetize that funnel (Pro tier, hosted scanning, dashboards, org policy, evidence/compliance packs).\n- Group into a few themes. Each roadmap item: area (agentshield/ecc-pro/ecc-core/both), horizon (now/next/later), effort (S/M/L/XL), impact (low/medium/high/flagship), a concrete mrrAngle, a description, and linkedItems (PR/issue refs from the triage that map to it).\n- Fold the AgentShield false-positive cluster fixes into "now" (trust is a conversion gate).\n- top5Now = the five highest-leverage things to do immediately.\n\nDATA:\n${bundle}`,
186+
{ label: 'synthesize:roadmap', phase: 'Synthesize', agentType: 'general-purpose', schema: ROADMAP_SCHEMA }
187+
);
188+
189+
return { survey: surveyClean, research: researchClean, roadmap };

0 commit comments

Comments
 (0)