Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
55 commits
Select commit Hold shift + click to select a range
f698e3e
docs: add MRR-biased ECC Pro + AgentShield security roadmap
affaan-m Jun 22, 2026
a26a0d5
docs(design): add hosted Pro fleet dashboard design (Sentry for agent…
affaan-m Jun 22, 2026
e8244d9
feat(control-pane): serve 3D agent-airspace viz + /api/proximity feed…
affaan-m Jun 25, 2026
e3f4679
fix(clv2): escape $HOME before pgrep -f in migrate-homunculus.sh (#2339)
gaurav0107 Jun 25, 2026
2bc924f
fix(clv2): harden registry writes and project deletion (#2294, #2297)…
affaan-m Jun 25, 2026
1031d31
feat(workflows): add orch-review native Workflow pilot (#2363)
pythonstrup Jun 29, 2026
d65d3e0
Update yarn.lock (#2342)
danielnguyenfinhub Jun 29, 2026
909ae2f
Add memxus configuration to mcp-servers.json (#2355)
gpitrella Jun 29, 2026
85dfb07
Fix for docs: Scope Decision Guide table duplicated in SKILL.md and o…
Angad2005 Jun 29, 2026
8973d0f
fix(llm): align Claude provider with current Anthropic API (#2133)
quadcent Jun 29, 2026
9896644
fix(release): derive approval gate paths from version (#2383)
SiaoZeng Jun 29, 2026
73895b5
fix(release): derive video suite paths from version (#2384)
SiaoZeng Jun 29, 2026
00b443e
ci: isolate OMP workflow verification (#2382)
SiaoZeng Jun 29, 2026
acd078f
fix(tests): resolve 10 failing tests on Windows (#2307)
Tahiti18 Jun 29, 2026
b1d5d63
fix(hooks): quote args when probing Windows .cmd MCP servers via shel…
phobicdotno Jun 29, 2026
88f6894
fix(hooks): guard doc-file-warning stdin listeners behind require.mai…
sshworld Jun 29, 2026
64797fd
fix(windows): prefer PowerShell over bash to prevent zombie process a…
cd1amond Jun 29, 2026
c295012
feat(session): LLM-powered session summary via claude -p (#2388)
Tanaka-VivereGratis Jun 29, 2026
1ba1640
chore(deps): update anthropic requirement from >=0.25.0 to >=0.111.0 …
dependabot[bot] Jun 29, 2026
e676d1d
chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#2328)
dependabot[bot] Jun 29, 2026
891412c
chore(deps): bump slsa-framework/slsa-github-generator/.github/workfl…
dependabot[bot] Jun 29, 2026
333e3bb
chore(deps): bump cron from 0.16.0 to 0.17.0 in /ecc2 (#2333)
dependabot[bot] Jun 29, 2026
f54c0b2
chore(deps-dev): update pytest requirement from >=8.0 to >=9.1.1 (#2324)
dependabot[bot] Jun 29, 2026
61fd5b2
chore(deps-dev): update mypy requirement from >=1.10 to >=2.1.0 (#2326)
dependabot[bot] Jun 29, 2026
723399f
chore(deps-dev): update pytest-cov requirement from >=4.1 to >=7.1.0 …
dependabot[bot] Jun 29, 2026
ad08352
chore(deps): bump the actions-minor-and-patch group across 1 director…
dependabot[bot] Jun 29, 2026
6d36d1e
chore(deps): bump the cargo-minor-and-patch group across 1 directory …
dependabot[bot] Jun 29, 2026
2159ed2
chore(deps-dev): bump eslint from 9.39.2 to 10.6.0 (#2260)
dependabot[bot] Jun 29, 2026
0cf17cc
fix(ci): unbreak main after dependabot batch (checkout SHA + lint) (#…
affaan-m Jun 30, 2026
61c103d
feat: add ecc-recipes skill (#2319)
KyawZinLatt Jun 30, 2026
237b0b9
feat(skills): add mailtrap-email-integration skill (#2288)
dieudonneAwa Jun 30, 2026
d178db8
docs(code-tour): document ref-field semantics to prevent PR-tour file…
carloscarvallo Jun 30, 2026
ec49251
fix(gateguard): finish tool-agnostic checklist across edit gate and S…
mc856 Jun 30, 2026
8c75abf
feat(skills): harden the file upload validation section in django-sec…
jvirgovic Jun 30, 2026
3a46c82
docs(skills): update Prisma and Zod API patterns for cross-version co…
m18897829375 Jun 30, 2026
7976e6f
feat(skills): make tdd-workflow test-runner aware (npm/pnpm/yarn/bun)…
pythonstrup Jun 30, 2026
1c3a989
refactor(commands): remove duplicated content in skill-create and lea…
pythonstrup Jun 30, 2026
be91f21
chore(catalog): sync manifests after skill batch (#2319 #2288 #2273 #…
affaan-m Jun 30, 2026
f12b106
fix(clv2): align Python _update_registry schema with shell counterpar…
gaurav0107 Jun 30, 2026
a89b32c
fix(clv2): serialize observer signal-counter to stop dropped incremen…
gaurav0107 Jun 30, 2026
a6d12ec
fix(clv2): surface SIGALRM timeout drops in observe.sh (#2373)
gaurav0107 Jun 30, 2026
a36148f
test(clv2): add coverage for instinct-cli prune, projects ops, promot…
gaurav0107 Jun 30, 2026
f720885
fix(clv2): archive observations only after successful analysis in obs…
gaurav0107 Jun 30, 2026
c2bcc4e
feat(continuous-learning-v2): make observer model configurable via EC…
jack-finance-able Jun 30, 2026
a141db3
feat(rules,skills): add React Native / Expo rules pack and react-nati…
yerros Jun 30, 2026
b5806b3
Add growth-log skill: methodology for effective learning capture (#2377)
YuhaoLin2005 Jun 30, 2026
51bced9
Stop hook: verify thinking quality at session end — task completeness…
YuhaoLin2005 Jun 30, 2026
0bd2b2c
feat: add loop-design-check skill (design + review goal-oriented agen…
qshanx Jun 30, 2026
81af407
chore(catalog): sync manifests + fix skill emoji (wave 2) (#2395)
affaan-m Jun 30, 2026
6fac227
fix(plan-orchestrate): detect ecc@ecc marketplace + emit ecc: agent p…
devin-ai-integration[bot] Jul 4, 2026
3af4676
refactor: consolidate duplicated hook-root resolver into shared resol…
devin-ai-integration[bot] Jul 4, 2026
1a74709
fix: docs/COMMAND-REGISTRY.json check fails on fresh Windows clone (m…
Cb2i Jul 4, 2026
914a58a
feat(workflows): re-land orch-review workflow + add /orch-review comm…
pythonstrup Jul 4, 2026
18d9780
Merge branch 'pr2321' into merge-test-2321
affaan-m Jul 4, 2026
b8df3e0
docs: replace personal absolute paths with repo-relative agentshield/…
affaan-m Jul 4, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
docs: add MRR-biased ECC Pro + AgentShield security roadmap
Output of a multi-agent survey + research pass: capability map of AgentShield
and ECC Pro, triage of every open PR/issue on both repos, and web research on
competitors, unbuilt ideas, and dev-tool demand. 17 items across 4 themes
(now/next/later) scored for free-to-paid conversion, each linked to the real
PRs/issues that implement it. Includes the reusable workflow script that
generated it.

Headline: ecc-agentshield is ~30K downloads/month with near-zero monetization
bridge, and the agent-proximity moat is computed but never rendered. Roadmap
removes trust blockers (FP cluster), makes the moat visible (PR #2320), then
productizes local CLI primitives into hosted Pro surfaces.
  • Loading branch information
affaan-m committed Jun 22, 2026
commit f698e3edfd911b3895bf9bbe5027e995d21ce0e5
189 changes: 189 additions & 0 deletions .claude/workflows/ecc-pro-security-roadmap.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,189 @@
export const meta = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Workflow surface placement conflicts with AGENTS.md policy

AGENTS.md designates skills/ as the canonical workflow surface and states "New workflow contributions should land in skills/ first." Placing this file under .claude/workflows/ instead bypasses that convention. If .claude/workflows/ is intentionally a separate, framework-level runtime surface distinct from ECC skills, a brief comment in the file or a pointer in AGENTS.md would clarify the distinction for future contributors.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

name: 'ecc-pro-security-roadmap',
description: 'Survey + web-research + triage both ECC and AgentShield, then synthesize a prioritized ECC Pro security roadmap',
whenToUse: 'Quarterly product/security planning for ECC Pro and AgentShield',
phases: [
{ title: 'Survey', detail: 'map current AgentShield + ECC Pro capability, triage open PRs/issues on both repos' },
{ title: 'Research', detail: 'recent agentic-security CVEs, competitor gaps, unbuilt ideas, Sentry/code-review feature demand' },
{ title: 'Synthesize', detail: 'merge everything into a prioritized, MRR-biased roadmap' }
]
};

// ----- shared schemas -----
const TRIAGE_SCHEMA = {
type: 'object',
additionalProperties: false,
properties: {
repo: { type: 'string' },
items: {
type: 'array',
items: {
type: 'object',
additionalProperties: false,
properties: {
ref: { type: 'string', description: 'e.g. "PR #103" or "issue #102"' },
title: { type: 'string' },
category: { type: 'string', enum: ['merge', 'close', 'needs-work', 'triage-later', 'security-priority'] },
rationale: { type: 'string' },
proValue: { type: 'string', description: 'how this maps to ECC Pro / MRR, or "none"' }
},
required: ['ref', 'title', 'category', 'rationale', 'proValue']
}
},
summary: { type: 'string' }
},
required: ['repo', 'items', 'summary']
};

const CAPABILITY_SCHEMA = {
type: 'object',
additionalProperties: false,
properties: {
area: { type: 'string' },
haveToday: { type: 'array', items: { type: 'string' } },
gaps: { type: 'array', items: { type: 'string' } },
proLeverage: { type: 'array', items: { type: 'string' }, description: 'what could plausibly be paid/Pro-tier' },
summary: { type: 'string' }
},
required: ['area', 'haveToday', 'gaps', 'proLeverage', 'summary']
};

const RESEARCH_SCHEMA = {
type: 'object',
additionalProperties: false,
properties: {
topic: { type: 'string' },
findings: {
type: 'array',
items: {
type: 'object',
additionalProperties: false,
properties: {
title: { type: 'string' },
detail: { type: 'string' },
source: { type: 'string', description: 'URL, CVE id, or product name' },
gapVsUs: { type: 'string', enum: ['we-have-it', 'partial', 'missing'] },
relevanceToAgentShield: { type: 'string' },
proOpportunity: { type: 'string', description: 'how this could become ECC Pro / paid value' }
},
required: ['title', 'detail', 'source', 'gapVsUs', 'proOpportunity']

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 relevanceToAgentShield is declared in the RESEARCH_SCHEMA properties but omitted from the required array. Agents can skip it silently and schema validation will pass — meaning the synthesis step may receive incomplete research objects where the key relevance mapping is absent without any error or warning.

Suggested change
required: ['title', 'detail', 'source', 'gapVsUs', 'proOpportunity']
required: ['title', 'detail', 'source', 'gapVsUs', 'relevanceToAgentShield', 'proOpportunity']

}
},
summary: { type: 'string' }
},
required: ['topic', 'findings', 'summary']
};
Comment on lines +51 to +75

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Schema inconsistency: relevanceToAgentShield is optional while other fields are required.

In RESEARCH_SCHEMA, the field relevanceToAgentShield appears in properties (line 66) but is omitted from the required array (line 69). All other schemas (TRIAGE_SCHEMA, CAPABILITY_SCHEMA, ROADMAP_SCHEMA) require every defined property. This breaks the pattern and makes relevanceToAgentShield silently optional, which may allow research agents to skip relevance assessments.

🔧 Proposed fix to make the field required
     },
     summary: { type: 'string' }
   },
-  required: ['topic', 'findings', 'summary']
+  required: ['topic', 'findings', 'summary'],
+  patternProperties: {
+    '^findings$': {
+      items: {
+        required: ['title', 'detail', 'source', 'gapVsUs', 'relevanceToAgentShield', 'proOpportunity']
+      }
+    }
+  }
 };

Alternatively, if relevanceToAgentShield is intentionally optional, document why it deviates from the all-required pattern used in the other three schemas.

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
const RESEARCH_SCHEMA = {
type: 'object',
additionalProperties: false,
properties: {
topic: { type: 'string' },
findings: {
type: 'array',
items: {
type: 'object',
additionalProperties: false,
properties: {
title: { type: 'string' },
detail: { type: 'string' },
source: { type: 'string', description: 'URL, CVE id, or product name' },
gapVsUs: { type: 'string', enum: ['we-have-it', 'partial', 'missing'] },
relevanceToAgentShield: { type: 'string' },
proOpportunity: { type: 'string', description: 'how this could become ECC Pro / paid value' }
},
required: ['title', 'detail', 'source', 'gapVsUs', 'proOpportunity']
}
},
summary: { type: 'string' }
},
required: ['topic', 'findings', 'summary']
};
const RESEARCH_SCHEMA = {
type: 'object',
additionalProperties: false,
properties: {
topic: { type: 'string' },
findings: {
type: 'array',
items: {
type: 'object',
additionalProperties: false,
properties: {
title: { type: 'string' },
detail: { type: 'string' },
source: { type: 'string', description: 'URL, CVE id, or product name' },
gapVsUs: { type: 'string', enum: ['we-have-it', 'partial', 'missing'] },
relevanceToAgentShield: { type: 'string' },
proOpportunity: { type: 'string', description: 'how this could become ECC Pro / paid value' }
},
required: ['title', 'detail', 'source', 'gapVsUs', 'relevanceToAgentShield', 'proOpportunity']
}
},
summary: { type: 'string' }
},
required: ['topic', 'findings', 'summary']
};
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/workflows/ecc-pro-security-roadmap.js around lines 51 - 75, The
RESEARCH_SCHEMA has an inconsistency where the property relevanceToAgentShield
is defined in the properties object of the findings items but is missing from
the required array. To fix this and align with the pattern used in
TRIAGE_SCHEMA, CAPABILITY_SCHEMA, and ROADMAP_SCHEMA where all defined
properties are required, add relevanceToAgentShield to the required array within
the findings items schema. The required array should include title, detail,
source, gapVsUs, relevanceToAgentShield, and proOpportunity.


const ROADMAP_SCHEMA = {
type: 'object',
additionalProperties: false,
properties: {
themes: {
type: 'array',
items: {
type: 'object',
additionalProperties: false,
properties: { name: { type: 'string' }, rationale: { type: 'string' } },
required: ['name', 'rationale']
}
},
items: {
type: 'array',
items: {
type: 'object',
additionalProperties: false,
properties: {
title: { type: 'string' },
area: { type: 'string', enum: ['agentshield', 'ecc-pro', 'ecc-core', 'both'] },
horizon: { type: 'string', enum: ['now', 'next', 'later'] },
effort: { type: 'string', enum: ['S', 'M', 'L', 'XL'] },
impact: { type: 'string', enum: ['low', 'medium', 'high', 'flagship'] },
mrrAngle: { type: 'string' },
description: { type: 'string' },
linkedItems: { type: 'array', items: { type: 'string' } }
},
required: ['title', 'area', 'horizon', 'effort', 'impact', 'mrrAngle', 'description', 'linkedItems']
}
},
top5Now: { type: 'array', items: { type: 'string' } },
summary: { type: 'string' }
},
required: ['themes', 'items', 'top5Now', 'summary']
};

const GUARDRAILS = [
'CONSTRAINTS: research/triage only. Do NOT modify any code, do NOT open/close/merge PRs, do NOT post comments,',
'do NOT send any external message. Return findings as data only.',
'Brand it "ECC" (never "everything claude code"). AgentShield was FEATURED at a hackathon, never say it "won".',
'AgentShield npm package is "ecc-agentshield". Local clone: ~/GitHub/ECC/agentshield. ECC repo: affaan-m/ECC. AgentShield repo: affaan-m/agentshield.',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Hardcoded personal local filesystem paths make the workflow non-portable. Any contributor on a different machine will get ENOENT errors from the agent() calls because ~/GitHub/ECC/agentshield and ~/GitHub/ECC/everything-claude-code almost certainly don't exist there. The paths should be expressed relative to the repository root or converted to environment-variable references that callers can override.

Suggested change
'AgentShield npm package is "ecc-agentshield". Local clone: ~/GitHub/ECC/agentshield. ECC repo: affaan-m/ECC. AgentShield repo: affaan-m/agentshield.',
`AgentShield npm package is "ecc-agentshield". Local clone: ${process.env.AGENTSHIELD_PATH ?? '~/GitHub/ECC/agentshield'}. ECC repo: affaan-m/ECC. AgentShield repo: affaan-m/agentshield.`,

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

'You have Bash (gh CLI), Read, Grep, Glob, and web tools (load via ToolSearch: WebSearch / firecrawl / exa).'
].join(' ');

phase('Survey');

const surveyThunks = [
() =>
agent(
`${GUARDRAILS}\n\nSURVEY AgentShield's CURRENT detection capability. Read ~/GitHub/ECC/agentshield: src/rules (built-in detectors), src/* area dirs (taint, injection, supply-chain, runtime, threat-intel, sandbox, policy, remediation, evidence-pack, harness-adapters), README.md, CHANGELOG.md, WORKING-CONTEXT.md. Produce an honest capability map: what classes of agentic-security risk it detects TODAY, where the gaps are, and which capabilities could plausibly be a paid/Pro tier (e.g. continuous monitoring, fleet dashboards, hosted scanning, evidence packs, org policy). area="agentshield-capability".`,
{ label: 'survey:agentshield-capability', phase: 'Survey', agentType: 'general-purpose', schema: CAPABILITY_SCHEMA }
),
() =>
agent(
`${GUARDRAILS}\n\nSURVEY the CURRENT state of ECC Pro / paid surface. Read in ~/GitHub/ECC/everything-claude-code: scripts/lib/control-pane/* (control pane, proximity, viz), scripts/lib/agent-proximity/*, docs/design/agent-proximity.md, README.md, any pricing/Pro/Enterprise mentions. Determine: what is free vs what is positioned as Pro/Enterprise today, what monetizable surfaces exist (control pane, 3D agent-airspace observability, shared knowledge, JIT team workflows, kanban), and where the paid value story is thin. area="ecc-pro-surface".`,
{ label: 'survey:ecc-pro-surface', phase: 'Survey', agentType: 'general-purpose', schema: CAPABILITY_SCHEMA }
),
() =>
agent(
`${GUARDRAILS}\n\nTRIAGE every OPEN PR and ISSUE on the ECC repo (affaan-m/ECC). Use gh: \`gh pr list --repo affaan-m/ECC --state open --limit 80 --json number,title,author,isDraft\` and \`gh issue list --repo affaan-m/ECC --state open --limit 80 --json number,title,labels\`. For the higher-signal ones, peek at the diff/body (\`gh pr view <n> --repo affaan-m/ECC\`). Categorize each: merge / close / needs-work / triage-later / security-priority, with a one-line rationale and any Pro/MRR value. Prioritize identifying security-relevant and Pro-relevant items. repo="affaan-m/ECC".`,
{ label: 'triage:ecc', phase: 'Survey', agentType: 'general-purpose', schema: TRIAGE_SCHEMA }
),
() =>
agent(
`${GUARDRAILS}\n\nTRIAGE every OPEN PR and ISSUE on the AgentShield repo (affaan-m/agentshield). Use gh similarly. Pay special attention to the false-positive cluster (issues #100, #102, #99 "bm", PR #103) where the scanner penalizes its own recommended fix and flags benign strings — these hurt trust and conversion. Also assess #101 (external rule-pack loader --rule-pack) and #97 (FAQ docs). Categorize each: merge / close / needs-work / triage-later / security-priority, with rationale and Pro/MRR value. repo="affaan-m/agentshield".`,
{ label: 'triage:agentshield', phase: 'Survey', agentType: 'general-purpose', schema: TRIAGE_SCHEMA }
)
];

phase('Research');

const researchThunks = [
() =>
agent(
`${GUARDRAILS}\n\nDEEP RESEARCH: recent (2025-2026) CVEs and disclosed vulnerability classes in AGENTIC / LLM / MCP security that a scanner like AgentShield should detect. Use web tools (ToolSearch then WebSearch / firecrawl / exa). Cover: MCP server vulns (tool poisoning, rug-pull tool updates, prompt injection via tool descriptions, confused-deputy), CVEs in popular agent frameworks / MCP servers, npm/PyPI supply-chain attacks targeting AI tooling, prompt-injection-driven RCE, memory/context poisoning, credential exfiltration via agents. For each finding mark gapVsUs (we-have-it / partial / missing) vs AgentShield's current detectors, and the Pro opportunity. topic="agentic-cves-2025-2026".`,
{ label: 'research:cves', phase: 'Research', agentType: 'general-purpose', schema: RESEARCH_SCHEMA }
),
() =>
agent(
`${GUARDRAILS}\n\nDEEP RESEARCH: competitor / adjacent tools in agent + LLM + supply-chain security and what they do that AgentShield does NOT. Use web tools. Cover products like: Protect AI, Lakera, Prompt Security, HiddenLayer, Snyk, Socket.dev, Endor Labs, Semgrep, GitGuardian, Invariant Labs (MCP-scan), Cloudflare/others' MCP security, plus any new entrants. For each, note their headline capability, whether AgentShield has it (gapVsUs), and how a comparable or better capability could be packaged as ECC Pro paid value. Also: pull npm download stats for "ecc-agentshield" to ground the growth story if reachable. topic="competitor-gap-analysis".`,
{ label: 'research:competitors', phase: 'Research', agentType: 'general-purpose', schema: RESEARCH_SCHEMA }
),
() =>
agent(
`${GUARDRAILS}\n\nIDEATION: agentic-security capabilities that have been discussed/considered for AgentShield or ECC but NOT yet built, plus net-new ideas grounded in the threat model. Read ~/GitHub/ECC/agentshield/WORKING-CONTEXT.md and any docs/ for hints of deferred work; read the AgentShield README for the current feature set; then reason about the gaps. Think across the kill chain: discovery/config scan -> PR-time review -> CI gate -> runtime monitor -> incident evidence. Candidate ideas: real-time runtime guardrails, MCP supply-chain provenance/lockfile attestation, taint-tracking across tool calls, behavioral baselining of agents, secret/credential flow tracing, autofix with verification, hosted continuous scanning + dashboards, org policy as code, agent-identity/least-privilege. Mark gapVsUs and proOpportunity for each. topic="unbuilt-ideation".`,
{ label: 'research:ideation', phase: 'Research', agentType: 'general-purpose', schema: RESEARCH_SCHEMA }
),
() =>
agent(
`${GUARDRAILS}\n\nRESEARCH: what developers actually want from existing security + code-review tooling (Sentry, GitHub code scanning / CodeQL, Snyk, Semgrep, SonarQube, Dependabot) and where those tools fall short for AI-agent codebases. Use web tools (look at user complaints, feature requests, comparison posts). Identify the unmet demand AgentShield Pro could capture: e.g. PR-time security review tuned for agent configs, low-false-positive findings, IDE/editor integration, runtime error+security telemetry like Sentry but for agents, autofix, SARIF/GitHub integration, evidence/compliance packs. For each, gapVsUs and proOpportunity. topic="devtool-demand-gaps".`,
{ label: 'research:devtool-demand', phase: 'Research', agentType: 'general-purpose', schema: RESEARCH_SCHEMA }
)
];

// Survey and research have no cross-dependency; run all 8 concurrently (the
// runtime caps concurrency anyway) and barrier here — synthesis needs everything.
const [survey, research] = await Promise.all([parallel(surveyThunks), parallel(researchThunks)]);

const surveyClean = survey.filter(Boolean);
const researchClean = research.filter(Boolean);
log(`survey: ${surveyClean.length}/4 returned, research: ${researchClean.length}/4 returned`);

phase('Synthesize');

const bundle = JSON.stringify({ survey: surveyClean, research: researchClean }, null, 2);

const roadmap = await agent(
`${GUARDRAILS}\n\nYou are the synthesis lead. Below is JSON from 4 survey agents (AgentShield capability, ECC Pro surface, ECC repo triage, AgentShield repo triage) and 4 research agents (CVEs, competitors, unbuilt ideation, devtool demand).\n\nProduce a PRIORITIZED, MRR-BIASED roadmap for ECC Pro (its AgentShield and ECC portions). Rules:\n- Bias hard toward what converts free users to paid and grows MRR. AgentShield is doing ~10k npm downloads/week (~30k/month) on "ecc-agentshield" - that is a huge top-of-funnel; the roadmap must include how to monetize that funnel (Pro tier, hosted scanning, dashboards, org policy, evidence/compliance packs).\n- Group into a few themes. Each roadmap item: area (agentshield/ecc-pro/ecc-core/both), horizon (now/next/later), effort (S/M/L/XL), impact (low/medium/high/flagship), a concrete mrrAngle, a description, and linkedItems (PR/issue refs from the triage that map to it).\n- Fold the AgentShield false-positive cluster fixes into "now" (trust is a conversion gate).\n- top5Now = the five highest-leverage things to do immediately.\n\nDATA:\n${bundle}`,
{ label: 'synthesize:roadmap', phase: 'Synthesize', agentType: 'general-purpose', schema: ROADMAP_SCHEMA }
);

return { survey: surveyClean, research: researchClean, roadmap };
Loading