ccs-artifact-evaluation
Use when packaging ACM CCS artifacts for the artifact-evaluation committee and the ACM badges — Artifacts Available, Artifacts Evaluated Functional, Artifacts Evaluated Reusable, and Results Reproduced — covering what security evaluators inspect, how to make attacks and defenses turnkey, and how to…
Install / Use
npx skills add brycewang-stanford/Awesome-Journal-Skills --skill ccs-artifact-evaluationInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of ccs-artifact-evaluation
ccs-artifact-evaluation scores 83/100 on our quality scale, 835th of 1,062 Security skills we index.
Its SKILL.md is 3.8 KB long, split into 6 sections with 1 code example: a solid amount of guidance for an agent.
With 1,158 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 18 days ago, so ccs-artifact-evaluation is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
ccs-artifact-evaluation compared with similar skills
All 4 of these similar skills score higher than ccs-artifact-evaluation; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| ccs-artifact-evaluation (this skill)by brycewang-stanford | 83 | 1.2k | 18d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 12d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 12d ago | SKILL.md |
Frequently asked questions
- How do I install ccs-artifact-evaluation?
- Run
npx skills add brycewang-stanford/Awesome-Journal-Skills --skill ccs-artifact-evaluation. The install tabs above show the steps for each supported agent. - Which AI agents does ccs-artifact-evaluation work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is ccs-artifact-evaluation safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is ccs-artifact-evaluation still maintained?
- The repository was last updated 18 days ago, so ccs-artifact-evaluation is actively maintained.
Skill content
View source on GitHubname: ccs-artifact-evaluation description: Use when packaging ACM CCS artifacts for the artifact-evaluation committee and the ACM badges — Artifacts Available, Artifacts Evaluated Functional, Artifacts Evaluated Reusable, and Results Reproduced — covering what security evaluators inspect, how to make attacks and defenses turnkey, and how to justify withheld artifacts.
CCS Artifact Evaluation
Use this for artifact packaging around CCS. CCS runs an optional artifact-evaluation process after acceptance; passing artifacts earn ACM badges that appear on the paper's first page. Reopen the current call for artifacts for the exact badge set, submission form, and deadlines.
The ACM badge ladder
| Badge | What it certifies | What the committee does | |---|---|---| | Artifacts Available | The artifact is publicly archived with a stable identifier | Confirms the artifact is retrievable and permanent | | Artifacts Evaluated - Functional | The artifact runs and does what the paper says | Executes it against the documented steps | | Artifacts Evaluated - Reusable | It exceeds functional quality and others can reuse it | Judges structure, documentation, and reusability | | Results Reproduced | The main paper results are independently reproduced | Reruns experiments and checks they support the claims |
Available is about archival permanence; Functional and Reusable are about quality; Results Reproduced is the highest bar and requires the committee to regenerate your headline numbers.
Artifact plan
- Decide which claims the artifact must support: the exploit, the defense overhead, the measurement pipeline, or the protocol implementation.
- Make the security claim turnkey: one documented command per headline result, with expected output, runtime, and the hardware assumed.
- Anonymize nothing at this stage — artifact evaluation is post-acceptance and single-blind or open — but do pin versions, dependencies, and a container so it runs on a clean machine.
- For dangerous artifacts (working exploits, malware, live attack tooling), gate access, document safe-handling, and follow the responsible-disclosure posture from the paper.
- Justify anything withheld: licensing, disclosure embargo, subject safety, or premature-release risk, and offer partial, synthetic, or redacted substitutes that still let evaluators check the method.
What security evaluators open first
| Claim type | First artifact inspected | Common failure caught | |---|---|---| | Exploit against real software | The PoC and its target build instructions | Target version unspecified; PoC fails to build | | Defense with overhead numbers | The benchmark runner and instrumented build | Overhead cannot be reproduced; workload undocumented | | Measurement study | The collection and classification scripts | Classification rule differs from the paper's prose | | Cryptographic implementation | Test vectors and the reference build | No test vectors; outputs cannot be checked |
Worked vignette: packaging a fuzzing-tool artifact
A hypothetical accepted paper presents a new fuzzer that found N bugs. For Reusable and Results Reproduced: ship a container pinning the fuzzer, the target corpus, and the seed set; document one command to reproduce a representative crash and one to rerun a bounded campaign; provide the bug list with disclosure status; and note which crashes are embargoed pending vendor patches, offering redacted reproducers for those.
Output format
[Target badges] available / functional / reusable / results-reproduced
[Contents] <code / data / container / test vectors / logs>
[Turnkey level] one-command / scripted / descriptive / weak
[Safe-handling] <gating and disclosure posture for dangerous artifacts>
[Withheld-and-justified] <what and why, with substitute offered>
[Fixes before submission] <ordered list>
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
