ccs-experiments
Use when designing or auditing ACM CCS experiments, attack demonstrations, adaptive-attack defense evaluations, security measurements, baselines, overhead and cost reporting, ablations, and claim-to-evidence fit, with emphasis on evidence that survives an adversarial program committee rather than le…
Install / Use
npx skills add brycewang-stanford/Awesome-Journal-Skills --skill ccs-experimentsInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of ccs-experiments
ccs-experiments scores 83/100 on our quality scale, 836th of 1,062 Security skills we index.
Its SKILL.md is 3.7 KB long, split into 7 sections with 1 code example: a solid amount of guidance for an agent.
With 1,158 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 18 days ago, so ccs-experiments is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
ccs-experiments compared with similar skills
All 4 of these similar skills score higher than ccs-experiments; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| ccs-experiments (this skill)by brycewang-stanford | 83 | 1.2k | 18d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 12d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 12d ago | SKILL.md |
Frequently asked questions
- How do I install ccs-experiments?
- Run
npx skills add brycewang-stanford/Awesome-Journal-Skills --skill ccs-experiments. The install tabs above show the steps for each supported agent. - Which AI agents does ccs-experiments work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is ccs-experiments safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is ccs-experiments still maintained?
- The repository was last updated 18 days ago, so ccs-experiments is actively maintained.
Skill content
View source on GitHubname: ccs-experiments description: Use when designing or auditing ACM CCS experiments, attack demonstrations, adaptive-attack defense evaluations, security measurements, baselines, overhead and cost reporting, ablations, and claim-to-evidence fit, with emphasis on evidence that survives an adversarial program committee rather than leaderboard wins.
CCS Experiments
Use this before submission when the attack demonstration, defense evaluation, or measurement story is not yet locked.
Experiment audit
- Map each security claim to a specific artifact: an exploit run, an overhead measurement, a coverage number, a false-positive/false-negative table, or a measurement dataset.
- For attacks, demonstrate the exploit against a realistic, named target (software version, platform, configuration) and report the resource cost to the attacker.
- For defenses, evaluate against an adaptive attacker built with knowledge of the defense, and report performance overhead, memory cost, and any compatibility breakage.
- For measurements, validate sampling: document the population, the vantage point, coverage and blind spots, and ground-truth checks against known cases.
- Include baselines that represent the state of the art in attack or defense, not strawmen.
- Report variance for stochastic results and audit for leakage, selection bias, and any mismatch between the threat model and the tested configuration.
What experiments are for at this venue
- CCS experiments exist to make a security claim undeniable to a skeptic, not to top a benchmark. One clean end-to-end exploit against a real target outweighs a table of micro-benchmarks.
- The strongest defense design triad: the attack it stops, an adaptive attack that knows the defense, and a deployment-cost measurement. Missing the middle element is the classic CCS defense reject.
- Reviewers, often practitioners, check whether the evaluation environment matches the threat model. A defense claimed for production but tested only on a toy in a lab invites the relevance question.
Attack-and-defense evaluation table
| Security claim | Matching evidence | Reject pattern avoided | |---|---|---| | Exploit is practical | End-to-end run on named target with attacker cost | "Works only in a lab against a strawman" | | Defense stops the attack | Detection/prevention rate on the original attack | "No numbers, only a design argument" | | Defense resists adaptation | Adaptive attacker with defense knowledge, degraded results | "Only the non-adaptive attack was tried" | | Deployment is feasible | Overhead, memory, compatibility on a realistic workload | "Security claimed, cost never measured" |
Vignette: evaluating a control-flow-integrity defense
Suppose the paper proposes a fine-grained CFI scheme. The matching plan: reproduce a known code-reuse attack and show it blocked; construct an adaptive attacker that respects the CFI policy and search for surviving gadget chains; then measure runtime overhead and binary-size growth on a standard benchmark suite. Every claim ties to a numbered table, and the adaptive result is reported even when it dents the headline.
Reporting floor
- Name every target's exact version and configuration; "a popular browser" is not a target.
- Report the attacker's resource budget (queries, time, samples) and the defense's measured overhead rather than vague "negligible cost" language.
Output format
[Experiment readiness] strong / adequate / weak
[Claim -> evidence map] <claim: exploit run / overhead table / measurement>
[Missing security evidence] <adaptive attack / baseline / cost / validation>
[Threat-model mismatch] <where the setup breaks the stated model>
[Decision-critical next run] <one experiment>
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
