SkillAgentSearch skills...

ccs-reproducibility

Use when strengthening ACM CCS reproducibility evidence, including the artifact-availability posture, threat-model-to-evidence mapping, attack reproduction steps, defense overhead measurement, measurement-dataset provenance, environment and version pinning, and honest justification when artifacts ca…

Install / Use

npx skills add brycewang-stanford/Awesome-Journal-Skills --skill ccs-reproducibility

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

83/100

Supported Platforms

Universal

Tags

Our assessment of ccs-reproducibility

ccs-reproducibility scores 83/100 on our quality scale, 2896th of 4,610 Development & Engineering skills we index.

Its SKILL.md is 3.5 KB long, split into 6 sections with 1 code example: a solid amount of guidance for an agent.

With 1,158 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
15/20
Description
15/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 18 days ago, so ccs-reproducibility is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

ccs-reproducibility compared with similar skills

All 4 of these similar skills score higher than ccs-reproducibility; compare them before choosing.

SkillScoreStarsUpdatedFormat
ccs-reproducibility (this skill)by brycewang-stanford831.2k18d agoSKILL.md
ai-job-searchby MadsLorentzen10044.8ktodayCLAUDE.md
claude-howtoby luongnv8910041.7k3d agoCLAUDE.md
algorithmic-artby anthropics100177.9k10d agoSKILL.md
pptxby anthropics100177.9k10d agoSKILL.md

Frequently asked questions

How do I install ccs-reproducibility?
Run npx skills add brycewang-stanford/Awesome-Journal-Skills --skill ccs-reproducibility. The install tabs above show the steps for each supported agent.
Which AI agents does ccs-reproducibility work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is ccs-reproducibility safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is ccs-reproducibility still maintained?
The repository was last updated 18 days ago, so ccs-reproducibility is actively maintained.

name: ccs-reproducibility description: Use when strengthening ACM CCS reproducibility evidence, including the artifact-availability posture, threat-model-to-evidence mapping, attack reproduction steps, defense overhead measurement, measurement-dataset provenance, environment and version pinning, and honest justification when artifacts cannot be shared.

CCS Reproducibility

Use this before submission and again before the artifact-evaluation deadline. Reopen the current CFP and call for artifacts to confirm what availability statement and packaging CCS expects this cycle.

Evidence map

  • Map each security claim — every attack, defense guarantee, and measurement result — to a verifiable location: a script, a config, a dataset, a proof, or a logged run.
  • For attacks, record the target's exact version and configuration, the attacker's resource budget, and the sequence of steps that reproduce the exploit.
  • For defenses, record the workload, the overhead-measurement method, the hardware, and the adaptive attacker used, so the cost-versus-security tradeoff can be rechecked.
  • For measurements, document the vantage point, the collection window, the sampling frame, known blind spots, and the ground-truth validation.
  • When artifacts cannot be shared — licensing, responsible disclosure, subject safety, or premature-release risk — say so explicitly and offer partial, synthetic, or redacted artifacts that still let a reader assess the methodology.

Availability-posture table

| Claim type | What full sharing looks like | Honest fallback when sharing is blocked | |---|---|---| | Exploit against deployed software | Runnable PoC plus target build | Redacted PoC, disclosed-and-patched note, synthetic target | | Defense with overhead numbers | Instrumented build and benchmark scripts | Binaries plus measurement scripts if source is proprietary | | Internet-scale measurement | Dataset plus collection tooling | Aggregated data with subject-privacy justification for the rest | | Cryptographic protocol | Reference implementation and test vectors | Spec plus test vectors if the implementation is embargoed |

Claiming an artifact is unavailable without a reason CCS accepts (a license, a disclosure embargo, subject safety) reads as evasion; state the specific reason and offer the closest shareable substitute.

Vignette: a measurement paper on vulnerable hosts

Consider a study scanning the Internet for a misconfiguration. Its reproducibility spine: the scan methodology and rate-limiting, the classification rule for "vulnerable," the ground-truth sample validated by hand, the ethics of scanning and notification, and an aggregated dataset that preserves the finding without exposing individual vulnerable hosts to opportunistic attackers.

Degrees of reproducibility

  • Turnkey: one command reproduces the attack or the overhead measurement from pinned configs.
  • Scripted: scripts exist but need documented manual steps or gated data access.
  • Descriptive: prose detailed enough that a competent security researcher could rebuild it.

For CCS, aim turnkey for anything you submit to artifact evaluation, and state the achieved level honestly rather than overpromising a one-command reproduction that fails on a clean host.

Output format

[Claim inventory] <claim -> evidence location>
[Availability posture] full / partial / justified-withheld
[Reproducibility gaps] <versions / configs / budgets / provenance / ethics>
[Paper fixes] <must appear in main PDF or appendix>
[Artifact fixes] <packaging additions before the AE deadline>

Related Skills

View on GitHub
GitHub Stars1.2k
CategoryDevelopment
Updated18d ago
Forks153

Languages

Stata

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions