CCS Artifact Evaluation

SkillSecurity

Use when packaging ACM CCS artifacts for the artifact-evaluation committee and the ACM badges — Artifacts Available, Artifacts Evaluated Functional, Artifacts Evaluated Reusable, and Results Reproduced — covering what security evaluators inspect, how to make attacks and defenses turnkey, and how to justify withheld artifacts.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the CCS Artifact Evaluation skill

What this skill tells your AI

The instructions your AI receives, as published by brycewang-stanford/awesome-journal-skills in ACM-CCS-Skills/skills/ccs-artifact-evaluation/SKILL.md and read by ahel’s review.

Use this for artifact packaging around CCS. CCS runs an optional artifact-evaluation process after acceptance; passing artifacts earn ACM badges that appear on the paper's first page. Reopen the current call for artifacts for the exact badge set, submission form, and deadlines.

The ACM badge ladder

BadgeWhat it certifiesWhat the committee does
Artifacts AvailableThe artifact is publicly archived with a stable identifierConfirms the artifact is retrievable and permanent
Artifacts Evaluated - FunctionalThe artifact runs and does what the paper saysExecutes it against the documented steps
Artifacts Evaluated - ReusableIt exceeds functional quality and others can reuse itJudges structure, documentation, and reusability
Results ReproducedThe main paper results are independently reproducedReruns experiments and checks they support the claims

Available is about archival permanence; Functional and Reusable are about quality; Results Reproduced is the highest bar and requires the committee to regenerate your headline numbers.

Artifact plan

  • Decide which claims the artifact must support: the exploit, the defense overhead, the measurement pipeline, or the protocol implementation.
  • Make the security claim turnkey: one documented command per headline result, with expected output, runtime, and the hardware assumed.
  • Anonymize nothing at this stage — artifact evaluation is post-acceptance and single-blind or open — but do pin versions, dependencies, and a container so it runs on a clean machine.
  • For dangerous artifacts (working exploits, malware, live attack tooling), gate access, document safe-handling, and follow the responsible-disclosure posture from the paper.
  • Justify anything withheld: licensing, disclosure embargo, subject safety, or premature-release risk, and offer partial, synthetic, or redacted substitutes that still let evaluators check the method.

What security evaluators open first

Claim typeFirst artifact inspectedCommon failure caught
Exploit against real softwareThe PoC and its target build instructionsTarget version unspecified; PoC fails to build
Defense with overhead numbersThe benchmark runner and instrumented buildOverhead cannot be reproduced; workload undocumented
Measurement studyThe collection and classification scriptsClassification rule differs from the paper's prose
Cryptographic implementationTest vectors and the reference buildNo test vectors; outputs cannot be checked

Worked vignette: packaging a fuzzing-tool artifact

A hypothetical accepted paper presents a new fuzzer that found N bugs. For Reusable and Results Reproduced: ship a container pinning the fuzzer, the target corpus, and the seed set; document one command to reproduce a representative crash and one to rerun a bounded campaign; provide the bug list with disclosure status; and note which crashes are embargoed pending vendor patches, offering redacted reproducers for those.

Output format

[Target badges] available / functional / reusable / results-reproduced
[Contents] <code / data / container / test vectors / logs>
[Turnkey level] one-command / scripted / descriptive / weak
[Safe-handling] <gating and disclosure posture for dangerous artifacts>
[Withheld-and-justified] <what and why, with substitute offered>
[Fixes before submission] <ordered list>

Signals

GitHub stars
1k
Forks
146
Last commit
Aug 2026
Advanced
Catalog kind
skill
Gateway key
ccs-artifact-evaluation
Source
github.com/brycewang-stanford/awesome-journal-skills