Security Deep Dive Short
alpha-omega-security/scrutineer
Eval-only short-prompt variant of security-deep-dive for A/B testing against the production prompt.
A skill your agent uses when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses…
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills usenixsec-experiments --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/USENIX-Security-Skills/skills/usenixsec-experiments .claude/skills/usenixsec-experiments && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "usenixsec-experiments" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/USENIX-Security-Skills/skills/usenixsec-experiments into .claude/skills/usenixsec-experiments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "usenixsec-experiments", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/USENIX-Security-Skills/skills/usenixsec-experimentsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills usenixsec-experiments --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/USENIX-Security-Skills/skills/usenixsec-experiments .agents/skills/usenixsec-experiments && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "usenixsec-experiments" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/USENIX-Security-Skills/skills/usenixsec-experiments into .agents/skills/usenixsec-experiments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "usenixsec-experiments", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills usenixsec-experiments --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/USENIX-Security-Skills/skills/usenixsec-experiments .cursor/skills/usenixsec-experiments && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "usenixsec-experiments" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/USENIX-Security-Skills/skills/usenixsec-experiments into .cursor/skills/usenixsec-experiments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "usenixsec-experiments", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/brycewang-stanford/Awesome-Journal-Skills.git --path USENIX-Security-Skills/skills/usenixsec-experiments--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills usenixsec-experiments --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/USENIX-Security-Skills/skills/usenixsec-experiments .gemini/skills/usenixsec-experiments && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "usenixsec-experiments" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/USENIX-Security-Skills/skills/usenixsec-experiments into .gemini/skills/usenixsec-experiments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "usenixsec-experiments", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills usenixsec-experimentsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/USENIX-Security-Skills/skills/usenixsec-experiments .github/skills/usenixsec-experiments && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "usenixsec-experiments" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/USENIX-Security-Skills/skills/usenixsec-experiments into .github/skills/usenixsec-experiments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "usenixsec-experiments", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install brycewang-stanford/Awesome-Journal-Skills usenixsec-experiments --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/USENIX-Security-Skills/skills/usenixsec-experiments .opencode/skills/usenixsec-experiments && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "usenixsec-experiments" agent skill from https://github.com/brycewang-stanford/Awesome-Journal-Skills/tree/main/USENIX-Security-Skills/skills/usenixsec-experiments into .opencode/skills/usenixsec-experiments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "usenixsec-experiments", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
usenixsec-experimentsA skill your agent uses when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses…
Usenixsec Experiments is an agent skill from brycewang-stanford/Awesome-Journal-Skills. Use when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses, false-positive and vantage-point rigor for detection and measurement, ethical experimentation on live systems, and honest baselines.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering A/B testing and Threat modeling. The repository describes itself as: Journal-specific Claude Code/Codex skill packs covering mainstream journals — AER, QJE, Nature, Cell, 管理世界, 经济研究 & 200+ more — your fast track to getting published. | 覆盖主流期刊的… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 932eb23. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Usenixsec Experiments loads about 1.5k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 662 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from brycewang-stanford/Awesome-Journal-Skills at commit 932eb23, republished under its MIT licence (© brycewang-stanford). 662 words, ~1,472 tokens.
.claude/skills/usenixsec-experiments/SKILL.md (or your agent's skills folder).The evaluation is where USENIX Security papers are won or lost, and the committee
reads it as an adversary would: looking for the experiment you did not run because
it would have hurt. This skill audits security evaluations against the venue's
specific rigor bars. It pairs with usenixsec-reproducibility (making runs
regenerable) and usenixsec-writing-style (reporting them).
| Claim type | The experiment reviewers demand | The usual gap |
|---|---|---|
| Attack | End-to-end demonstration on a realistic target, success rate over trials | Works only in a toy setup; success rate is one lucky run |
| Defense | Adaptive attacker who knows the defense, plus overhead | Evaluated only against the original, non-adaptive attack |
| Detection | Detection rate and false-positive rate on realistic base rates | FPR measured on a clean dataset, not deployment traffic |
| Measurement | Cross-vantage / cross-time validity of the finding | Single vantage, single snapshot, over-generalized |
| System/protocol | Correctness + performance vs a credible baseline | Baseline is a strawman or an unoptimized reimplementation |
The recurring failure is the non-adaptive defense evaluation. A defense that stops the attack it was designed against proves little; reviewers want the attacker who adapts to the defense, and its absence is the single most common reason a technically sound defense paper is rejected here.
Detection and classification results live or die on realistic base rates. A 99% detection rate with a 1% false-positive rate is useless at internet scale where benign events outnumber malicious ones a million to one. Report:
# Precision at deployment base rate — the number a security reviewer recomputes
def precision_at_base_rate(tpr, fpr, base_rate):
tp = tpr * base_rate
fp = fpr * (1 - base_rate)
return tp / (tp + fp) if (tp + fp) else float("nan")
# 99% TPR, 1% FPR sounds great; at 1-in-100k malicious it is nearly worthless:
print(precision_at_base_rate(0.99, 0.01, 1e-5)) # ~0.00099Fuzzing, randomized attacks, timing side channels, and ML pipelines are all nondeterministic. The venue expects distributions, not anecdotes:
Much USENIX Security evaluation touches real networks, real users, or real devices. The evaluation design and the Ethical Considerations appendix must agree:
[Claim-experiment map] each claim → experiment → threat-model consistency
[Adaptive check] defense evaluated against an adaptive attacker: yes/no
[Base-rate check] FPR + precision at deployment base rate reported: yes/no
[Statistics] repetitions + dispersion for stochastic results
[Ethics] live-system controls in methodology and appendix aligned
[Gaps] ordered fix list before submission© brycewang-stanford, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in USENIX-Security-Skills/skills/usenixsec-experiments of brycewang-stanford/Awesome-Journal-Skills.
Open the folder on GitHubat commit 932eb23
Usenixsec Experiments next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Usenixsec Experiments this skillbrycewang-stanford/Awesome-Journal-Skills | 1.2k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Security Deep Dive Shortalpha-omega-security/scrutineer | 239 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 188 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Create Rulecartography-cncf/cartography | 4.1k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Commit Security Scancodexstar69/bug-hunter | 519 | — | ~629 | Automated safety check: Pass | MIT |
alpha-omega-security/scrutineer
Eval-only short-prompt variant of security-deep-dive for A/B testing against the production prompt.
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
cartography-cncf/cartography
Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when running and reporting the analysis for an Annals of the American Association of Geographers manuscript — spatial statistics and modeling, remote-sensing accuracy, or…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when positioning an Annals of the American Association of Geographers manuscript in the literature — engaging geographic scholarship across the relevant area and the…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when responding to an Annals of the American Association of Geographers decision letter (major/minor revision) — building a point-by-point response to the subject editor and…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when defending the research design of an Annals of the American Association of Geographers manuscript — spatial/quantitative analysis and GIScience, remote-sensing and…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when you need to understand how the Annals of the American Association of Geographers evaluates a manuscript — double-anonymous review routed through a subject editor by…
brycewang-stanford/Awesome-Journal-Skills
A skill your agent uses when running the final pre-submission preflight for the Annals of the American Association of Geographers via ScholarOne Manuscripts — area/article-type selection…
Categories
A skill your agent uses when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses…. Usenixsec Experiments is an agent skill from brycewang-stanford/Awesome-Journal-Skills. Use when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses, false-positive and vantage-point rigor for detection and measurement, ethical experimentation on live systems, and honest baselines.
Usenixsec Experiments fits situations like: auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments; adaptive-attacker analysis for defenses; false-positive and vantage-point rigor for detection and measurement; ethical experimentation on live systems.
Run `npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a claude-code`. Or copy the skill folder (USENIX-Security-Skills/skills/usenixsec-experiments in brycewang-stanford/Awesome-Journal-Skills) into .claude/skills/usenixsec-experiments in your project. Claude Code loads it when a task matches its description.
Run `npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a codex`. Or copy the skill folder (USENIX-Security-Skills/skills/usenixsec-experiments in brycewang-stanford/Awesome-Journal-Skills) into .agents/skills/usenixsec-experiments in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/usenixsec-experiments, .gemini/skills/usenixsec-experiments, .github/skills/usenixsec-experiments and .opencode/skills/usenixsec-experiments in your project.
SKILL.md names no scripts, command-line tools or credentials: Usenixsec Experiments is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Usenixsec Experiments is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Usenixsec Experiments: Security Deep Dive Short (alpha-omega-security/scrutineer, 239 stars), Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Forensify (alexgreensh/repo-forensics, 188 stars) and Create Rule (cartography-cncf/cartography, 4.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
brycewang-stanford (a GitHub user) maintains it in brycewang-stanford/Awesome-Journal-Skills, which has 1,228 GitHub stars. The repository holds 2,387 skills in this directory. The repository was last updated on September 27, 2026.
Source: brycewang-stanford/Awesome-Journal-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.