A skill your agent uses when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses…

MITAuto-check passedSecurity

Install Usenixsec Experiments

skills CLI
$ npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install brycewang-stanford/Awesome-Journal-Skills usenixsec-experiments --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/brycewang-stanford/Awesome-Journal-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/USENIX-Security-Skills/skills/usenixsec-experiments .claude/skills/usenixsec-experiments && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
usenixsec-experiments
GitHub stars
1.2k
Token cost
~1.5k tokens
SKILL.md length
662 words
Files
1
Skills in repo
2,387
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses…

  • Works in 4 steps: Scanning/measurement: rate-limit, honor… → Human subjects: IRB approval or a… → Vulnerability testing: prefer owned or… → …
  • Auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments
  • SKILL.md covers Match the experiment to the…, The base-rate discipline for…, Statistical honesty for… and Experimenting on live systems,…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Usenixsec Experiments is an agent skill from brycewang-stanford/Awesome-Journal-Skills. Use when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses, false-positive and vantage-point rigor for detection and measurement, ethical experimentation on live systems, and honest baselines.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering A/B testing and Threat modeling. The repository describes itself as: Journal-specific Claude Code/Codex skill packs covering mainstream journals — AER, QJE, Nature, Cell, 管理世界, 经济研究 & 200+ more — your fast track to getting published. | 覆盖主流期刊的… The licence is MIT.

When your agent uses it

  • Auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments
  • Adaptive-attacker analysis for defenses
  • False-positive and vantage-point rigor for detection and measurement
  • Ethical experimentation on live systems

Example prompts

  • “/usenixsec-experiments”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Scanning/measurement: rate-limit, honor opt-out and blocklists, use
  2. Human subjects: IRB approval or a documented equivalent; if the work would
  3. Vulnerability testing: prefer owned or authorized targets; for
  4. Data handling: minimize collection, protect any PII, and delete per the

What it can do on your machine

Read from SKILL.md and the folder at commit 932eb23. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Usenixsec Experiments loads about 1.5k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 662 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from brycewang-stanford/Awesome-Journal-Skills at commit 932eb23, republished under its MIT licence (© brycewang-stanford). 662 words, ~1,472 tokens.

Download SKILL.mdSave it as .claude/skills/usenixsec-experiments/SKILL.md (or your agent's skills folder).
name
usenixsec-experiments
description
Use when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses, false-positive and vantage-point rigor for detection and measurement, ethical experimentation on live systems, and honest baselines.

USENIX Security Experiments

The evaluation is where USENIX Security papers are won or lost, and the committee reads it as an adversary would: looking for the experiment you did not run because it would have hurt. This skill audits security evaluations against the venue's specific rigor bars. It pairs with usenixsec-reproducibility (making runs regenerable) and usenixsec-writing-style (reporting them).

Match the experiment to the claim type

Claim typeThe experiment reviewers demandThe usual gap
AttackEnd-to-end demonstration on a realistic target, success rate over trialsWorks only in a toy setup; success rate is one lucky run
DefenseAdaptive attacker who knows the defense, plus overheadEvaluated only against the original, non-adaptive attack
DetectionDetection rate and false-positive rate on realistic base ratesFPR measured on a clean dataset, not deployment traffic
MeasurementCross-vantage / cross-time validity of the findingSingle vantage, single snapshot, over-generalized
System/protocolCorrectness + performance vs a credible baselineBaseline is a strawman or an unoptimized reimplementation

The recurring failure is the non-adaptive defense evaluation. A defense that stops the attack it was designed against proves little; reviewers want the attacker who adapts to the defense, and its absence is the single most common reason a technically sound defense paper is rejected here.

The base-rate discipline for detection

Detection and classification results live or die on realistic base rates. A 99% detection rate with a 1% false-positive rate is useless at internet scale where benign events outnumber malicious ones a million to one. Report:

  • TPR and FPR separately, never a single "accuracy" that hides class imbalance.
  • The base rate of the deployment you claim, and the resulting precision at that base rate (the base-rate fallacy is a named reviewer objection).
  • ROC/PR behavior across thresholds, not one operating point chosen after the fact.
python
# Precision at deployment base rate — the number a security reviewer recomputes
def precision_at_base_rate(tpr, fpr, base_rate):
    tp = tpr * base_rate
    fp = fpr * (1 - base_rate)
    return tp / (tp + fp) if (tp + fp) else float("nan")

# 99% TPR, 1% FPR sounds great; at 1-in-100k malicious it is nearly worthless:
print(precision_at_base_rate(0.99, 0.01, 1e-5))   # ~0.00099

Statistical honesty for stochastic security results

Fuzzing, randomized attacks, timing side channels, and ML pipelines are all nondeterministic. The venue expects distributions, not anecdotes:

  • Repeat campaigns; report count, median, and dispersion (IQR or CI), not a max.
  • For "our fuzzer finds more bugs," control the compute budget and report bug-discovery over time across seeds, with a rank test for significance.
  • Timing/side-channel claims need enough traces to bound noise, and the analysis should survive a skeptic recomputing the statistic from released traces.
Show full SKILL.md (287 more words)Show less

Experimenting on live systems, ethically

Much USENIX Security evaluation touches real networks, real users, or real devices. The evaluation design and the Ethical Considerations appendix must agree:

  1. Scanning/measurement: rate-limit, honor opt-out and blocklists, use dedicated hosts with informative reverse DNS and a project page. Report these controls in the methodology, not only the appendix.
  2. Human subjects: IRB approval or a documented equivalent; if the work would need IRB elsewhere and you lack one, say so and describe your safeguards — the ethics guidelines call for exactly this.
  3. Vulnerability testing: prefer owned or authorized targets; for found-in-the-wild flaws, disclose before publishing and state the timeline.
  4. Data handling: minimize collection, protect any PII, and delete per the stated plan. A reviewer who spots avoidable harm can sink the paper on ethics alone, independent of the science.

Baselines and ablations that hold up

  • Compare against the state of the art, reimplemented faithfully or run from released artifacts; a beaten strawman invites a reject.
  • Ablate the components you claim matter — a "our key insight is X" claim needs the variant without X.
  • Include the honest negative space: regimes where the attack fails or the defense is too costly. Reviewers here read omission as concealment.

Pre-submission evaluation audit

  1. Every claim mapped to an experiment; every experiment to a threat-model assumption it respects.
  2. Defenses: adaptive-attacker experiment present and genuinely adaptive.
  3. Detection: FPR at realistic base rate, precision computed.
  4. Stochastic results: repetitions and dispersion reported.
  5. Live-system work: ethical controls in both methodology and appendix.
  6. Baselines current; ablations cover the claimed-critical parts.

Reverify each cycle

  • Any evaluation-reporting checklist the current CFP adds (待核实 for '27).
  • Current ethics-guidelines wording on live experiments and human subjects.

Output format

text
[Claim-experiment map] each claim → experiment → threat-model consistency
[Adaptive check] defense evaluated against an adaptive attacker: yes/no
[Base-rate check] FPR + precision at deployment base rate reported: yes/no
[Statistics] repetitions + dispersion for stochastic results
[Ethics] live-system controls in methodology and appendix aligned
[Gaps] ordered fix list before submission

© brycewang-stanford, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in USENIX-Security-Skills/skills/usenixsec-experiments of brycewang-stanford/Awesome-Journal-Skills.

Open the folder on GitHubat commit 932eb23

Compare with similar skills

Usenixsec Experiments next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Usenixsec Experiments compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Usenixsec Experiments this skillbrycewang-stanford/Awesome-Journal-Skills1.2k—~1.5kAutomated safety check: PassMIT
Security Deep Dive Shortalpha-omega-security/scrutineer239—~1.3kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Create Rulecartography-cncf/cartography4.1k—~3kAutomated safety check: PassApache-2.0
Commit Security Scancodexstar69/bug-hunter519—~629Automated safety check: PassMIT

Similar skills

  • Security Deep Dive Short

    alpha-omega-security/scrutineer

    Eval-only short-prompt variant of security-deep-dive for A/B testing against the production prompt.

    239 GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 12 days ago
    SecurityAuto-check: notes
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    SecurityAuto-check passed
  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    519 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from brycewang-stanford/Awesome-Journal-Skills

All 2,387 skills in this repo
  • Aaag Data Analysis

    brycewang-stanford/Awesome-Journal-Skills

    A skill your agent uses when running and reporting the analysis for an Annals of the American Association of Geographers manuscript — spatial statistics and modeling, remote-sensing accuracy, or…

    1.2k GitHub stars~1.3k tokensUpdated 12 days ago
    Auto-check passed
  • Aaag Literature Positioning

    brycewang-stanford/Awesome-Journal-Skills

    A skill your agent uses when positioning an Annals of the American Association of Geographers manuscript in the literature — engaging geographic scholarship across the relevant area and the…

    1.2k GitHub stars~1.3k tokensUpdated 12 days ago
    Auto-check passed
  • Aaag Rebuttal

    brycewang-stanford/Awesome-Journal-Skills

    A skill your agent uses when responding to an Annals of the American Association of Geographers decision letter (major/minor revision) — building a point-by-point response to the subject editor and…

    1.2k GitHub stars~1.4k tokensUpdated 12 days ago
    Auto-check passed
  • Aaag Research Design

    brycewang-stanford/Awesome-Journal-Skills

    A skill your agent uses when defending the research design of an Annals of the American Association of Geographers manuscript — spatial/quantitative analysis and GIScience, remote-sensing and…

    1.2k GitHub stars~1.4k tokensUpdated 12 days ago
    Auto-check passed
  • Aaag Review Process

    brycewang-stanford/Awesome-Journal-Skills

    A skill your agent uses when you need to understand how the Annals of the American Association of Geographers evaluates a manuscript — double-anonymous review routed through a subject editor by…

    1.2k GitHub stars~1.3k tokensUpdated 12 days ago
    Auto-check passed
  • Aaag Submission

    brycewang-stanford/Awesome-Journal-Skills

    A skill your agent uses when running the final pre-submission preflight for the Annals of the American Association of Geographers via ScholarOne Manuscripts — area/article-type selection…

    1.2k GitHub stars~1.6k tokensUpdated 12 days ago
    Auto-check passed

Questions about Usenixsec Experiments

What does Usenixsec Experiments do?

A skill your agent uses when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses…. Usenixsec Experiments is an agent skill from brycewang-stanford/Awesome-Journal-Skills. Use when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses, false-positive and vantage-point rigor for detection and measurement, ethical experimentation on live systems, and honest baselines.

When should I use Usenixsec Experiments?

Usenixsec Experiments fits situations like: auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments; adaptive-attacker analysis for defenses; false-positive and vantage-point rigor for detection and measurement; ethical experimentation on live systems.

How do I install Usenixsec Experiments in Claude Code?

Run `npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a claude-code`. Or copy the skill folder (USENIX-Security-Skills/skills/usenixsec-experiments in brycewang-stanford/Awesome-Journal-Skills) into .claude/skills/usenixsec-experiments in your project. Claude Code loads it when a task matches its description.

How do I install Usenixsec Experiments in Codex?

Run `npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a codex`. Or copy the skill folder (USENIX-Security-Skills/skills/usenixsec-experiments in brycewang-stanford/Awesome-Journal-Skills) into .agents/skills/usenixsec-experiments in your project. Codex loads it when a task matches its description.

Can I use Usenixsec Experiments in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add brycewang-stanford/Awesome-Journal-Skills --skill usenixsec-experiments -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/usenixsec-experiments, .gemini/skills/usenixsec-experiments, .github/skills/usenixsec-experiments and .opencode/skills/usenixsec-experiments in your project.

What does Usenixsec Experiments need to run?

SKILL.md names no scripts, command-line tools or credentials: Usenixsec Experiments is instructions for the agent only. Our summary lists: Python 3.

Does Usenixsec Experiments access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Usenixsec Experiments safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Usenixsec Experiments use?

Usenixsec Experiments is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Usenixsec Experiments use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Usenixsec Experiments?

Skills that share tags, products or a category with Usenixsec Experiments: Security Deep Dive Short (alpha-omega-security/scrutineer, 239 stars), Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Forensify (alexgreensh/repo-forensics, 188 stars) and Create Rule (cartography-cncf/cartography, 4.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Usenixsec Experiments?

brycewang-stanford (a GitHub user) maintains it in brycewang-stanford/Awesome-Journal-Skills, which has 1,228 GitHub stars. The repository holds 2,387 skills in this directory. The repository was last updated on September 27, 2026.

Source: brycewang-stanford/Awesome-Journal-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.