---
name: cfp-combined-review
description: Review one CFP draft through separate cybersecurity-conference and hacker-conference lenses, then reconcile their advice. Use when the target venue is undecided, the author wants a cross-conference stress test, or a proposal may need different framing for different audiences.
---

# Combined CFP review

Produce two honest assessments and one revision plan. Do not average the scores: the profiles use different dimensions and denominators.

Read both [references/cybersecurity-rubric.md](references/cybersecurity-rubric.md) and [references/hacker-rubric.md](references/hacker-rubric.md) before reviewing.

## Review

1. Collect the complete draft and supporting facts. Unknown publication, disclosure, or commercial-relationship answers remain unknown.
2. Perform one meaning-focused reading pass. Verify novelty with current authoritative sources when available; otherwise label it unverified.
3. Score the cybersecurity profile out of 100 and the hacker profile out of 97. Never rescale or average them.
4. Identify shared findings first. Then identify real disagreements: practical defensive value versus hacker fit, tool-supported research versus demo shape, professional audience reach versus practitioner mechanism, and disclosure/timeliness differences.
5. Produce one ranked revision plan. A shared concern outranks a venue-specific polish issue. Explain when the same research needs different framing for the two rooms.

Never invent research, evidence, CVEs, versions, results, sources, credentials, or release plans. For Black Hat, refine author-written text within the current AI-use rules rather than originating a submission.

## Response

Lead with two score cards: `cybersecurity score/100` and `hacker score/97`, each with its own band. Follow with shared blockers, venue-specific findings, strengths, open questions, and a single three-to-five-item revision plan. End with a venue-fit recommendation based on the demonstrated work and state its uncertainty.


---

# Included reference: cybersecurity-rubric.md

# Cybersecurity profile

Score: novelty and differentiation 20; technical depth and outline 17; practical value 10; evidence and deliverable 14; vendor neutrality 10; speaker credibility 8; claims realism 5; audience draw 6; disclosure maturity 5; track and audience fit 5. Total 100.

Bands: 85–100 strong on the page; 65–84 solid with gaps; 45–64 borderline; below 45 not ready.

Judge the specific contribution rather than the topic. Separate novelty from a dramatic target. Credit useful, actionable defensive work. Require a followable outline, disclosed commercial context, bounded claims, and mature vulnerability disclosure when applicable. Earlier work is neutral when the increment is substantial and explicit; an unchanged recorded talk is a major timeliness problem. Treat tool-program redirects as format advice.


---

# Included reference: hacker-rubric.md

# Hacker profile

Score: evidence of a real break 25; hacker-talk fit 25; outline quality 18; novelty articulation 9; concreteness 10; speaker credibility 10. Total 97 by design.

Bands: 75–97 strong shape; 65–74 competitive; 55–64 borderline; 45–54 weak for the room; below 45 not ready.

Require an artifact, method, result, or irreplaceable first-hand account. Identify whether the abstract speaks to practitioners or buyers. The outline must contain the attack or evidence. Known primitives may produce a new capability; prior presentation is neutral when differentiated. Do not over-penalize normal exploit preconditions, tool-program redirects, or honest prior art. War stories use first-hand access as evidence but still need a transferable lesson.

