Make sure you build from source, or you won't be able to properly debug. I've been tied up with other things, but the PoC didn't want to build for me as-is, and I didn't have more than a few mins to spare, so I didn't do any editing. Tomorrow I'm taking a day off from EVERYTHING, since I finally finished the project that has kept me busy (I really hate iOS apps). Starting Monday, I'll take a closer look, if no one else has by then.
The two PoC's handle the hard stuff, it's not like you need to build your ROP chains from scratch.
Alternatively, if anyone has access to one of the various jtag setups (typically used for unlocking and restoring bricks) you could dump the entire nand for me... If I've got no luck with anything else, I'll get the bus pirate and usbjtagnt out and really go to work. That shouldn't be needed though.