Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[curriculum-eval] side-quest-17-07-repo-poisoning.md: cognitive_load — four defense layers taught in one uninterrupted pass (23 concepts)

Cerrado Apto para principiantes
#3,897 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
78/100
Tipo de issue
Documentación
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
markdown

Línea de trabajo

Abre workshop/side-quest-17-07-repo-poisoning.md y revisa la introducción y las cuatro subsecciones de defensa nombradas. Comprueba la redacción del número de capas y coloca la autocomprobación solicitada después de las dos primeras subsecciones, dejando sin cambios los ejercicios existentes y el Checkpoint final. La tarea está terminada cuando la página refleja la estructura de capas acordada e incluye la lista de comprobación de recuperación intermedia.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

curriculum documentation quality

File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.95 / 10.0 (corpus mean: 6.09) — second-lowest score in the corpus
Corrected Overall Score (after fixing the checkpoint/scaffolding regex bug reported separately): 7.70 / 10.0 — cognitive_load and active_learning remain the residual gaps.

Flagged Dimensions:

Dimension Score Benchmark Delta
cognitive_load 5.8 ≤800 words, ≤15 new concepts -2.1 (1234 words, 54% over target) and -4.0 (23 concepts, 53% over the 15-concept ceiling)
active_learning 2.7 density ≥ 3 -0.3 (density 0.81)

Root Cause (≤ 2 sentences):
This page teaches four independent defense layers in one pass (contents: read permissions, safe-outputs: create-pull-request, protected-files path restrictions, and network.allowed-domains), each introducing its own distinct frontmatter syntax and config keys, which drives the concept count to 23 — the highest new-concept load flagged in the corpus alongside the highest word count among findings.

Evidence (quoted from the file):

"gh-aw gives you three layers to prevent repository poisoning."

[followed by four ##-level subsections: "Declare read-only permissions", "Route writes through a pull request", "Restrict which paths can change", "Limit network destinations" — each with its own YAML frontmatter example]

The intro promises "three layers" but the page actually walks through four distinct defensive mechanisms back-to-back with no intermediate checkpoint, each requiring the learner to hold the prior mechanism's syntax in memory while absorbing the next.

Learning Science Rationale:
Sweller's Cognitive Load Theory identifies "element interactivity" as the key driver of intrinsic load: concepts that must be understood simultaneously (here, four defensive YAML configurations that compose together) impose far more working-memory burden than an equivalent word count of independent facts. Presenting all four defenses in one uninterrupted pass before any practice or self-check risks exceeding working memory capacity (typically cited as ~4 chunks), especially for the corpus's most content-dense side quest.

Improvement Prompt (for an agent):

In workshop/side-quest-17-07-repo-poisoning.md, reduce concept density and add mid-page retrieval practice:

1. Fix the intro line "gh-aw gives you three layers to prevent repository poisoning." to say "four layers" (it currently undercounts the four subsections that follow: read-only permissions, safe-outputs PR routing, protected-files path restrictions, and network.allowed-domains) — or alternatively, merge "Restrict which paths can change" into the "Route writes through a pull request" section as a sub-point, since protected-files is a modifier of create-pull-request rather than a standalone layer, reducing four taught layers to three.

2. After the first two subsections ("Declare read-only permissions" and "Route writes through a pull request"), insert a short 2-item checklist self-check before continuing to the remaining layers, e.g.:
   - [ ] I can explain why `contents: read` alone prevents a direct commit
   - [ ] I can explain what `create-pull-request` adds on top of read-only permissions

   This breaks the four-layer block into two smaller chunks with a retrieval checkpoint between them, reducing simultaneous element interactivity.

3. Keep the existing "Spot the Dangerous Frontmatter" and "Harden Your Workflow" exercises and the final Checkpoint unchanged.

Expected Score After Fix: ≈8.2 / 10.0 (concept load reduced from 23 toward ~17-18 by merging protected-files under create-pull-request; activity_density raised slightly by the added mid-page checklist; combined with the companion checkpoint/scaffolding regex fix already applied in the corrected baseline).

Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 147.3 AIC · ⌖ 18.6 AIC · ⊞ 9K · ◷

  • expires on Sep 28, 2026, 9:51 AM UTC
Lenguaje dominante
JavaScript
Estrellas
49
Forks
20
Merge medio
9 h 44 min
PR fusionados (30 d)
25

Preparar el entorno

Aún no hemos revisado los archivos de configuración de este proyecto. Empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de githubnext/gh-aw-workshop

Todos los issues de githubnext/gh-aw-workshop

Issues similares

Más issues de JavaScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.