Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[curriculum-eval] side-quest-17-07-repo-poisoning.md: cognitive_load/active_learning — three defenses presented back-to-back without checkpoints

クローズ 初心者向け
#3,853 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
88/100
issue の種類
ドキュメント
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
markdown

調査の方向性

workshop/side-quest-17-07-repo-poisoning.md を編集し、「AW はこれにどう対処するか」の下にある3つの小節に加えて、「攻撃」と「これが重要な理由」に焦点を当てます。各防御の後に短いセルフチェックを追加し、3つのコードサンプルと既存のcheckpointを維持したまま、重複している導入部分を削減してから、npx --yes markdownlint-cli2 "**/*.md" を実行します。3つの防御が維持され、それぞれにチェックリストがあり、Markdown lintコマンドが成功すれば完了です。

索引モデルが issue の本文から書いたものです。

説明

curriculum documentation quality

File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.95 / 10.0 (corpus mean: 6.09)

Flagged Dimensions:

Dimension Score Benchmark Delta
cognitive_load 5.8 ≤ 800 words, ≤ 15 new concepts −2.2 word count (1234 words); −4.0 concepts (23 vs. 15)
active_learning 2.7 density ≥ 3 −7.3 (density 0.81)

Note: checkpoint_quality is reported as 0.0/has_checkpoint: false due to a confirmed tooling regex bug (see companion issue on curriculum_assessment.py) — this file has a ## :white_check_mark: Checkpoint with 6 items. Excluded from this finding.

Root Cause (≤ 2 sentences):
This step layers three distinct defensive techniques (read-only permissions, create-pull-request safe-outputs, and network.allowed-domains) plus an attack narrative and a "Why This Matters" section into one 1234-word, 23-new-concept page, well above both the word-count and concept-count ideals for a single step, while the three YAML code samples are dense but not paired with any intermediate checklist/decision points to break up the reading.

Evidence (quoted from the file):

gh-aw gives you three layers to prevent repository poisoning.

Declare read-only permissions ... ### Route writes through a pull request ... ### Restrict outbound network access

Learning Science Rationale:
Sweller's Cognitive Load Theory recommends chunking a topic with three parallel sub-techniques into digestible units with a checkpoint between them; presenting all three YAML-configured defenses back-to-back in one long scroll, on top of the attack-scenario narrative that precedes them, risks split-attention and extraneous load for a security topic where precise recall of each defense matters. This is a create-level side quest ("Apply the three gh-aw defences"), which is pedagogically appropriate as a capstone security topic, but the density argues for restructuring rather than removing content.

Improvement Prompt (for an agent):

Edit workshop/side-quest-17-07-repo-poisoning.md to reduce cognitive load while preserving all three defenses:

1. Add a short "Quick self-check" checklist (- [ ] ...) after each of the three ### subsections under "How AW Defends Against It" (read-only permissions, pull-request routing, network.allowed-domains), asking the learner to confirm they can identify the relevant frontmatter key for that defense in their own workflow file. This breaks the three-technique block into three checkable chunks and raises measurable activity density.
2. Trim "The Attack" and "Why This Matters" sections by ~150-200 words combined, keeping the core scenario (issue body -> hidden instruction -> exfiltrated secret) but removing repeated framing sentences that restate the same risk in different words.
3. Keep the existing ## :white_check_mark: Checkpoint section and all three code samples intact.
4. Re-run npx --yes markdownlint-cli2 "**/*.md" after editing.

Expected Score After Fix: 6.9 / 10.0

Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 84.8 AIC · ⌖ 7.78 AIC · ⊞ 9K · ◷

  • expires on Sep 27, 2026, 8:49 AM UTC
主要言語
JavaScript
スター
49
フォーク
20
平均マージ
7時間 55分
マージ済み PR(30日)
30

環境構築

このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

githubnext/gh-aw-workshop のほかの issue

githubnext/gh-aw-workshop の issue をすべて見る

似ている issue

JavaScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。