Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[curriculum-eval] side-quest-17-07-repo-poisoning.md: cognitive_load — 23 security concepts introduced before any worked example

オープン 初心者向け
#4,309 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
72/100
issue の種類
ドキュメント
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
github, markdown, yaml
領域
content

調査の方向性

workshop/side-quest-17-07-repo-poisoning.mdを読み、「The Attack」「Why This Matters」「How AW Defends Against It」に重点を置いてください。要求されている脆弱なYAMLの実例と「Spot the risk」演習を追加し、その後、防御策をラベル付きの例と短いチェックリストに分けてください。レッスンに大幅な文章を追加することなく、実践的な確認項目が増えていることが完了の条件です。改訂したファイルが一貫して読めることを確認してください。

索引モデルが issue の本文から書いたものです。

説明

curriculum documentation quality

File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.95 / 10.0 (corpus mean: 6.09)

Flagged Dimensions:

Dimension Score Benchmark Delta
active_learning 2.7 density ≥ 3 → 10 -7.3
cognitive_load 5.8 ≤800 words, ≤15 concepts → 10 -4.2

Root Cause (≤ 2 sentences):
This security side quest introduces 23 new concepts (permissions scoping, contents: read/write, safe-outputs: create-pull-request, network.allowed-domains, protected-files, branch protection, CODEOWNERS, content-driven manipulation) across 1,234 words of mostly narrative/explanatory prose (the "Attack" and "Why This Matters" sections) before any hands-on application, so cognitive load is high while activity density stays low.

Evidence (quoted from the file):

"Repository poisoning is what happens when a misdirected agent with write access commits changes an attacker designed — not changes the workflow author intended." — this scenario-and-rationale narrative spans roughly 300 words across two full sections before the reader reaches any applied defensive configuration.

Learning Science Rationale:
Sweller's Cognitive Load Theory predicts that introducing many new, interdependent security concepts (permission scoping, safe-outputs, network allowlisting, protected-files, branch protection) in rapid narrative succession without intermediate worked examples overloads working memory capacity (typically 4±1 novel chunks), making it hard for learners to encode the causal chain between "why the attack works" and "which specific field stops it."

Improvement Prompt (for an agent):

Edit workshop/side-quest-17-07-repo-poisoning.md to reduce cognitive load and raise active
learning density. After "The Attack" and "Why This Matters" sections, insert a short worked
example (a 5-10 line YAML code block showing a vulnerable frontmatter snippet with
`contents: write` and no `network.allowed-domains`) immediately followed by a "Spot the risk"
checklist-style micro-exercise asking the learner to identify the dangerous field before
revealing the fix. Split the "How AW Defends Against It" section (which currently introduces
contents:read, safe-outputs:create-pull-request, network.allowed-domains, and protected-files
together) into one labeled code example per defense, each with its own 1-2 item inline
checklist, so code_blocks + checklist_items increases relative to word_count without adding
new prose.

Expected Score After Fix: 6.3-6.8 / 10.0

Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 96.9 AIC · ⌖ 19.9 AIC · ⊞ 10.4K · ◷

  • expires on Oct 8, 2026, 11:43 PM UTC
主要言語
JavaScript
スター
52
フォーク
26
平均マージ
11時間 32分
マージ済み PR(30日)
22

環境構築

Codespaces で開く

このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。

  • Dockerfile・Docker Compose ファイルなし
  • プルリクエストのテンプレートなし
  • コントリビューションガイドなし

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

githubnext/gh-aw-workshop のほかの issue

githubnext/gh-aw-workshop の issue をすべて見る

似ている issue

JavaScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。