Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[curriculum-eval] side-quest-17-07-repo-poisoning.md: cognitive_load — four defense layers taught in one uninterrupted pass (23 concepts)

Đang mở Phù hợp với người mới
#3,897 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 2 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
78/100
Loại issue
Tài liệu
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
markdown
Lĩnh vực
content, documentation

Hướng nghiên cứu

Mở workshop/side-quest-17-07-repo-poisoning.md và xem lại phần giới thiệu cùng bốn tiểu mục phòng thủ được nêu tên. Kiểm tra cách diễn đạt về số lượng lớp và đặt phần tự kiểm tra được yêu cầu sau hai tiểu mục đầu tiên, đồng thời giữ nguyên các bài tập hiện có và Checkpoint cuối. Được xem là hoàn tất khi trang phản ánh cấu trúc lớp đã thống nhất và bao gồm checklist truy xuất trung gian.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

curriculum documentation quality

File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.95 / 10.0 (corpus mean: 6.09) — second-lowest score in the corpus
Corrected Overall Score (after fixing the checkpoint/scaffolding regex bug reported separately): 7.70 / 10.0 — cognitive_load and active_learning remain the residual gaps.

Flagged Dimensions:

Dimension Score Benchmark Delta
cognitive_load 5.8 ≤800 words, ≤15 new concepts -2.1 (1234 words, 54% over target) and -4.0 (23 concepts, 53% over the 15-concept ceiling)
active_learning 2.7 density ≥ 3 -0.3 (density 0.81)

Root Cause (≤ 2 sentences):
This page teaches four independent defense layers in one pass (contents: read permissions, safe-outputs: create-pull-request, protected-files path restrictions, and network.allowed-domains), each introducing its own distinct frontmatter syntax and config keys, which drives the concept count to 23 — the highest new-concept load flagged in the corpus alongside the highest word count among findings.

Evidence (quoted from the file):

"gh-aw gives you three layers to prevent repository poisoning."

[followed by four ##-level subsections: "Declare read-only permissions", "Route writes through a pull request", "Restrict which paths can change", "Limit network destinations" — each with its own YAML frontmatter example]

The intro promises "three layers" but the page actually walks through four distinct defensive mechanisms back-to-back with no intermediate checkpoint, each requiring the learner to hold the prior mechanism's syntax in memory while absorbing the next.

Learning Science Rationale:
Sweller's Cognitive Load Theory identifies "element interactivity" as the key driver of intrinsic load: concepts that must be understood simultaneously (here, four defensive YAML configurations that compose together) impose far more working-memory burden than an equivalent word count of independent facts. Presenting all four defenses in one uninterrupted pass before any practice or self-check risks exceeding working memory capacity (typically cited as ~4 chunks), especially for the corpus's most content-dense side quest.

Improvement Prompt (for an agent):

In workshop/side-quest-17-07-repo-poisoning.md, reduce concept density and add mid-page retrieval practice:

1. Fix the intro line "gh-aw gives you three layers to prevent repository poisoning." to say "four layers" (it currently undercounts the four subsections that follow: read-only permissions, safe-outputs PR routing, protected-files path restrictions, and network.allowed-domains) — or alternatively, merge "Restrict which paths can change" into the "Route writes through a pull request" section as a sub-point, since protected-files is a modifier of create-pull-request rather than a standalone layer, reducing four taught layers to three.

2. After the first two subsections ("Declare read-only permissions" and "Route writes through a pull request"), insert a short 2-item checklist self-check before continuing to the remaining layers, e.g.:
   - [ ] I can explain why `contents: read` alone prevents a direct commit
   - [ ] I can explain what `create-pull-request` adds on top of read-only permissions

   This breaks the four-layer block into two smaller chunks with a retrieval checkpoint between them, reducing simultaneous element interactivity.

3. Keep the existing "Spot the Dangerous Frontmatter" and "Harden Your Workflow" exercises and the final Checkpoint unchanged.

Expected Score After Fix: ≈8.2 / 10.0 (concept load reduced from 23 toward ~17-18 by merging protected-files under create-pull-request; activity_density raised slightly by the added mid-page checklist; combined with the companion checkpoint/scaffolding regex fix already applied in the corrected baseline).

Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 147.3 AIC · ⌖ 18.6 AIC · ⊞ 9K · ◷

  • expires on Sep 28, 2026, 9:51 AM UTC
Ngôn ngữ chính
JavaScript
Star
49
Fork
20
Merge trung bình
7 giờ 55 phút
Pull request đã merge (30 ngày)
30

Chuẩn bị môi trường

Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của githubnext/gh-aw-workshop

Tất cả issue của githubnext/gh-aw-workshop

Issue tương tự

Thêm issue về JavaScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.