[curriculum-eval] side-quest-17-07-repo-poisoning.md: cognitive_load — four defense layers taught in one uninterrupted pass (23 concepts)
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- markdown
- Lĩnh vực
- content, documentation
Hướng nghiên cứu
Mở workshop/side-quest-17-07-repo-poisoning.md và xem lại phần giới thiệu cùng bốn tiểu mục phòng thủ được nêu tên. Kiểm tra cách diễn đạt về số lượng lớp và đặt phần tự kiểm tra được yêu cầu sau hai tiểu mục đầu tiên, đồng thời giữ nguyên các bài tập hiện có và Checkpoint cuối. Được xem là hoàn tất khi trang phản ánh cấu trúc lớp đã thống nhất và bao gồm checklist truy xuất trung gian.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.95 / 10.0 (corpus mean: 6.09) — second-lowest score in the corpus
Corrected Overall Score (after fixing the checkpoint/scaffolding regex bug reported separately): 7.70 / 10.0 — cognitive_load and active_learning remain the residual gaps.
Flagged Dimensions:
| Dimension | Score | Benchmark | Delta |
|---|---|---|---|
| cognitive_load | 5.8 |
≤800 words, ≤15 new concepts | -2.1 (1234 words, 54% over target) and -4.0 (23 concepts, 53% over the 15-concept ceiling) |
| active_learning | 2.7 |
density ≥ 3 | -0.3 (density 0.81) |
Root Cause (≤ 2 sentences):
This page teaches four independent defense layers in one pass (contents: read permissions, safe-outputs: create-pull-request, protected-files path restrictions, and network.allowed-domains), each introducing its own distinct frontmatter syntax and config keys, which drives the concept count to 23 — the highest new-concept load flagged in the corpus alongside the highest word count among findings.
Evidence (quoted from the file):
"gh-aw gives you three layers to prevent repository poisoning."
[followed by four
##-level subsections: "Declare read-only permissions", "Route writes through a pull request", "Restrict which paths can change", "Limit network destinations" — each with its own YAML frontmatter example]
The intro promises "three layers" but the page actually walks through four distinct defensive mechanisms back-to-back with no intermediate checkpoint, each requiring the learner to hold the prior mechanism's syntax in memory while absorbing the next.
Learning Science Rationale:
Sweller's Cognitive Load Theory identifies "element interactivity" as the key driver of intrinsic load: concepts that must be understood simultaneously (here, four defensive YAML configurations that compose together) impose far more working-memory burden than an equivalent word count of independent facts. Presenting all four defenses in one uninterrupted pass before any practice or self-check risks exceeding working memory capacity (typically cited as ~4 chunks), especially for the corpus's most content-dense side quest.
Improvement Prompt (for an agent):
In workshop/side-quest-17-07-repo-poisoning.md, reduce concept density and add mid-page retrieval practice:
1. Fix the intro line "gh-aw gives you three layers to prevent repository poisoning." to say "four layers" (it currently undercounts the four subsections that follow: read-only permissions, safe-outputs PR routing, protected-files path restrictions, and network.allowed-domains) — or alternatively, merge "Restrict which paths can change" into the "Route writes through a pull request" section as a sub-point, since protected-files is a modifier of create-pull-request rather than a standalone layer, reducing four taught layers to three.
2. After the first two subsections ("Declare read-only permissions" and "Route writes through a pull request"), insert a short 2-item checklist self-check before continuing to the remaining layers, e.g.:
- [ ] I can explain why `contents: read` alone prevents a direct commit
- [ ] I can explain what `create-pull-request` adds on top of read-only permissions
This breaks the four-layer block into two smaller chunks with a retrieval checkpoint between them, reducing simultaneous element interactivity.
3. Keep the existing "Spot the Dangerous Frontmatter" and "Harden Your Workflow" exercises and the final Checkpoint unchanged.
Expected Score After Fix: ≈8.2 / 10.0 (concept load reduced from 23 toward ~17-18 by merging protected-files under create-pull-request; activity_density raised slightly by the added mid-page checklist; combined with the companion checkpoint/scaffolding regex fix already applied in the corrected baseline).
Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 147.3 AIC · ⌖ 18.6 AIC · ⊞ 9K · ◷
- expires on Sep 28, 2026, 9:51 AM UTC
- Ngôn ngữ chính
- JavaScript
- Star
- 49
- Fork
- 20
- Merge trung bình
- 7 giờ 55 phút
- Pull request đã merge (30 ngày)
- 30
Chuẩn bị môi trường
Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của githubnext/gh-aw-workshop
-
[aw] Upgrade availableĐang mởagentic-workflows
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
githubnext/gh-aw-workshop#3933 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
documentation
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
githubnext/gh-aw-workshop#3932 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
feedback simulation workshop
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
githubnext/gh-aw-workshop#3931 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
agentic-workflows documentation workflow-editor
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
githubnext/gh-aw-workshop#3927 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
githubnext/gh-aw-workshop#3926 ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của githubnext/gh-aw-workshop
Issue tương tự
-
factory-active factory-automatic harness/codex task-bug-reproduction-success task-identify-harness-labels-done task-identify-issue-type-done
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
vercel/ai#21582 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
ux
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
rr-djk/rr-djuikoo.com#53 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Add shacl12-inference-rulesĐang mởnew spec review
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
w3c/browser-specs#2666 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
thim81/openapi-format#238 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
decentespresso/dye2#13 ·