Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[curriculum-eval] side-quest-17-07-repo-poisoning.md: cognitive_load — 23 security concepts introduced before any worked example

Đang mở Phù hợp với người mới
#4,309 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
72/100
Loại issue
Tài liệu
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
github, markdown, yaml
Lĩnh vực
content

Hướng nghiên cứu

Đọc workshop/side-quest-17-07-repo-poisoning.md, tập trung vào “The Attack”, “Why This Matters” và “How AW Defends Against It”. Thêm ví dụ YAML dễ bị tấn công và bài tập “Spot the risk” theo yêu cầu, sau đó chia các biện pháp phòng vệ thành những ví dụ có nhãn kèm danh sách kiểm tra ngắn. Công việc hoàn tất khi bài học có thêm các bước kiểm tra thực hành mà không bổ sung nhiều nội dung văn xuôi; hãy xác minh tệp đã chỉnh sửa đọc mạch lạc.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

curriculum documentation quality

File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.95 / 10.0 (corpus mean: 6.09)

Flagged Dimensions:

Dimension Score Benchmark Delta
active_learning 2.7 density ≥ 3 → 10 -7.3
cognitive_load 5.8 ≤800 words, ≤15 concepts → 10 -4.2

Root Cause (≤ 2 sentences):
This security side quest introduces 23 new concepts (permissions scoping, contents: read/write, safe-outputs: create-pull-request, network.allowed-domains, protected-files, branch protection, CODEOWNERS, content-driven manipulation) across 1,234 words of mostly narrative/explanatory prose (the "Attack" and "Why This Matters" sections) before any hands-on application, so cognitive load is high while activity density stays low.

Evidence (quoted from the file):

"Repository poisoning is what happens when a misdirected agent with write access commits changes an attacker designed — not changes the workflow author intended." — this scenario-and-rationale narrative spans roughly 300 words across two full sections before the reader reaches any applied defensive configuration.

Learning Science Rationale:
Sweller's Cognitive Load Theory predicts that introducing many new, interdependent security concepts (permission scoping, safe-outputs, network allowlisting, protected-files, branch protection) in rapid narrative succession without intermediate worked examples overloads working memory capacity (typically 4±1 novel chunks), making it hard for learners to encode the causal chain between "why the attack works" and "which specific field stops it."

Improvement Prompt (for an agent):

Edit workshop/side-quest-17-07-repo-poisoning.md to reduce cognitive load and raise active
learning density. After "The Attack" and "Why This Matters" sections, insert a short worked
example (a 5-10 line YAML code block showing a vulnerable frontmatter snippet with
`contents: write` and no `network.allowed-domains`) immediately followed by a "Spot the risk"
checklist-style micro-exercise asking the learner to identify the dangerous field before
revealing the fix. Split the "How AW Defends Against It" section (which currently introduces
contents:read, safe-outputs:create-pull-request, network.allowed-domains, and protected-files
together) into one labeled code example per defense, each with its own 1-2 item inline
checklist, so code_blocks + checklist_items increases relative to word_count without adding
new prose.

Expected Score After Fix: 6.3-6.8 / 10.0

Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 96.9 AIC · ⌖ 19.9 AIC · ⊞ 10.4K · ◷

  • expires on Oct 8, 2026, 11:43 PM UTC
Ngôn ngữ chính
JavaScript
Star
52
Fork
26
Merge trung bình
11 giờ 32 phút
Pull request đã merge (30 ngày)
22

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

  • Không có Dockerfile hay tệp Docker Compose
  • Không có mẫu pull request
  • Không có hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của githubnext/gh-aw-workshop

Tất cả issue của githubnext/gh-aw-workshop

Issue tương tự

Thêm issue về JavaScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.