[curriculum-eval] side-quest-17-07-repo-poisoning.md: cognitive_load — 23 security concepts introduced before any worked example
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 72/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- github, markdown, yaml
- Lĩnh vực
- content
Hướng nghiên cứu
Đọc workshop/side-quest-17-07-repo-poisoning.md, tập trung vào “The Attack”, “Why This Matters” và “How AW Defends Against It”. Thêm ví dụ YAML dễ bị tấn công và bài tập “Spot the risk” theo yêu cầu, sau đó chia các biện pháp phòng vệ thành những ví dụ có nhãn kèm danh sách kiểm tra ngắn. Công việc hoàn tất khi bài học có thêm các bước kiểm tra thực hành mà không bổ sung nhiều nội dung văn xuôi; hãy xác minh tệp đã chỉnh sửa đọc mạch lạc.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.95 / 10.0 (corpus mean: 6.09)
Flagged Dimensions:
| Dimension | Score | Benchmark | Delta |
|---|---|---|---|
| active_learning | 2.7 |
density ≥ 3 → 10 | -7.3 |
| cognitive_load | 5.8 |
≤800 words, ≤15 concepts → 10 | -4.2 |
Root Cause (≤ 2 sentences):
This security side quest introduces 23 new concepts (permissions scoping, contents: read/write, safe-outputs: create-pull-request, network.allowed-domains, protected-files, branch protection, CODEOWNERS, content-driven manipulation) across 1,234 words of mostly narrative/explanatory prose (the "Attack" and "Why This Matters" sections) before any hands-on application, so cognitive load is high while activity density stays low.
Evidence (quoted from the file):
"Repository poisoning is what happens when a misdirected agent with write access commits changes an attacker designed — not changes the workflow author intended." — this scenario-and-rationale narrative spans roughly 300 words across two full sections before the reader reaches any applied defensive configuration.
Learning Science Rationale:
Sweller's Cognitive Load Theory predicts that introducing many new, interdependent security concepts (permission scoping, safe-outputs, network allowlisting, protected-files, branch protection) in rapid narrative succession without intermediate worked examples overloads working memory capacity (typically 4±1 novel chunks), making it hard for learners to encode the causal chain between "why the attack works" and "which specific field stops it."
Improvement Prompt (for an agent):
Edit workshop/side-quest-17-07-repo-poisoning.md to reduce cognitive load and raise active
learning density. After "The Attack" and "Why This Matters" sections, insert a short worked
example (a 5-10 line YAML code block showing a vulnerable frontmatter snippet with
`contents: write` and no `network.allowed-domains`) immediately followed by a "Spot the risk"
checklist-style micro-exercise asking the learner to identify the dangerous field before
revealing the fix. Split the "How AW Defends Against It" section (which currently introduces
contents:read, safe-outputs:create-pull-request, network.allowed-domains, and protected-files
together) into one labeled code example per defense, each with its own 1-2 item inline
checklist, so code_blocks + checklist_items increases relative to word_count without adding
new prose.
Expected Score After Fix: 6.3-6.8 / 10.0
Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 96.9 AIC · ⌖ 19.9 AIC · ⊞ 10.4K · ◷
- expires on Oct 8, 2026, 11:43 PM UTC
- Ngôn ngữ chính
- JavaScript
- Star
- 52
- Fork
- 26
- Merge trung bình
- 11 giờ 32 phút
- Pull request đã merge (30 ngày)
- 22
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Không có hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của githubnext/gh-aw-workshop
-
[workshop-sim] Repair: Add a fallback sample .lock.yml to the Agentic Workflows Intro Activity 1Đang mởfeedback simulation workshop
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
githubnext/gh-aw-workshop#4328 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
documentation guidelines
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
githubnext/gh-aw-workshop#4314 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
curriculum documentation quality
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
githubnext/gh-aw-workshop#4311 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
curriculum documentation quality
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
githubnext/gh-aw-workshop#4310 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
curriculum documentation quality
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
githubnext/gh-aw-workshop#4308 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của githubnext/gh-aw-workshop
Issue tương tự
-
ci-install-db-tools stall-case tests flake: stalled apt-get can be killed before it logs its callĐang mởeffort:low model:light plan planner:opus-5-5 tests
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Bug 🐞
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
mozilla-mobile/firefox-ios#35986 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug(sight): the dashboard's text truncations split surrogate pairs and show broken charactersĐang mởcomponent:sight
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
agentic-os-org/ANOLISA#6738 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug Durable Agents Observability (AI Telemetry) status: needs triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
mastra-ai/mastra#26470 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature/cohorts feature/feature-flags team/feature-flags
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
Maintainer thường phản hồi trong vòng 1 ngày