Skip to content

[curriculum-eval] side-quest-17-07-repo-poisoning.md: active_learning — exposition-heavy pacing delays hands-on exercises #3404

Description

@github-actions

File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.97 / 10.0 (corpus mean: 6.14)

Flagged Dimensions:

Dimension Score Benchmark Delta
active_learning 2.7 density ≥ 3 → 10 -7.3
cognitive_load 5.9 ≤ 800 words, ≤ 15 concepts -4.1

Root Cause (≤ 2 sentences):
At 1,224 words and 23 new bolded/code terms (permissions, toolsets, safe-outputs, protected-files, allowed-files, network.allowed-domains, etc.), the page front-loads a large amount of declarative explanation (three defence layers, a table, a frontmatter diff) before the learner reaches the two hands-on exercises, so the activity density (code blocks + checklist items per 100 words) is only 0.82 against an ideal of ≥ 3. The missing_checkpoint flag confirmed by inspection is a false positive caused by the :white_check_mark: shortcode regex bug (see companion finding), so the real issue here is pacing, not an absent checkpoint.

Evidence (quoted from the file):

"Repository poisoning is what happens when a misdirected agent with write access commits changes an attacker designed — not changes the workflow author intended... The embedded YAML block in that issue body would define a job that exfiltrates ${{ secrets.GITHUB_TOKEN }} to an attacker-controlled server."

Learning Science Rationale:
Mayer's coherence principle and Sweller's Cognitive Load Theory both predict that extended prose exposition before any learner action increases extraneous load and reduces retention — by the time the learner reaches "Exercise: Spot the Dangerous Frontmatter" they have already processed ~900 words of new vocabulary and three code examples with no intervening check for understanding, so working memory is likely saturated before the first opportunity to apply the concept.

Improvement Prompt (for an agent):

Edit workshop/side-quest-17-07-repo-poisoning.md to reduce cognitive load and raise activity density. Specifically:
1. Move the "Exercise: Spot the Dangerous Frontmatter" section earlier, immediately after "The Attack" section, so the learner applies the concept before reading all three defence layers in full detail.
2. Split the "How AW Defends Against It" section (currently four sub-defences: read-only permissions, pull-request routing, protected-files, network restrictions) into two shorter passes, each followed by a 1-2 item inline check (e.g. a short "which line above prevents X?" question with a collapsible answer), instead of one long unbroken exposition.
3. Trim the vocabulary table/prose so introduced terms (permissions, toolsets, safe-outputs, protected-files, allowed-files, network.allowed-domains) are limited to what's used in the two exercises; move any terms not exercised into a linked reference page instead of defining them inline.
4. Keep the existing checkpoint section as-is (it is present and well-formed; do not add a duplicate).
Verify by re-running the corpus scoring script and confirming activity_density rises above 1.5 and word_count/new_concepts move closer to the 800-word / 15-concept targets.

Expected Score After Fix: 6.6 / 10.0

Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 76.7 AIC · ⌖ 17.4 AIC · ⊞ 9.5K · ◷

  • expires on Sep 16, 2026, 1:00 PM UTC

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions