File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.97 / 10.0 (corpus mean: 6.14)
Flagged Dimensions:
| Dimension |
Score |
Benchmark |
Delta |
| active_learning |
2.7 |
density ≥ 3 → 10 |
-7.3 |
| cognitive_load |
5.9 |
≤ 800 words, ≤ 15 concepts |
-4.1 |
Root Cause (≤ 2 sentences):
At 1,224 words and 23 new bolded/code terms (permissions, toolsets, safe-outputs, protected-files, allowed-files, network.allowed-domains, etc.), the page front-loads a large amount of declarative explanation (three defence layers, a table, a frontmatter diff) before the learner reaches the two hands-on exercises, so the activity density (code blocks + checklist items per 100 words) is only 0.82 against an ideal of ≥ 3. The missing_checkpoint flag confirmed by inspection is a false positive caused by the :white_check_mark: shortcode regex bug (see companion finding), so the real issue here is pacing, not an absent checkpoint.
Evidence (quoted from the file):
"Repository poisoning is what happens when a misdirected agent with write access commits changes an attacker designed — not changes the workflow author intended... The embedded YAML block in that issue body would define a job that exfiltrates ${{ secrets.GITHUB_TOKEN }} to an attacker-controlled server."
Learning Science Rationale:
Mayer's coherence principle and Sweller's Cognitive Load Theory both predict that extended prose exposition before any learner action increases extraneous load and reduces retention — by the time the learner reaches "Exercise: Spot the Dangerous Frontmatter" they have already processed ~900 words of new vocabulary and three code examples with no intervening check for understanding, so working memory is likely saturated before the first opportunity to apply the concept.
Improvement Prompt (for an agent):
Edit workshop/side-quest-17-07-repo-poisoning.md to reduce cognitive load and raise activity density. Specifically:
1. Move the "Exercise: Spot the Dangerous Frontmatter" section earlier, immediately after "The Attack" section, so the learner applies the concept before reading all three defence layers in full detail.
2. Split the "How AW Defends Against It" section (currently four sub-defences: read-only permissions, pull-request routing, protected-files, network restrictions) into two shorter passes, each followed by a 1-2 item inline check (e.g. a short "which line above prevents X?" question with a collapsible answer), instead of one long unbroken exposition.
3. Trim the vocabulary table/prose so introduced terms (permissions, toolsets, safe-outputs, protected-files, allowed-files, network.allowed-domains) are limited to what's used in the two exercises; move any terms not exercised into a linked reference page instead of defining them inline.
4. Keep the existing checkpoint section as-is (it is present and well-formed; do not add a duplicate).
Verify by re-running the corpus scoring script and confirming activity_density rises above 1.5 and word_count/new_concepts move closer to the 800-word / 15-concept targets.
Expected Score After Fix: 6.6 / 10.0
Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 76.7 AIC · ⌖ 17.4 AIC · ⊞ 9.5K · ◷
File:
workshop/side-quest-17-07-repo-poisoning.mdOverall Score:
4.97 / 10.0(corpus mean:6.14)Flagged Dimensions:
Root Cause (≤ 2 sentences):
At 1,224 words and 23 new bolded/code terms (permissions, toolsets, safe-outputs, protected-files, allowed-files, network.allowed-domains, etc.), the page front-loads a large amount of declarative explanation (three defence layers, a table, a frontmatter diff) before the learner reaches the two hands-on exercises, so the activity density (code blocks + checklist items per 100 words) is only 0.82 against an ideal of ≥ 3. The
missing_checkpointflag confirmed by inspection is a false positive caused by the:white_check_mark:shortcode regex bug (see companion finding), so the real issue here is pacing, not an absent checkpoint.Evidence (quoted from the file):
Learning Science Rationale:
Mayer's coherence principle and Sweller's Cognitive Load Theory both predict that extended prose exposition before any learner action increases extraneous load and reduces retention — by the time the learner reaches "Exercise: Spot the Dangerous Frontmatter" they have already processed ~900 words of new vocabulary and three code examples with no intervening check for understanding, so working memory is likely saturated before the first opportunity to apply the concept.
Improvement Prompt (for an agent):
Expected Score After Fix:
6.6 / 10.0