cd /news/artificial-intelligence/the-security-dictionary-trail-editio… · home › topics › artificial-intelligence › article
[ARTICLE · art-148837] src=dev.to ↗ pub= topic=artificial-intelligence verified=true sentiment=↑ positive

The Security Dictionary: Trail Edition — Cybersecurity Concepts as Outdoor Missions, Powered by Local Gemma

A developer built The Security Dictionary: Trail Edition, a self-contained HTML tool that teaches children ages 5–13 cybersecurity concepts by turning them into outdoor missions, with missions generated locally by Google's Gemma 2B model via Ollama and narration pre-generated with ElevenLabs. The project's core engineering challenge was prompt-tuning the small model to reliably produce safe, structured, age-appropriate missions, with an explicit safety block barring children from touching, tasting, chasing or approaching unfamiliar things. Fifteen missions across five concepts and three reading levels were baked into the page so it runs offline with no model server or internet connection.

by read4 min views1 publishedOct 10, 2026

This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass The Security Dictionary: Trail Edition — a tool that teaches kids cybersecurity by sending them outside.

Pick an explorer's age, where you're exploring, and how long you've got. The tool hands you a security concept framed as an outdoor mission, and a warm voice reads it aloud — so the phone goes in your pocket and the learning happens in the real world.

It's a branch of The Security Dictionary, a project where I take intimidating security language and make it understandable. This asks the next question: what if understanding didn't begin with another definition, but with an experience?

My whole background is "finding what doesn't belong" — atmospheric anomalies, fraud, threat hunting. That's not a definition you memorize; it's a reflex you build by doing. So I wondered what happens if a kid learns a security concept by hunting for it outside first, and the definition comes after. Map an alert to a knocked-over flowerpot. Map a firewall to the backyard fence. The definition lands because the kid already lived it.

It's built for kids ages 5–13 (three reading levels), and honestly for any family that wants a reason to put the screens down and go look at something.

The flow: pick your explorer → get a mission → tap listen → a warm voice reads it aloud → pocket the phone and head out → come back for the payoff that connects what you found to the security concept.

Cybersecurity, learned outside. An offline tool that turns security concepts into kid-friendly outdoor missions — so the phone goes in your pocket and the learning happens in the real world.

Built for the [Hacktoberfest 2026 Open-Source AI Challenge, Week 1: Touch Grass](https://dev.to/challenges/hacktoberfest-week1-2026-10-05).

A branch of [The Security Dictionary](https://www.datasecchronicles.com) by DataSec Chronicles.

Pick an explorer age, a place, and how long you've got. The tool gives you a security concept framed as a mission you do outside:

A warm voice reads the mission aloud, so…

The whole thing is one self-contained HTML file plus the mission prompts and the generated narration — no build step, no framework. The prompts/ folder has the exact template and safety constraints used to generate the missions.

Local open-weight model — Google Gemma, via Ollama (gemma2:2b). Every mission is generated locally by Gemma. The model takes one security concept plus the child's age and writes a fresh, age-appropriate mission — the same concept becomes a different mission each time, which a static list of scavenger hunts could never do. That variety is the whole reason to use a model at all.

The interesting engineering was constraining a tiny local model to behave. A 2B model drifts — it invents unsafe suggestions, slips into markdown, pads and repeats. Getting it to reliably produce a safe, structured, age-appropriate mission took real prompt-tuning: too loose, and it invented things that weren't there; too tight, and it dropped the actual teaching. The balance point is the technical heart of this project. The safety block in the prompt is explicit — the model is told never to have a child touch, taste, chase, approach anything unfamiliar, enter unsafe areas, identify or eat plants, or leave their adult's area. Generative output aimed at children needs constraints built for the context it runs in.

I generated each of the five concepts across three reading levels (5–7, 8–10, 11–13) — fifteen missions — then baked them into the page so it runs with no model server and no internet.

Voice — ElevenLabs. The narration is pre-generated with ElevenLabs and embedded in the page, so it plays offline once loaded. Voice here isn't a feature I bolted on because this was an AI challenge. I added it because requiring a child to read generated instructions would undermine the entire premise — the interface needed to disappear so the kid could listen, pocket the phone, and go. For a kid who finds reading hard, that's not a convenience; it's what makes the tool usable at all. Not every kid learns best by reading.

Three reasons, and they're the reason the project holds together rather than nice-to-haves:

The open pieces aren't decoration. They are the project.

I tested it with a kid in my target age range. I let her drive — press the buttons, hit "Give me a mission." She got Firewall, tapped listen, and smiled at the voice. Then she went and found the fence in the backyard, and said she understood the concept better having found it first. I could see her following along as the voice spoke — the screen genuinely receded. Her words: "I really like this."

And it did the one thing the theme asks for: it got us outside to look around.

It also gave me a real finding. On the 11–13 tier — which currently falls back to a plain browser voice instead of the ElevenLabs narration — she immediately didn't like it. That told me the voice isn't a nice-to-have; it's load-bearing for whether a kid stays engaged. Next build: real voice across all three age tiers, not just 8–10.

Built with 💜 by DataSec Chronicles. The tool changes, the question doesn't.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @google 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/the-security-diction…] indexed:0 read:4min 2026-10-10 · —