{"slug": "the-security-dictionary-trail-edition-cybersecurity-concepts-as-outdoor-missions", "title": "The Security Dictionary: Trail Edition — Cybersecurity Concepts as Outdoor Missions, Powered by Local Gemma", "summary": "A developer built The Security Dictionary: Trail Edition, a self-contained HTML tool that teaches children ages 5–13 cybersecurity concepts by turning them into outdoor missions, with missions generated locally by Google's Gemma 2B model via Ollama and narration pre-generated with ElevenLabs. The project's core engineering challenge was prompt-tuning the small model to reliably produce safe, structured, age-appropriate missions, with an explicit safety block barring children from touching, tasting, chasing or approaching unfamiliar things. Fifteen missions across five concepts and three reading levels were baked into the page so it runs offline with no model server or internet connection.", "body_md": "*This is a submission for the [Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass](https://dev.to/challenges/hacktoberfest-week1-2026-10-05)*\n\n**The Security Dictionary: Trail Edition** — a tool that teaches kids cybersecurity by sending them *outside*.\n\nPick an explorer's age, where you're exploring, and how long you've got. The tool hands you a security concept framed as an outdoor mission, and a warm voice reads it aloud — so the phone goes in your pocket and the learning happens in the real world.\n\nIt's a branch of [The Security Dictionary](https://www.datasecchronicles.com), a project where I take intimidating security language and make it understandable. This asks the next question: what if understanding didn't begin with another definition, but with an *experience*?\n\nMy whole background is \"finding what doesn't belong\" — atmospheric anomalies, fraud, threat hunting. That's not a definition you memorize; it's a reflex you build by doing. So I wondered what happens if a kid learns a security concept by hunting for it outside first, and the definition comes *after*. Map an alert to a knocked-over flowerpot. Map a firewall to the backyard fence. The definition lands because the kid already lived it.\n\nIt's built for kids ages 5–13 (three reading levels), and honestly for any family that wants a reason to put the screens down and go look at something.\n\nThe flow: pick your explorer → get a mission → tap listen → a warm voice reads it aloud → pocket the phone and head out → come back for the payoff that connects what you found to the security concept.\n\nCybersecurity, learned outside. An offline tool that turns security concepts into kid-friendly outdoor missions — so the phone goes in your pocket and the learning happens in the real world.\n\nBuilt for the [Hacktoberfest 2026 Open-Source AI Challenge, Week 1: Touch Grass](https://dev.to/challenges/hacktoberfest-week1-2026-10-05).\n\nA branch of [The Security Dictionary](https://www.datasecchronicles.com) by DataSec Chronicles.\n\nPick an explorer age, a place, and how long you've got. The tool gives you a security concept framed as a mission you do outside:\n\nA warm voice reads the mission aloud, so…\n\nThe whole thing is one self-contained HTML file plus the mission prompts and the generated narration — no build step, no framework. The [`prompts/`](https://github.com/Tash925/security-dictionary-trail-edition/tree/main/prompts) folder has the exact template and safety constraints used to generate the missions.\n\n**Local open-weight model — Google Gemma, via [Ollama](https://ollama.com) (`gemma2:2b`).**\n\nEvery mission is generated locally by Gemma. The model takes one security concept plus the child's age and writes a fresh, age-appropriate mission — the same concept becomes a different mission each time, which a static list of scavenger hunts could never do. That variety is the whole reason to use a model at all.\n\nThe interesting engineering was constraining a *tiny* local model to behave. A 2B model drifts — it invents unsafe suggestions, slips into markdown, pads and repeats. Getting it to reliably produce a safe, structured, age-appropriate mission took real prompt-tuning: too loose, and it invented things that weren't there; too tight, and it dropped the actual teaching. The balance point is the technical heart of this project. The safety block in the prompt is explicit — the model is told never to have a child touch, taste, chase, approach anything unfamiliar, enter unsafe areas, identify or eat plants, or leave their adult's area. Generative output aimed at children needs constraints built for the context it runs in.\n\nI generated each of the five concepts across three reading levels (5–7, 8–10, 11–13) — fifteen missions — then baked them into the page so it runs with no model server and no internet.\n\n**Voice — [ElevenLabs](https://elevenlabs.io).**\n\nThe narration is pre-generated with ElevenLabs and embedded in the page, so it plays offline once loaded. Voice here isn't a feature I bolted on because this was an AI challenge. I added it because requiring a child to *read* generated instructions would undermine the entire premise — the interface needed to disappear so the kid could listen, pocket the phone, and go. For a kid who finds reading hard, that's not a convenience; it's what makes the tool usable at all. Not every kid learns best by reading.\n\nThree reasons, and they're the reason the project holds together rather than nice-to-haves:\n\nThe open pieces aren't decoration. They *are* the project.\n\nI tested it with a kid in my target age range. I let her drive — press the buttons, hit \"Give me a mission.\" She got Firewall, tapped listen, and smiled at the voice. Then she went and found the fence in the backyard, and said she understood the concept better having found it first. I could see her following along as the voice spoke — the screen genuinely receded. Her words: *\"I really like this.\"*\n\nAnd it did the one thing the theme asks for: it got us outside to look around.\n\nIt also gave me a real finding. On the 11–13 tier — which currently falls back to a plain browser voice instead of the ElevenLabs narration — she immediately didn't like it. That told me the voice isn't a nice-to-have; it's load-bearing for whether a kid stays engaged. **Next build: real voice across all three age tiers, not just 8–10.**\n\nBuilt with 💜 by [DataSec Chronicles](https://www.datasecchronicles.com). *The tool changes, the question doesn't.*", "url": "https://wpnews.pro/news/the-security-dictionary-trail-edition-cybersecurity-concepts-as-outdoor-missions", "canonical_source": "https://dev.to/data_secchronicles/the-security-dictionary-trail-edition-cybersecurity-concepts-as-outdoor-missions-powered-by-1fj4", "published_at": "2026-10-10 17:09:42+00:00", "updated_at": "2026-10-10 17:18:56.461968+00:00", "lang": "en", "topics": ["artificial-intelligence", "large-language-models", "ai-tools", "generative-ai"], "entities": ["Google", "Gemma", "Ollama", "ElevenLabs", "The Security Dictionary", "DataSec Chronicles", "Hacktoberfest"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/the-security-dictionary-trail-edition-cybersecurity-concepts-as-outdoor-missions", "markdown": "https://wpnews.pro/news/the-security-dictionary-trail-edition-cybersecurity-concepts-as-outdoor-missions.md", "text": "https://wpnews.pro/news/the-security-dictionary-trail-edition-cybersecurity-concepts-as-outdoor-missions.txt", "jsonld": "https://wpnews.pro/news/the-security-dictionary-trail-edition-cybersecurity-concepts-as-outdoor-missions.jsonld"}}