This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass
What I Built
The Security Dictionary: Trail Edition — a tool that teaches kids cybersecurity by sending them outside.
Pick an explorer's age, where you're exploring, and how long you've got. The tool hands you a security concept framed as an outdoor mission, and a warm voice reads it aloud — so the phone goes in your pocket and the learning happens in the real world.
- IOC → find three clues something was here before you
- Alert → notice what grabs your attention
- Firewall → find barriers that let some things through and keep others out
- Encryption → invent a secret signal only you and a friend understand
- Phishing → spot something tempting — feel the pull, but don't go to it
It's a branch of The Security Dictionary, a project where I take intimidating security language and make it understandable. This asks the next question: what if understanding didn't begin with another definition, but with an experience?
My whole background is "finding what doesn't belong" — atmospheric anomalies, fraud, threat hunting. That's not a definition you memorize; it's a reflex you build by doing. So I wondered what happens if a kid learns a security concept by hunting for it outside first, and the definition comes after. Map an alert to a knocked-over flowerpot. Map a firewall to the backyard fence. The definition lands because the kid already lived it.
It's built for kids ages 5–13 (three reading levels), and honestly for any family that wants a reason to put the screens down and go look at something.
Demo
The flow: pick your explorer → get a mission → tap listen → a warm voice reads it aloud → pocket the phone and head out → come back for the payoff that connects what you found to the security concept.
Code
Tash925
/
security-dictionary-trail-edition
Cybersecurity, learned outside — kid-friendly outdoor missions powered by local Gemma + ElevenLabs. Hacktoberfest 2026.
The Security Dictionary: Trail Edition 🌿
Cybersecurity, learned outside. An offline tool that turns security concepts into kid-friendly outdoor missions — so the phone goes in your pocket and the learning happens in the real world.
Built for the Hacktoberfest 2026 Open-Source AI Challenge, Week 1: Touch Grass.
A branch of The Security Dictionary by DataSec Chronicles.
What it does
Pick an explorer age, a place, and how long you've got. The tool gives you a security concept framed as a mission you do outside:
- IOC → find three clues something was here before you
- Alert → notice what grabs your attention
- Firewall → find barriers that let some things through and keep others out
- Encryption → invent a secret signal only you and a friend understand
- Phishing → spot something tempting — feel the pull, but don't go to it
A warm voice reads the mission aloud, so…
The whole thing is one self-contained HTML file plus the mission prompts and the generated narration — no build step, no framework. The prompts/ folder has the exact template and safety constraints used to generate the missions.
How I Built It
Local open-weight model — Google Gemma, via Ollama (gemma2:2b).
Every mission is generated locally by Gemma. The model takes one security concept plus the child's age and writes a fresh, age-appropriate mission — the same concept becomes a different mission each time, which a static list of scavenger hunts could never do. That variety is the whole reason to use a model at all.
The interesting engineering was constraining a tiny local model to behave. A 2B model drifts — it invents unsafe suggestions, slips into markdown, pads and repeats. Getting it to reliably produce a safe, structured, age-appropriate mission took real prompt-tuning: too loose, and it invented things that weren't there; too tight, and it dropped the actual teaching. The balance point is the technical heart of this project. The safety block in the prompt is explicit — the model is told never to have a child touch, taste, chase, approach anything unfamiliar, enter unsafe areas, identify or eat plants, or leave their adult's area. Generative output aimed at children needs constraints built for the context it runs in.
I generated each of the five concepts across three reading levels (5–7, 8–10, 11–13) — fifteen missions — then baked them into the page so it runs with no model server and no internet.
Voice — ElevenLabs.
The narration is pre-generated with ElevenLabs and embedded in the page, so it plays offline once loaded. Voice here isn't a feature I bolted on because this was an AI challenge. I added it because requiring a child to read generated instructions would undermine the entire premise — the interface needed to disappear so the kid could listen, pocket the phone, and go. For a kid who finds reading hard, that's not a convenience; it's what makes the tool usable at all. Not every kid learns best by reading.
Why Does Open Innovation Matter?
Three reasons, and they're the reason the project holds together rather than nice-to-haves:
- It runs offline. On a trail, in a backyard, anywhere with no signal. A cloud API can't promise that.
- No child's data leaves the device. This is a tool for kids. A cloud-based version would send a child's inputs to someone else's server. Running an open model locally means it never has to — and as a security person, that's the difference between a tool I'd hand my own kids and one I wouldn't. For a children's tool, local isn't a performance choice. It's the whole reason it can be trusted.
- It costs nothing to run, so any family or classroom can use it, not just ones who can afford API bills.
The open pieces aren't decoration. They are the project.
How It Went (I took it outside)
I tested it with a kid in my target age range. I let her drive — press the buttons, hit "Give me a mission." She got Firewall, tapped listen, and smiled at the voice. Then she went and found the fence in the backyard, and said she understood the concept better having found it first. I could see her following along as the voice spoke — the screen genuinely receded. Her words: "I really like this."
And it did the one thing the theme asks for: it got us outside to look around.
It also gave me a real finding. On the 11–13 tier — which currently falls back to a plain browser voice instead of the ElevenLabs narration — she immediately didn't like it. That told me the voice isn't a nice-to-have; it's load-bearing for whether a kid stays engaged. Next build: real voice across all three age tiers, not just 8–10.
Prize Categories
- Best Use of Gemma — Gemma (open-weight, via Ollama) generates every mission locally. It's the engine of the whole tool.
- Best Use of ElevenLabs — ElevenLabs gives the missions a voice, which is what lets a child listen instead of read and actually put the screen away.
Built with 💜 by DataSec Chronicles. The tool changes, the question doesn't.
Top comments (0)