elastic / elastic/fleet-server
[aw] Detection Runs
- Dominant language
- Go
- Stars
- 113
- Forks
- 117
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 112
Description
This issue tracks all runs where threat detection flagged problems in agentic workflows in this repository. Each workflow run that completes with a detection warning or failure posts a comment here.
What is a Detection Problem?
A detection problem occurs when the threat detection system either:
- **Detects potential security threats** (prompt injection, secret leak, malicious patch)
- **Fails to produce results** (agent failure, parse error)
When `continue-on-error: true` (the default), these problems produce warnings and safe outputs still proceed. When `continue-on-error: false`, they block safe outputs entirely.
How This Helps
This issue helps you:
- Track workflows where threat detection raised concerns
- Review patterns of detection warnings or failures
- Identify false positives or recurring issues with threat detection
- Monitor the health of the threat detection system
Resources
- [GitHub Agentic Workflows Documentation](https://github.com/github/gh-aw)
> [!TIP]
> To configure threat detection behavior, update the frontmatter:
> ```yaml
> safe-outputs:
> threat-detection:
> continue-on-error: true # Warnings only (default)
> # continue-on-error: false # Strict mode — block safe outputs
> ```
---
> This issue is automatically managed by GitHub Agentic Workflows. Do not close this issue manually.
>
> **No action to take** - Do not assign to an agent.
> - [x] expires on Sep 26, 2026, 3:11 PM UTC
Contributor guide
Research direction
This is an automatically managed tracker for threat-detection warnings and failures in GitHub Agentic Workflows; no repository file, test, or entry point is named. Start with the linked GitHub Agentic Workflows Documentation and the safe-outputs.threat-detection frontmatter shown here. Done is not defined because the issue explicitly says no action is required and not to assign it to an agent.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 5/100