github / github/gh-aw-threat-detection

[detection-stats] Detection stats for github/gh-aw - 2026-08-31

Open
#1,012 0 comments 0 reactions 0 assignees View on GitHub
automation detection-stats
Dominant language
Go
Stars
13
Forks
7
Avg merge
9h 52m
Merged PRs (30d)
25

Description

External-detector runs analysed: **578** · Detection-job error rate: **0%** · Soft failures: **58** · Threat rate: **0%** (0 threats of 219 verdicts).

## Summary
# gh-aw detection statistics - 2026-08-31 (UTC)

Repository: `github/gh-aw`
Window: `2026-08-31T00:00:00Z` .. `2026-08-31T23:59:59Z`
API requests: 1408, rate-limit pauses: 1
Data complete: yes

## Totals

| Metric | Count |
|---|---|
| Workflow runs in window | 997 |
| Agentic runs (`*.lock.yml`) | 752 |
| Runs with a `detection` job | 617 |
| ... using the external detector | 578 |
| ... using the built-in detector | 39 |
| ... detector could not be determined | 0 |
| Agentic runs without a `detection` job | 135 |

All rates below are over the **external detector** population (578 runs). Since gh-aw #54111 the external detector is the compile-time default; a run counts as external when its `detection` job showed the `Install threat-detect binary` step, when another run of the same workflow did that day, or when the workflow is `.lock.yml` and no run showed the built-in shape (a completed detection job with steps but no marker). Runs on a workflow that opted out with `features: gh-aw-detection: false` count as built-in.

## Detection job outcomes

| Outcome | Count | Rate |
|---|---|---|
| `success` | 351 | 60.73% |
| `skipped` | 227 | 39.27% |

**Error rate (failure/timed_out/action_required): 0%**

## Verdict availability

| State | Meaning | Count |
|---|---|---|
| `present` | detection artifact downloaded and parsed | 219 |
| `absent` | detection job ran but published no artifact (soft failure) | 58 |
| `skipped` | detection job was skipped or was still running (nothing to fetch) | 227 |
| `unreadable` | artifact zip could not be unpacked | 74 |

Green detection jobs that published no verdict: **58** (detection steps are `continue-on-error`, so a missing verdict artifact is the only reliable signal for these).

## Detection results

| Result | Count |
|---|---|
| Runs with a parsed verdict | 219 |
| Clean (no threat) | 219 |
| Any threat | 0 |
| `prompt_injection` | 0 |
| `secret_leak` | 0 |
| `malicious_patch` | 0 |

**Threat rate (of runs with a verdict): 0%**

## By workflow

| Workflow | Runs | Failed | Cancelled | Skipped | No verdict | Threats |
|---|---|---|---|---|---|---|
| PR Sous Chef | 79 | 0 | 0 | 0 | 0 | 0 |
| Deployment Incident Monitor | 48 | 0 | 0 | 48 | 0 | 0 |
| Daily Trajectory Grader Implementer | 47 | 0 | 0 | 47 | 0 | 0 |
| [aw] Failure Investigator (6h) | 47 | 0 | 0 | 43 | 0 | 0 |
| Issue Monster | 46 | 0 | 0 | 0 | 0 | 0 |
| Avenger | 24 | 0 | 0 | 19 | 5 | 0 |
| Q | 21 | 0 | 0 | 21 | 0 | 0 |
| Daily Go Test Parallelizer | 12 | 0 | 0 | 0 | 12 | 0 |
| PR Description Updater | 11 | 0 | 0 | 1 | 0 | 0 |
| Auto-Triage Issues | 10 | 0 | 0 | 3 | 1 | 0 |
| Contribution Check | 6 | 0 | 0 | 0 | 0 | 0 |
| Code Scanning Fixer | 4 | 0 | 0 | 0 | 2 | 0 |
| Deep Report | 4 | 0 | 0 | 0 | 0 | 0 |
| PR Triage Agent | 4 | 0 | 0 | 0 | 1 | 0 |
| Squad — ``@copilot`` this PR has no successful forward-progress signal yet. | 3 | 0 | 0 | 3 | 0 | 0 |
| Test Quality Sentinel | 3 | 0 | 0 | 0 | 0 | 0 |
| Workflow Generator | 3 | 0 | 0 | 3 | 0 | 0 |
| Daily Credit Limit Test | 2 | 0 | 0 | 1 | 0 | 0 |
| Impeccable Skills Reviewer | 2 | 0 | 0 | 0 | 0 | 0 |
| Matt Pocock Skills Reviewer | 2 | 0 | 0 | 0 | 0 | 0 |
| PR Code Quality Reviewer | 2 | 0 | 0 | 0 | 0 | 0 |
| Ponytail Reviewer | 2 | 0 | 0 | 0 | 0 | 0 |
| Squad — Integrate gh-aw-firewall v0.28.11 attested artifact contract atomically | 2 | 0 | 0 | 2 | 0 | 0 |
| 1. List all Go packages with their doc comments | 1 | 0 | 0 | 0 | 1 | 0 |
| Agent Job Health Monitor | 1 | 0 | 0 | 0 | 1 | 0 |

_192 further workflows omitted; see `stats.json`._

## Notable runs

_See the `detection-stats-` artifact for the full notable-runs table (74+ entries, all `absent`/`unreadable` verdicts, no failures or threats observed today)._

## Change since 2026-08-30

| Metric | 2026-08-30 | 2026-08-31 | Δ | 7-day mean |
|---|---|---|---|---|
| External detector runs | 602 | 578 | -24 | 907.6 |
| Error rate | 0.0% | 0.0% | 0 | — |
| Soft failures | 53 | 58 | +5 | 50.3 |
| With verdict | 273 | 219 | -54 | 339.6 |
| Any threat | 0 | 0 | 0 | 0.35% (rate) |
| Threat rate | 0.0% | 0.0% | 0 | — |

## Watch list

- Daily Go Test Parallelizer — 0 failed, 12 without a verdict, out of 12 runs
- Avenger — 0 failed, 5 without a verdict, out of 24 runs
- Code Scanning Fixer — 0 failed, 2 without a verdict, out of 4 runs
- Auto-Triage Issues — 0 failed, 1 without a verdict, out of 10 runs
- PR Triage Agent — 0 failed, 1 without a verdict, out of 4 runs

Collected by: https://github.com/github/gh-aw-threat-detection/actions/runs/33467999750
Full data: the detection-stats-33467999750 artifact on that run.

> Generated by [Detection Stats Daily](https://github.com/github/gh-aw-threat-detection/actions/runs/33467999750) · copilot · auto · 27.7 AIC · ⌖ 14.8 AIC · ⊞ 11.3K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw-threat-detection+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw-threat-detection%2Fdetection-stats-daily%22&type=issues)

Contributor guide

Open the contributing guide

Research direction

This is an automated detection-statistics report and names no source file, test, or requested change. Start by reviewing the linked detection-stats artifact and workflow run to identify a concrete follow-up. The report itself is complete; no implementation definition of done is provided.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, go
Domain
observability, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.