github / github/gh-aw-threat-detection
[detection-stats] Detection stats for github/gh-aw - 2026-09-01
- Dominant language
- Go
- Stars
- 13
- Forks
- 7
- Avg merge
- 9h 52m
- Merged PRs (30d)
- 25
Description
844 external-detector runs analysed on 2026-09-01, detection-job error rate 0%, soft failures 83, threat rate 0% (of 225 verdicts).
## Summary
# gh-aw detection statistics - 2026-09-01 (UTC)
Repository: `github/gh-aw`
Window: `2026-09-01T00:00:00Z` .. `2026-09-01T23:59:59Z`
API requests: 2568, rate-limit pauses: 1
Data complete: yes
## Totals
| Metric | Count |
|---|---|
| Workflow runs in window | 2755 |
| Agentic runs (`*.lock.yml`) | 1858 |
| Runs with a `detection` job | 1423 |
| ... using the external detector | 844 |
| ... using the built-in detector | 579 |
| ... detector could not be determined | 0 |
| Agentic runs without a `detection` job | 435 |
All rates below are over the **external detector** population (844 runs). Since gh-aw #54111 the external detector is the compile-time default; a run counts as external when its `detection` job showed the `Install threat-detect binary` step, when another run of the same workflow did that day, or when the workflow is `.lock.yml` and no run showed the built-in shape (a completed detection job with steps but no marker). Runs on a workflow that opted out with `features: gh-aw-detection: false` count as built-in.
## Detection job outcomes
| Outcome | Count | Rate |
|---|---|---|
| `skipped` | 465 | 55.09% |
| `success` | 376 | 44.55% |
| `cancelled` | 3 | 0.36% |
**Error rate (failure/timed_out/action_required): 0%**
## Verdict availability
| State | Meaning | Count |
|---|---|---|
| `present` | detection artifact downloaded and parsed | 225 |
| `absent` | detection job ran but published no artifact (soft failure) | 84 |
| `skipped` | detection job was skipped or was still running (nothing to fetch) | 465 |
| `unreadable` | artifact zip could not be unpacked | 70 |
Green detection jobs that published no verdict: **83** (detection steps are `continue-on-error`, so a missing verdict artifact is the only reliable signal for these).
## Detection results
| Result | Count |
|---|---|
| Runs with a parsed verdict | 225 |
| Clean (no threat) | 225 |
| Any threat | 0 |
| `prompt_injection` | 0 |
| `secret_leak` | 0 |
| `malicious_patch` | 0 |
**Threat rate (of runs with a verdict): 0%**
## By workflow
| Workflow | Runs | Failed | Cancelled | Skipped | No verdict | Threats |
|---|---|---|---|---|---|---|
| Q | 80 | 0 | 0 | 80 | 0 | 0 |
| Deployment Incident Monitor | 79 | 0 | 0 | 79 | 0 | 0 |
| PR Sous Chef | 76 | 0 | 1 | 0 | 0 | 0 |
| Daily Trajectory Grader Implementer | 47 | 0 | 0 | 47 | 0 | 0 |
| [aw] Failure Investigator (6h) | 47 | 0 | 0 | 43 | 0 | 0 |
| Issue Monster | 44 | 0 | 0 | 0 | 3 | 0 |
| Avenger | 24 | 0 | 0 | 14 | 10 | 0 |
| Smoke Gemini | 21 | 0 | 0 | 20 | 1 | 0 |
| Changeset Generator | 17 | 0 | 1 | 14 | 3 | 0 |
| Code Refiner | 17 | 0 | 0 | 15 | 2 | 0 |
| The Great Escapi | 17 | 0 | 0 | 14 | 2 | 0 |
| PR Description Updater | 15 | 0 | 0 | 6 | 0 | 0 |
| Auto-Triage Issues | 14 | 0 | 0 | 6 | 3 | 0 |
| Daily Go Test Parallelizer | 12 | 0 | 0 | 0 | 12 | 0 |
| Design Decision Gate 🏗️ | 11 | 0 | 0 | 4 | 0 | 0 |
| Matt Pocock Skills Reviewer | 9 | 0 | 0 | 0 | 5 | 0 |
| Workflow Generator | 9 | 0 | 0 | 9 | 0 | 0 |
| Impeccable Skills Reviewer | 8 | 0 | 0 | 0 | 4 | 0 |
| PR Code Quality Reviewer | 8 | 0 | 0 | 0 | 0 | 0 |
| Ponytail Reviewer | 8 | 0 | 0 | 0 | 0 | 0 |
| Test Quality Sentinel | 8 | 0 | 0 | 0 | 2 | 0 |
| Contribution Check | 6 | 0 | 0 | 0 | 0 | 0 |
| Code Scanning Fixer | 4 | 0 | 0 | 0 | 1 | 0 |
| Deep Report | 4 | 0 | 0 | 0 | 0 | 0 |
| PR Triage Agent | 4 | 0 | 0 | 0 | 0 | 0 |
_230 further workflows omitted; see `stats.json`._
## Notable runs
_105 notable runs recorded (all with `success`/`cancelled` job conclusions and `absent`/`unreadable` verdict states, no threats); see `stats.json` for the full list._
## Change since 2026-08-31
| Metric | 2026-08-31 | 2026-09-01 | Δ | 7-day mean (08-25..08-31) |
|---|---|---|---|---|
| External detector runs | 578 | 844 | +266 | 847.1 |
| Error rate | 0.0% | 0% | 0.0 pp | 0.0% |
| Soft failures | 58 | 83 | +25 | 45.6 |
| Runs with verdict | 219 | 225 | +6 | 304.3 |
| Any threat | 0 | 0 | 0 | 1.0 |
| Threat rate | 0.0% | 0% | 0.0 pp | 0.32% |
## Watch list
- Daily Go Test Parallelizer — 0 failed, 12 without a verdict, out of 12 runs
- Avenger — 0 failed, 10 without a verdict, out of 24 runs
- Matt Pocock Skills Reviewer — 0 failed, 5 without a verdict, out of 9 runs
- Impeccable Skills Reviewer — 0 failed, 4 without a verdict, out of 8 runs
- Issue Monster — 0 failed, 3 without a verdict, out of 44 runs
Collected by: https://github.com/github/gh-aw-threat-detection/actions/runs/33588877484
Full data: the detection-stats-33588877484 artifact on that run.
> Generated by [Detection Stats Daily](https://github.com/github/gh-aw-threat-detection/actions/runs/33588877484) · copilot · auto · 27.1 AIC · ⌖ 5.73 AIC · ⊞ 11.3K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw-threat-detection+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw-threat-detection%2Fdetection-stats-daily%22&type=issues)
Contributor guide
Research direction
Start with the linked Detection Stats Daily workflow run and its detection-stats-33588877484 artifact; the issue body is a generated daily report and points to stats.json for omitted data. No file, test, or requested change is identified, so completion criteria must be clarified before implementation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- observability, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100