github / github/gh-aw-threat-detection

[detection-stats] Detection stats for github/gh-aw - 2026-09-01

Open
#1,017 0 comments 0 reactions 0 assignees View on GitHub
automation detection-stats
Dominant language
Go
Stars
13
Forks
7
Avg merge
9h 52m
Merged PRs (30d)
25

Description

844 external-detector runs analysed on 2026-09-01, detection-job error rate 0%, soft failures 83, threat rate 0% (of 225 verdicts).

## Summary

# gh-aw detection statistics - 2026-09-01 (UTC)

Repository: `github/gh-aw`
Window: `2026-09-01T00:00:00Z` .. `2026-09-01T23:59:59Z`
API requests: 2568, rate-limit pauses: 1
Data complete: yes

## Totals

| Metric | Count |
|---|---|
| Workflow runs in window | 2755 |
| Agentic runs (`*.lock.yml`) | 1858 |
| Runs with a `detection` job | 1423 |
| ... using the external detector | 844 |
| ... using the built-in detector | 579 |
| ... detector could not be determined | 0 |
| Agentic runs without a `detection` job | 435 |

All rates below are over the **external detector** population (844 runs). Since gh-aw #54111 the external detector is the compile-time default; a run counts as external when its `detection` job showed the `Install threat-detect binary` step, when another run of the same workflow did that day, or when the workflow is `.lock.yml` and no run showed the built-in shape (a completed detection job with steps but no marker). Runs on a workflow that opted out with `features: gh-aw-detection: false` count as built-in.

## Detection job outcomes

| Outcome | Count | Rate |
|---|---|---|
| `skipped` | 465 | 55.09% |
| `success` | 376 | 44.55% |
| `cancelled` | 3 | 0.36% |

**Error rate (failure/timed_out/action_required): 0%**

## Verdict availability

| State | Meaning | Count |
|---|---|---|
| `present` | detection artifact downloaded and parsed | 225 |
| `absent` | detection job ran but published no artifact (soft failure) | 84 |
| `skipped` | detection job was skipped or was still running (nothing to fetch) | 465 |
| `unreadable` | artifact zip could not be unpacked | 70 |

Green detection jobs that published no verdict: **83** (detection steps are `continue-on-error`, so a missing verdict artifact is the only reliable signal for these).

## Detection results

| Result | Count |
|---|---|
| Runs with a parsed verdict | 225 |
| Clean (no threat) | 225 |
| Any threat | 0 |
| `prompt_injection` | 0 |
| `secret_leak` | 0 |
| `malicious_patch` | 0 |

**Threat rate (of runs with a verdict): 0%**

## By workflow

| Workflow | Runs | Failed | Cancelled | Skipped | No verdict | Threats |
|---|---|---|---|---|---|---|
| Q | 80 | 0 | 0 | 80 | 0 | 0 |
| Deployment Incident Monitor | 79 | 0 | 0 | 79 | 0 | 0 |
| PR Sous Chef | 76 | 0 | 1 | 0 | 0 | 0 |
| Daily Trajectory Grader Implementer | 47 | 0 | 0 | 47 | 0 | 0 |
| [aw] Failure Investigator (6h) | 47 | 0 | 0 | 43 | 0 | 0 |
| Issue Monster | 44 | 0 | 0 | 0 | 3 | 0 |
| Avenger | 24 | 0 | 0 | 14 | 10 | 0 |
| Smoke Gemini | 21 | 0 | 0 | 20 | 1 | 0 |
| Changeset Generator | 17 | 0 | 1 | 14 | 3 | 0 |
| Code Refiner | 17 | 0 | 0 | 15 | 2 | 0 |
| The Great Escapi | 17 | 0 | 0 | 14 | 2 | 0 |
| PR Description Updater | 15 | 0 | 0 | 6 | 0 | 0 |
| Auto-Triage Issues | 14 | 0 | 0 | 6 | 3 | 0 |
| Daily Go Test Parallelizer | 12 | 0 | 0 | 0 | 12 | 0 |
| Design Decision Gate 🏗️ | 11 | 0 | 0 | 4 | 0 | 0 |
| Matt Pocock Skills Reviewer | 9 | 0 | 0 | 0 | 5 | 0 |
| Workflow Generator | 9 | 0 | 0 | 9 | 0 | 0 |
| Impeccable Skills Reviewer | 8 | 0 | 0 | 0 | 4 | 0 |
| PR Code Quality Reviewer | 8 | 0 | 0 | 0 | 0 | 0 |
| Ponytail Reviewer | 8 | 0 | 0 | 0 | 0 | 0 |
| Test Quality Sentinel | 8 | 0 | 0 | 0 | 2 | 0 |
| Contribution Check | 6 | 0 | 0 | 0 | 0 | 0 |
| Code Scanning Fixer | 4 | 0 | 0 | 0 | 1 | 0 |
| Deep Report | 4 | 0 | 0 | 0 | 0 | 0 |
| PR Triage Agent | 4 | 0 | 0 | 0 | 0 | 0 |

_230 further workflows omitted; see `stats.json`._

## Notable runs

_105 notable runs recorded (all with `success`/`cancelled` job conclusions and `absent`/`unreadable` verdict states, no threats); see `stats.json` for the full list._

## Change since 2026-08-31

| Metric | 2026-08-31 | 2026-09-01 | Δ | 7-day mean (08-25..08-31) |
|---|---|---|---|---|
| External detector runs | 578 | 844 | +266 | 847.1 |
| Error rate | 0.0% | 0% | 0.0 pp | 0.0% |
| Soft failures | 58 | 83 | +25 | 45.6 |
| Runs with verdict | 219 | 225 | +6 | 304.3 |
| Any threat | 0 | 0 | 0 | 1.0 |
| Threat rate | 0.0% | 0% | 0.0 pp | 0.32% |

## Watch list

- Daily Go Test Parallelizer — 0 failed, 12 without a verdict, out of 12 runs
- Avenger — 0 failed, 10 without a verdict, out of 24 runs
- Matt Pocock Skills Reviewer — 0 failed, 5 without a verdict, out of 9 runs
- Impeccable Skills Reviewer — 0 failed, 4 without a verdict, out of 8 runs
- Issue Monster — 0 failed, 3 without a verdict, out of 44 runs

Collected by: https://github.com/github/gh-aw-threat-detection/actions/runs/33588877484
Full data: the detection-stats-33588877484 artifact on that run.

> Generated by [Detection Stats Daily](https://github.com/github/gh-aw-threat-detection/actions/runs/33588877484) · copilot · auto · 27.1 AIC · ⌖ 5.73 AIC · ⊞ 11.3K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw-threat-detection+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw-threat-detection%2Fdetection-stats-daily%22&type=issues)

Contributor guide

Open the contributing guide

Research direction

Start with the linked Detection Stats Daily workflow run and its detection-stats-33588877484 artifact; the issue body is a generated daily report and points to stats.json for omitted data. No file, test, or requested change is identified, so completion criteria must be clarified before implementation.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
observability, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.