github / github/gh-aw-threat-detection
[detection-stats] Detection stats for github/gh-aw - 2026-09-02
- Dominant language
- Go
- Stars
- 13
- Forks
- 7
- Avg merge
- 9h 52m
- Merged PRs (30d)
- 25
Description
998 external-detector runs analysed, detection-job error rate 0%, soft-failure count 76, threat rate 0.35%.
## Summary
# gh-aw detection statistics - 2026-09-02 (UTC)
Repository: `github/gh-aw`
Window: `2026-09-02T00:00:00Z` .. `2026-09-02T23:59:59Z`
API requests: 2715, rate-limit pauses: 1
Data complete: yes
## Totals
| Metric | Count |
|---|---|
| Workflow runs in window | 3362 |
| Agentic runs (`*.lock.yml`) | 1899 |
| Runs with a `detection` job | 999 |
| ... using the external detector | 998 |
| ... using the built-in detector | 1 |
| ... detector could not be determined | 0 |
| Agentic runs without a `detection` job | 900 |
All rates below are over the **external detector** population (998 runs). Since gh-aw #54111 the external detector is the compile-time default; a run counts as external when its `detection` job showed the `Install threat-detect binary` step, when another run of the same workflow did that day, or when the workflow is `.lock.yml` and no run showed the built-in shape (a completed detection job with steps but no marker). Runs on a workflow that opted out with `features: gh-aw-detection: false` count as built-in.
## Detection job outcomes
| Outcome | Count | Rate |
|---|---|---|
| `skipped` | 573 | 57.41% |
| `success` | 423 | 42.38% |
| `cancelled` | 2 | 0.2% |
**Error rate (failure/timed_out/action_required): 0%**
## Verdict availability
| State | Meaning | Count |
|---|---|---|
| `present` | detection artifact downloaded and parsed | 282 |
| `absent` | detection job ran but published no artifact (soft failure) | 76 |
| `skipped` | detection job was skipped or was still running (nothing to fetch) | 573 |
| `unreadable` | artifact zip could not be unpacked | 67 |
Green detection jobs that published no verdict: **76** (detection steps are `continue-on-error`, so a missing verdict artifact is the only reliable signal for these).
## Detection results
| Result | Count |
|---|---|
| Runs with a parsed verdict | 282 |
| Clean (no threat) | 281 |
| Any threat | 1 |
| `prompt_injection` | 1 |
| `secret_leak` | 0 |
| `malicious_patch` | 0 |
**Threat rate (of runs with a verdict): 0.35%**
(Full per-workflow and notable-run tables were truncated in this digest for length; see the `detection-stats-` artifact for the complete `stats.json`.)
## Change since 2026-09-01
| Metric | 2026-09-01 | 2026-09-02 | Δ | 7-day mean |
|---|---|---|---|---|
| External detector runs | 844 | 998 | +154 | 678.9 |
| Error rate | 0% | 0% | 0 | 0% |
| Soft failures | 83 | 76 | -7 | 50.4 |
| Runs with verdict | 225 | 282 | +57 | 275.6 |
| Any threat | 0 | 1 | +1 | 0.9 |
| Threat rate | 0.00% | 0.35% | +0.35 | 0.29% |
## Watch list
- Avenger — 0 failed, 16 without a verdict, out of 24 runs
- Daily Go Test Parallelizer — 0 failed, 12 without a verdict, out of 12 runs
- Test Quality Sentinel — 0 failed, 4 without a verdict, out of 20 runs
- Matt Pocock Skills Reviewer — 0 failed, 3 without a verdict, out of 19 runs
- Impeccable Skills Reviewer — 0 failed, 2 without a verdict, out of 17 runs
Collected by: https://github.com/github/gh-aw-threat-detection/actions/runs/33717560924
Full data: the detection-stats-33717560924 artifact on that run.
> Generated by [Detection Stats Daily](https://github.com/github/gh-aw-threat-detection/actions/runs/33717560924) · copilot · auto · 23.1 AIC · ⌖ 5.57 AIC · ⊞ 11.3K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw-threat-detection+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw-threat-detection%2Fdetection-stats-daily%22&type=issues)
Contributor guide
Research direction
This issue is an automated Detection Stats Daily report rather than a requested code change. Start with the linked Detection Stats Daily workflow run and its detection-stats-33717560924 artifact; no acceptance criteria or target file is provided, so completion cannot be determined from the issue alone.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- observability, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100