github / github/gh-aw-threat-detection
[detection-stats] Detection stats for github/gh-aw - 2026-09-05
- Dominant language
- Go
- Stars
- 13
- Forks
- 7
- Avg merge
- 9h 52m
- Merged PRs (30d)
- 25
Description
> [!CAUTION]
> agentic threat detected
> Threat detection flagged this output in warn mode. Manual review is REQUIRED before any follow-up automation.
>
>
>
> Details
>
> Potential security threats were detected in the agent output.
>
> Review the [workflow run logs](https://github.com/github/gh-aw-threat-detection/actions/runs/34010218962) for details.
>
692 external-detector runs analysed on 2026-09-05; detection-job error rate 0%; soft failures 63; threat rate 0% (of 252 verdicts).
## Summary
# gh-aw detection statistics - 2026-09-05 (UTC)
Repository: `github/gh-aw`
Window: `2026-09-05T00:00:00Z` .. `2026-09-05T23:59:59Z`
API requests: 2079, rate-limit pauses: 1
Data complete: yes
## Totals
| Metric | Count |
|---|---|
| Workflow runs in window | 2658 |
| Agentic runs (`*.lock.yml`) | 1415 |
| Runs with a `detection` job | 731 |
| ... using the external detector | 692 |
| ... using the built-in detector | 39 |
| ... detector could not be determined | 0 |
| Agentic runs without a `detection` job | 684 |
All rates below are over the **external detector** population (692 runs). Since gh-aw #54111 the external detector is the compile-time default; a run counts as external when its `detection` job showed the `Install threat-detect binary` step, when another run of the same workflow did that day, or when the workflow is `.lock.yml` and no run showed the built-in shape (a completed detection job with steps but no marker). Runs on a workflow that opted out with `features: gh-aw-detection: false` count as built-in.
## Detection job outcomes
| Outcome | Count | Rate |
|---|---|---|
| `success` | 347 | 50.14% |
| `skipped` | 345 | 49.86% |
**Error rate (failure/timed_out/action_required): 0%**
## Verdict availability
| State | Meaning | Count |
|---|---|---|
| `present` | detection artifact downloaded and parsed | 252 |
| `absent` | detection job ran but published no artifact (soft failure) | 63 |
| `skipped` | detection job was skipped or was still running (nothing to fetch) | 345 |
| `unreadable` | artifact zip could not be unpacked | 32 |
Green detection jobs that published no verdict: **63** (detection steps are `continue-on-error`, so a missing verdict artifact is the only reliable signal for these).
## Detection results
| Result | Count |
|---|---|
| Runs with a parsed verdict | 252 |
| Clean (no threat) | 252 |
| Any threat | 0 |
| `prompt_injection` | 0 |
| `secret_leak` | 0 |
| `malicious_patch` | 0 |
**Threat rate (of runs with a verdict): 0%**
## By workflow
| Workflow | Runs | Failed | Cancelled | Skipped | No verdict | Threats |
|---|---|---|---|---|---|---|
| PR Sous Chef | 86 | 0 | 0 | 0 | 4 | 0 |
| Deployment Incident Monitor | 69 | 0 | 0 | 69 | 0 | 0 |
| Q | 69 | 0 | 0 | 69 | 0 | 0 |
| Daily Trajectory Grader Implementer | 47 | 0 | 0 | 47 | 0 | 0 |
| Issue Monster | 47 | 0 | 0 | 12 | 0 | 0 |
| [aw] Failure Investigator (6h) | 47 | 0 | 0 | 43 | 1 | 0 |
| Avenger | 24 | 0 | 0 | 19 | 5 | 0 |
| Daily Go Test Parallelizer | 12 | 0 | 0 | 2 | 3 | 0 |
| Design Decision Gate 🏗️ | 11 | 0 | 0 | 0 | 0 | 0 |
| Impeccable Skills Reviewer | 11 | 0 | 0 | 0 | 0 | 0 |
| Matt Pocock Skills Reviewer | 11 | 0 | 0 | 0 | 0 | 0 |
| PR Code Quality Reviewer | 11 | 0 | 0 | 0 | 0 | 0 |
| Test Quality Sentinel | 11 | 0 | 0 | 0 | 3 | 0 |
| Ponytail Reviewer | 10 | 0 | 0 | 0 | 0 | 0 |
| Auto-Triage Issues | 9 | 0 | 0 | 0 | 8 | 0 |
| Contribution Check | 6 | 0 | 0 | 0 | 0 | 0 |
| Squad — Add compiler support for dynamic repository enclave policies | 5 | 0 | 0 | 5 | 0 | 0 |
| Code Scanning Fixer | 4 | 0 | 0 | 0 | 0 | 0 |
| Deep Report | 4 | 0 | 0 | 0 | 0 | 0 |
| PR Triage Agent | 4 | 0 | 0 | 0 | 1 | 0 |
| Squad — ``@copilot`` please refresh this PR for maintainer review: re-run your dependency-update finishing pass, ensure the branch is up to date with the base branch, and use the `pr-finisher` skill before handing back off.
> [!WARNING]
>
> Firewall blocked 1 domain
>
> The following domain was blocked by the firewall during workflow execution:
>
> - `github.com`
>
> To allow these domains, add them to the `network.allowed` list in your workflow frontmatter:
>
> ```yaml
> netw... | 4 | 0 | 0 | 4 | 0 | 0 |
| Squad — @copilot please triage this PR for forward progress. Review current checks/reviews, refresh the branch if appropriate, and run the `pr-finisher` skill.
Run: https://github.com/github/gh-aw/actions/runs/33969570497
> Generated by [👨🍳 PR Sous Chef](https://github.com/github/gh-aw/actions/runs/33969570497) · pi · gpt54 · 13.6 AIC · ⌖ 8.68 AIC · ⊞ 9.2K · [◷](https://github.com/search?q=repo:github%2Fgh-aw+%22gh-aw-workflow-call-id:+github%2Fgh-aw%2Fpr-sous-chef%22&type=is... | 4 | 0 | 0 | 4 | 0 | 0 |
| Squad — ```hidden
pr-sous-chef
```
@copilot Please take the next forward-progress pass on this PR.
- Re-check the latest branch and CI state on current HEAD.
- If no code changes are needed and the remaining blocker is only maintainer-side CI approval/re-trigger or routine review follow-through, say that explicitly in maintainer-facing terms.
- Then run the `pr-finisher` skill and hand the PR back to maintainers concisely.
> Generated by PR Sous Chef: https://github.com/github/gh-aw/actions/runs/3395... | 4 | 0 | 0 | 4 | 0 | 0 |
| Squad — ```hidden
pr-sous-chef
```
``@copilot`` Please take the next forward-progress pass on this PR.
- Re-check the latest branch and CI state on current HEAD.
- If no code changes are needed and the remaining blocker is only maintainer-side CI approval/re-trigger or routine review follow-through, say that explicitly in maintainer-facing terms.
- Then run the `pr-finisher` skill and hand the PR back to maintainers concisely.
> Generated by PR Sous Chef: https://github.com/github/gh-aw/actions/runs/3399... | 4 | 0 | 0 | 4 | 0 | 0 |
| Smoke Issues | 3 | 0 | 0 | 0 | 0 | 0 |
_167 further workflows omitted; see `stats.json`._
## Notable runs
| Workflow | Run | Job conclusion | Verdict | Threats | Reported reason |
|---|---|---|---|---|---|
| Agent Job Health Monitor | [33998213656](https://github.com/github/gh-aw/actions/runs/33998213656) | `success` | `absent` | - | `-` |
| Agent Persona Explorer | [33974886706](https://github.com/github/gh-aw/actions/runs/33974886706) | `success` | `absent` | - | `-` |
| Agentic Workflow Audit Agent | [33992523113](https://github.com/github/gh-aw/actions/runs/33992523113) | `success` | `absent` | - | `-` |
| Auto-Triage Issues | [33950085204](https://github.com/github/gh-aw/actions/runs/33950085204) | `success` | `absent` | - | `-` |
| Auto-Triage Issues | [33966120309](https://github.com/github/gh-aw/actions/runs/33966120309) | `success` | `absent` | - | `-` |
| Auto-Triage Issues | [33982810308](https://github.com/github/gh-aw/actions/runs/33982810308) | `success` | `absent` | - | `-` |
| Auto-Triage Issues | [33983902612](https://github.com/github/gh-aw/actions/runs/33983902612) | `success` | `absent` | - | `-` |
| Auto-Triage Issues | [33987816193](https://github.com/github/gh-aw/actions/runs/33987816193) | `success` | `absent` | - | `-` |
| Auto-Triage Issues | [33998789638](https://github.com/github/gh-aw/actions/runs/33998789638) | `success` | `absent` | - | `-` |
| Auto-Triage Issues | [33998852434](https://github.com/github/gh-aw/actions/runs/33998852434) | `success` | `absent` | - | `-` |
| Auto-Triage Issues | [33998866739](https://github.com/github/gh-aw/actions/runs/33998866739) | `success` | `absent` | - | `-` |
| Avenger | [33934824020](https://github.com/github/gh-aw/actions/runs/33934824020) | `success` | `absent` | - | `-` |
| Avenger | [33947347863](https://github.com/github/gh-aw/actions/runs/33947347863) | `success` | `absent` | - | `-` |
| Avenger | [33950434728](https://github.com/github/gh-aw/actions/runs/33950434728) | `success` | `absent` | - | `-` |
| Avenger | [33960733960](https://github.com/github/gh-aw/actions/runs/33960733960) | `success` | `absent` | - | `-` |
| Avenger | [33995941693](https://github.com/github/gh-aw/actions/runs/33995941693) | `success` | `absent` | - | `-` |
| CLI Version Checker | [33947250516](https://github.com/github/gh-aw/actions/runs/33947250516) | `success` | `absent` | - | `-` |
| Cache directory setup | [33998782878](https://github.com/github/gh-aw/actions/runs/33998782878) | `success` | `absent` | - | `-` |
| Daily AWF Spec Compiler Surfacing Review | [33995518233](https://github.com/github/gh-aw/actions/runs/33995518233) | `success` | `absent` | - | `-` |
| Daily AstroStyleLite Markdown Spellcheck | [33941717031](https://github.com/github/gh-aw/actions/runs/33941717031) | `success` | `unreadable` | - | `-` |
| Daily CLI Performance Agent | [33972965658](https://github.com/github/gh-aw/actions/runs/33972965658) | `success` | `absent` | - | `-` |
| Daily Cache Strategy Analyzer | [33984179571](https://github.com/github/gh-aw/actions/runs/33984179571) | `success` | `absent` | - | `-` |
| Daily Cli Tools Tester | [33946875591](https://github.com/github/gh-aw/actions/runs/33946875591) | `success` | `absent` | - | `-` |
| Daily Code Debt Cleanup — Aider | [33985333922](https://github.com/github/gh-aw/actions/runs/33985333922) | `success` | `absent` | - | `-` |
| Daily Code Metrics and Trend Tracking Agent | [33984198790](https://github.com/github/gh-aw/actions/runs/33984198790) | `success` | `absent` | - | `-` |
| Daily Community Attribution Updater | [33939471908](https://github.com/github/gh-aw/actions/runs/33939471908) | `success` | `absent` | - | `-` |
| Daily Compiler Quality Check | [33939532566](https://github.com/github/gh-aw/actions/runs/33939532566) | `success` | `absent` | - | `-` |
| Daily Compiler Threat Spec Optimizer | [33939474537](https://github.com/github/gh-aw/actions/runs/33939474537) | `success` | `absent` | - | `-` |
| Daily Documentation Diagram | [33945806941](https://github.com/github/gh-aw/actions/runs/33945806941) | `success` | `absent` | - | `-` |
| Daily Documentation Updater | [33961192104](https://github.com/github/gh-aw/actions/runs/33961192104) | `success` | `absent` | - | `-` |
| Daily Go Test Parallelizer | [33944825652](https://github.com/github/gh-aw/actions/runs/33944825652) | `success` | `absent` | - | `-` |
| Daily Go Test Parallelizer | [33966484770](https://github.com/github/gh-aw/actions/runs/33966484770) | `success` | `absent` | - | `-` |
| Daily Go Test Parallelizer | [33971894411](https://github.com/github/gh-aw/actions/runs/33971894411) | `success` | `absent` | - | `-` |
| Daily Go Test Stubs — Aider | [33977965345](https://github.com/github/gh-aw/actions/runs/33977965345) | `success` | `absent` | - | `-` |
| Daily Grader Audit | [33953303348](https://github.com/github/gh-aw/actions/runs/33953303348) | `success` | `unreadable` | - | `-` |
| Daily Max Ai Credits Test | [33962897625](https://github.com/github/gh-aw/actions/runs/33962897625) | `success` | `absent` | - | `-` |
| Daily Regulatory Report Generator | [33992551577](https://github.com/github/gh-aw/actions/runs/33992551577) | `success` | `absent` | - | `-` |
| Daily Safe Output Tool Optimizer | [33991433673](https://github.com/github/gh-aw/actions/runs/33991433673) | `success` | `unreadable` | - | `-` |
| Daily Safe Outputs Git Simulator | [33944662648](https://github.com/github/gh-aw/actions/runs/33944662648) | `success` | `unreadable` | - | `-` |
| Daily Spending Forecast | [33958541017](https://github.com/github/gh-aw/actions/runs/33958541017) | `success` | `absent` | - | `-` |
| Daily Team Evolution Insights | [33989708881](https://github.com/github/gh-aw/actions/runs/33989708881) | `success` | `absent` | - | `-` |
| Daily action/setup/* Security Audit | [33939494696](https://github.com/github/gh-aw/actions/runs/33939494696) | `success` | `absent` | - | `-` |
| Deep Report | [33983874094](https://github.com/github/gh-aw/actions/runs/33983874094) | `success` | `unreadable` | - | `-` |
| Documentation Unbloat | [33934719417](https://github.com/github/gh-aw/actions/runs/33934719417) | `success` | `absent` | - | `-` |
| Duplicate Code Detector | [33994117227](https://github.com/github/gh-aw/actions/runs/33994117227) | `success` | `absent` | - | `-` |
| ESLint Monster | [33994403234](https://github.com/github/gh-aw/actions/runs/33994403234) | `success` | `absent` | - | `-` |
| ESLint Refiner | [33946910021](https://github.com/github/gh-aw/actions/runs/33946910021) | `success` | `unreadable` | - | `-` |
| GPL Dependency Cleaner (gpclean) | [33941715442](https://github.com/github/gh-aw/actions/runs/33941715442) | `success` | `absent` | - | `-` |
| GitHub Remote MCP Authentication Test | [33947301523](https://github.com/github/gh-aw/actions/runs/33947301523) | `success` | `absent` | - | `-` |
| Go Logger Enhancement | [33941761948](https://github.com/github/gh-aw/actions/runs/33941761948) | `success` | `unreadable` | - | `-` |
| Instructions Janitor | [33955546240](https://github.com/github/gh-aw/actions/runs/33955546240) | `success` | `absent` | - | `-` |
| Issue Arborist | [33946848960](https://github.com/github/gh-aw/actions/runs/33946848960) | `success` | `absent` | - | `-` |
| Issue Monster | [33936113218](https://github.com/github/gh-aw/actions/runs/33936113218) | `success` | `unreadable` | - | `-` |
| Issue Monster | [33939917799](https://github.com/github/gh-aw/actions/runs/33939917799) | `success` | `unreadable` | - | `-` |
| Issue Monster | [33942568111](https://github.com/github/gh-aw/actions/runs/33942568111) | `success` | `unreadable` | - | `-` |
| Issue Monster | [33949997889](https://github.com/github/gh-aw/actions/runs/33949997889) | `success` | `unreadable` | - | `-` |
| Issue Monster | [33952222559](https://github.com/github/gh-aw/actions/runs/33952222559) | `success` | `unreadable` | - | `-` |
| Issue Monster | [33953125471](https://github.com/github/gh-aw/actions/runs/33953125471) | `success` | `unreadable` | - | `-` |
| Issue Monster | [33957647565](https://github.com/github/gh-aw/actions/runs/33957647565) | `success` | `unreadable` | - | `-` |
| Issue Monster | [33958548450](https://github.com/github/gh-aw/actions/runs/33958548450) | `success` | `unreadable` | - | `-` |
_35 further notable runs omitted; see `stats.json`._
## Change since 2026-09-04
| Metric | 2026-09-04 | 2026-09-05 | Delta | 7-day mean (08-29..09-04) |
|---|---|---|---|---|
| External detector runs | 844 | 692 | -152 | 758.99 |
| Error rate | 0.0% | 0.0% | 0.0pp | 0.0% |
| Soft failures | 117 | 63 | -54 | 69.57 |
| Runs with verdict | 238 | 252 | +14 | 262.29 |
| Any threat | 0 | 0 | 0 | 0.14 |
| Threat rate | 0.0% | 0.0% | 0.0pp | 0.05% |
## Watch list
- Auto-Triage Issues — 0 failed, 8 without a verdict, out of 9 runs
- Avenger — 0 failed, 5 without a verdict, out of 24 runs
- PR Sous Chef — 0 failed, 4 without a verdict, out of 86 runs
- Daily Go Test Parallelizer — 0 failed, 3 without a verdict, out of 12 runs
- Test Quality Sentinel — 0 failed, 3 without a verdict, out of 11 runs
Collected by: https://github.com/github/gh-aw-threat-detection/actions/runs/34010218962
Full data: the detection-stats-34010218962 artifact on that run.
> Generated by [Detection Stats Daily](https://github.com/github/gh-aw-threat-detection/actions/runs/34010218962) · copilot · auto · 28.4 AIC · ⌖ 9.64 AIC · ⊞ 11.3K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw-threat-detection+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw-threat-detection%2Fdetection-stats-daily%22&type=issues)
Contributor guide
Research direction
Review the linked workflow run logs first, then compare this report with stats.json, which the issue identifies as the source for omitted workflows. The issue defines no code change, target file, test, or acceptance criteria, so there is no verifiable “done” state until maintainers specify the intended follow-up.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100