github / github/gh-aw-threat-detection
[detection-stats] Detection stats for github/gh-aw - 2026-09-14
- Dominant language
- Go
- Stars
- 13
- Forks
- 7
- Avg merge
- 9h 52m
- Merged PRs (30d)
- 25
Description
External-detector runs analysed: 635 · detection-job error rate: 0.63% · soft failures: 0 · threat rate (of runs with a verdict): 0.71%
## Summary
# gh-aw detection statistics - 2026-09-14 (UTC)
Repository: `github/gh-aw`
Window: `2026-09-14T00:00:00Z` .. `2026-09-14T23:59:59Z`
API requests: 1605, rate-limit pauses: 1
Data complete: yes
## Totals
| Metric | Count |
|---|---|
| Workflow runs in window | 1462 |
| Agentic runs (`*.lock.yml`) | 875 |
| Runs with a `detection` job | 636 |
| ... using the external detector | 635 |
| ... using the built-in detector | 1 |
| ... detector could not be determined | 0 |
| Agentic runs without a `detection` job | 239 |
All rates below are over the **external detector** population (635 runs). Since gh-aw #54111 the external detector is the compile-time default; a run counts as external when its `detection` job showed the `Install threat-detect binary` step, when another run of the same workflow did that day, or when the workflow is `.lock.yml` and no run showed the built-in shape (a completed detection job with steps but no marker). Runs on a workflow that opted out with `features: gh-aw-detection: false` count as built-in.
## Detection job outcomes
| Outcome | Count | Rate |
|---|---|---|
| `success` | 352 | 55.43% |
| `skipped` | 279 | 43.94% |
| `failure` | 4 | 0.63% |
**Error rate (failure/timed_out/action_required): 0.63%**
## Verdict availability
| State | Meaning | Count |
|---|---|---|
| `present` | detection artifact downloaded and parsed | 140 |
| `absent` | detection job ran but published no artifact (soft failure) | 1 |
| `skipped` | detection job was skipped or was still running (nothing to fetch) | 279 |
| `unreadable` | artifact zip could not be unpacked | 215 |
Green detection jobs that published no verdict: **0** (detection steps are `continue-on-error`, so a missing verdict artifact is the only reliable signal for these).
## Detection results
| Result | Count |
|---|---|
| Runs with a parsed verdict | 140 |
| Clean (no threat) | 139 |
| Any threat | 1 |
| `prompt_injection` | 1 |
| `secret_leak` | 0 |
| `malicious_patch` | 0 |
**Threat rate (of runs with a verdict): 0.71%**
## By workflow
| Workflow | Runs | Failed | Cancelled | Skipped | No verdict | Threats |
|---|---|---|---|---|---|---|
| PR Sous Chef | 78 | 0 | 0 | 16 | 0 | 0 |
| Deployment Incident Monitor | 54 | 0 | 0 | 54 | 0 | 0 |
| Daily Trajectory Grader Implementer | 46 | 0 | 0 | 46 | 0 | 0 |
| [aw] Failure Investigator (6h) | 46 | 0 | 0 | 42 | 0 | 0 |
| Issue Monster | 45 | 0 | 0 | 1 | 0 | 0 |
| Q | 33 | 0 | 0 | 33 | 0 | 0 |
| Avenger | 24 | 1 | 0 | 20 | 0 | 0 |
| Daily Go Test Parallelizer | 12 | 0 | 0 | 1 | 0 | 0 |
| Test Quality Sentinel | 10 | 0 | 0 | 0 | 0 | 0 |
| Auto-Triage Issues | 9 | 0 | 0 | 4 | 0 | 0 |
| Design Decision Gate 🏗️ | 9 | 0 | 0 | 0 | 0 | 0 |
| Impeccable Skills Reviewer | 9 | 0 | 0 | 0 | 0 | 0 |
| Matt Pocock Skills Reviewer | 9 | 0 | 0 | 0 | 0 | 0 |
| PR Code Quality Reviewer | 9 | 0 | 0 | 0 | 0 | 0 |
| Ponytail Reviewer | 9 | 0 | 0 | 0 | 0 | 0 |
| Contribution Check | 6 | 0 | 0 | 0 | 0 | 0 |
| Workflow Generator | 5 | 0 | 0 | 5 | 0 | 0 |
| Code Scanning Fixer | 4 | 0 | 0 | 0 | 0 | 1 |
| Deep Report | 4 | 0 | 0 | 0 | 0 | 0 |
| PR Triage Agent | 4 | 1 | 0 | 0 | 0 | 0 |
| Daily Credit Limit Test | 2 | 0 | 0 | 1 | 0 | 0 |
| Daily File Diet | 2 | 0 | 0 | 1 | 0 | 0 |
| Squad — ``@copilot`` run pr-finisher skill | 2 | 0 | 0 | 2 | 0 | 0 |
| 1. List all Go packages with their doc comments | 1 | 0 | 0 | 0 | 0 | 0 |
| Agent Job Health Monitor | 1 | 0 | 0 | 0 | 0 | 0 |
_202 further workflows omitted; see `stats.json`._
## Notable runs
| Workflow | Run | Job conclusion | Verdict | Threats | Reported reason |
|---|---|---|---|---|---|
| Code Scanning Fixer | [34846315083](https://github.com/github/gh-aw/actions/runs/34846315083) | `success` | `present` | prompt_injection | `-` |
| Avenger | [34856336377](https://github.com/github/gh-aw/actions/runs/34856336377) | `failure (Install AWF binary)` | `unreadable` | - | `-` |
| Daily CLI Performance Agent | [34858297054](https://github.com/github/gh-aw/actions/runs/34858297054) | `failure (Install AWF binary)` | `unreadable` | - | `-` |
| Dead Code Removal Agent | [34855276009](https://github.com/github/gh-aw/actions/runs/34855276009) | `failure (Upload threat detection artifact)` | `absent` | - | `-` |
| PR Triage Agent | [34814858011](https://github.com/github/gh-aw/actions/runs/34814858011) | `failure (Install AWF binary)` | `unreadable` | - | `-` |
_(further notable runs omitted; see `stats.json`)_
## Change since 2026-09-13
| Metric | 2026-09-13 | 2026-09-14 | Δ | 7-day mean |
|---|---|---|---|---|
| External detector runs | 601 | 635 | +34 | 909.14 |
| Error rate (%) | 1.00 | 0.63 | -0.37 | 0.20 |
| Soft failures | 0 | 0 | 0 | 70.29 |
| Runs with verdict | 145 | 140 | -5 | 221.71 |
| Any threat | 0 | 1 | +1 | 0.14 |
| Threat rate (%) | 0.00 | 0.71 | +0.71 | 0.05 |
## Watch list
- Dead Code Removal Agent — 1 failed, 1 without a verdict, out of 1 runs
- Avenger — 1 failed, 0 without a verdict, out of 24 runs
- PR Triage Agent — 1 failed, 0 without a verdict, out of 4 runs
- Daily CLI Performance Agent — 1 failed, 0 without a verdict, out of 1 runs
Collected by: https://github.com/github/gh-aw-threat-detection/actions/runs/34926854843
Full data: the detection-stats-34926854843 artifact on that run.
> Generated by [Detection Stats Daily](https://github.com/github/gh-aw-threat-detection/actions/runs/34926854843) · copilot · auto · 25.6 AIC · ⌖ 8.28 AIC · ⊞ 10K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw-threat-detection+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw-threat-detection%2Fdetection-stats-daily%22&type=issues)
Contributor guide
Research direction
The report points to stats.json and the detection-stats-34926854843 artifact, collected by the Detection Stats Daily workflow. Start by reviewing those generated outputs and the linked run; no requested code or documentation change is provided, so a concrete definition of done is absent.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, go
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100