github / github/gh-aw-threat-detection
[detection-stats] Detection stats for github/gh-aw - 2026-08-28
- Dominant language
- Go
- Stars
- 13
- Forks
- 7
- Avg merge
- 9h 52m
- Merged PRs (30d)
- 25
Description
724 external-detector runs analysed, detection-job error rate 0%, 35 soft failures, threat rate 0% (of 297 verdicts).
## Summary
# gh-aw detection statistics - 2026-08-28 (UTC)
Repository: `github/gh-aw`
Window: `2026-08-28T00:00:00Z` .. `2026-08-28T23:59:59Z`
API requests: 2044, rate-limit pauses: 1
Data complete: yes
## Totals
| Metric | Count |
|---|---|
| Workflow runs in window | 2342 |
| Agentic runs (`*.lock.yml`) | 1258 |
| Runs with a `detection` job | 738 |
| ... using the external detector | 724 |
| ... using the built-in detector | 14 |
| ... detector could not be determined | 0 |
| Agentic runs without a `detection` job | 520 |
All rates below are over the **external detector** population (724 runs). Since gh-aw #54111 the external detector is the compile-time default; a run counts as external when its `detection` job showed the `Install threat-detect binary` step, when another run of the same workflow did that day, or when the workflow is `.lock.yml` and no run showed the built-in shape (a completed detection job with steps but no marker). Runs on a workflow that opted out with `features: gh-aw-detection: false` count as built-in.
## Detection job outcomes
| Outcome | Count | Rate |
|---|---|---|
| `success` | 395 | 54.56% |
| `skipped` | 329 | 45.44% |
**Error rate (failure/timed_out/action_required): 0%**
## Verdict availability
| State | Meaning | Count |
|---|---|---|
| `present` | detection artifact downloaded and parsed | 297 |
| `absent` | detection job ran but published no artifact (soft failure) | 35 |
| `skipped` | detection job was skipped or was still running (nothing to fetch) | 329 |
| `unreadable` | artifact zip could not be unpacked | 63 |
Green detection jobs that published no verdict: **35** (detection steps are `continue-on-error`, so a missing verdict artifact is the only reliable signal for these).
## Detection results
| Result | Count |
|---|---|
| Runs with a parsed verdict | 297 |
| Clean (no threat) | 297 |
| Any threat | 0 |
| `prompt_injection` | 0 |
| `secret_leak` | 0 |
| `malicious_patch` | 0 |
**Threat rate (of runs with a verdict): 0%**
## Reasons reported by gh-aw
From the `[aw] Detection Runs` tracking issue (warning/failure conclusions only), restricted to runs in the external-detector population above.
| Reason | Count |
|---|---|
| `parse_error` | 54 |
| `agent_failure` | 42 |
## By workflow
(top 25 of 294 workflows; see `stats.json` for the remaining 269)
| Workflow | Runs | Failed | Cancelled | Skipped | No verdict | Threats |
|---|---|---|---|---|---|---|
| Q | 89 | 0 | 0 | 89 | 0 | 0 |
| Deployment Incident Monitor | 73 | 0 | 0 | 73 | 0 | 0 |
| Test Quality Sentinel | 28 | 0 | 0 | 0 | 0 | 0 |
| Design Decision Gate 🏗️ | 24 | 0 | 0 | 1 | 2 | 0 |
| Impeccable Skills Reviewer | 24 | 0 | 0 | 0 | 0 | 0 |
| Matt Pocock Skills Reviewer | 24 | 0 | 0 | 0 | 0 | 0 |
| PR Code Quality Reviewer | 24 | 0 | 0 | 0 | 0 | 0 |
| Ponytail Reviewer | 24 | 0 | 0 | 0 | 0 | 0 |
| PR Description Updater | 17 | 0 | 0 | 1 | 0 | 0 |
| Auto-Triage Issues | 16 | 0 | 0 | 5 | 0 | 0 |
| PR Sous Chef | 15 | 0 | 0 | 1 | 0 | 0 |
| Issue Monster | 11 | 0 | 0 | 3 | 0 | 0 |
| Workflow Generator | 11 | 0 | 0 | 11 | 0 | 0 |
| Avenger | 9 | 0 | 0 | 2 | 7 | 0 |
| Daily Go Test Parallelizer | 6 | 0 | 0 | 0 | 0 | 0 |
| Squad — ``@copilot`` run pr-finisher skill | 6 | 0 | 0 | 6 | 0 | 0 |
| Contribution Check | 5 | 0 | 0 | 0 | 0 | 0 |
| Squad — ``@copilot`` resolve the merge conflicts on this branch. | 5 | 0 | 0 | 5 | 0 | 0 |
| Code Scanning Fixer | 4 | 0 | 0 | 0 | 1 | 0 |
| Deep Report | 4 | 0 | 0 | 0 | 1 | 0 |
| PR Triage Agent | 4 | 0 | 0 | 0 | 1 | 0 |
| Windows Runner Integration Test | 4 | 0 | 0 | 0 | 4 | 0 |
| [aw] Failure Investigator (6h) | 4 | 0 | 0 | 0 | 0 | 0 |
| Squad — /windows | 3 | 0 | 0 | 3 | 0 | 0 |
_269 further workflows omitted; see `stats.json`._
## Notable runs
_See the `stats.json` artifact for the full list of notable runs (61 total, 38 omitted here for brevity)._
## Change since 2026-08-27
| Metric | 2026-08-27 | 2026-08-28 | Δ | 7-day mean |
|---|---|---|---|---|
| External-detector runs | 632 | 724 | +92 | 1011.0 |
| Error rate | 0.0% | 0% | 0.0 pp | 0.04% |
| Soft failures | 64 | 35 | -29 | 57.4 |
| Threat rate (of verdicts) | 1.13% | 0% | -1.13 pp | 0.55% |
## Watch list
- Avenger — 0 failed, 7 without a verdict, out of 9 runs
- Windows Runner Integration Test — 0 failed, 4 without a verdict, out of 4 runs
- Design Decision Gate 🏗️ — 0 failed, 2 without a verdict, out of 24 runs
- Code Scanning Fixer — 0 failed, 1 without a verdict, out of 4 runs
- Deep Report — 0 failed, 1 without a verdict, out of 4 runs
Collected by: https://github.com/github/gh-aw-threat-detection/actions/runs/33232589390
Full data: the detection-stats-33232589390 artifact on that run.
> Generated by [Detection Stats Daily](https://github.com/github/gh-aw-threat-detection/actions/runs/33232589390) · copilot · auto · 29.7 AIC · ⌖ 7.76 AIC · ⊞ 11.3K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw-threat-detection+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw-threat-detection%2Fdetection-stats-daily%22&type=issues)
Contributor guide
Research direction
Start with the detection-stats-33232589390 artifact and its stats.json file, then review the Detection Stats Daily workflow run linked in the report. The issue provides measurements and watch-list entries but no requested change or acceptance criteria, so a contributor would need clarification before defining what done means.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- observability, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100