Skip to content

[detection-stats] Detection stats for github/gh-aw - 2026-08-22 #933

Description

@github-actions

962 external-detector runs analysed on 2026-08-22; detection-job error rate 0%; soft failures 71; threat rate 0.47% (2/429 runs with a verdict).

Summary

gh-aw detection statistics - 2026-08-22 (UTC)

Repository: github/gh-aw
Window: 2026-08-22T00:00:00Z .. 2026-08-22T23:59:59Z
API requests: 2938, rate-limit pauses: 1
Data complete: yes

Totals

Metric Count
Workflow runs in window 3781
Agentic runs (*.lock.yml) 1955
Runs with a detection job 980
... using the external detector 962
... using the built-in detector 18
... detector could not be determined 0
Agentic runs without a detection job 975

All rates below are over the external detector population (962 runs). Since gh-aw #54111 the external detector is the compile-time default; a run counts as external when its detection job showed the Install threat-detect binary step, when another run of the same workflow did that day, or when the workflow is .lock.yml and no run showed the built-in shape (a completed detection job with steps but no marker). Runs on a workflow that opted out with features: gh-aw-detection: false count as built-in.

Detection job outcomes

Outcome Count Rate
success 503 52.29%
skipped 459 47.71%

Error rate (failure/timed_out/action_required): 0%

Verdict availability

State Meaning Count
present detection artifact downloaded and parsed 429
absent detection job ran but published no artifact (soft failure) 71
skipped detection job was skipped or was still running (nothing to fetch) 459
unreadable artifact zip could not be unpacked 3

Green detection jobs that published no verdict: 71 (detection steps are continue-on-error, so a missing verdict artifact is the only reliable signal for these).

Detection results

Result Count
Runs with a parsed verdict 429
Clean (no threat) 427
Any threat 2
prompt_injection 1
secret_leak 0
malicious_patch 1

Threat rate (of runs with a verdict): 0.47%

Reasons reported by gh-aw

From the [aw] Detection Runs tracking issue (warning/failure conclusions only), restricted to runs in the external-detector population above.

Reason Count
agent_failure 73
threat_detected 2

By workflow

Workflow Runs Failed Cancelled Skipped No verdict Threats
Q 151 0 0 151 0 0
PR Sous Chef 78 0 0 0 11 0
Deployment Incident Monitor 61 0 0 61 0 0
Issue Monster 46 0 0 21 6 0
Test Quality Sentinel 43 0 0 0 2 0
Design Decision Gate 🏗️ 42 0 0 1 3 0
Impeccable Skills Reviewer 42 0 0 0 2 0
Matt Pocock Skills Reviewer 42 0 0 0 2 0
PR Code Quality Reviewer 42 0 0 0 2 0
Ponytail Reviewer 42 0 0 0 4 0
Avenger 22 0 0 16 2 0
Daily Go Test Parallelizer 12 0 0 9 0 0
PR Description Updater 12 0 0 4 1 1
Squad — @copilot resolve the merge conflicts on this branch. 10 0 0 10 0 0
Auto-Triage Issues 7 0 0 1 1 0
Contribution Check 5 0 0 1 0 0
Code Scanning Fixer 4 0 0 0 1 0
Workflow Generator 4 0 0 4 0 0
[aw] Failure Investigator (6h) 4 0 0 0 1 0
Deep Report 3 0 0 0 0 0
PR Triage Agent 3 0 0 0 0 0

260 further workflows omitted; see stats.json.

Notable runs

Selected examples (79 notable runs total in the full data; showing a subset here, see stats.json for the complete list):

Workflow Run Job conclusion Verdict Threats Reported reason
Daily Community Attribution Updater 32546873672 success present malicious_patch threat_detected
PR Description Updater 32548155220 success present prompt_injection threat_detected
Agent Job Health Monitor 32604582938 success absent - agent_failure
Agentic Workflow Audit Agent 32598934886 success absent - agent_failure
Auto-Triage Issues 32572717304 success absent - agent_failure
Avenger 32597081051 success absent - agent_failure
Avenger 32599906451 success absent - agent_failure

(remaining rows omitted for brevity — see stats.json for the full list)

Change since 2026-08-21

Metric 2026-08-21 2026-08-22 Delta
External-detector runs 1001 962 -39
Error rate 0.3% 0% -0.3 pp
Soft failures 54 71 +17
Runs with verdict 481 429 -52
Any threat 2 2 0
Threat rate 0.42% 0.47% +0.05 pp

(Fewer than 7 history entries exist, so no 7-day mean column yet.)

Watch list

  • PR Sous Chef — 0 failed, 11 without a verdict, out of 78 runs
  • Issue Monster — 0 failed, 6 without a verdict, out of 46 runs
  • Ponytail Reviewer — 0 failed, 4 without a verdict, out of 42 runs
  • Design Decision Gate 🏗️ — 0 failed, 3 without a verdict, out of 42 runs
  • Test Quality Sentinel — 0 failed, 2 without a verdict, out of 43 runs

Collected by: https://github.com/github/gh-aw-threat-detection/actions/runs/32617093541
Full data: the detection-stats-32617093541 artifact on that run.

Generated by Detection Stats Daily · auto · 35.6 AIC · ⌖ 9.92 AIC · ⊞ 11.3K ·

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions