[detection-analysis] Detection Analysis Report — 2026-07-22 (last 24h) #47427
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Detection Analysis Report. A newer discussion is available at Discussion #47671. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
2026-07-21T23:37:52Z→2026-07-22T23:37:52ZWarning
3 workflows whose names imply an audit/analysis role are running without
gh-aw-detection: true. See the Misconfigured Workflows section for the recommended fixes.Comparison Chart
Misconfigured Workflows
Rule 2 — workflow name contains an audit/analysis keyword (
audit,analyzer,report,detector,monitor,inspector) but no run in the window hadgh-aw-detection: true. The documented opt-out (Daily Agentic Workflow AIC Usage Audit, mirrored fromgithubnext/agentic-ops) was excluded.report, detection absentgh-aw-detection: trueto the engine config and recompile the.lock.ymlreport, detection absentgh-aw-detection: trueto the engine config and recompile the.lock.ymlreport, detection absentgh-aw-detection: trueto the engine config and recompile the.lock.ymlRules that did not flag anything this window:
falseon a workflow with >3 runs): no detection-disabled workflow exceeded 3 runs in the fetched data. Caveat: only 24h of logs were downloaded, so the full 7-day count could not be computed.truebut detection steps failed): 6 detection-enabled runs failed, but every failure was in the agent-execution step (Execute GitHub Copilot CLI/Execute Claude Code CLI). Their threat-detection steps were skipped and theConclude threat detectionstep succeeded, so none qualify.Recommendations
gh-aw-detection: trueto each workflow's engine block and recompile so the threat-detection stage runs on their outputs.CI Optimization Coach,Daily Max Ai Credits Test,GitHub MCP Structural Analysis,Daily Agent of the Day Blog Writer,Daily Issues Report Generator,Daily BYOK Ollama Test). These are agent/CLI execution failures, unrelated to detection, but drag the detection cohort's success rate to 92.8% vs. 95.4% for regular runs.agenticworkflows logsdownload hit the 300s timeout, yielding a partial dataset (280 in-window runs with completeaw_info.json).View All Run Metrics
Detection column: ✅ on = every run had⚠️ mixed = varied within window.
gh-aw-detection: true; ❌ off/absent = no run enabled detection;View Historical Trend
24 days of history (last 30-day window). Detection adoption and both cohorts' run volume are trending up; detection success rate holds in the mid-to-high 80s/90s.
References:
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
awmgmcpgSee Network Configuration for more information.
All reactions