[detection-analysis] Detection Analysis Report — 2026-07-23 (24h) #47671
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Detection Analysis Report. A newer discussion is available at Discussion #47873. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
2026-07-23T05:50:31Z→2026-07-23T23:10:42Zgh-aw-detection: true): 96 (33.6%)Warning
4 workflow(s) whose names imply monitoring/analysis are running without
gh-aw-detection: true. See the table below for recommended fixes.At-a-glance comparison:
Detection-enabled runs consume ~24% more tokens on average (expected — detection adds analysis steps) while holding a comparable success rate (within ~1 point of regular runs).
Comparison Chart
Misconfigured Workflows
All four flags are rule 2 (workflow name contains
report/audit/analyzer/monitor/detector/inspectorbut lacksgh-aw-detection: true). No high-volume detection-disabled workflows (rule 1: max detection-off volume was 2 runs) and no alternating/mixed workflows (rule 4) were found. The documented opt-outDaily Agentic Workflow AIC Usage Auditwas excluded from name-based flagging.gh-aw-detection: trueto frontmattergh-aw-detection: trueto frontmattergh-aw-detection: trueto frontmattergh-aw-detection: trueto frontmatterView All Run Metrics (129 workflows)
View Historical Trend
30-day trend of regular vs. detection run volume, with the detection success-rate band. Both regular and detection run volumes have climbed sharply over the past week; detection success rate has stayed in the 85–95% band.
Recommendations
gh-aw-detection: trueto the frontmatter ofStatic Analysis Report,Deep Report,Daily Security Observability Report, andDaily Regulatory Report Generator. Their names signal monitoring/analysis intent, which is exactly the case detection is meant to cover. If any is intentionally exempt, document a repository-level opt-out (as done forDaily Agentic Workflow AIC Usage Audit) so it stops being re-flagged.Note on window: the
logsfetch reached its download limit before completing the full crawl, so 286 fully-downloaded runs were analyzed; rule 1's ">3 runs in 7 days" was evaluated against this 24h window as a proxy (no candidate exceeded 3 detection-off runs regardless).References:
All reactions