Skip to content

[deep-report] Enable gh-aw-detection on Daily AIC Usage Audit and Organization Health Report #43811

Description

@github-actions

Description

The Detection Analysis Report (discussion #43797) found two audit/report-class workflows running without threat detection: Daily Agentic Workflow AIC Usage Audit and Organization Health Report. Detection-enabled runs show a higher success rate (90.9% vs 85.1%) at comparable token cost, and audit/report workflows are exactly the class that should carry detection.

What to do

Add gh-aw-detection: true to the frontmatter of both workflows and recompile their lock files. Consider defaulting detection to true in the audit/analysis scaffold to stop the daily re-flag at the source.

Expected Impact

Brings two report workflows under detection coverage; removes them from the daily misconfiguration re-flag; nudges fleet-wide detection adoption (currently 33%).

Suggested Agent

Workflow-config / Instructions Janitor agent.

Estimated Effort

Quick (< 1 hour)

Data Source

DeepReport Intelligence Briefing 2026-07-06; source discussion #43797 (Detection Analysis Report).

Generated by 🔬 Deep Report · 204.6 AIC · ⌖ 17.5 AIC · ⊞ 10.2K ·

  • expires on Jul 8, 2026, 8:03 AM UTC-08:00

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions