You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Window evaluated: last 24 full hours (UTC), report generated 2026-06-29
Data coverage caveat: the logs download was truncated by a 60s gateway timeout, so the analyzed sample covers runs created 2026-06-29T10:31Z → 13:55Z (75 runs). Older runs in the 24h window were not retrievable in this run.
Total runs analyzed: 75 (74 completed, 1 still in progress)
Detection-enabled runs: 19 (25.3%)
Regular runs: 56 (74.7%)
Misconfigured workflows found: 7
Warning
7 workflows were flagged for detection misconfigurations — 1 high-frequency workflow with detection explicitly disabled and 6 analysis/audit/report workflows missing gh-aw-detection: true. See the table below.
Comparison Chart
Metric
Regular Runs
Detection Runs
Total runs
56
19
Success rate
100.0%
94.7%
Avg tokens
n/a*
n/a*
Failure count
0
1
Misconfigured count
—
7
* Token usage was 0 / unpopulated in aw_info.json and token_usage.jsonl for every run in this window (these are predominantly Copilot-engine runs that did not emit token metrics), so per-group average tokens could not be computed.
The single detection-run failure is "Daily Max AI Credits Test (Intentionally Fails)" — a by-design failure test. Its threat-detection job steps ran/skipped correctly (no detection-job error), so it is not counted as a detection misconfiguration.
Misconfigured Workflows
Workflow
Misconfiguration type
Runs
Recommended fix
Smoke CI
(1) detection explicitly disabled on active workflow (10 runs/24h)
10
Confirm gh-aw-detection: false is intentional for this fast CI smoke check; otherwise enable detection. Likely acceptable for a low-risk CI gate — document the exemption.
Trend chart requires ≥7 days of history; the cache currently holds 3 days (2026-06-27 → 2026-06-29). The trend chart will be generated automatically once 7 days accumulate in cache-memory/trending/detection-metrics/history.jsonl.
Recommendations
Add gh-aw-detection: true to the 6 analysis/audit/report workflows listed above — these read external data and produce reports, exactly the class of workflow threat detection is meant to cover.
Confirm the Smoke CI exemption.gh-aw-detection: false across 10 runs is likely intentional for a fast CI gate; if so, document the exemption so it stops being flagged. Otherwise enable detection.
Investigate token metrics. Token usage is reported as 0 for all runs in this window, which blocks the avg-token comparison. Verify whether Copilot-engine runs are expected to emit token_usage.
Fix the logs download window. The logs tool repeatedly hit the 60s gateway timeout, truncating coverage to ~3.4h instead of 24h. Consider paging by count/date ranges so the full window can be analyzed.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
-
Summary
logsdownload was truncated by a 60s gateway timeout, so the analyzed sample covers runs created 2026-06-29T10:31Z → 13:55Z (75 runs). Older runs in the 24h window were not retrievable in this run.Warning
7 workflows were flagged for detection misconfigurations — 1 high-frequency workflow with detection explicitly disabled and 6 analysis/audit/report workflows missing
gh-aw-detection: true. See the table below.Comparison Chart
* Token usage was 0 / unpopulated in
aw_info.jsonandtoken_usage.jsonlfor every run in this window (these are predominantly Copilot-engine runs that did not emit token metrics), so per-group average tokens could not be computed.The single detection-run failure is "Daily Max AI Credits Test (Intentionally Fails)" — a by-design failure test. Its threat-detection job steps ran/skipped correctly (no detection-job error), so it is not counted as a detection misconfiguration.
Misconfigured Workflows
gh-aw-detection: falseis intentional for this fast CI smoke check; otherwise enable detection. Likely acceptable for a low-risk CI gate — document the exemption.gh-aw-detection: trueto frontmatter.gh-aw-detection: trueto frontmatter.gh-aw-detection: trueto frontmatter.gh-aw-detection: trueto frontmatter.gh-aw-detection: trueto frontmatter.gh-aw-detection: trueto frontmatter.View All Run Metrics
View Historical Trend
Trend chart requires ≥7 days of history; the cache currently holds 3 days (2026-06-27 → 2026-06-29). The trend chart will be generated automatically once 7 days accumulate in
cache-memory/trending/detection-metrics/history.jsonl.Recommendations
gh-aw-detection: trueto the 6 analysis/audit/report workflows listed above — these read external data and produce reports, exactly the class of workflow threat detection is meant to cover.gh-aw-detection: falseacross 10 runs is likely intentional for a fast CI gate; if so, document the exemption so it stops being flagged. Otherwise enable detection.token_usage.logstool repeatedly hit the 60s gateway timeout, truncating coverage to ~3.4h instead of 24h. Consider paging bycount/date ranges so the full window can be analyzed.References:
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
awmgmcpgSee Network Configuration for more information.
Beta Was this translation helpful? Give feedback.
All reactions