You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Top trigger combinations: schedule+workflow_dispatch (211), bare workflow_dispatch (68), pull_request+schedule+workflow_dispatch (29).
Dominant cron: 0 0 */2 * * (every 2 days) in 50 workflows — by far the most common schedule.
Safe outputs analysis
create_discussion: 93 workflows (1 workflow — pr-sous-chef.lock.yml — could not be mapped to a category via config or fallback regex; all other 92 resolved cleanly, so detection coverage is 98.9%, well above the 90% threshold).
Discussion categories: audits (79), announcements (5), artifacts (2), dev (2), research (2), general (1), daily-news (1).
Most common non-baseline safe outputs: create_issue (173), add_comment (74), create_pull_request (65), push_repo_memory (34), add_labels (32).
safe_outputs_config_missing: 1 lockfile (not all 334 — detection is functioning correctly, this is a genuine single gap, not a parser failure).
Structural characteristics
2,381 total jobs (avg ~7.1/workflow), 48,208 total steps, 21,441 script (run:) steps.
Timeout distribution: 10m (379), 45m (331), 60m (323) dominate; long tail up to 300m.
Permission patterns (agent job / union across jobs)
Scope
Read
Write (union)
contents
334
227
issues
261
318
pull-requests
255
146
discussions
53
96
actions
139
140
copilot-requests
—
158
security-events
14
3
332 of 334 workflows (99.4%) grant at least one write scope in their effective (union) job permissions. permissions_unknown: 0 — agent-job permission blocks parsed successfully for every lockfile.
engine_unknown: 0 — every lockfile resolved an engine via gh-aw-metadata.
Tool & MCP patterns
Server
Count
safeoutputs
310
github
185
work-queue
31
agenticworkflows
27
mcpscripts
25
serena
17
7 lockfiles required the legacy mcp__... comment-scraping fallback (no mcp_servers manifest).
Interesting findings
work-queue MCP usage nearly doubled (16 → 31 workflows) since 2026-10-08, the largest single-day jump in the dataset.
actions: read permission adoption jumped +15 (124 → 139) in one day, tracking a parallel +15 rise in union actions/contents write scopes — consistent with several workflows gaining new job-level permission blocks rather than a broad policy change.
Despite 334 workflows, only 13 distinct permission scopes and 14 distinct engines appear — the ecosystem is concentrated on a handful of patterns (copilot/codex/claude cover 80% of engines).
dispatch_workflow safe-output usage keeps creeping up (7 → 8 → 9 over the last 3 days), suggesting growing adoption of cross-workflow dispatch patterns.
Only one workflow (pr-sous-chef.lock.yml) has an unresolved discussion category — worth a manual check since every other create_discussion workflow maps cleanly.
Historical trends (vs. prior days)
Metric
2026-10-06
2026-10-08
2026-10-09 (today)
Lockfiles
323
333
334
Total bytes
51,345,375
53,260,630
53,401,626
workflow_dispatch
315
324
325
schedule
248
243
244
Total jobs
—
2,376
2,381 (+5)
Total steps
—
48,114
48,208 (+94)
create_discussion workflows
—
93
93 (flat)
work-queue MCP usage
—
16
31 (+15, ~2x)
actions write (union)
—
125
140 (+15)
workflows_with_any_write
—
330
332 (+2)
Net 3-day growth: +11 lockfiles, +2,056,251 bytes (~4% size growth), steady creep in workflow_dispatch and schedule adoption.
Recommendations
Investigate pr-sous-chef.lock.yml's create_discussion config to close the one unresolved category mapping.
Monitor the work-queue MCP and actions-scope permission jump — confirm it reflects intended new workflows/jobs rather than an unintended permission widening.
Given 332/334 workflows already carry a write scope, continue to audit new workflows against least-privilege defaults at review time.
Methodology: single-script compact JSON analysis (lockfile_stats_v4.py, cached in cache-memory), parsing gh-aw-metadata/gh-aw-manifest header comments and GH_AW_SAFE_OUTPUTS_CONFIG env JSON rather than frontmatter (lockfiles carry no top-level engine: or permissions: signal).
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Scope: 334 compiled
.github/workflows/*.lock.ymlfiles, 53.4 MB total. 0 malformed/skipped.Executive summary
workflow_dispatchFile size distribution
Trigger analysis
Top trigger combinations:
schedule+workflow_dispatch(211), bareworkflow_dispatch(68),pull_request+schedule+workflow_dispatch(29).Dominant cron:
0 0 */2 * *(every 2 days) in 50 workflows — by far the most common schedule.Safe outputs analysis
create_discussion: 93 workflows (1 workflow —pr-sous-chef.lock.yml— could not be mapped to a category via config or fallback regex; all other 92 resolved cleanly, so detection coverage is 98.9%, well above the 90% threshold).audits(79),announcements(5),artifacts(2),dev(2),research(2),general(1),daily-news(1).create_issue(173),add_comment(74),create_pull_request(65),push_repo_memory(34),add_labels(32).safe_outputs_config_missing: 1 lockfile (not all 334 — detection is functioning correctly, this is a genuine single gap, not a parser failure).Structural characteristics
run:) steps.Permission patterns (agent job / union across jobs)
332 of 334 workflows (99.4%) grant at least one write scope in their effective (union) job permissions.
permissions_unknown: 0 — agent-job permission blocks parsed successfully for every lockfile.Engine distribution
agent_id)engine_unknown: 0 — every lockfile resolved an engine viagh-aw-metadata.Tool & MCP patterns
7 lockfiles required the legacy
mcp__...comment-scraping fallback (nomcp_serversmanifest).Interesting findings
work-queueMCP usage nearly doubled (16 → 31 workflows) since 2026-10-08, the largest single-day jump in the dataset.actions: readpermission adoption jumped +15 (124 → 139) in one day, tracking a parallel +15 rise in unionactions/contentswrite scopes — consistent with several workflows gaining new job-level permission blocks rather than a broad policy change.copilot/codex/claudecover 80% of engines).dispatch_workflowsafe-output usage keeps creeping up (7 → 8 → 9 over the last 3 days), suggesting growing adoption of cross-workflow dispatch patterns.pr-sous-chef.lock.yml) has an unresolved discussion category — worth a manual check since every othercreate_discussionworkflow maps cleanly.Historical trends (vs. prior days)
create_discussionworkflowswork-queueMCP usageactionswrite (union)workflows_with_any_writeNet 3-day growth: +11 lockfiles, +2,056,251 bytes (~4% size growth), steady creep in
workflow_dispatchandscheduleadoption.Recommendations
pr-sous-chef.lock.yml'screate_discussionconfig to close the one unresolved category mapping.work-queueMCP andactions-scope permission jump — confirm it reflects intended new workflows/jobs rather than an unintended permission widening.Methodology: single-script compact JSON analysis (
lockfile_stats_v4.py, cached incache-memory), parsinggh-aw-metadata/gh-aw-manifestheader comments andGH_AW_SAFE_OUTPUTS_CONFIGenv JSON rather than frontmatter (lockfiles carry no top-levelengine:orpermissions:signal).All reactions