Pin the threat-detection model on every agentic workflow - #10729

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model
Aug 25, 2026
Merged

Pin the threat-detection model on every agentic workflow#10729
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model

Conversation

@nohwnd

Copy link
Copy Markdown
Member

The detection job keeps recording parse_error even when the job itself succeeds. The default
detection model alias sometimes wraps its result line in Markdown emphasis, and gh-aw's parser
slices the JSON at a fixed offset from the start of the line instead of from the index of the marker
it just located. The two leading asterisks move the cut two characters into RESULT, so it tries to
parse T:{"prompt"…:

📄 Lines containing THREAT_DETECTION_RESULT (1 of 194):
[155] **THREAT_DETECTION_RESULT:{"prompt_injection":false,"secret_leak":false,…**
##[error]❌ Failed to parse detection result: Unexpected token 'T', "T:{"prompt"... is not valid JSON

The parser is parse_threat_detection_results.cjs inside the gh-aw actions bundle that every run
downloads, so the bug cannot be fixed in this repository. Pinning the detector to a model that does
not add the emphasis is the mitigation, and
microsoft/testfx#10684 already proved it works for
the expert-review workflows.

This applies the same pin to the 29 workflows that were still on the default alias. Where several
workflows share an import the pin goes in the shared file, so shared/address-review-shared.md,
shared/msbuild-review-shared.md, shared/parallel-safety-audit-shared.md and
shared/test-reviewer-shared.md cover seven locks between them. malicious-code-scan.md already
declared threat-detection, so it gets engine: inside its existing block. The expert-review trio
and Test Improver were already pinned and are unchanged.

The workflows README gains a section for this failure, including how to tell it apart from the
Install GitHub Copilot CLI cause that produces the same parse_error: if the log shows
Lines containing THREAT_DETECTION_RESULT (1 of N) the marker exists and this is the formatting
cause, and if it shows No THREAT_DETECTION_RESULT found it is the installer cause covered by
microsoft/testfx#10427.

Observed on:

One thing to weigh: this moves every workflow's detection job onto gpt-5-mini instead of the
default alias, so there is some extra cost. The PR-triggered review workflows run most often and
already made that move in
microsoft/testfx#10684, and the rest are mostly
daily scheduled runs, so the marginal cost is small. If you would rather scope it down, the runs
above only justify Test Improver, Test Reviewer, Parallel-safety audit, Sub-Issue Closer and Build
Failure Analysis.

The local compile also rewrote the pinned github/gh-aw-actions/setup SHA in agentic_commands.yml
back to a mutable tag, which is
microsoft/testfx#10258 again, on a gh aw whose
version matches the lock headers. That file is restored to its committed state and is not in this
diff; the README note about compiling on the pinned toolchain now says a matching compiler_version
is not enough to prevent it.

Verified: compiled with gh aw compile --strict on gh-aw v0.86.2, matching the compiler_version
recorded in every existing lock. All 33 locks now report "detection_agent_model":"gpt-5-mini", no
COPILOT_MODEL: detection remains, python .github/scripts/check_action_pins.py passes over 2345
references, and no uses: line changed anywhere in the diff.

Refs microsoft/testfx#10711

🤖

The default `detection` model alias sometimes wraps its result line in Markdown
emphasis. gh-aw's parser slices the JSON at a fixed offset from the start of the
line instead of from the marker index it just located, so the two leading
asterisks move the cut inside `RESULT` and the run is recorded as `parse_error`
even though detection itself succeeded. The parser lives in the gh-aw actions
bundle that each run downloads, so it cannot be fixed in this repository.
Pin `safe-outputs.threat-detection.engine.model` to `gpt-5-mini` on the 29
workflows still on the default alias, matching what #10684 already did for the
expert-review workflows. Where several workflows share an import the pin goes in
the shared file. `malicious-code-scan.md` already declared `threat-detection`,
so it gets `engine:` inside the existing block.
Also document the failure in the workflows README, including how to tell it
apart from the `Install GitHub Copilot CLI` cause that produces the same
`parse_error`.
Refs #10711
🤖
CopilotAI balanced review requested due to automatic review settings August 25, 2026 12:40

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Review Summary

This PR pins safe-outputs.threat-detection.engine.model: gpt-5-mini across 29 agentic workflows to work around the gh-aw parser bug where the default detection alias wraps its THREAT_DETECTION_RESULT JSON in Markdown emphasis, causing parse_error. The README is updated with troubleshooting guidance.

Verdict Table

#DimensionSeverityFinding
1Algorithmic CorrectnessMAJORN/A — no logic changes
2Public API SurfaceCRITICALN/A — no API changes
3Thread SafetyMAJORN/A
4Resource ManagementMAJORN/A
5Error HandlingMAJORN/A
6Backward CompatibilityCRITICALN/A
7PerformanceMAJORN/A
8SecurityCRITICALN/A
9Cross-TFMMAJORN/A
10IPC/Wire FormatCRITICALN/A
11LocalizationMINORN/A
12Test QualityMAJORN/A
13Naming & ConventionsMINORN/A
14DocumentationMINOR✅ Clean — README section is well-structured
15Null SafetyMAJORN/A
16Disposal & LifetimeMAJORN/A
17ConfigurationMINOR✅ Clean — consistent pattern across all workflows
18Build IntegrationMAJOR✅ Clean — all locks recompiled with --strict, compiler_version matches
19Logging & TelemetryMINORN/A
20Code DuplicationMINOR✅ Shared files used where possible (4 shared imports cover 7 locks)
21Scope DisciplineMINOR✅ Single concern — model pin only
22TODO PolicyMINORN/A

Assessment

No blocking issues found. The change is mechanical and consistent: every .md source gets the same threat-detection engine block (with a comment referencing #10711), every .lock.yml is regenerated with matching detection_agent_model metadata, no uses: lines changed, and the malicious-code-scan.md (which already had a threat-detection: block with continue-on-error: true) correctly gets the engine: sub-block added alongside the existing property. The README troubleshooting section clearly differentiates this failure mode from the installer-related parse_error documented in #10427.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins threat detection to gpt-5-mini across agentic workflows, mitigating malformed Markdown-wrapped detection results.

Changes:

  • Configures the model directly or through shared workflow imports.
  • Regenerates 29 lock files in strict mode.
  • Documents diagnosis, mitigation, and action-pin validation.

Reviewed changes

Copilot reviewed 56 out of 56 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/add-tests.mdPins detection model.
.github/workflows/add-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/address-review.agent.lock.ymlApplies shared model pin.
.github/workflows/adhoc-qa.mdPins detection model.
.github/workflows/adhoc-qa.lock.ymlRegenerates compiled workflow.
.github/workflows/autofix.agent.lock.ymlApplies shared model pin.
.github/workflows/build-failure-analysis-command.mdPins detection model.
.github/workflows/build-failure-analysis-command.lock.ymlRegenerates compiled workflow.
.github/workflows/build-failure-analysis.mdPins detection model.
.github/workflows/build-failure-analysis.lock.ymlRegenerates compiled workflow.
.github/workflows/code-simplifier.mdPins detection model.
.github/workflows/code-simplifier.lock.ymlRegenerates compiled workflow.
.github/workflows/daily-file-diet.mdPins detection model.
.github/workflows/daily-file-diet.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-issue-bundler.mdPins detection model.
.github/workflows/dependabot-issue-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-pr-bundler.mdPins detection model.
.github/workflows/dependabot-pr-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/duplicate-code-detector.mdPins detection model.
.github/workflows/duplicate-code-detector.lock.ymlRegenerates compiled workflow.
.github/workflows/efficiency-improver.mdPins detection model.
.github/workflows/efficiency-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/glossary-maintainer.mdPins detection model.
.github/workflows/glossary-maintainer.lock.ymlRegenerates compiled workflow.
.github/workflows/link-checker.mdPins detection model.
.github/workflows/link-checker.lock.ymlRegenerates compiled workflow.
.github/workflows/malicious-code-scan.mdExtends existing detection settings.
.github/workflows/malicious-code-scan.lock.ymlRegenerates compiled workflow.
.github/workflows/markdown-linter.mdPins detection model.
.github/workflows/markdown-linter.lock.ymlRegenerates compiled workflow.
.github/workflows/msbuild-quality-review.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit-command.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit.lock.ymlApplies shared model pin.
.github/workflows/perf-improver.mdPins detection model.
.github/workflows/perf-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/pr-fix.mdPins detection model.
.github/workflows/pr-fix.lock.ymlRegenerates compiled workflow.
.github/workflows/q.mdPins detection model.
.github/workflows/q.lock.ymlRegenerates compiled workflow.
.github/workflows/README.mdDocuments parse errors and pin safety.
.github/workflows/repository-quality-improver.mdPins detection model.
.github/workflows/repository-quality-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/resource-lock-refactoring.mdPins detection model.
.github/workflows/resource-lock-refactoring.lock.ymlRegenerates compiled workflow.
.github/workflows/shared/address-review-shared.mdPins two consuming workflows.
.github/workflows/shared/msbuild-review-shared.mdPins its consuming workflow.
.github/workflows/shared/parallel-safety-audit-shared.mdPins two consuming workflows.
.github/workflows/shared/test-reviewer-shared.mdPins two consuming workflows.
.github/workflows/sub-issue-closer.mdPins detection model.
.github/workflows/sub-issue-closer.lock.ymlRegenerates compiled workflow.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlApplies shared model pin.
.github/workflows/test-reviewer.agent.lock.ymlApplies shared model pin.
.github/workflows/unskip-closed-tests.mdPins detection model.
.github/workflows/unskip-closed-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/weekly-issue-activity.mdPins detection model.
.github/workflows/weekly-issue-activity.lock.ymlRegenerates compiled workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit 491b236 into mainAug 25, 2026
21 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the nohwnd-pin-threat-detection-model branch August 25, 2026 13:42
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 25, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10729 pinned the
threat-detection model on every agentic workflow, so both sides carry a
different generated metadata hash for the same file.
The .md source merged cleanly and keeps both changes, so the lock file was
regenerated from it with `gh aw compile --action-mode action --action-tag
v0.86.2`. The result has main's threat-detection pin and this branch's lint
job, and the pin audit passes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@nohwnd@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Pin the threat-detection model on every agentic workflow - #10729

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model
Aug 25, 2026
Merged

Pin the threat-detection model on every agentic workflow#10729
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model

Conversation

@nohwnd

Copy link
Copy Markdown
Member

The detection job keeps recording parse_error even when the job itself succeeds. The default
detection model alias sometimes wraps its result line in Markdown emphasis, and gh-aw's parser
slices the JSON at a fixed offset from the start of the line instead of from the index of the marker
it just located. The two leading asterisks move the cut two characters into RESULT, so it tries to
parse T:{"prompt"…:

📄 Lines containing THREAT_DETECTION_RESULT (1 of 194):
[155] **THREAT_DETECTION_RESULT:{"prompt_injection":false,"secret_leak":false,…**
##[error]❌ Failed to parse detection result: Unexpected token 'T', "T:{"prompt"... is not valid JSON

The parser is parse_threat_detection_results.cjs inside the gh-aw actions bundle that every run
downloads, so the bug cannot be fixed in this repository. Pinning the detector to a model that does
not add the emphasis is the mitigation, and
microsoft/testfx#10684 already proved it works for
the expert-review workflows.

This applies the same pin to the 29 workflows that were still on the default alias. Where several
workflows share an import the pin goes in the shared file, so shared/address-review-shared.md,
shared/msbuild-review-shared.md, shared/parallel-safety-audit-shared.md and
shared/test-reviewer-shared.md cover seven locks between them. malicious-code-scan.md already
declared threat-detection, so it gets engine: inside its existing block. The expert-review trio
and Test Improver were already pinned and are unchanged.

The workflows README gains a section for this failure, including how to tell it apart from the
Install GitHub Copilot CLI cause that produces the same parse_error: if the log shows
Lines containing THREAT_DETECTION_RESULT (1 of N) the marker exists and this is the formatting
cause, and if it shows No THREAT_DETECTION_RESULT found it is the installer cause covered by
microsoft/testfx#10427.

Observed on:

One thing to weigh: this moves every workflow's detection job onto gpt-5-mini instead of the
default alias, so there is some extra cost. The PR-triggered review workflows run most often and
already made that move in
microsoft/testfx#10684, and the rest are mostly
daily scheduled runs, so the marginal cost is small. If you would rather scope it down, the runs
above only justify Test Improver, Test Reviewer, Parallel-safety audit, Sub-Issue Closer and Build
Failure Analysis.

The local compile also rewrote the pinned github/gh-aw-actions/setup SHA in agentic_commands.yml
back to a mutable tag, which is
microsoft/testfx#10258 again, on a gh aw whose
version matches the lock headers. That file is restored to its committed state and is not in this
diff; the README note about compiling on the pinned toolchain now says a matching compiler_version
is not enough to prevent it.

Verified: compiled with gh aw compile --strict on gh-aw v0.86.2, matching the compiler_version
recorded in every existing lock. All 33 locks now report "detection_agent_model":"gpt-5-mini", no
COPILOT_MODEL: detection remains, python .github/scripts/check_action_pins.py passes over 2345
references, and no uses: line changed anywhere in the diff.

Refs microsoft/testfx#10711

🤖

The default `detection` model alias sometimes wraps its result line in Markdown
emphasis. gh-aw's parser slices the JSON at a fixed offset from the start of the
line instead of from the marker index it just located, so the two leading
asterisks move the cut inside `RESULT` and the run is recorded as `parse_error`
even though detection itself succeeded. The parser lives in the gh-aw actions
bundle that each run downloads, so it cannot be fixed in this repository.
Pin `safe-outputs.threat-detection.engine.model` to `gpt-5-mini` on the 29
workflows still on the default alias, matching what #10684 already did for the
expert-review workflows. Where several workflows share an import the pin goes in
the shared file. `malicious-code-scan.md` already declared `threat-detection`,
so it gets `engine:` inside the existing block.
Also document the failure in the workflows README, including how to tell it
apart from the `Install GitHub Copilot CLI` cause that produces the same
`parse_error`.
Refs #10711
🤖
CopilotAI balanced review requested due to automatic review settings August 25, 2026 12:40

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Review Summary

This PR pins safe-outputs.threat-detection.engine.model: gpt-5-mini across 29 agentic workflows to work around the gh-aw parser bug where the default detection alias wraps its THREAT_DETECTION_RESULT JSON in Markdown emphasis, causing parse_error. The README is updated with troubleshooting guidance.

Verdict Table

#DimensionSeverityFinding
1Algorithmic CorrectnessMAJORN/A — no logic changes
2Public API SurfaceCRITICALN/A — no API changes
3Thread SafetyMAJORN/A
4Resource ManagementMAJORN/A
5Error HandlingMAJORN/A
6Backward CompatibilityCRITICALN/A
7PerformanceMAJORN/A
8SecurityCRITICALN/A
9Cross-TFMMAJORN/A
10IPC/Wire FormatCRITICALN/A
11LocalizationMINORN/A
12Test QualityMAJORN/A
13Naming & ConventionsMINORN/A
14DocumentationMINOR✅ Clean — README section is well-structured
15Null SafetyMAJORN/A
16Disposal & LifetimeMAJORN/A
17ConfigurationMINOR✅ Clean — consistent pattern across all workflows
18Build IntegrationMAJOR✅ Clean — all locks recompiled with --strict, compiler_version matches
19Logging & TelemetryMINORN/A
20Code DuplicationMINOR✅ Shared files used where possible (4 shared imports cover 7 locks)
21Scope DisciplineMINOR✅ Single concern — model pin only
22TODO PolicyMINORN/A

Assessment

No blocking issues found. The change is mechanical and consistent: every .md source gets the same threat-detection engine block (with a comment referencing #10711), every .lock.yml is regenerated with matching detection_agent_model metadata, no uses: lines changed, and the malicious-code-scan.md (which already had a threat-detection: block with continue-on-error: true) correctly gets the engine: sub-block added alongside the existing property. The README troubleshooting section clearly differentiates this failure mode from the installer-related parse_error documented in #10427.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins threat detection to gpt-5-mini across agentic workflows, mitigating malformed Markdown-wrapped detection results.

Changes:

  • Configures the model directly or through shared workflow imports.
  • Regenerates 29 lock files in strict mode.
  • Documents diagnosis, mitigation, and action-pin validation.

Reviewed changes

Copilot reviewed 56 out of 56 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/add-tests.mdPins detection model.
.github/workflows/add-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/address-review.agent.lock.ymlApplies shared model pin.
.github/workflows/adhoc-qa.mdPins detection model.
.github/workflows/adhoc-qa.lock.ymlRegenerates compiled workflow.
.github/workflows/autofix.agent.lock.ymlApplies shared model pin.
.github/workflows/build-failure-analysis-command.mdPins detection model.
.github/workflows/build-failure-analysis-command.lock.ymlRegenerates compiled workflow.
.github/workflows/build-failure-analysis.mdPins detection model.
.github/workflows/build-failure-analysis.lock.ymlRegenerates compiled workflow.
.github/workflows/code-simplifier.mdPins detection model.
.github/workflows/code-simplifier.lock.ymlRegenerates compiled workflow.
.github/workflows/daily-file-diet.mdPins detection model.
.github/workflows/daily-file-diet.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-issue-bundler.mdPins detection model.
.github/workflows/dependabot-issue-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-pr-bundler.mdPins detection model.
.github/workflows/dependabot-pr-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/duplicate-code-detector.mdPins detection model.
.github/workflows/duplicate-code-detector.lock.ymlRegenerates compiled workflow.
.github/workflows/efficiency-improver.mdPins detection model.
.github/workflows/efficiency-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/glossary-maintainer.mdPins detection model.
.github/workflows/glossary-maintainer.lock.ymlRegenerates compiled workflow.
.github/workflows/link-checker.mdPins detection model.
.github/workflows/link-checker.lock.ymlRegenerates compiled workflow.
.github/workflows/malicious-code-scan.mdExtends existing detection settings.
.github/workflows/malicious-code-scan.lock.ymlRegenerates compiled workflow.
.github/workflows/markdown-linter.mdPins detection model.
.github/workflows/markdown-linter.lock.ymlRegenerates compiled workflow.
.github/workflows/msbuild-quality-review.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit-command.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit.lock.ymlApplies shared model pin.
.github/workflows/perf-improver.mdPins detection model.
.github/workflows/perf-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/pr-fix.mdPins detection model.
.github/workflows/pr-fix.lock.ymlRegenerates compiled workflow.
.github/workflows/q.mdPins detection model.
.github/workflows/q.lock.ymlRegenerates compiled workflow.
.github/workflows/README.mdDocuments parse errors and pin safety.
.github/workflows/repository-quality-improver.mdPins detection model.
.github/workflows/repository-quality-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/resource-lock-refactoring.mdPins detection model.
.github/workflows/resource-lock-refactoring.lock.ymlRegenerates compiled workflow.
.github/workflows/shared/address-review-shared.mdPins two consuming workflows.
.github/workflows/shared/msbuild-review-shared.mdPins its consuming workflow.
.github/workflows/shared/parallel-safety-audit-shared.mdPins two consuming workflows.
.github/workflows/shared/test-reviewer-shared.mdPins two consuming workflows.
.github/workflows/sub-issue-closer.mdPins detection model.
.github/workflows/sub-issue-closer.lock.ymlRegenerates compiled workflow.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlApplies shared model pin.
.github/workflows/test-reviewer.agent.lock.ymlApplies shared model pin.
.github/workflows/unskip-closed-tests.mdPins detection model.
.github/workflows/unskip-closed-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/weekly-issue-activity.mdPins detection model.
.github/workflows/weekly-issue-activity.lock.ymlRegenerates compiled workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit 491b236 into mainAug 25, 2026
21 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the nohwnd-pin-threat-detection-model branch August 25, 2026 13:42
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 25, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10729 pinned the
threat-detection model on every agentic workflow, so both sides carry a
different generated metadata hash for the same file.
The .md source merged cleanly and keeps both changes, so the lock file was
regenerated from it with `gh aw compile --action-mode action --action-tag
v0.86.2`. The result has main's threat-detection pin and this branch's lint
job, and the pin audit passes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@nohwnd@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Pin the threat-detection model on every agentic workflow - #10729

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model
Aug 25, 2026
Merged

Pin the threat-detection model on every agentic workflow#10729
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model

Conversation

@nohwnd

Copy link
Copy Markdown
Member

The detection job keeps recording parse_error even when the job itself succeeds. The default
detection model alias sometimes wraps its result line in Markdown emphasis, and gh-aw's parser
slices the JSON at a fixed offset from the start of the line instead of from the index of the marker
it just located. The two leading asterisks move the cut two characters into RESULT, so it tries to
parse T:{"prompt"…:

📄 Lines containing THREAT_DETECTION_RESULT (1 of 194):
[155] **THREAT_DETECTION_RESULT:{"prompt_injection":false,"secret_leak":false,…**
##[error]❌ Failed to parse detection result: Unexpected token 'T', "T:{"prompt"... is not valid JSON

The parser is parse_threat_detection_results.cjs inside the gh-aw actions bundle that every run
downloads, so the bug cannot be fixed in this repository. Pinning the detector to a model that does
not add the emphasis is the mitigation, and
microsoft/testfx#10684 already proved it works for
the expert-review workflows.

This applies the same pin to the 29 workflows that were still on the default alias. Where several
workflows share an import the pin goes in the shared file, so shared/address-review-shared.md,
shared/msbuild-review-shared.md, shared/parallel-safety-audit-shared.md and
shared/test-reviewer-shared.md cover seven locks between them. malicious-code-scan.md already
declared threat-detection, so it gets engine: inside its existing block. The expert-review trio
and Test Improver were already pinned and are unchanged.

The workflows README gains a section for this failure, including how to tell it apart from the
Install GitHub Copilot CLI cause that produces the same parse_error: if the log shows
Lines containing THREAT_DETECTION_RESULT (1 of N) the marker exists and this is the formatting
cause, and if it shows No THREAT_DETECTION_RESULT found it is the installer cause covered by
microsoft/testfx#10427.

Observed on:

One thing to weigh: this moves every workflow's detection job onto gpt-5-mini instead of the
default alias, so there is some extra cost. The PR-triggered review workflows run most often and
already made that move in
microsoft/testfx#10684, and the rest are mostly
daily scheduled runs, so the marginal cost is small. If you would rather scope it down, the runs
above only justify Test Improver, Test Reviewer, Parallel-safety audit, Sub-Issue Closer and Build
Failure Analysis.

The local compile also rewrote the pinned github/gh-aw-actions/setup SHA in agentic_commands.yml
back to a mutable tag, which is
microsoft/testfx#10258 again, on a gh aw whose
version matches the lock headers. That file is restored to its committed state and is not in this
diff; the README note about compiling on the pinned toolchain now says a matching compiler_version
is not enough to prevent it.

Verified: compiled with gh aw compile --strict on gh-aw v0.86.2, matching the compiler_version
recorded in every existing lock. All 33 locks now report "detection_agent_model":"gpt-5-mini", no
COPILOT_MODEL: detection remains, python .github/scripts/check_action_pins.py passes over 2345
references, and no uses: line changed anywhere in the diff.

Refs microsoft/testfx#10711

🤖

The default `detection` model alias sometimes wraps its result line in Markdown
emphasis. gh-aw's parser slices the JSON at a fixed offset from the start of the
line instead of from the marker index it just located, so the two leading
asterisks move the cut inside `RESULT` and the run is recorded as `parse_error`
even though detection itself succeeded. The parser lives in the gh-aw actions
bundle that each run downloads, so it cannot be fixed in this repository.
Pin `safe-outputs.threat-detection.engine.model` to `gpt-5-mini` on the 29
workflows still on the default alias, matching what #10684 already did for the
expert-review workflows. Where several workflows share an import the pin goes in
the shared file. `malicious-code-scan.md` already declared `threat-detection`,
so it gets `engine:` inside the existing block.
Also document the failure in the workflows README, including how to tell it
apart from the `Install GitHub Copilot CLI` cause that produces the same
`parse_error`.
Refs #10711
🤖
CopilotAI balanced review requested due to automatic review settings August 25, 2026 12:40

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Review Summary

This PR pins safe-outputs.threat-detection.engine.model: gpt-5-mini across 29 agentic workflows to work around the gh-aw parser bug where the default detection alias wraps its THREAT_DETECTION_RESULT JSON in Markdown emphasis, causing parse_error. The README is updated with troubleshooting guidance.

Verdict Table

#DimensionSeverityFinding
1Algorithmic CorrectnessMAJORN/A — no logic changes
2Public API SurfaceCRITICALN/A — no API changes
3Thread SafetyMAJORN/A
4Resource ManagementMAJORN/A
5Error HandlingMAJORN/A
6Backward CompatibilityCRITICALN/A
7PerformanceMAJORN/A
8SecurityCRITICALN/A
9Cross-TFMMAJORN/A
10IPC/Wire FormatCRITICALN/A
11LocalizationMINORN/A
12Test QualityMAJORN/A
13Naming & ConventionsMINORN/A
14DocumentationMINOR✅ Clean — README section is well-structured
15Null SafetyMAJORN/A
16Disposal & LifetimeMAJORN/A
17ConfigurationMINOR✅ Clean — consistent pattern across all workflows
18Build IntegrationMAJOR✅ Clean — all locks recompiled with --strict, compiler_version matches
19Logging & TelemetryMINORN/A
20Code DuplicationMINOR✅ Shared files used where possible (4 shared imports cover 7 locks)
21Scope DisciplineMINOR✅ Single concern — model pin only
22TODO PolicyMINORN/A

Assessment

No blocking issues found. The change is mechanical and consistent: every .md source gets the same threat-detection engine block (with a comment referencing #10711), every .lock.yml is regenerated with matching detection_agent_model metadata, no uses: lines changed, and the malicious-code-scan.md (which already had a threat-detection: block with continue-on-error: true) correctly gets the engine: sub-block added alongside the existing property. The README troubleshooting section clearly differentiates this failure mode from the installer-related parse_error documented in #10427.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins threat detection to gpt-5-mini across agentic workflows, mitigating malformed Markdown-wrapped detection results.

Changes:

  • Configures the model directly or through shared workflow imports.
  • Regenerates 29 lock files in strict mode.
  • Documents diagnosis, mitigation, and action-pin validation.

Reviewed changes

Copilot reviewed 56 out of 56 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/add-tests.mdPins detection model.
.github/workflows/add-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/address-review.agent.lock.ymlApplies shared model pin.
.github/workflows/adhoc-qa.mdPins detection model.
.github/workflows/adhoc-qa.lock.ymlRegenerates compiled workflow.
.github/workflows/autofix.agent.lock.ymlApplies shared model pin.
.github/workflows/build-failure-analysis-command.mdPins detection model.
.github/workflows/build-failure-analysis-command.lock.ymlRegenerates compiled workflow.
.github/workflows/build-failure-analysis.mdPins detection model.
.github/workflows/build-failure-analysis.lock.ymlRegenerates compiled workflow.
.github/workflows/code-simplifier.mdPins detection model.
.github/workflows/code-simplifier.lock.ymlRegenerates compiled workflow.
.github/workflows/daily-file-diet.mdPins detection model.
.github/workflows/daily-file-diet.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-issue-bundler.mdPins detection model.
.github/workflows/dependabot-issue-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-pr-bundler.mdPins detection model.
.github/workflows/dependabot-pr-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/duplicate-code-detector.mdPins detection model.
.github/workflows/duplicate-code-detector.lock.ymlRegenerates compiled workflow.
.github/workflows/efficiency-improver.mdPins detection model.
.github/workflows/efficiency-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/glossary-maintainer.mdPins detection model.
.github/workflows/glossary-maintainer.lock.ymlRegenerates compiled workflow.
.github/workflows/link-checker.mdPins detection model.
.github/workflows/link-checker.lock.ymlRegenerates compiled workflow.
.github/workflows/malicious-code-scan.mdExtends existing detection settings.
.github/workflows/malicious-code-scan.lock.ymlRegenerates compiled workflow.
.github/workflows/markdown-linter.mdPins detection model.
.github/workflows/markdown-linter.lock.ymlRegenerates compiled workflow.
.github/workflows/msbuild-quality-review.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit-command.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit.lock.ymlApplies shared model pin.
.github/workflows/perf-improver.mdPins detection model.
.github/workflows/perf-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/pr-fix.mdPins detection model.
.github/workflows/pr-fix.lock.ymlRegenerates compiled workflow.
.github/workflows/q.mdPins detection model.
.github/workflows/q.lock.ymlRegenerates compiled workflow.
.github/workflows/README.mdDocuments parse errors and pin safety.
.github/workflows/repository-quality-improver.mdPins detection model.
.github/workflows/repository-quality-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/resource-lock-refactoring.mdPins detection model.
.github/workflows/resource-lock-refactoring.lock.ymlRegenerates compiled workflow.
.github/workflows/shared/address-review-shared.mdPins two consuming workflows.
.github/workflows/shared/msbuild-review-shared.mdPins its consuming workflow.
.github/workflows/shared/parallel-safety-audit-shared.mdPins two consuming workflows.
.github/workflows/shared/test-reviewer-shared.mdPins two consuming workflows.
.github/workflows/sub-issue-closer.mdPins detection model.
.github/workflows/sub-issue-closer.lock.ymlRegenerates compiled workflow.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlApplies shared model pin.
.github/workflows/test-reviewer.agent.lock.ymlApplies shared model pin.
.github/workflows/unskip-closed-tests.mdPins detection model.
.github/workflows/unskip-closed-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/weekly-issue-activity.mdPins detection model.
.github/workflows/weekly-issue-activity.lock.ymlRegenerates compiled workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit 491b236 into mainAug 25, 2026
21 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the nohwnd-pin-threat-detection-model branch August 25, 2026 13:42
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 25, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10729 pinned the
threat-detection model on every agentic workflow, so both sides carry a
different generated metadata hash for the same file.
The .md source merged cleanly and keeps both changes, so the lock file was
regenerated from it with `gh aw compile --action-mode action --action-tag
v0.86.2`. The result has main's threat-detection pin and this branch's lint
job, and the pin audit passes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@nohwnd@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Pin the threat-detection model on every agentic workflow - #10729

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model
Aug 25, 2026
Merged

Pin the threat-detection model on every agentic workflow#10729
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model

Conversation

@nohwnd

Copy link
Copy Markdown
Member

The detection job keeps recording parse_error even when the job itself succeeds. The default
detection model alias sometimes wraps its result line in Markdown emphasis, and gh-aw's parser
slices the JSON at a fixed offset from the start of the line instead of from the index of the marker
it just located. The two leading asterisks move the cut two characters into RESULT, so it tries to
parse T:{"prompt"…:

📄 Lines containing THREAT_DETECTION_RESULT (1 of 194):
[155] **THREAT_DETECTION_RESULT:{"prompt_injection":false,"secret_leak":false,…**
##[error]❌ Failed to parse detection result: Unexpected token 'T', "T:{"prompt"... is not valid JSON

The parser is parse_threat_detection_results.cjs inside the gh-aw actions bundle that every run
downloads, so the bug cannot be fixed in this repository. Pinning the detector to a model that does
not add the emphasis is the mitigation, and
microsoft/testfx#10684 already proved it works for
the expert-review workflows.

This applies the same pin to the 29 workflows that were still on the default alias. Where several
workflows share an import the pin goes in the shared file, so shared/address-review-shared.md,
shared/msbuild-review-shared.md, shared/parallel-safety-audit-shared.md and
shared/test-reviewer-shared.md cover seven locks between them. malicious-code-scan.md already
declared threat-detection, so it gets engine: inside its existing block. The expert-review trio
and Test Improver were already pinned and are unchanged.

The workflows README gains a section for this failure, including how to tell it apart from the
Install GitHub Copilot CLI cause that produces the same parse_error: if the log shows
Lines containing THREAT_DETECTION_RESULT (1 of N) the marker exists and this is the formatting
cause, and if it shows No THREAT_DETECTION_RESULT found it is the installer cause covered by
microsoft/testfx#10427.

Observed on:

One thing to weigh: this moves every workflow's detection job onto gpt-5-mini instead of the
default alias, so there is some extra cost. The PR-triggered review workflows run most often and
already made that move in
microsoft/testfx#10684, and the rest are mostly
daily scheduled runs, so the marginal cost is small. If you would rather scope it down, the runs
above only justify Test Improver, Test Reviewer, Parallel-safety audit, Sub-Issue Closer and Build
Failure Analysis.

The local compile also rewrote the pinned github/gh-aw-actions/setup SHA in agentic_commands.yml
back to a mutable tag, which is
microsoft/testfx#10258 again, on a gh aw whose
version matches the lock headers. That file is restored to its committed state and is not in this
diff; the README note about compiling on the pinned toolchain now says a matching compiler_version
is not enough to prevent it.

Verified: compiled with gh aw compile --strict on gh-aw v0.86.2, matching the compiler_version
recorded in every existing lock. All 33 locks now report "detection_agent_model":"gpt-5-mini", no
COPILOT_MODEL: detection remains, python .github/scripts/check_action_pins.py passes over 2345
references, and no uses: line changed anywhere in the diff.

Refs microsoft/testfx#10711

🤖

The default `detection` model alias sometimes wraps its result line in Markdown
emphasis. gh-aw's parser slices the JSON at a fixed offset from the start of the
line instead of from the marker index it just located, so the two leading
asterisks move the cut inside `RESULT` and the run is recorded as `parse_error`
even though detection itself succeeded. The parser lives in the gh-aw actions
bundle that each run downloads, so it cannot be fixed in this repository.
Pin `safe-outputs.threat-detection.engine.model` to `gpt-5-mini` on the 29
workflows still on the default alias, matching what #10684 already did for the
expert-review workflows. Where several workflows share an import the pin goes in
the shared file. `malicious-code-scan.md` already declared `threat-detection`,
so it gets `engine:` inside the existing block.
Also document the failure in the workflows README, including how to tell it
apart from the `Install GitHub Copilot CLI` cause that produces the same
`parse_error`.
Refs #10711
🤖
CopilotAI balanced review requested due to automatic review settings August 25, 2026 12:40

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Review Summary

This PR pins safe-outputs.threat-detection.engine.model: gpt-5-mini across 29 agentic workflows to work around the gh-aw parser bug where the default detection alias wraps its THREAT_DETECTION_RESULT JSON in Markdown emphasis, causing parse_error. The README is updated with troubleshooting guidance.

Verdict Table

#DimensionSeverityFinding
1Algorithmic CorrectnessMAJORN/A — no logic changes
2Public API SurfaceCRITICALN/A — no API changes
3Thread SafetyMAJORN/A
4Resource ManagementMAJORN/A
5Error HandlingMAJORN/A
6Backward CompatibilityCRITICALN/A
7PerformanceMAJORN/A
8SecurityCRITICALN/A
9Cross-TFMMAJORN/A
10IPC/Wire FormatCRITICALN/A
11LocalizationMINORN/A
12Test QualityMAJORN/A
13Naming & ConventionsMINORN/A
14DocumentationMINOR✅ Clean — README section is well-structured
15Null SafetyMAJORN/A
16Disposal & LifetimeMAJORN/A
17ConfigurationMINOR✅ Clean — consistent pattern across all workflows
18Build IntegrationMAJOR✅ Clean — all locks recompiled with --strict, compiler_version matches
19Logging & TelemetryMINORN/A
20Code DuplicationMINOR✅ Shared files used where possible (4 shared imports cover 7 locks)
21Scope DisciplineMINOR✅ Single concern — model pin only
22TODO PolicyMINORN/A

Assessment

No blocking issues found. The change is mechanical and consistent: every .md source gets the same threat-detection engine block (with a comment referencing #10711), every .lock.yml is regenerated with matching detection_agent_model metadata, no uses: lines changed, and the malicious-code-scan.md (which already had a threat-detection: block with continue-on-error: true) correctly gets the engine: sub-block added alongside the existing property. The README troubleshooting section clearly differentiates this failure mode from the installer-related parse_error documented in #10427.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins threat detection to gpt-5-mini across agentic workflows, mitigating malformed Markdown-wrapped detection results.

Changes:

  • Configures the model directly or through shared workflow imports.
  • Regenerates 29 lock files in strict mode.
  • Documents diagnosis, mitigation, and action-pin validation.

Reviewed changes

Copilot reviewed 56 out of 56 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/add-tests.mdPins detection model.
.github/workflows/add-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/address-review.agent.lock.ymlApplies shared model pin.
.github/workflows/adhoc-qa.mdPins detection model.
.github/workflows/adhoc-qa.lock.ymlRegenerates compiled workflow.
.github/workflows/autofix.agent.lock.ymlApplies shared model pin.
.github/workflows/build-failure-analysis-command.mdPins detection model.
.github/workflows/build-failure-analysis-command.lock.ymlRegenerates compiled workflow.
.github/workflows/build-failure-analysis.mdPins detection model.
.github/workflows/build-failure-analysis.lock.ymlRegenerates compiled workflow.
.github/workflows/code-simplifier.mdPins detection model.
.github/workflows/code-simplifier.lock.ymlRegenerates compiled workflow.
.github/workflows/daily-file-diet.mdPins detection model.
.github/workflows/daily-file-diet.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-issue-bundler.mdPins detection model.
.github/workflows/dependabot-issue-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-pr-bundler.mdPins detection model.
.github/workflows/dependabot-pr-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/duplicate-code-detector.mdPins detection model.
.github/workflows/duplicate-code-detector.lock.ymlRegenerates compiled workflow.
.github/workflows/efficiency-improver.mdPins detection model.
.github/workflows/efficiency-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/glossary-maintainer.mdPins detection model.
.github/workflows/glossary-maintainer.lock.ymlRegenerates compiled workflow.
.github/workflows/link-checker.mdPins detection model.
.github/workflows/link-checker.lock.ymlRegenerates compiled workflow.
.github/workflows/malicious-code-scan.mdExtends existing detection settings.
.github/workflows/malicious-code-scan.lock.ymlRegenerates compiled workflow.
.github/workflows/markdown-linter.mdPins detection model.
.github/workflows/markdown-linter.lock.ymlRegenerates compiled workflow.
.github/workflows/msbuild-quality-review.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit-command.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit.lock.ymlApplies shared model pin.
.github/workflows/perf-improver.mdPins detection model.
.github/workflows/perf-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/pr-fix.mdPins detection model.
.github/workflows/pr-fix.lock.ymlRegenerates compiled workflow.
.github/workflows/q.mdPins detection model.
.github/workflows/q.lock.ymlRegenerates compiled workflow.
.github/workflows/README.mdDocuments parse errors and pin safety.
.github/workflows/repository-quality-improver.mdPins detection model.
.github/workflows/repository-quality-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/resource-lock-refactoring.mdPins detection model.
.github/workflows/resource-lock-refactoring.lock.ymlRegenerates compiled workflow.
.github/workflows/shared/address-review-shared.mdPins two consuming workflows.
.github/workflows/shared/msbuild-review-shared.mdPins its consuming workflow.
.github/workflows/shared/parallel-safety-audit-shared.mdPins two consuming workflows.
.github/workflows/shared/test-reviewer-shared.mdPins two consuming workflows.
.github/workflows/sub-issue-closer.mdPins detection model.
.github/workflows/sub-issue-closer.lock.ymlRegenerates compiled workflow.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlApplies shared model pin.
.github/workflows/test-reviewer.agent.lock.ymlApplies shared model pin.
.github/workflows/unskip-closed-tests.mdPins detection model.
.github/workflows/unskip-closed-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/weekly-issue-activity.mdPins detection model.
.github/workflows/weekly-issue-activity.lock.ymlRegenerates compiled workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit 491b236 into mainAug 25, 2026
21 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the nohwnd-pin-threat-detection-model branch August 25, 2026 13:42
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 25, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10729 pinned the
threat-detection model on every agentic workflow, so both sides carry a
different generated metadata hash for the same file.
The .md source merged cleanly and keeps both changes, so the lock file was
regenerated from it with `gh aw compile --action-mode action --action-tag
v0.86.2`. The result has main's threat-detection pin and this branch's lint
job, and the pin audit passes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@nohwnd@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Pin the threat-detection model on every agentic workflow - #10729

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model
Aug 25, 2026
Merged

Pin the threat-detection model on every agentic workflow#10729
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model

Conversation

@nohwnd

Copy link
Copy Markdown
Member

The detection job keeps recording parse_error even when the job itself succeeds. The default
detection model alias sometimes wraps its result line in Markdown emphasis, and gh-aw's parser
slices the JSON at a fixed offset from the start of the line instead of from the index of the marker
it just located. The two leading asterisks move the cut two characters into RESULT, so it tries to
parse T:{"prompt"…:

📄 Lines containing THREAT_DETECTION_RESULT (1 of 194):
[155] **THREAT_DETECTION_RESULT:{"prompt_injection":false,"secret_leak":false,…**
##[error]❌ Failed to parse detection result: Unexpected token 'T', "T:{"prompt"... is not valid JSON

The parser is parse_threat_detection_results.cjs inside the gh-aw actions bundle that every run
downloads, so the bug cannot be fixed in this repository. Pinning the detector to a model that does
not add the emphasis is the mitigation, and
microsoft/testfx#10684 already proved it works for
the expert-review workflows.

This applies the same pin to the 29 workflows that were still on the default alias. Where several
workflows share an import the pin goes in the shared file, so shared/address-review-shared.md,
shared/msbuild-review-shared.md, shared/parallel-safety-audit-shared.md and
shared/test-reviewer-shared.md cover seven locks between them. malicious-code-scan.md already
declared threat-detection, so it gets engine: inside its existing block. The expert-review trio
and Test Improver were already pinned and are unchanged.

The workflows README gains a section for this failure, including how to tell it apart from the
Install GitHub Copilot CLI cause that produces the same parse_error: if the log shows
Lines containing THREAT_DETECTION_RESULT (1 of N) the marker exists and this is the formatting
cause, and if it shows No THREAT_DETECTION_RESULT found it is the installer cause covered by
microsoft/testfx#10427.

Observed on:

One thing to weigh: this moves every workflow's detection job onto gpt-5-mini instead of the
default alias, so there is some extra cost. The PR-triggered review workflows run most often and
already made that move in
microsoft/testfx#10684, and the rest are mostly
daily scheduled runs, so the marginal cost is small. If you would rather scope it down, the runs
above only justify Test Improver, Test Reviewer, Parallel-safety audit, Sub-Issue Closer and Build
Failure Analysis.

The local compile also rewrote the pinned github/gh-aw-actions/setup SHA in agentic_commands.yml
back to a mutable tag, which is
microsoft/testfx#10258 again, on a gh aw whose
version matches the lock headers. That file is restored to its committed state and is not in this
diff; the README note about compiling on the pinned toolchain now says a matching compiler_version
is not enough to prevent it.

Verified: compiled with gh aw compile --strict on gh-aw v0.86.2, matching the compiler_version
recorded in every existing lock. All 33 locks now report "detection_agent_model":"gpt-5-mini", no
COPILOT_MODEL: detection remains, python .github/scripts/check_action_pins.py passes over 2345
references, and no uses: line changed anywhere in the diff.

Refs microsoft/testfx#10711

🤖

The default `detection` model alias sometimes wraps its result line in Markdown
emphasis. gh-aw's parser slices the JSON at a fixed offset from the start of the
line instead of from the marker index it just located, so the two leading
asterisks move the cut inside `RESULT` and the run is recorded as `parse_error`
even though detection itself succeeded. The parser lives in the gh-aw actions
bundle that each run downloads, so it cannot be fixed in this repository.
Pin `safe-outputs.threat-detection.engine.model` to `gpt-5-mini` on the 29
workflows still on the default alias, matching what #10684 already did for the
expert-review workflows. Where several workflows share an import the pin goes in
the shared file. `malicious-code-scan.md` already declared `threat-detection`,
so it gets `engine:` inside the existing block.
Also document the failure in the workflows README, including how to tell it
apart from the `Install GitHub Copilot CLI` cause that produces the same
`parse_error`.
Refs #10711
🤖
CopilotAI balanced review requested due to automatic review settings August 25, 2026 12:40

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Review Summary

This PR pins safe-outputs.threat-detection.engine.model: gpt-5-mini across 29 agentic workflows to work around the gh-aw parser bug where the default detection alias wraps its THREAT_DETECTION_RESULT JSON in Markdown emphasis, causing parse_error. The README is updated with troubleshooting guidance.

Verdict Table

#DimensionSeverityFinding
1Algorithmic CorrectnessMAJORN/A — no logic changes
2Public API SurfaceCRITICALN/A — no API changes
3Thread SafetyMAJORN/A
4Resource ManagementMAJORN/A
5Error HandlingMAJORN/A
6Backward CompatibilityCRITICALN/A
7PerformanceMAJORN/A
8SecurityCRITICALN/A
9Cross-TFMMAJORN/A
10IPC/Wire FormatCRITICALN/A
11LocalizationMINORN/A
12Test QualityMAJORN/A
13Naming & ConventionsMINORN/A
14DocumentationMINOR✅ Clean — README section is well-structured
15Null SafetyMAJORN/A
16Disposal & LifetimeMAJORN/A
17ConfigurationMINOR✅ Clean — consistent pattern across all workflows
18Build IntegrationMAJOR✅ Clean — all locks recompiled with --strict, compiler_version matches
19Logging & TelemetryMINORN/A
20Code DuplicationMINOR✅ Shared files used where possible (4 shared imports cover 7 locks)
21Scope DisciplineMINOR✅ Single concern — model pin only
22TODO PolicyMINORN/A

Assessment

No blocking issues found. The change is mechanical and consistent: every .md source gets the same threat-detection engine block (with a comment referencing #10711), every .lock.yml is regenerated with matching detection_agent_model metadata, no uses: lines changed, and the malicious-code-scan.md (which already had a threat-detection: block with continue-on-error: true) correctly gets the engine: sub-block added alongside the existing property. The README troubleshooting section clearly differentiates this failure mode from the installer-related parse_error documented in #10427.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins threat detection to gpt-5-mini across agentic workflows, mitigating malformed Markdown-wrapped detection results.

Changes:

  • Configures the model directly or through shared workflow imports.
  • Regenerates 29 lock files in strict mode.
  • Documents diagnosis, mitigation, and action-pin validation.

Reviewed changes

Copilot reviewed 56 out of 56 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/add-tests.mdPins detection model.
.github/workflows/add-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/address-review.agent.lock.ymlApplies shared model pin.
.github/workflows/adhoc-qa.mdPins detection model.
.github/workflows/adhoc-qa.lock.ymlRegenerates compiled workflow.
.github/workflows/autofix.agent.lock.ymlApplies shared model pin.
.github/workflows/build-failure-analysis-command.mdPins detection model.
.github/workflows/build-failure-analysis-command.lock.ymlRegenerates compiled workflow.
.github/workflows/build-failure-analysis.mdPins detection model.
.github/workflows/build-failure-analysis.lock.ymlRegenerates compiled workflow.
.github/workflows/code-simplifier.mdPins detection model.
.github/workflows/code-simplifier.lock.ymlRegenerates compiled workflow.
.github/workflows/daily-file-diet.mdPins detection model.
.github/workflows/daily-file-diet.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-issue-bundler.mdPins detection model.
.github/workflows/dependabot-issue-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-pr-bundler.mdPins detection model.
.github/workflows/dependabot-pr-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/duplicate-code-detector.mdPins detection model.
.github/workflows/duplicate-code-detector.lock.ymlRegenerates compiled workflow.
.github/workflows/efficiency-improver.mdPins detection model.
.github/workflows/efficiency-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/glossary-maintainer.mdPins detection model.
.github/workflows/glossary-maintainer.lock.ymlRegenerates compiled workflow.
.github/workflows/link-checker.mdPins detection model.
.github/workflows/link-checker.lock.ymlRegenerates compiled workflow.
.github/workflows/malicious-code-scan.mdExtends existing detection settings.
.github/workflows/malicious-code-scan.lock.ymlRegenerates compiled workflow.
.github/workflows/markdown-linter.mdPins detection model.
.github/workflows/markdown-linter.lock.ymlRegenerates compiled workflow.
.github/workflows/msbuild-quality-review.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit-command.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit.lock.ymlApplies shared model pin.
.github/workflows/perf-improver.mdPins detection model.
.github/workflows/perf-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/pr-fix.mdPins detection model.
.github/workflows/pr-fix.lock.ymlRegenerates compiled workflow.
.github/workflows/q.mdPins detection model.
.github/workflows/q.lock.ymlRegenerates compiled workflow.
.github/workflows/README.mdDocuments parse errors and pin safety.
.github/workflows/repository-quality-improver.mdPins detection model.
.github/workflows/repository-quality-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/resource-lock-refactoring.mdPins detection model.
.github/workflows/resource-lock-refactoring.lock.ymlRegenerates compiled workflow.
.github/workflows/shared/address-review-shared.mdPins two consuming workflows.
.github/workflows/shared/msbuild-review-shared.mdPins its consuming workflow.
.github/workflows/shared/parallel-safety-audit-shared.mdPins two consuming workflows.
.github/workflows/shared/test-reviewer-shared.mdPins two consuming workflows.
.github/workflows/sub-issue-closer.mdPins detection model.
.github/workflows/sub-issue-closer.lock.ymlRegenerates compiled workflow.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlApplies shared model pin.
.github/workflows/test-reviewer.agent.lock.ymlApplies shared model pin.
.github/workflows/unskip-closed-tests.mdPins detection model.
.github/workflows/unskip-closed-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/weekly-issue-activity.mdPins detection model.
.github/workflows/weekly-issue-activity.lock.ymlRegenerates compiled workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit 491b236 into mainAug 25, 2026
21 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the nohwnd-pin-threat-detection-model branch August 25, 2026 13:42
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 25, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10729 pinned the
threat-detection model on every agentic workflow, so both sides carry a
different generated metadata hash for the same file.
The .md source merged cleanly and keeps both changes, so the lock file was
regenerated from it with `gh aw compile --action-mode action --action-tag
v0.86.2`. The result has main's threat-detection pin and this branch's lint
job, and the pin audit passes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@nohwnd@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Pin the threat-detection model on every agentic workflow - #10729

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model
Aug 25, 2026
Merged

Pin the threat-detection model on every agentic workflow#10729
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model

Conversation

@nohwnd

Copy link
Copy Markdown
Member

The detection job keeps recording parse_error even when the job itself succeeds. The default
detection model alias sometimes wraps its result line in Markdown emphasis, and gh-aw's parser
slices the JSON at a fixed offset from the start of the line instead of from the index of the marker
it just located. The two leading asterisks move the cut two characters into RESULT, so it tries to
parse T:{"prompt"…:

📄 Lines containing THREAT_DETECTION_RESULT (1 of 194):
[155] **THREAT_DETECTION_RESULT:{"prompt_injection":false,"secret_leak":false,…**
##[error]❌ Failed to parse detection result: Unexpected token 'T', "T:{"prompt"... is not valid JSON

The parser is parse_threat_detection_results.cjs inside the gh-aw actions bundle that every run
downloads, so the bug cannot be fixed in this repository. Pinning the detector to a model that does
not add the emphasis is the mitigation, and
microsoft/testfx#10684 already proved it works for
the expert-review workflows.

This applies the same pin to the 29 workflows that were still on the default alias. Where several
workflows share an import the pin goes in the shared file, so shared/address-review-shared.md,
shared/msbuild-review-shared.md, shared/parallel-safety-audit-shared.md and
shared/test-reviewer-shared.md cover seven locks between them. malicious-code-scan.md already
declared threat-detection, so it gets engine: inside its existing block. The expert-review trio
and Test Improver were already pinned and are unchanged.

The workflows README gains a section for this failure, including how to tell it apart from the
Install GitHub Copilot CLI cause that produces the same parse_error: if the log shows
Lines containing THREAT_DETECTION_RESULT (1 of N) the marker exists and this is the formatting
cause, and if it shows No THREAT_DETECTION_RESULT found it is the installer cause covered by
microsoft/testfx#10427.

Observed on:

One thing to weigh: this moves every workflow's detection job onto gpt-5-mini instead of the
default alias, so there is some extra cost. The PR-triggered review workflows run most often and
already made that move in
microsoft/testfx#10684, and the rest are mostly
daily scheduled runs, so the marginal cost is small. If you would rather scope it down, the runs
above only justify Test Improver, Test Reviewer, Parallel-safety audit, Sub-Issue Closer and Build
Failure Analysis.

The local compile also rewrote the pinned github/gh-aw-actions/setup SHA in agentic_commands.yml
back to a mutable tag, which is
microsoft/testfx#10258 again, on a gh aw whose
version matches the lock headers. That file is restored to its committed state and is not in this
diff; the README note about compiling on the pinned toolchain now says a matching compiler_version
is not enough to prevent it.

Verified: compiled with gh aw compile --strict on gh-aw v0.86.2, matching the compiler_version
recorded in every existing lock. All 33 locks now report "detection_agent_model":"gpt-5-mini", no
COPILOT_MODEL: detection remains, python .github/scripts/check_action_pins.py passes over 2345
references, and no uses: line changed anywhere in the diff.

Refs microsoft/testfx#10711

🤖

The default `detection` model alias sometimes wraps its result line in Markdown
emphasis. gh-aw's parser slices the JSON at a fixed offset from the start of the
line instead of from the marker index it just located, so the two leading
asterisks move the cut inside `RESULT` and the run is recorded as `parse_error`
even though detection itself succeeded. The parser lives in the gh-aw actions
bundle that each run downloads, so it cannot be fixed in this repository.
Pin `safe-outputs.threat-detection.engine.model` to `gpt-5-mini` on the 29
workflows still on the default alias, matching what #10684 already did for the
expert-review workflows. Where several workflows share an import the pin goes in
the shared file. `malicious-code-scan.md` already declared `threat-detection`,
so it gets `engine:` inside the existing block.
Also document the failure in the workflows README, including how to tell it
apart from the `Install GitHub Copilot CLI` cause that produces the same
`parse_error`.
Refs #10711
🤖
CopilotAI balanced review requested due to automatic review settings August 25, 2026 12:40

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Review Summary

This PR pins safe-outputs.threat-detection.engine.model: gpt-5-mini across 29 agentic workflows to work around the gh-aw parser bug where the default detection alias wraps its THREAT_DETECTION_RESULT JSON in Markdown emphasis, causing parse_error. The README is updated with troubleshooting guidance.

Verdict Table

#DimensionSeverityFinding
1Algorithmic CorrectnessMAJORN/A — no logic changes
2Public API SurfaceCRITICALN/A — no API changes
3Thread SafetyMAJORN/A
4Resource ManagementMAJORN/A
5Error HandlingMAJORN/A
6Backward CompatibilityCRITICALN/A
7PerformanceMAJORN/A
8SecurityCRITICALN/A
9Cross-TFMMAJORN/A
10IPC/Wire FormatCRITICALN/A
11LocalizationMINORN/A
12Test QualityMAJORN/A
13Naming & ConventionsMINORN/A
14DocumentationMINOR✅ Clean — README section is well-structured
15Null SafetyMAJORN/A
16Disposal & LifetimeMAJORN/A
17ConfigurationMINOR✅ Clean — consistent pattern across all workflows
18Build IntegrationMAJOR✅ Clean — all locks recompiled with --strict, compiler_version matches
19Logging & TelemetryMINORN/A
20Code DuplicationMINOR✅ Shared files used where possible (4 shared imports cover 7 locks)
21Scope DisciplineMINOR✅ Single concern — model pin only
22TODO PolicyMINORN/A

Assessment

No blocking issues found. The change is mechanical and consistent: every .md source gets the same threat-detection engine block (with a comment referencing #10711), every .lock.yml is regenerated with matching detection_agent_model metadata, no uses: lines changed, and the malicious-code-scan.md (which already had a threat-detection: block with continue-on-error: true) correctly gets the engine: sub-block added alongside the existing property. The README troubleshooting section clearly differentiates this failure mode from the installer-related parse_error documented in #10427.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins threat detection to gpt-5-mini across agentic workflows, mitigating malformed Markdown-wrapped detection results.

Changes:

  • Configures the model directly or through shared workflow imports.
  • Regenerates 29 lock files in strict mode.
  • Documents diagnosis, mitigation, and action-pin validation.

Reviewed changes

Copilot reviewed 56 out of 56 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/add-tests.mdPins detection model.
.github/workflows/add-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/address-review.agent.lock.ymlApplies shared model pin.
.github/workflows/adhoc-qa.mdPins detection model.
.github/workflows/adhoc-qa.lock.ymlRegenerates compiled workflow.
.github/workflows/autofix.agent.lock.ymlApplies shared model pin.
.github/workflows/build-failure-analysis-command.mdPins detection model.
.github/workflows/build-failure-analysis-command.lock.ymlRegenerates compiled workflow.
.github/workflows/build-failure-analysis.mdPins detection model.
.github/workflows/build-failure-analysis.lock.ymlRegenerates compiled workflow.
.github/workflows/code-simplifier.mdPins detection model.
.github/workflows/code-simplifier.lock.ymlRegenerates compiled workflow.
.github/workflows/daily-file-diet.mdPins detection model.
.github/workflows/daily-file-diet.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-issue-bundler.mdPins detection model.
.github/workflows/dependabot-issue-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-pr-bundler.mdPins detection model.
.github/workflows/dependabot-pr-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/duplicate-code-detector.mdPins detection model.
.github/workflows/duplicate-code-detector.lock.ymlRegenerates compiled workflow.
.github/workflows/efficiency-improver.mdPins detection model.
.github/workflows/efficiency-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/glossary-maintainer.mdPins detection model.
.github/workflows/glossary-maintainer.lock.ymlRegenerates compiled workflow.
.github/workflows/link-checker.mdPins detection model.
.github/workflows/link-checker.lock.ymlRegenerates compiled workflow.
.github/workflows/malicious-code-scan.mdExtends existing detection settings.
.github/workflows/malicious-code-scan.lock.ymlRegenerates compiled workflow.
.github/workflows/markdown-linter.mdPins detection model.
.github/workflows/markdown-linter.lock.ymlRegenerates compiled workflow.
.github/workflows/msbuild-quality-review.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit-command.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit.lock.ymlApplies shared model pin.
.github/workflows/perf-improver.mdPins detection model.
.github/workflows/perf-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/pr-fix.mdPins detection model.
.github/workflows/pr-fix.lock.ymlRegenerates compiled workflow.
.github/workflows/q.mdPins detection model.
.github/workflows/q.lock.ymlRegenerates compiled workflow.
.github/workflows/README.mdDocuments parse errors and pin safety.
.github/workflows/repository-quality-improver.mdPins detection model.
.github/workflows/repository-quality-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/resource-lock-refactoring.mdPins detection model.
.github/workflows/resource-lock-refactoring.lock.ymlRegenerates compiled workflow.
.github/workflows/shared/address-review-shared.mdPins two consuming workflows.
.github/workflows/shared/msbuild-review-shared.mdPins its consuming workflow.
.github/workflows/shared/parallel-safety-audit-shared.mdPins two consuming workflows.
.github/workflows/shared/test-reviewer-shared.mdPins two consuming workflows.
.github/workflows/sub-issue-closer.mdPins detection model.
.github/workflows/sub-issue-closer.lock.ymlRegenerates compiled workflow.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlApplies shared model pin.
.github/workflows/test-reviewer.agent.lock.ymlApplies shared model pin.
.github/workflows/unskip-closed-tests.mdPins detection model.
.github/workflows/unskip-closed-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/weekly-issue-activity.mdPins detection model.
.github/workflows/weekly-issue-activity.lock.ymlRegenerates compiled workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit 491b236 into mainAug 25, 2026
21 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the nohwnd-pin-threat-detection-model branch August 25, 2026 13:42
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 25, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10729 pinned the
threat-detection model on every agentic workflow, so both sides carry a
different generated metadata hash for the same file.
The .md source merged cleanly and keeps both changes, so the lock file was
regenerated from it with `gh aw compile --action-mode action --action-tag
v0.86.2`. The result has main's threat-detection pin and this branch's lint
job, and the pin audit passes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@nohwnd@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Pin the threat-detection model on every agentic workflow - #10729

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model
Aug 25, 2026
Merged

Pin the threat-detection model on every agentic workflow#10729
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model

Conversation

@nohwnd

Copy link
Copy Markdown
Member

The detection job keeps recording parse_error even when the job itself succeeds. The default
detection model alias sometimes wraps its result line in Markdown emphasis, and gh-aw's parser
slices the JSON at a fixed offset from the start of the line instead of from the index of the marker
it just located. The two leading asterisks move the cut two characters into RESULT, so it tries to
parse T:{"prompt"…:

📄 Lines containing THREAT_DETECTION_RESULT (1 of 194):
[155] **THREAT_DETECTION_RESULT:{"prompt_injection":false,"secret_leak":false,…**
##[error]❌ Failed to parse detection result: Unexpected token 'T', "T:{"prompt"... is not valid JSON

The parser is parse_threat_detection_results.cjs inside the gh-aw actions bundle that every run
downloads, so the bug cannot be fixed in this repository. Pinning the detector to a model that does
not add the emphasis is the mitigation, and
microsoft/testfx#10684 already proved it works for
the expert-review workflows.

This applies the same pin to the 29 workflows that were still on the default alias. Where several
workflows share an import the pin goes in the shared file, so shared/address-review-shared.md,
shared/msbuild-review-shared.md, shared/parallel-safety-audit-shared.md and
shared/test-reviewer-shared.md cover seven locks between them. malicious-code-scan.md already
declared threat-detection, so it gets engine: inside its existing block. The expert-review trio
and Test Improver were already pinned and are unchanged.

The workflows README gains a section for this failure, including how to tell it apart from the
Install GitHub Copilot CLI cause that produces the same parse_error: if the log shows
Lines containing THREAT_DETECTION_RESULT (1 of N) the marker exists and this is the formatting
cause, and if it shows No THREAT_DETECTION_RESULT found it is the installer cause covered by
microsoft/testfx#10427.

Observed on:

One thing to weigh: this moves every workflow's detection job onto gpt-5-mini instead of the
default alias, so there is some extra cost. The PR-triggered review workflows run most often and
already made that move in
microsoft/testfx#10684, and the rest are mostly
daily scheduled runs, so the marginal cost is small. If you would rather scope it down, the runs
above only justify Test Improver, Test Reviewer, Parallel-safety audit, Sub-Issue Closer and Build
Failure Analysis.

The local compile also rewrote the pinned github/gh-aw-actions/setup SHA in agentic_commands.yml
back to a mutable tag, which is
microsoft/testfx#10258 again, on a gh aw whose
version matches the lock headers. That file is restored to its committed state and is not in this
diff; the README note about compiling on the pinned toolchain now says a matching compiler_version
is not enough to prevent it.

Verified: compiled with gh aw compile --strict on gh-aw v0.86.2, matching the compiler_version
recorded in every existing lock. All 33 locks now report "detection_agent_model":"gpt-5-mini", no
COPILOT_MODEL: detection remains, python .github/scripts/check_action_pins.py passes over 2345
references, and no uses: line changed anywhere in the diff.

Refs microsoft/testfx#10711

🤖

The default `detection` model alias sometimes wraps its result line in Markdown
emphasis. gh-aw's parser slices the JSON at a fixed offset from the start of the
line instead of from the marker index it just located, so the two leading
asterisks move the cut inside `RESULT` and the run is recorded as `parse_error`
even though detection itself succeeded. The parser lives in the gh-aw actions
bundle that each run downloads, so it cannot be fixed in this repository.
Pin `safe-outputs.threat-detection.engine.model` to `gpt-5-mini` on the 29
workflows still on the default alias, matching what #10684 already did for the
expert-review workflows. Where several workflows share an import the pin goes in
the shared file. `malicious-code-scan.md` already declared `threat-detection`,
so it gets `engine:` inside the existing block.
Also document the failure in the workflows README, including how to tell it
apart from the `Install GitHub Copilot CLI` cause that produces the same
`parse_error`.
Refs #10711
🤖
CopilotAI balanced review requested due to automatic review settings August 25, 2026 12:40

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Review Summary

This PR pins safe-outputs.threat-detection.engine.model: gpt-5-mini across 29 agentic workflows to work around the gh-aw parser bug where the default detection alias wraps its THREAT_DETECTION_RESULT JSON in Markdown emphasis, causing parse_error. The README is updated with troubleshooting guidance.

Verdict Table

#DimensionSeverityFinding
1Algorithmic CorrectnessMAJORN/A — no logic changes
2Public API SurfaceCRITICALN/A — no API changes
3Thread SafetyMAJORN/A
4Resource ManagementMAJORN/A
5Error HandlingMAJORN/A
6Backward CompatibilityCRITICALN/A
7PerformanceMAJORN/A
8SecurityCRITICALN/A
9Cross-TFMMAJORN/A
10IPC/Wire FormatCRITICALN/A
11LocalizationMINORN/A
12Test QualityMAJORN/A
13Naming & ConventionsMINORN/A
14DocumentationMINOR✅ Clean — README section is well-structured
15Null SafetyMAJORN/A
16Disposal & LifetimeMAJORN/A
17ConfigurationMINOR✅ Clean — consistent pattern across all workflows
18Build IntegrationMAJOR✅ Clean — all locks recompiled with --strict, compiler_version matches
19Logging & TelemetryMINORN/A
20Code DuplicationMINOR✅ Shared files used where possible (4 shared imports cover 7 locks)
21Scope DisciplineMINOR✅ Single concern — model pin only
22TODO PolicyMINORN/A

Assessment

No blocking issues found. The change is mechanical and consistent: every .md source gets the same threat-detection engine block (with a comment referencing #10711), every .lock.yml is regenerated with matching detection_agent_model metadata, no uses: lines changed, and the malicious-code-scan.md (which already had a threat-detection: block with continue-on-error: true) correctly gets the engine: sub-block added alongside the existing property. The README troubleshooting section clearly differentiates this failure mode from the installer-related parse_error documented in #10427.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins threat detection to gpt-5-mini across agentic workflows, mitigating malformed Markdown-wrapped detection results.

Changes:

  • Configures the model directly or through shared workflow imports.
  • Regenerates 29 lock files in strict mode.
  • Documents diagnosis, mitigation, and action-pin validation.

Reviewed changes

Copilot reviewed 56 out of 56 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/add-tests.mdPins detection model.
.github/workflows/add-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/address-review.agent.lock.ymlApplies shared model pin.
.github/workflows/adhoc-qa.mdPins detection model.
.github/workflows/adhoc-qa.lock.ymlRegenerates compiled workflow.
.github/workflows/autofix.agent.lock.ymlApplies shared model pin.
.github/workflows/build-failure-analysis-command.mdPins detection model.
.github/workflows/build-failure-analysis-command.lock.ymlRegenerates compiled workflow.
.github/workflows/build-failure-analysis.mdPins detection model.
.github/workflows/build-failure-analysis.lock.ymlRegenerates compiled workflow.
.github/workflows/code-simplifier.mdPins detection model.
.github/workflows/code-simplifier.lock.ymlRegenerates compiled workflow.
.github/workflows/daily-file-diet.mdPins detection model.
.github/workflows/daily-file-diet.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-issue-bundler.mdPins detection model.
.github/workflows/dependabot-issue-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-pr-bundler.mdPins detection model.
.github/workflows/dependabot-pr-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/duplicate-code-detector.mdPins detection model.
.github/workflows/duplicate-code-detector.lock.ymlRegenerates compiled workflow.
.github/workflows/efficiency-improver.mdPins detection model.
.github/workflows/efficiency-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/glossary-maintainer.mdPins detection model.
.github/workflows/glossary-maintainer.lock.ymlRegenerates compiled workflow.
.github/workflows/link-checker.mdPins detection model.
.github/workflows/link-checker.lock.ymlRegenerates compiled workflow.
.github/workflows/malicious-code-scan.mdExtends existing detection settings.
.github/workflows/malicious-code-scan.lock.ymlRegenerates compiled workflow.
.github/workflows/markdown-linter.mdPins detection model.
.github/workflows/markdown-linter.lock.ymlRegenerates compiled workflow.
.github/workflows/msbuild-quality-review.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit-command.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit.lock.ymlApplies shared model pin.
.github/workflows/perf-improver.mdPins detection model.
.github/workflows/perf-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/pr-fix.mdPins detection model.
.github/workflows/pr-fix.lock.ymlRegenerates compiled workflow.
.github/workflows/q.mdPins detection model.
.github/workflows/q.lock.ymlRegenerates compiled workflow.
.github/workflows/README.mdDocuments parse errors and pin safety.
.github/workflows/repository-quality-improver.mdPins detection model.
.github/workflows/repository-quality-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/resource-lock-refactoring.mdPins detection model.
.github/workflows/resource-lock-refactoring.lock.ymlRegenerates compiled workflow.
.github/workflows/shared/address-review-shared.mdPins two consuming workflows.
.github/workflows/shared/msbuild-review-shared.mdPins its consuming workflow.
.github/workflows/shared/parallel-safety-audit-shared.mdPins two consuming workflows.
.github/workflows/shared/test-reviewer-shared.mdPins two consuming workflows.
.github/workflows/sub-issue-closer.mdPins detection model.
.github/workflows/sub-issue-closer.lock.ymlRegenerates compiled workflow.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlApplies shared model pin.
.github/workflows/test-reviewer.agent.lock.ymlApplies shared model pin.
.github/workflows/unskip-closed-tests.mdPins detection model.
.github/workflows/unskip-closed-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/weekly-issue-activity.mdPins detection model.
.github/workflows/weekly-issue-activity.lock.ymlRegenerates compiled workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit 491b236 into mainAug 25, 2026
21 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the nohwnd-pin-threat-detection-model branch August 25, 2026 13:42
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 25, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10729 pinned the
threat-detection model on every agentic workflow, so both sides carry a
different generated metadata hash for the same file.
The .md source merged cleanly and keeps both changes, so the lock file was
regenerated from it with `gh aw compile --action-mode action --action-tag
v0.86.2`. The result has main's threat-detection pin and this branch's lint
job, and the pin audit passes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@nohwnd@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Pin the threat-detection model on every agentic workflow - #10729

Merged
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model
Aug 25, 2026
Merged

Pin the threat-detection model on every agentic workflow#10729
Amaury Levé (Evangelink) merged 2 commits into
mainfrom
nohwnd-pin-threat-detection-model

Conversation

@nohwnd

Copy link
Copy Markdown
Member

The detection job keeps recording parse_error even when the job itself succeeds. The default
detection model alias sometimes wraps its result line in Markdown emphasis, and gh-aw's parser
slices the JSON at a fixed offset from the start of the line instead of from the index of the marker
it just located. The two leading asterisks move the cut two characters into RESULT, so it tries to
parse T:{"prompt"…:

📄 Lines containing THREAT_DETECTION_RESULT (1 of 194):
[155] **THREAT_DETECTION_RESULT:{"prompt_injection":false,"secret_leak":false,…**
##[error]❌ Failed to parse detection result: Unexpected token 'T', "T:{"prompt"... is not valid JSON

The parser is parse_threat_detection_results.cjs inside the gh-aw actions bundle that every run
downloads, so the bug cannot be fixed in this repository. Pinning the detector to a model that does
not add the emphasis is the mitigation, and
microsoft/testfx#10684 already proved it works for
the expert-review workflows.

This applies the same pin to the 29 workflows that were still on the default alias. Where several
workflows share an import the pin goes in the shared file, so shared/address-review-shared.md,
shared/msbuild-review-shared.md, shared/parallel-safety-audit-shared.md and
shared/test-reviewer-shared.md cover seven locks between them. malicious-code-scan.md already
declared threat-detection, so it gets engine: inside its existing block. The expert-review trio
and Test Improver were already pinned and are unchanged.

The workflows README gains a section for this failure, including how to tell it apart from the
Install GitHub Copilot CLI cause that produces the same parse_error: if the log shows
Lines containing THREAT_DETECTION_RESULT (1 of N) the marker exists and this is the formatting
cause, and if it shows No THREAT_DETECTION_RESULT found it is the installer cause covered by
microsoft/testfx#10427.

Observed on:

One thing to weigh: this moves every workflow's detection job onto gpt-5-mini instead of the
default alias, so there is some extra cost. The PR-triggered review workflows run most often and
already made that move in
microsoft/testfx#10684, and the rest are mostly
daily scheduled runs, so the marginal cost is small. If you would rather scope it down, the runs
above only justify Test Improver, Test Reviewer, Parallel-safety audit, Sub-Issue Closer and Build
Failure Analysis.

The local compile also rewrote the pinned github/gh-aw-actions/setup SHA in agentic_commands.yml
back to a mutable tag, which is
microsoft/testfx#10258 again, on a gh aw whose
version matches the lock headers. That file is restored to its committed state and is not in this
diff; the README note about compiling on the pinned toolchain now says a matching compiler_version
is not enough to prevent it.

Verified: compiled with gh aw compile --strict on gh-aw v0.86.2, matching the compiler_version
recorded in every existing lock. All 33 locks now report "detection_agent_model":"gpt-5-mini", no
COPILOT_MODEL: detection remains, python .github/scripts/check_action_pins.py passes over 2345
references, and no uses: line changed anywhere in the diff.

Refs microsoft/testfx#10711

🤖

The default `detection` model alias sometimes wraps its result line in Markdown
emphasis. gh-aw's parser slices the JSON at a fixed offset from the start of the
line instead of from the marker index it just located, so the two leading
asterisks move the cut inside `RESULT` and the run is recorded as `parse_error`
even though detection itself succeeded. The parser lives in the gh-aw actions
bundle that each run downloads, so it cannot be fixed in this repository.
Pin `safe-outputs.threat-detection.engine.model` to `gpt-5-mini` on the 29
workflows still on the default alias, matching what #10684 already did for the
expert-review workflows. Where several workflows share an import the pin goes in
the shared file. `malicious-code-scan.md` already declared `threat-detection`,
so it gets `engine:` inside the existing block.
Also document the failure in the workflows README, including how to tell it
apart from the `Install GitHub Copilot CLI` cause that produces the same
`parse_error`.
Refs #10711
🤖
CopilotAI balanced review requested due to automatic review settings August 25, 2026 12:40

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

🤖 Automated review by GitHub Copilot. Generated by the Expert Code Review workflow. To request a follow-up action, reply by tagging @copilot directly.

Review Summary

This PR pins safe-outputs.threat-detection.engine.model: gpt-5-mini across 29 agentic workflows to work around the gh-aw parser bug where the default detection alias wraps its THREAT_DETECTION_RESULT JSON in Markdown emphasis, causing parse_error. The README is updated with troubleshooting guidance.

Verdict Table

#DimensionSeverityFinding
1Algorithmic CorrectnessMAJORN/A — no logic changes
2Public API SurfaceCRITICALN/A — no API changes
3Thread SafetyMAJORN/A
4Resource ManagementMAJORN/A
5Error HandlingMAJORN/A
6Backward CompatibilityCRITICALN/A
7PerformanceMAJORN/A
8SecurityCRITICALN/A
9Cross-TFMMAJORN/A
10IPC/Wire FormatCRITICALN/A
11LocalizationMINORN/A
12Test QualityMAJORN/A
13Naming & ConventionsMINORN/A
14DocumentationMINOR✅ Clean — README section is well-structured
15Null SafetyMAJORN/A
16Disposal & LifetimeMAJORN/A
17ConfigurationMINOR✅ Clean — consistent pattern across all workflows
18Build IntegrationMAJOR✅ Clean — all locks recompiled with --strict, compiler_version matches
19Logging & TelemetryMINORN/A
20Code DuplicationMINOR✅ Shared files used where possible (4 shared imports cover 7 locks)
21Scope DisciplineMINOR✅ Single concern — model pin only
22TODO PolicyMINORN/A

Assessment

No blocking issues found. The change is mechanical and consistent: every .md source gets the same threat-detection engine block (with a comment referencing #10711), every .lock.yml is regenerated with matching detection_agent_model metadata, no uses: lines changed, and the malicious-code-scan.md (which already had a threat-detection: block with continue-on-error: true) correctly gets the engine: sub-block added alongside the existing property. The README troubleshooting section clearly differentiates this failure mode from the installer-related parse_error documented in #10427.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Pins threat detection to gpt-5-mini across agentic workflows, mitigating malformed Markdown-wrapped detection results.

Changes:

  • Configures the model directly or through shared workflow imports.
  • Regenerates 29 lock files in strict mode.
  • Documents diagnosis, mitigation, and action-pin validation.

Reviewed changes

Copilot reviewed 56 out of 56 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/add-tests.mdPins detection model.
.github/workflows/add-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/address-review.agent.lock.ymlApplies shared model pin.
.github/workflows/adhoc-qa.mdPins detection model.
.github/workflows/adhoc-qa.lock.ymlRegenerates compiled workflow.
.github/workflows/autofix.agent.lock.ymlApplies shared model pin.
.github/workflows/build-failure-analysis-command.mdPins detection model.
.github/workflows/build-failure-analysis-command.lock.ymlRegenerates compiled workflow.
.github/workflows/build-failure-analysis.mdPins detection model.
.github/workflows/build-failure-analysis.lock.ymlRegenerates compiled workflow.
.github/workflows/code-simplifier.mdPins detection model.
.github/workflows/code-simplifier.lock.ymlRegenerates compiled workflow.
.github/workflows/daily-file-diet.mdPins detection model.
.github/workflows/daily-file-diet.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-issue-bundler.mdPins detection model.
.github/workflows/dependabot-issue-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/dependabot-pr-bundler.mdPins detection model.
.github/workflows/dependabot-pr-bundler.lock.ymlRegenerates compiled workflow.
.github/workflows/duplicate-code-detector.mdPins detection model.
.github/workflows/duplicate-code-detector.lock.ymlRegenerates compiled workflow.
.github/workflows/efficiency-improver.mdPins detection model.
.github/workflows/efficiency-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/glossary-maintainer.mdPins detection model.
.github/workflows/glossary-maintainer.lock.ymlRegenerates compiled workflow.
.github/workflows/link-checker.mdPins detection model.
.github/workflows/link-checker.lock.ymlRegenerates compiled workflow.
.github/workflows/malicious-code-scan.mdExtends existing detection settings.
.github/workflows/malicious-code-scan.lock.ymlRegenerates compiled workflow.
.github/workflows/markdown-linter.mdPins detection model.
.github/workflows/markdown-linter.lock.ymlRegenerates compiled workflow.
.github/workflows/msbuild-quality-review.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit-command.lock.ymlApplies shared model pin.
.github/workflows/parallel-safety-audit.lock.ymlApplies shared model pin.
.github/workflows/perf-improver.mdPins detection model.
.github/workflows/perf-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/pr-fix.mdPins detection model.
.github/workflows/pr-fix.lock.ymlRegenerates compiled workflow.
.github/workflows/q.mdPins detection model.
.github/workflows/q.lock.ymlRegenerates compiled workflow.
.github/workflows/README.mdDocuments parse errors and pin safety.
.github/workflows/repository-quality-improver.mdPins detection model.
.github/workflows/repository-quality-improver.lock.ymlRegenerates compiled workflow.
.github/workflows/resource-lock-refactoring.mdPins detection model.
.github/workflows/resource-lock-refactoring.lock.ymlRegenerates compiled workflow.
.github/workflows/shared/address-review-shared.mdPins two consuming workflows.
.github/workflows/shared/msbuild-review-shared.mdPins its consuming workflow.
.github/workflows/shared/parallel-safety-audit-shared.mdPins two consuming workflows.
.github/workflows/shared/test-reviewer-shared.mdPins two consuming workflows.
.github/workflows/sub-issue-closer.mdPins detection model.
.github/workflows/sub-issue-closer.lock.ymlRegenerates compiled workflow.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlApplies shared model pin.
.github/workflows/test-reviewer.agent.lock.ymlApplies shared model pin.
.github/workflows/unskip-closed-tests.mdPins detection model.
.github/workflows/unskip-closed-tests.lock.ymlRegenerates compiled workflow.
.github/workflows/weekly-issue-activity.mdPins detection model.
.github/workflows/weekly-issue-activity.lock.ymlRegenerates compiled workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit 491b236 into mainAug 25, 2026
21 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the nohwnd-pin-threat-detection-model branch August 25, 2026 13:42
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 25, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10729 pinned the
threat-detection model on every agentic workflow, so both sides carry a
different generated metadata hash for the same file.
The .md source merged cleanly and keeps both changes, so the lock file was
regenerated from it with `gh aw compile --action-mode action --action-tag
v0.86.2`. The result has main's threat-detection pin and this branch's lint
job, and the pin audit passes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@nohwnd@Evangelink