Description
The Daily Secrets Analysis workflow's job-/step-level secret-reference split could not be computed today (#66242): "not computed (the grep heuristic from the prompt is unreliable on 323 files)". The workflow's own recommendation is to replace the grep-based heuristic with a proper YAML-parsing check, since a line-based grep can't reliably tell whether a secrets.* reference sits at job level vs step level in GitHub Actions YAML.
Expected Impact
Restores a metric the daily report currently can't produce (job-/step-level secret reference split across 323 compiled workflow lock files), making the daily secrets report more complete without changing its security posture (which is already green: 323/323 redaction, 323/323 permission blocks).
Suggested Fix
Replace the grep heuristic in the Daily Secrets Analysis workflow prompt/scripts with a YAML-aware parse (e.g. walk jobs.*.steps[] vs jobs.*.env/jobs.* top-level keys) to classify each secrets.* reference by scope.
Acceptance Criteria
Suggested Agent
Agent familiar with the Daily Secrets Analysis workflow (.github/workflows/daily-secrets-analysis.md or equivalent) and YAML parsing in the project's existing toolchain.
Estimated Effort
Quick (< 1 hour).
Data Source
Daily Secrets Analysis Report — 2026-10-06 (#66242), Recommendation #2.
Generated by 🔬 Deep Report · claude · agent · 421.8 AIC · ⌖ 9.14 AIC · ⊞ 7.1K · ◷
Description
The Daily Secrets Analysis workflow's job-/step-level secret-reference split could not be computed today (#66242): "not computed (the grep heuristic from the prompt is unreliable on 323 files)". The workflow's own recommendation is to replace the grep-based heuristic with a proper YAML-parsing check, since a line-based grep can't reliably tell whether a
secrets.*reference sits at job level vs step level in GitHub Actions YAML.Expected Impact
Restores a metric the daily report currently can't produce (job-/step-level secret reference split across 323 compiled workflow lock files), making the daily secrets report more complete without changing its security posture (which is already green: 323/323 redaction, 323/323 permission blocks).
Suggested Fix
Replace the grep heuristic in the Daily Secrets Analysis workflow prompt/scripts with a YAML-aware parse (e.g. walk
jobs.*.steps[]vsjobs.*.env/jobs.*top-level keys) to classify eachsecrets.*reference by scope.Acceptance Criteria
Suggested Agent
Agent familiar with the Daily Secrets Analysis workflow (
.github/workflows/daily-secrets-analysis.mdor equivalent) and YAML parsing in the project's existing toolchain.Estimated Effort
Quick (< 1 hour).
Data Source
Daily Secrets Analysis Report — 2026-10-06 (#66242), Recommendation #2.