[workshop-sync] side-quest-25-01-audit-reference.md: wrong artifact file names (safeoutputs.jsonl, mcp-logs/) and unverifiable "⌖ AIC" terminolo
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 84/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- javascript
- Domain
- documentation
Research direction
Start with workshop/side-quest-25-01-audit-reference.md and compare its artifact names and AIC terminology against the referenced artifacts, audit, and cost-management documentation. Update the listed filenames, MCP log guidance, and classifier AIC wording to match those references. Done when the workshop file uses the documented names and describes classifier AIC in its Model Routing context.
Written by the indexing model from the issue text.
Description
Workshop file reviewed
workshop/side-quest-25-01-audit-reference.md
Problem
- The agent artifact file table lists:
| safeoutputs.jsonl | Every safe-output declaration the agent emitted |
The live reference/artifacts/ doc names this file agent_output.json, not safeoutputs.jsonl — that filename does not appear anywhere in the artifacts documentation.
- The same table lists:
| mcp-logs/ | One log file per MCP server, listing every tool call and result |
Searching the raw HTML of both reference/artifacts/ and reference/audit/ for "mcp-logs" and "mcp_logs" returns zero matches. The documented structure for MCP/network traffic is the firewall-audit-logs artifact (downloaded via --artifacts mcp, per the Artifact Sets table: "mcp → firewall-audit-logs → MCP gateway traffic logs") or sandbox/firewall/logs/api-proxy-logs/ within the unified agent artifact — not a per-MCP-server mcp-logs/ directory.
- The file repeatedly uses a "⌖ AIC" / "Threat-detection AIC" metric:
**Threat-detection AIC (⌖ AIC)** — credits consumed by the firewall's threat-detection model, reported separately from agent inference
| ⌖ AIC | 3 |(in the sample audit report)
The **⌖ AIC** column in gh aw logs output shows credits consumed by the threat-detection model
Exhaustive searches of reference/audit/, reference/cost-management/, and the full gh aw CLI help snapshot found zero matches for "⌖" or "Threat-detection AIC". The actual documented term is "classifier AIC", part of the Model Routing summary for routed runs — a distinct concept from firewall threat detection.
Current correct behaviour
- Safe-output data file:
agent_output.json(perreference/artifacts/→ "agent" artifact section) - MCP/network traffic logs:
firewall-audit-logsartifact orsandbox/firewall/logs/api-proxy-logs/(per Artifact Sets table) - AIC routing terminology: "classifier AIC" (per
reference/cost-management/andreference/audit/), not "⌖ AIC" / "Threat-detection AIC"
The --parse flag, log.md/firewall.md output filenames, network.allowed frontmatter syntax, and the gh aw audit <run-id> --parse / gh aw logs <workflow-id> --artifacts all command forms in this file are all accurate and need no changes.
Suggested fix
- Replace
safeoutputs.jsonlwithagent_output.jsonin the artifact file table. - Replace the
mcp-logs/row and the "Explore MCP tool calls" exercise with the documentedsandbox/firewall/logs/api-proxy-logs/path orfirewall-audit-logsartifact (--artifacts mcp), and update the.github/aw/logs/<run-id>/mcp-logs/path reference accordingly. - Replace "Threat-detection AIC (⌖ AIC)" and all "⌖ AIC" mentions (including in the sample report table and checkpoint) with the documented "classifier AIC" terminology, correcting the description to match its Model Routing context (routed runs only), or remove the bullet if no direct equivalent exists.
References: https://github.github.com/gh-aw/reference/artifacts/, https://github.github.com/gh-aw/reference/audit/, https://github.github.com/gh-aw/reference/cost-management/ (all confirmed reachable, HTTP 200)
Generated by 🔍 Workshop Sync Check · copilot · auto · 239.5 AIC · ⌖ 8.28 AIC · ⊞ 9.2K · ◷
- expires on Oct 12, 2026, 5:49 AM UTC
- Dominant language
- JavaScript
- Stars
- 52
- Forks
- 26
- Avg merge
- 12h 58m
- Merged PRs (30d)
- 15
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from githubnext/gh-aw-workshop
-
documentation
Difficulty 1/5 Under an hour Newbie friendliness 91/100
githubnext/gh-aw-workshop#4458 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
githubnext/gh-aw-workshop#4456 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 73/100
githubnext/gh-aw-workshop#4455 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
githubnext/gh-aw-workshop#4454 ·
Maintainers usually reply within 1 day
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
githubnext/gh-aw-workshop#4449 ·
Maintainers usually reply within 1 day
All issues in githubnext/gh-aw-workshop
Similar issues
-
enhancement good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
anoopcodehack/DevBoard#609 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
openai/codex-plugin-cc#813 ·
-
area: ops type: test
Difficulty 2/5 1-3 hours Newbie friendliness 79/100
accensa/x402-facilitator-stellar#559 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
bilawalsidhu/gods-eye-view#1060 ·
Maintainers usually reply within 1 day
-
Progress difficulty filter lists Hard before MediumPossibly taken @Pandamachi claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
sysprog21/codetrial#281 · 1 comment ·
Maintainers usually reply within 1 day