Skip to main content
{ Vulnerability Management / Reporting and Compliance / Ghost Agent Factory }

GitHub Dependabot Triage Agent Report

Provides a weekly compliance report on the agent runs inside the Ghost Agent Factory for Dependabot triage and recheck agents, with alerts dismissed, alerts reopened, and analyst time saved.

What this agent does

This read-only agent reports each week on the runs of the Ghost Agent Factory agents that triage and recheck Dependabot alerts on a GitHub repository. It reads every run from the last 7 days, with its status, cost, metrics, and evidence files. It totals the alerts dismissed and reopened and estimates the analyst time saved.

The challenge

An automated triage agent dismisses alerts without a person reviewing each one. Security leaders and auditors need a record of what it dismissed, what it reopened, and whether it ran at all. Run logs answer those questions one run at a time. Nobody reads them all, so nobody sees the trend or the missed runs.

The solution

The agent computes every figure from the run records, so every number can be traced to a specific run. It fails the report when a read fails, instead of publishing zeros. It adds one short executive summary that states the value delivered and the open-risk trend, with no advice. Provides a weekly record of what the triage automation did and what it cost.

Workflow

  1. 01

    Read runs

    Read every triage and recheck run from the last 7 days, with its status, trigger, duration, cost, metrics, and evidence files.

  2. 02

    Total the results

    Sum the alerts dismissed and reopened, and read the reachable open alert count as a series across the week.

  3. 03

    Summarize

    Write a short executive summary that leads with the value delivered and states the open-risk trend.

  4. 04

    Publish

    Publish one report with the summary, the totals, a row per run, and each evidence file by hash.

Agent template

# GitHub Dependabot Triage Agent Report

## Measurable outcomes

Every triage and recheck run on a repository appears in one weekly report. Every figure in the report traces to a run record. Track the number of runs each report covers.

## Procedure

For a given repository, read the triage and recheck agents' runs from the last 7 days. Include each run's status, trigger, duration, token use, metrics, and evidence files. Sum the alerts dismissed, the alerts reopened, and the dismissals rechecked. Treat the reachable open alert count as a gauge: report the latest value and the full series across the week. Estimate analyst time saved at 5 minutes per dismissed alert, unless I set another rate. List each run with its metrics, and each evidence file by its hash without its contents. Flag each completed run that recorded no metrics. Fail the report when any read fails, because a report of zeros from a refused read is worse than no report. Compute every figure from the run records. The only written prose is a 2 to 3 sentence executive summary. It leads with the value delivered and reads the whole reachable open series, not only its ends. A rising reachable open count means real alerts surfaced, not a regression. The summary states facts and gives no advice.

## Requirements

It reads the triage and recheck agents' runs, metrics, and outputs through the Ghost Agent Factory MCP with a read-only API key, and needs nothing more. It never reads or changes the repository or its Dependabot alerts. Schedule it after the week's triage and recheck runs.