GitHub Security Lab Uses AI Agent to Discover 24 Android Vulnerabilities
GitHub Security Lab's open-source AI agent, Taskflow Agent, has successfully identified 24 vulnerabilities in Android applications, including a critical flaw in the OsmAnd navigation app.

GitHub Security Lab has unveiled a significant advancement in automated vulnerability discovery with its open-source AI agent, the Taskflow Agent. This innovative tool empowers security researchers by enabling them to package and share effective AI prompts and workflows, streamlining the process of identifying security flaws in software. Researchers have leveraged this agent to uncover a substantial number of vulnerabilities, with the latest efforts focusing on Android applications.
The Taskflow Agent operates by guiding large language models (LLMs) through custom-designed taskflows. These taskflows break down complex vulnerability research into manageable steps, allowing the AI to more efficiently detect sophisticated flaws that might otherwise be missed. By providing specific prompts and workflows, researchers can direct the AI's attention to critical areas and known vulnerability classes, significantly enhancing its detection capabilities.
To specifically target Android applications, researchers developed two key taskflows. The first, gather_mobile_entry_point_info.yaml, identifies potential entry points for attacks within the codebase, distinguishing between mobile-specific and general application entry points. This ensures the AI focuses on the relevant attack surface, even in projects containing multiple application types.
The second crucial taskflow, classify_application_local.yaml, instructs the LLM to consider a predefined list of popular vulnerability classes within the context of identified entry points and components. For instance, if an intent-based entry point is detected, the AI is prompted to specifically check for common intent-related vulnerabilities such as confused deputy or insecure broadcasts, thereby maintaining a comprehensive threat model.
This targeted approach has already yielded impressive results, with the GitHub Security Lab reporting over 20 vulnerabilities in various Android applications. A notable example highlighted is a vulnerability discovered in the popular OsmAnd navigation app, which has over 10 million downloads on the Google Play Store.
The OsmAnd vulnerability allowed malicious applications to track a device's location. The flaw resided in the exported MapActivity, which improperly handled intent extras when importing settings. By sending specially crafted intents with specific extras like silent_import and replace, any malicious app could trigger an undetected import of settings, potentially leading to location tracking or other unauthorized actions.
Beyond the OsmAnd example, the Taskflow Agent has been instrumental in discovering a total of 24 Android vulnerabilities to date. The project emphasizes that the taskflows are open-source and accessible via the seclab-taskflows repository, requiring a GitHub Copilot license for execution. Researchers can run these taskflows on their own projects to aid in vulnerability discovery.
The success of the Taskflow Agent underscores the growing impact of AI in cybersecurity. By automating and refining the vulnerability discovery process, tools like this can help developers and security teams proactively identify and address security weaknesses, ultimately leading to more secure software.