GitHub Security Lab's AI agent

GitHub Security Lab built the Taskflow Agent, an open source tool that lets security researchers automate, package, and share AI prompts and workflows. The team customized it to find vulnerabilities in Android applications.

How it works

Researchers wrote taskflows targeting mobile-specific vulnerability classes. For example, gather_mobile_entry_point_info.yaml separates entry points where attacker-controlled data could flow into mobile and non-mobile categories. classify_application_local.yaml checks common vulnerability types for each entry point. This helps the model find complex flaws faster.

Results

The team has reported 24 vulnerabilities so far. One is a user tracking flaw in the OsmAnd navigation app, which has over 10 million downloads. The vulnerabilities were disclosed through the responsible disclosure process.

Try it yourself

The taskflows are open source and easy to run. A GitHub Copilot license is required, and premium model requests are used. Start a codespace in the seclab-taskflows repository and run ./scripts/audit/run_mobile.sh myorg/myrepo in the terminal. Auditing a medium-sized repository can take one to two hours; results appear in the audit_results table in an SQLite viewer.