GitHub's open-source AI agent found 24 Android app vulnerabilities
GitHub Security Lab built an open-source 'Taskflow Agent' that uses custom AI prompt workflows to audit code for vulnerabilities, and used it to find and report over 24 vulnerabilities in Android applications. Two detailed examples show the agent finding a location-tracking flaw in the OsmAnd navigation app and an account-takeover chain in the Wikipedia Android app via a deeplink parsing bug. The team notes LLMs are strong at finding complex logic vulnerabilities and understand API behavior well, but struggle to correctly judge severity and often produce false positives, so findings still require human review. The taskflows are open source and can be run on any GitHub repository via a Copilot-powered codespace script, though running them consumes premium model requests and can take hours.