GitHub Security Lab released the open source AI agent Taskflow Agent for security auditing of Android applications
GitHub Security Lab has released Taskflow Agent, an open source AI agent that uses custom LLM prompts to automate the search for security bugs in Android applications. According to the company, the tool has thus found more than 24 vulnerabilities, for example in the navigation app OsmAnd.
GitHub Security Lab has published the open source tool Taskflow Agent, an AI agent designed for automated code security auditing. For Android applications, the team created specialized sets of prompts (taskflows) that guide a large language model step by step to search for specific vulnerability classes, instead of a general code search.
According to the company, the tool proceeds in two steps: first it identifies entry points in the code and divides them into mobile and non-mobile, then for each entry point it goes through a list of typical vulnerability classes – for example, confused deputy or insecure broadcasts in the case of intents. The combination of a stricter and a looser prompt is meant, according to the authors, to ensure that the model doesn't miss obvious bugs while still being able to creatively search for more complex problems across components.
Using these taskflow prompts, the team reported more than 24 vulnerabilities in Android applications. As an example, the authors cite the navigation app OsmAnd, with more than 10 million downloads, where the tool uncovered a bug in the exported MapActivity activity – it allowed a malicious app to import settings and track the device's location without the user's permission.
The tool is open source, but running it requires a GitHub Copilot license, because the prompts use premium model requests. According to the company, auditing a medium-sized repository takes one to two hours, and the results are displayed in an SQLite browser in the audit_results table. The source article further describes technical details of the vulnerability found in OsmAnd, but these details are not complete in the available text.
Why it matters
For security researchers and developers, this is a tool that automates part of the manual security analysis of Android code and, according to the company, can uncover bugs that a human auditor might overlook or wouldn't have time to look for. For companies developing Android applications, this means the possibility of carrying out faster security audits of their own code, but at the same time the risk that similar automated tools could be used by attackers to search for bugs in their applications in the same way.
Two audiences, two different impacts
What this means
For individuals
A security researcher or Android app developer can use the tool for an automated initial scan of their own code for typical vulnerability classes instead of purely manual analysis.
For a business
Companies developing Android applications can add the tool to their code security audit process and thereby reduce the costs of manual penetration testing, but deployment requires a GitHub Copilot license and consumes premium requests to the model.
Risks and complianceCheck the original
Event sources
only one source so far · 1 vydavatel, 0 independent. We count feeds from the same owner only once.