English

SecurityGitHubseclab-taskflow-agent

GitHub Security Lab Finds 24 Android Vulnerabilities Using Open-Source AI Agent

GitHub Security Lab has reported finding 24 vulnerabilities in Android applications using its open-source "seclab-taskflow-agent." This MCP-enabled multi-agent framework allows security researchers to automate, package, and share effective AI prompts and workflows. By splitting complex research into incremental steps through custom taskflow prompts, the tool helps Large Language Models (LLMs) identify intricate vulnerabilities that might otherwise be missed.

The taskflows were used to discover several high-impact vulnerabilities. In the OsmAnd navigation app, a vulnerability in an exported MapActivity allowed malicious applications to track a user's device location by overwriting settings via intent extras. In the Wikipedia Android app, a logic bug in a hostname parser allowed attackers to direct users to malicious websites through wikipedia:// deeplinks, potentially enabling account takeovers by leaking cookies.

While the framework demonstrated the ability of LLMs to find complex logic bugs, the researchers noted several challenges. LLMs tended to report low-severity issues or generate false positives when they failed to account for complex, device-specific mitigating factors. Consequently, the team emphasized that all findings must be reviewed by human security researchers. Using the taskflows requires a GitHub Copilot license and consumes premium model requests.

Sources

  1. We found 24 Android vulnerabilities using our open source AI security agent (Hacker News Frontpage, 2026-09-29)
  2. GitHub Security Lab