AI Briefing
Sign in

GitHub Security Lab Taskflow Agent Discovers 24 Android Vulnerabilities

·2026.09.29 04:00

Key point

The open-source GitHub Security Lab Taskflow Agent, which requires a GitHub Copilot license, uses custom taskflows to guide LLMs through incremental security auditing steps.

Details

The GitHub Security Lab Taskflow Agent is an open-source tool designed to help security researchers automate and share AI prompts for vulnerability discovery. By guiding Large Language Models (LLMs) through incremental steps, the agent successfully identified 24 Android vulnerabilities in various applications, including critical issues in OsmAnd and the Wikipedia Android app.

How the Taskflows Work

The agent uses custom YAML taskflows to split security research into manageable steps, helping LLMs find complex vulnerabilities they might otherwise miss. Key components include:

  • gather_mobile_entry_point_info.yaml: Separates code entry points into mobile and non-mobile categories to define the correct attack surface.
  • classify_application_local.yaml: Directs the LLM to check for specific vulnerability classes, such as confused deputy or insecure broadcasts, in the context of identified entry points.

Running the tool requires a GitHub Copilot license and can consume a large number of tokens due to multiple tool calls. The process typically takes one to two hours for a medium-sized repository.

Critical Vulnerabilities Discovered

The agent uncovered high-impact logic bugs that allow attackers to exploit exported Android activities.

  • OsmAnd Location Tracking: In the navigation app OsmAnd (over 10 million downloads), the agent found that the exported MapActivity accepted attacker-controlled intent extras. This allowed malicious apps to silently import settings, overwrite map tile URLs, and leak the user's exact coordinates and route data to an attacker's server without any user notification.
  • Wikipedia Account Takeover: A logic bug in the Wikipedia Android app's hostname parser allowed wikipedia:// deeplinks to load non-Wikipedia URLs ending in wikipedia.org. By chaining this with a cookie leakage issue, attackers could steal long-lived session tokens valid across all Wikimedia projects, leading to full account takeover.

Limitations and Best Practices

While LLMs demonstrate strong knowledge of API behavior and can generate functional proof-of-concept code, they struggle with severity estimation. The agent often reported low-severity bugs or failed to account for mitigating factors, such as internal storage priority over external storage. Consequently, every finding requires review by a security researcher to validate impact and eliminate false positives.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.