We found 24 Android vulnerabilities using our open source AI security agent
4 hours ago
- GitHub Security Lab Taskflow Agent lets security researchers automate, package, and share AI prompts and workflows for finding vulnerabilities, with a focus on Android apps.
- The taskflows are open source and require a GitHub Copilot license; they can be run via a codespace using the run_mobile.sh script, which may take 1-2 hours on medium repos.
- Custom Android-focused taskflows were created, such as gather_mobile_entry_point_info.yaml to separate mobile vs non-mobile entry points, and classify_application_local.yaml to check for mobile-specific vulnerability classes like intent-based issues.
- The taskflows found over 20 vulnerabilities in Android apps, including a critical bug in OsmAnd that lets malicious apps silently overwrite settings and leak location data, and a Wikipedia Android app deeplink vulnerability allowing cookie theft and account takeover.
- LLMs excel at finding logic vulnerabilities and understanding security-relevant APIs, but they often misjudge severity and produce false positives due to complex app behavior, requiring human security researcher review.
- AI-assisted security research is seen as a powerful and essential approach for securing open source projects, and the taskflow agent is open to community contributions.