GitHub's AI security agent has started finding vulnerabilities at scale. On September 28, GitHub Security Lab announced on its official blog that researchers using its open-source AI security agent have found and reported 24 vulnerabilities in Android applications — including two high-impact cases already publicly disclosed: one lets any app track a user's precise location, the other enables full account takeover of the Wikipedia app.
The tool is called seclab-taskflow-agent, and its auditing taskflows, seclab-taskflows, are fully open source. The idea is not to throw an entire codebase at a large model and hope for luck, but to use YAML prompts to break auditing into incremental steps, letting researchers package "how to audit" into reusable taskflows. For Android, two dedicated taskflows were added: gather_mobile_entry_point_info finds the code entry points that attacker-controlled data can flow through, separating mobile from non-mobile attack surfaces; classify_application_local then lists, per entry-point type, the common vulnerability classes to check — for example, when it sees an intent-based entry point, it reminds the model to look for mobile-specific issues like confused deputy or insecure broadcasts.
Running it is straightforward: open a Codespace on the seclab-taskflows repository and run ./scripts/audit/run_mobile.sh against a target repo; a medium-sized repository finishes in an hour or two, with results written to a SQLite database — just look for rows checked in the has_vulnerability column. There are two barriers to entry: a GitHub Copilot license is required, and audits consume a large number of premium model requests, so the token bill is not trivial.
Two Already-Disclosed High-Impact Cases
The first is OsmAnd, an open-source navigation app with over 10 million downloads. Its MapActivity is exported, so any app can send it intents; and the settings-import handler directly trusts intent extras like silent_import and replace. That means a malicious app with zero permissions can silently rewrite OsmAnd's settings and swap the map tile URLs for an attacker-controlled domain: every map tile the user loads sends its precise coordinates to the attacker's server — effectively real-time location leakage — and the same flaw exposes the origin and destination of every route the user takes, all without the user noticing anything.
The second is the Wikipedia Android app, where two logic bugs chain into account takeover. The app registers a wikipedia:// deeplink, but its hostname parser only checks the domain suffix, so domains like evil-wikipedia.org pass validation and can lure users to an attacker-controlled page; meanwhile the cookie manager's domain check also compares only suffixes, letting the attacker's page grab Wikipedia's long-lived session cookies — one cookie works across every Wikimedia project, leaking the username and long-term tokens together.
LLMs Can Find Vulnerabilities, but Can't Judge Their Severity
The blog is candid about the method's shortcomings: LLMs are good at finding vulnerabilities — even logic bugs humans easily miss — but poor at estimating severity. They routinely report low-impact issues and misjudge cases with mitigating factors, like path traversals constrained to external storage. Every finding still needs review by a researcher who understands mobile security, and serious cases require the model to actually build a proof of concept to confirm exploitability.
The significance here is not the number 24, but that an auditing methodology has been turned into an open-source, reproducible pipeline for the first time. Security Lab had previously open-sourced an AI fuzzing taskflow for C/C++ (point it at a repo address and it digs out vulnerabilities automatically); this release fills the mobile gap. For ordinary developers the practical value is direct: no need to wait for the security team — run it against your own repository and sweep up a batch of real issues first.