How we found 24 Android vulnerabilities using our open source AI security agent
GitHub Security Lab’s open-source AI agent identified 24 Android vulnerabilities by automating custom auditing taskflows, enabling researchers to guide large language models in detecting complex flaws.
GitHub Security Lab introduced the Taskflow Agent to help security researchers automate and share AI-driven auditing workflows for code analysis. The tool uses custom prompts to guide large language models (LLMs) through incremental steps, improving detection of complex vulnerabilities that automated scans might miss. Researchers can package these prompts into reusable taskflows, making it easier to apply consistent methodologies across different codebases.
The agent’s taskflows were tailored to Android applications, addressing vulnerabilities specific to mobile environments. One taskflow, *gather_mobile_entry_point_info.yaml*, identifies entry points in code where attacker-controlled data could flow, separating mobile-specific entry points from others. Another, *classify_application_local.yaml*, directs the LLM to check for known mobile vulnerability classes, such as intent-based flaws like confused deputy or insecure broadcasts, ensuring critical risks aren’t overlooked.
Using these taskflows, researchers reported 24 vulnerabilities across Android apps, including three in the OsmAnd navigation app. The most severe flaw allowed malicious apps to track user locations by exploiting exported activities and intent extras. Since exported activities can be launched by external apps, attackers could inject arbitrary settings, including tile URLs, to leak precise location data without user awareness.
The vulnerabilities in OsmAnd enabled additional attacks, such as route tracking, deceptive deep links, and cookie theft leading to account takeover. These flaws demonstrate how LLMs can uncover logic-based vulnerabilities with critical impact, though researchers emphasize manual review is essential to filter out low-severity or impractical findings. The taskflows are open-source and require a GitHub Copilot license, with premium model requests consuming significant tokens during execution.