GitHub Taskflow Agent Reports 24 Android Vulnerabilities via Custom Mobile Audit Prompts
GitHub's Taskflow Agent used structured mobile prompts to surface 24 Android vulnerabilities that standard LLM scans overlooked. The work demonstrates measurable gains from decomposing audits into entry-point isolation followed by class-specific classification. Continued application will test whether the same scaffolding scales to higher volumes of open-source and enterprise mobile codebases.
The agent executed two new taskflows, gather_mobile_entry_point_info.yaml and classify_application_local.yaml, against repositories containing mixed application types. These prompts isolated intent-based entry points and forced explicit checks for confused deputy, insecure broadcast, and related classes before allowing broader inference. Runs on OsmAnd, an app with over 10 million downloads, produced three confirmed issues including a tracking vector that survived prior manual audits.
Data from the audit_results SQLite table showed consistent detection only when strict classification preceded creative scanning; single-pass prompts missed 40 percent of the final disclosures. The approach mirrors patterns in prior LLM code-review studies where incremental decomposition improved recall on component-interaction flaws. Non-determinism remains visible: repeated runs on the same repo surfaced different high-severity candidates until the vulnerability list was fixed in the prompt.
Operationally, organizations can replicate the workflow inside GitHub Codespaces with a Copilot license, though token consumption scales with repository size and may exceed several hundred thousand requests per medium app. The method extends beyond the original taskflows by embedding Android threat-model constraints rather than relying on generic code understanding.
Next steps include scheduled re-audits of Play Store top-1000 apps and integration of the same taskflows into internal CI pipelines for continuous mobile surface monitoring.
GitHub: Taskflow Agent will surface at least 15 additional confirmed Android CVEs from public repos by end of Q2 2025
Sources (3)
- [1]Primary Source(https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/)
- [2]Supporting Source(https://arxiv.org/abs/2402.09186)
- [3]Supporting Source(https://source.android.com/docs/security/bulletins)