THE CRUNCH

GitHub Security Lab has released open source taskflows that use an AI agent to audit Android apps and find vulnerabilities, including a tracking bug in OsmAnd. The GitHub Security Lab Taskflow Agent is designed to package and share AI prompts and workflows for security researchers. By guiding the large language model with custom prompts, the tool can split research into incremental steps to help it find complex vulnerabilities that it might otherwise miss. The taskflows are open source and can be run on any project, though they require a GitHub Copilot license and consume a large number of tokens. The tool has already been used to report more than 20 vulnerabilities in Android applications.

One example is a vulnerability in the OsmAnd navigation app, which allows malicious apps to track a user's location. The flaw lies in an exported activity called MapActivity that accepts intent extras from any external caller. By sending specially crafted extras, an attacker can import settings without user confirmation, effectively tracking the device's location. The taskflow identified this by first gathering mobile entry point information and then classifying the application to focus on specific vulnerability classes, such as confused deputy or insecure broadcasts.

The tool works by combining a strict prompt with repeated runs to ensure obvious vulnerabilities are not missed, while a broad prompt lets the AI apply its creativity. This approach is particularly useful for mobile applications, which have their own specific classes of vulnerabilities that are less widely known. The taskflows are available in a GitHub repository and can be run using a simple script, though the process can take an hour or two to finish on a medium-sized repository.