GitHub Security Lab says its open-source Taskflow Agent helped find and report 24 vulnerabilities in Android applications. Rather than use one broad auditing prompt, researchers split the work into steps that identify mobile entry points and check Android-specific vulnerability classes.

Disclosed examples include an OsmAnd flaw that could let another app alter settings and expose route locations, and a chain of Wikipedia Android issues that could load an attacker-controlled page and leak long-lived account cookies. The cases show that language models can uncover consequential logic errors, not only familiar code patterns.

The tool still needs expert supervision. Models frequently overestimated severity, missed mitigating behavior and produced false positives unless asked to build and test a proof of concept. Developers can run the taskflows in a Codespace with a GitHub Copilot license, but scans can consume many premium requests and take one or two hours on a medium-sized repository.