← AI Switchboard
AI Switchboardby Waggle
SAFETY · September 29, 2026
Sep 28

GitHub's open-source audit agent finds 24 Android app vulnerabilities, including in a navigation app with 10 million downloads

GitHub Security Lab built mobile-specific ‘taskflows’ that steer the agent toward bugs generic prompts miss. It is agent-driven auditing used for defence, in a week full of it used for attack.

GitHub Security Lab researcher Kevin Stubbings published a post on 28 September describing mobile-specific audit “taskflows” built on the Lab's open-source Taskflow Agent. The headline counts 24 Android vulnerabilities; the body is more careful: “Using these taskflows, I've reported more than 20 vulnerabilities in Android applications.”

The method is the useful part. The taskflows separate a mobile app's entry points from a web app's and prompt the model to look for intent-based bugs, such as one app tricking another into acting on its behalf. Those are the bugs a generic ‘find vulnerabilities’ prompt tends to miss.

The worked example is OsmAnd, which the post describes as a popular third-party navigation app that, on Android, “has over 10 million downloads”. According to the post, an exported activity accepted data from other apps that should have stayed internal. GitHub says the bugs found have been disclosed through its advisories.

Two things are missing. The post does not name the model doing the work and does not give a false-positive rate, so there is no way to tell how much human triage sat behind the 24. Running the taskflows also requires a GitHub Copilot licence. Set beside yesterday's report of a two-agent auditor beating Codex on agent frameworks, the direction is clear: security review is becoming a job agents do, and the scoping of their instructions matters as much as the model.

  • Claimed “Using these taskflows, I've reported more than 20 vulnerabilities in Android applications.” The headline gives 24. The GitHub Blog
  • Confirmed OsmAnd's Android version “has over 10 million downloads”, per the post's worked example. The GitHub Blog
  • Confirmed The post names no model and gives no false-positive rate; the taskflows require a GitHub Copilot licence. The GitHub Blog

Safety, security & governanceAgents in the wild

Today in the September 29, 2026 edition · front page