Using the GitHub Security Lab Taskflow Agent, a GitHub security researcher has reported 24 vulnerabilities in Android applications, including a flaw in the OsmAnd navigation app that lets malicious apps track device location via exported MapActivity intent extras. The open-source taskflows guide LLMs through incremental auditing steps and require a GitHub Copilot license, consuming premium model requests. Combined strict and broad prompts across multiple runs help the AI find both obvious and complex vulnerabilities.
No score is assigned. Sources and their independence are shown in the citation chain below.