GitHub Security Lab's open-source AI security agent identified 24 vulnerabilities in various Android applications, including critical flaws in the OsmAnd navigation app and the Wikipedia app for Android. The OsmAnd vulnerability allows a malicious app to silently import and replace settings, potentially enabling covert location tracking. The Wikipedia app's vulnerability involves inadequate hostname validation for deep links, allowing attackers to load malicious content and potentially take over user accounts. The research highlights the effectiveness of AI in identifying vulnerabilities while emphasizing the need for human validation. The GitHub Security Lab Taskflow Agent automates security research workflows, focusing on mobile entry points and evaluating them against Android-specific vulnerability classes. The findings stress the importance of expert review for AI-generated results.