What happened
On Sept 24, 2026 GitHub published the Fuzzing Taskflow built on its Security Lab Taskflow Agent framework: an autonomous agent that takes a repo, identifies entrypoints, writes AFL++ harnesses, iterates coverage with doubling time budgets, triages crashes, and writes a vulnerability report per unique bug — with a deliberate design separating LLM decisions from MCP-tool execution.
Why it matters
A concrete open-source example of an AI agent doing the human-in-the-loop work of continuous fuzzing (harness writing, coverage chasing, crash triage), which normally doesn't scale — likely to feed OSS-Fuzz-style workflows; also illustrates safe-agent architecture (MCP tools own execution).
Applicability
Appsec engineers and OSS maintainers wanting automated vulnerability discovery on C/C++ repos can run it now in a disposable Codespace/VM; also a useful reference for agentic-security design patterns.