proomt

Search

Search posts, papers, and topics

All posts

GitHub OldAntonio Morales9 min readintermediate

AI-powered fuzzing with the GitHub Security Lab Taskflow Agent

Summary

GitHub Security Lab developed the Fuzzing Taskflow, an autonomous LLM-driven pipeline for C/C++ projects that automates continuous fuzzing from identifying entrypoints and writing harnesses to triaging crashes and generating vulnerability reports. It aims to reduce the human effort traditionally required for effective fuzzing campaigns.

  • The Fuzzing Taskflow automates the entire C/C++ fuzzing workflow using an LLM agent, from setup to reporting.
  • It employs a coverage-feedback loop with doubling time budgets and plateau detection to optimize fuzzing efficiency.
  • Four structure-aware fuzzing mechanisms are used, including dynamic dictionary generation and corpus splicing.
  • A stable, evolving corpus directory persists across iterations and campaigns, preventing loss of fuzzing progress.

Security engineers and C/C++ developers can leverage this autonomous agent to significantly scale their fuzzing efforts and reduce the manual overhead of bug discovery and triage.

7/10

Related reading

  1. Changing the game: How Google uses agentic AI to secure hundreds of millions of lines of code

    Google’s AI & Infrastructure team built an agentic pipeline (Mantis) that runs pre‑submit AI‑driven scans on every code check‑in, validates findings with a fast triage agent (AST + call‑graph analysis) achieving >92% precision in <1 min, then auto‑generates fixes via a bug‑fix agent. Localized threat models and a two‑step scan cut false‑positives to ~3% and prevent hundreds of vulnerabilities eac…

    Google Cloud Bloggoogle.com4 min
  2. Blog: How to Build a DevOps Agent

    This blog walks through the open‑source DevOps Agent Kit, which lets Claude Code or Cursor act as a DevOps assistant by connecting to CloudBees Unify, Jira, and Slack via MCP servers and to GitHub via the CLI. It provides a repeatable setup (Docker, Node, env file) and seven slash commands for pipeline overview, triage, security, release readiness, flag management, CI health scoring, and Jira tic…

    Codeshipcloudbees.com10 min
  3. Optimizing GitHub Actions for Agent PRs: Speculative Test Slicing and AST Impact Analysis

    A step‑by‑step guide for handling the flood of pull requests generated by code‑generation agents. It builds a TypeScript CLI that uses ts‑morph to do AST‑level change‑impact analysis, maps affected symbols to tests, and runs only those tests in a “speculative” GitHub Actions job while a full‑suite verification runs in the background. The article includes concrete CLI code, dependency choices, con…

    SitePointsitepoint.com17 min