agentusecasesAll 965 use cases
Security, Science & Hardware

Find security flaws in open-source software

Google's Big Sleep agent reported about 20 security flaws in open-source software, following its SQLite find.

Done withGemini

What they did
Big Sleep, built by Google DeepMind and Project Zero, was pointed at widely used open-source projects. It found and reported 20 previously unknown vulnerabilities, mostly in FFmpeg and ImageMagick. The article gives no detail on the agent's workflow or on how much human review was involved. It does describe the earlier SQLite case, where the agent traced the root cause of a flaw that Google's threat intelligence team had only seen signs of being exploited.
How it went
20 flaws were reported, and their details are withheld under standard disclosure procedures. The article says nothing on severity or fix status for these 20. The earlier SQLite bug (CVE-2025-6965) was rated 7.2 on CVSS.
Worth knowing
The specifics of the 20 flaws are not public yet, so you can't check them. The article also doesn't say how many reports were valid or how much human triage was needed.

Try it yourself with Gemini

Clone [open-source repository URL] and review its [language] code for likely security flaws such as memory safety bugs, injection, unsafe input parsing, and hardcoded secrets. Write up each finding in a file with the file path, a short explanation, and how severe you think it is. Do not change any code or open any issues or pull requests. Stop once you have a ranked list of your top [number] findings.

Read the original ↗

Source: computing.co.uk · Undated

Five of these in your inbox every morning

The best things people got an AI agent to do, each with the prompt to try it.

More like this