seclab-taskflow-agent: Define AI Workflows in YAML

Summary
A Python framework and CLI for building multi-agent workflows from YAML, with MCP tools and configurable model backends. It is aimed at security research, code auditing, and other repeatable agent tasks.
At a glance
- Language
- Python
- License
- MIT
- Stars
- 262
- Forks
- 34
- Added to OSRepos
- October 6, 2026
- Last analyzed
- October 6, 2026
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
GitHub Security Lab Taskflow Agent runs sequences of AI-agent tasks defined in YAML rather than custom orchestration code. Tasks can combine agent personalities, prompts, tools, and models, with templates and shared outputs connecting steps.
It is designed especially for security research workflows, such as code auditing and vulnerability triage. Use it when you want to describe and validate repeatable agent processes as configuration, or compare model responses within a taskflow.
Key Features
- YAML grammar for taskflows, agent personalities, prompts, toolboxes, and model configurations.
- MCP tool integration using stdio, SSE, and streamable HTTP transports.
- Multiple SDK backends: OpenAI Agents, GitHub Copilot, and Anthropic.
- Task-level retries, checkpoints, and resume support after failures.
- Offline linting for taskflows and referenced documents, plus JSON Schema output.
- Multi-model task execution with named outputs for downstream comparison or review.
- CLI and Docker deployment options.
Use Cases
- Security researchers can define repeatable code-audit workflows that give agents access to tools such as the included CodeQL MCP server.
- Security teams can automate structured triage of code-scanning alerts using task sequences and specialist agent prompts.
- Model evaluators can send the same task to multiple models and use a follow-up task to compare their answers.
- Developers exploring agent orchestration can prototype workflows in YAML before building custom orchestration code.
Getting Started
Requires Python 3.10 or newer, or Docker. To build from source and run an example taskflow:
git clone https://github.com/GitHubSecurityLab/seclab-taskflow-agent.git
cd seclab-taskflow-agent
python -m venv .venv
source .venv/bin/activate
pip install hatch
hatch build
hatch run main -t examples.taskflows.example
Set AI_API_TOKEN for an account entitled to use GitHub Copilot before running model-backed tasks. See the README for configuration, examples, and Docker instructions.
Alternatives
- mcp-agent: A general-purpose Python framework for MCP-based agents and composable workflows, rather than YAML-defined, security-focused task flows.
- autogen: A general multi-agent framework with broad model and tool integrations, rather than a CLI centered on repeatable YAML security tasks.
- deepagents: A Python harness focused on planning, delegation, and context management, rather than configuring multi-agent workflows in YAML.
Considerations
The project describes itself as experimental and is maintained for ongoing Security Lab work. Running agent tasks requires access to a compatible model endpoint and credentials, and MCP toolboxes may require additional services or environment configuration. Docker is documented as a deployment convenience, not a security boundary. Backend capabilities differ, so taskflows may need adjustment when switching SDKs.
Found this useful?
Share it with someone who would like seclab-taskflow-agent.
Source repository
Open the original repository on GitHub.
Related repositories
Similar repositories that may be relevant next.

lilbee: Run Local AI and Search Your Files
October 6, 2026
lilbee is a local AI model manager and search engine for files, code, and crawled websites. It offers cited answers through a terminal app, CLI, MCP server, REST API, and Python library.

AgentSec: Audit AI Agent Workflows for Security Risks
October 6, 2026
AgentSec statically analyzes AI agent workflows for excessive permissions and paths from untrusted input to dangerous capabilities. It is aimed at developers and security teams reviewing supported agent frameworks before deployment or as part of CI.

omnigent: Orchestrate AI Coding Agents Across Harnesses
October 5, 2026
Omnigent provides a shared orchestration layer for AI coding agents, with policies, sandboxing, and team collaboration. It suits developers who want to combine agent runtimes and access sessions across devices without tying workflows to one harness.

agentevals: Evaluate AI Agents from OpenTelemetry Traces
October 4, 2026
agentevals scores AI agent behavior from existing OpenTelemetry traces, without rerunning agents or making extra model calls. It suits teams building instrumented agents that need local evaluation, golden-set checks, or CI quality gates.