{"name":"seclab-taskflow-agent: Define AI Workflows in YAML","description":"A Python framework and CLI for building multi-agent workflows from YAML, with MCP tools and configurable model backends. It is aimed at security research, code auditing, and other repeatable agent tasks.","github":"https://github.com/GitHubSecurityLab/seclab-taskflow-agent","url":"https://osrepos.com/repo/githubsecuritylab-seclab-taskflow-agent","source":"osrepos.com","sourceDescription":"This repository profile is provided by osrepos.com, an open source repository discovery platform.","repositoryProfile":"https://osrepos.com/repo/githubsecuritylab-seclab-taskflow-agent","generatedFor":"open source discovery and AI-assisted research","markdown":"https://osrepos.com/repo/githubsecuritylab-seclab-taskflow-agent.md","json":"https://osrepos.com/repo/githubsecuritylab-seclab-taskflow-agent.json","topics":["python","ai-agents","mcp","security","yaml-taskflows","security-research","agent-orchestration"],"keywords":["python","ai-agents","mcp","security","yaml-taskflows","security-research","agent-orchestration"],"stars":null,"summary":"A Python framework and CLI for building multi-agent workflows from YAML, with MCP tools and configurable model backends. It is aimed at security research, code auditing, and other repeatable agent tasks.","content":"## Overview\n\nGitHub Security Lab Taskflow Agent runs sequences of AI-agent tasks defined in YAML rather than custom orchestration code. Tasks can combine agent personalities, prompts, tools, and models, with templates and shared outputs connecting steps.\n\nIt is designed especially for security research workflows, such as code auditing and vulnerability triage. Use it when you want to describe and validate repeatable agent processes as configuration, or compare model responses within a taskflow.\n\n## Key Features\n\n- YAML grammar for taskflows, agent personalities, prompts, toolboxes, and model configurations.\n- MCP tool integration using stdio, SSE, and streamable HTTP transports.\n- Multiple SDK backends: OpenAI Agents, GitHub Copilot, and Anthropic.\n- Task-level retries, checkpoints, and resume support after failures.\n- Offline linting for taskflows and referenced documents, plus JSON Schema output.\n- Multi-model task execution with named outputs for downstream comparison or review.\n- CLI and Docker deployment options.\n\n## Use Cases\n\n- Security researchers can define repeatable code-audit workflows that give agents access to tools such as the included CodeQL MCP server.\n- Security teams can automate structured triage of code-scanning alerts using task sequences and specialist agent prompts.\n- Model evaluators can send the same task to multiple models and use a follow-up task to compare their answers.\n- Developers exploring agent orchestration can prototype workflows in YAML before building custom orchestration code.\n\n## Project Facts\n\n- Language: Python\n- License: MIT\n- Stars: 262\n- Forks: 34\n- Topics: none listed\n- Archived: no\n\n## Getting Started\n\nRequires Python 3.10 or newer, or Docker. To build from source and run an example taskflow:\n\n```bash\ngit clone https://github.com/GitHubSecurityLab/seclab-taskflow-agent.git\ncd seclab-taskflow-agent\npython -m venv .venv\nsource .venv/bin/activate\npip install hatch\nhatch build\nhatch run main -t examples.taskflows.example\n```\n\nSet `AI_API_TOKEN` for an account entitled to use GitHub Copilot before running model-backed tasks. See the [README](https://github.com/GitHubSecurityLab/seclab-taskflow-agent) for configuration, examples, and Docker instructions.\n\n## Alternatives\n\n- [mcp-agent](https://osrepos.com/repo/lastmile-ai-mcp-agent): A general-purpose Python framework for MCP-based agents and composable workflows, rather than YAML-defined, security-focused task flows.\n- [autogen](https://osrepos.com/repo/microsoft-autogen): A general multi-agent framework with broad model and tool integrations, rather than a CLI centered on repeatable YAML security tasks.\n- [deepagents](https://osrepos.com/repo/hwchase17-deepagents): A Python harness focused on planning, delegation, and context management, rather than configuring multi-agent workflows in YAML.\n\n## Considerations\n\nThe project describes itself as experimental and is maintained for ongoing Security Lab work. Running agent tasks requires access to a compatible model endpoint and credentials, and MCP toolboxes may require additional services or environment configuration. Docker is documented as a deployment convenience, not a security boundary. Backend capabilities differ, so taskflows may need adjustment when switching SDKs.","metrics":{"detailViews":1,"githubClicks":1},"dates":{"published":null,"modified":"2026-10-06T15:04:21.000Z"}}