miles-rl-training

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The installation instructions in SKILL.md direct users to clone a repository (https://github.com/radixark/miles.git) and execute pip install -e .. This procedure involves downloading and running the setup.py or pyproject.toml configuration files from an unverified third-party source.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to pull and run a Docker image (radixark/miles:latest) and references several GitHub repositories belonging to users or organizations not recognized as trusted vendors or well-known services (e.g., radixark/miles, THUDM/slime, sgl-project/sglang, and zhaochenyang20/Awesome-ML-SYS-Tutorial). These represent unverified external dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of untrusted external content.
  • Ingestion points: The skill processes model checkpoints via the --hf-checkpoint flag and training data via the --prompt-data flag (documented in SKILL.md).
  • Boundary markers: No delimiters, XML tags, or instructions to ignore embedded commands are present in the training workflows to protect the agent from malicious content within these files.
  • Capability inventory: The training framework executes complex shell commands (e.g., python train.py) and performs extensive file system and hardware (GPU) operations.
  • Sanitization: There is no evidence of validation or sanitization of the training data or checkpoint metadata before they are processed by the training logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — miles-rl-training