miles-rl-training
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The installation instructions in
SKILL.mddirect users to clone a repository (https://github.com/radixark/miles.git) and executepip install -e .. This procedure involves downloading and running thesetup.pyorpyproject.tomlconfiguration files from an unverified third-party source. - [EXTERNAL_DOWNLOADS]: The skill instructs the user to pull and run a Docker image (
radixark/miles:latest) and references several GitHub repositories belonging to users or organizations not recognized as trusted vendors or well-known services (e.g.,radixark/miles,THUDM/slime,sgl-project/sglang, andzhaochenyang20/Awesome-ML-SYS-Tutorial). These represent unverified external dependencies. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of untrusted external content.
- Ingestion points: The skill processes model checkpoints via the
--hf-checkpointflag and training data via the--prompt-dataflag (documented inSKILL.md). - Boundary markers: No delimiters, XML tags, or instructions to ignore embedded commands are present in the training workflows to protect the agent from malicious content within these files.
- Capability inventory: The training framework executes complex shell commands (e.g.,
python train.py) and performs extensive file system and hardware (GPU) operations. - Sanitization: There is no evidence of validation or sanitization of the training data or checkpoint metadata before they are processed by the training logic.
Audit Metadata