uv-miles-rl-training

Warn

Audited by Snyk on Feb 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill's installation instructions explicitly run "git clone https://github.com/radixark/miles.git" followed by pip installs, which fetches and installs remote code (https://github.com/radixark/miles) that will be executed as part of running the skill, meeting the fetch+execute and required-dependency criteria.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 27, 2026, 12:41 PM