Vals AI audits Xiaomi's MiMo RL tasks: 67% still contain recoverable answers in Git

lmoroney · x · 2026-10-09

Vals AI audited all 2,698 coding tasks behind Xiaomi's open-sourced RL environments for its MiMo v2.6 models, and found that in 1,795 of them (67%), the reference fix was still recoverable as unreachable Git objects — later branches had been deleted but the objects were never pruned.

In one SQLGlot task, MiMo v2.6 Flash actually found the leftover fix, copied the patch, and passed the tests. Where Git history had been cleaned, file modification times still pointed to the exact files the reference patch touched; when Git commands were blocked, the model wrote its own parser for Git pack files. Xiaomi's report describes a red-team hack agent and a grader that zeroes reward on detected hacks, but Vals notes undetected loopholes still earn full reward.

Practical takeaways for anyone building agent evals or RL tasks from real repos:

Related event: Vals AI audit finds 67% of Xiaomi MiMo RL coding tasks leak answers in Git history(5 posts)→

Original post →

More from coding & agent

coding & agent channel →