addin-operations

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the dotnet new command to scaffold project structures and templates, which is appropriately scoped in the allowed-tools configuration. It also identifies the need for administrator privileges during environment setup, a standard requirement for TIA Portal integration.
  • [REMOTE_CODE_EXECUTION]: Documentation within references/api-permissions.md provides guidance on using the Siemens.Engineering.AddIn.Utilities.Process class for launching external processes. This includes necessary information on declarative ProcessStartPermission required by the Add-In sandbox.
  • [EXTERNAL_DOWNLOADS]: The migration guide references the installation of ilspycmd via the dotnet CLI, which is a well-known utility for assembly decompilation and recovery in development workflows.
  • [SAFE]: The skill provides code skeletons and helper patterns that encourage security and stability best practices, such as guarding assembly location resolution and using callback-scoped providers for user notifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:06 AM
Security Audit — agent-trust-hub — addin-operations