plc-code-analysis

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze external PLC code and configuration files, creating a surface for indirect prompt injection where malicious instructions embedded in the analyzed data could attempt to override the agent's behavior.
  • Ingestion points: As described in SKILL.md, the skill processes user-supplied SCL/Structured Text, SimaticML XML files, and data retrieved via MCP tools including get_block_content and read_hardware_config.
  • Boundary markers: Absent. The instructions lack explicit delimiters or instructions for the agent to ignore natural language commands embedded within the code comments or metadata of the files being audited.
  • Capability inventory: The skill uses a suite of MCP tools (browse_project_tree, get_block_content, list_tag_tables, read_cross_references, read_hardware_config, compile_check) to retrieve and validate PLC environment data.
  • Sanitization: Absent. There is no mention of sanitizing or escaping the content of the PLC code before it is processed through the five analysis passes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 12:25 PM
Security Audit — agent-trust-hub — plc-code-analysis