tia-devices-general

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data and project content which could serve as a vector for indirect prompt injection.
  • Ingestion points: Data enters the agent's context through CSV file imports via telecontrolManagement.ImportDataPoints and recursive iteration of hardware devices and catalog entries within the Siemens TIA Portal environment.
  • Boundary markers: The skill instructions mandate explicit authorization for project mutations and require resolving exact object identities, providing a procedural boundary against accidental execution of embedded instructions.
  • Capability inventory: The skill utilizes extensive modification capabilities including device creation, deletion, type changes, and attribute modifications, as well as file system exports and project compilation commands.
  • Sanitization: No specific validation or escaping mechanisms for the imported CSV data or project-level string attributes are detailed in the reference files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:06 AM
Security Audit — agent-trust-hub — tia-devices-general