tia-hmi-operations

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents API methods for importing HMI data from external XML files, which represents an attack surface where an agent could be induced to process untrusted data.
  • Ingestion points: XML import methods documented in references/hmi-composition-hierarchy.md, references/hmi-target.md, references/tags.md, references/unified-connections.md, references/unified-overview.md, references/unified-system-services.md, and references/unified-tags-alarms.md.
  • Boundary markers: Absent. The documentation does not provide instructions for the agent to use delimiters or ignore instructions within the data being imported.
  • Capability inventory: The documented API includes methods for object deletion (Delete), data export (Export), attribute modification (SetAttribute), and object creation (Create) across all HMI subsystems.
  • Sanitization: Absent. The reference materials do not include validation or sanitization patterns for the content of imported XML files before they are applied to the HMI project.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:06 AM
Security Audit — agent-trust-hub — tia-hmi-operations