tia-hmi-operations
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents API methods for importing HMI data from external XML files, which represents an attack surface where an agent could be induced to process untrusted data.
- Ingestion points: XML import methods documented in
references/hmi-composition-hierarchy.md,references/hmi-target.md,references/tags.md,references/unified-connections.md,references/unified-overview.md,references/unified-system-services.md, andreferences/unified-tags-alarms.md. - Boundary markers: Absent. The documentation does not provide instructions for the agent to use delimiters or ignore instructions within the data being imported.
- Capability inventory: The documented API includes methods for object deletion (
Delete), data export (Export), attribute modification (SetAttribute), and object creation (Create) across all HMI subsystems. - Sanitization: Absent. The reference materials do not include validation or sanitization patterns for the content of imported XML files before they are applied to the HMI project.
Audit Metadata