tia-plc-operations

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from multiple external file formats, creating a potential vector for indirect prompt injection.
  • Ingestion points: The skill utilizes methods such as Import(), ImportFromXlsx(), CreateFromFile(), LoadCamData(), and LoadSource() across several files including references/blocks.md, references/tags-types.md, references/external-sources.md, and references/software-units.md.
  • Boundary markers: No explicit instructions or delimiters are provided to help the agent distinguish between its system instructions and the content within processed files.
  • Capability inventory: The skill allows for significant system impact through actions like Compile(), Delete(), UpdateProgram(), and GoOnline() as described in references/blocks.md and references/online-status.md.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of content from external files before processing.
  • [COMMAND_EXECUTION]: The skill allows for the execution of administrative and engineering commands that can modify PLC logic and hardware state.
  • Evidence: Reference files like references/blocks.md and references/compare.md provide instructions for methods like plcBlock.Compile(), plcSoftware.UpdateProgram(), and onlineProvider.GoOnline(), which grant control over the PLC lifecycle and program execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:07 AM
Security Audit — agent-trust-hub — tia-plc-operations