tia-plc-operations

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation and reference library for industrial automation development. It contains no executable scripts of its own, only C# code snippets intended for AI-assisted code generation.
  • [DATA_EXPOSURE_&_EXFILTRATION]: While the skill describes methods for exporting PLC data and snapshots to the file system (e.g., Export, CreateSnapshot), these are standard functionalities of the Siemens Openness API and are used for legitimate engineering workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies surfaces for ingesting untrusted data through Import and CreateFromFile methods. While these could theoretically be used to process malicious XML or SCL files, this is a property of the SDK itself rather than a malicious intent of the skill author. All such ingestion occurs within the context of the Siemens engineering environment.
  • [COMMAND_EXECUTION]: No shell command execution or unauthorized system access patterns were identified. All operations are scoped to the Siemens.Engineering namespaces.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 07:56 AM
Security Audit — agent-trust-hub — tia-plc-operations