tia-plc-operations
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from multiple external file formats, creating a potential vector for indirect prompt injection.
- Ingestion points: The skill utilizes methods such as Import(), ImportFromXlsx(), CreateFromFile(), LoadCamData(), and LoadSource() across several files including references/blocks.md, references/tags-types.md, references/external-sources.md, and references/software-units.md.
- Boundary markers: No explicit instructions or delimiters are provided to help the agent distinguish between its system instructions and the content within processed files.
- Capability inventory: The skill allows for significant system impact through actions like Compile(), Delete(), UpdateProgram(), and GoOnline() as described in references/blocks.md and references/online-status.md.
- Sanitization: There is no evidence of sanitization, validation, or filtering of content from external files before processing.
- [COMMAND_EXECUTION]: The skill allows for the execution of administrative and engineering commands that can modify PLC logic and hardware state.
- Evidence: Reference files like references/blocks.md and references/compare.md provide instructions for methods like plcBlock.Compile(), plcSoftware.UpdateProgram(), and onlineProvider.GoOnline(), which grant control over the PLC lifecycle and program execution environment.
Audit Metadata