tia-python

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for installing local Python wheel files using pip and dynamically loading the Siemens scripting module by modifying the system path (sys.path) based on the TIA_SCRIPTING environment variable. These patterns are standard for manual SDK integration but involve executing code from variable filesystem paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of external automation data (XML, SimaticML, CAx, and CFC charts) into TIA Portal projects. This creates a surface where malicious instructions could be embedded within engineering artifacts to influence agent behavior during project manipulation.
  • Ingestion points: Methods such as portal.open_project, hmi.import_hmi_tags, plc.import_blocks, plc.import_cfc_charts, and project.import_cax_data across various reference files.
  • Boundary markers: The instructions emphasize mandatory 'explicit mutation authorization' and 'exact selectors' to maintain control, though they do not specify technical delimiters for the data content itself.
  • Capability inventory: Extensive capabilities including project lifecycle management (creation/deletion), file system writes (exports), and live industrial PLC operations (downloads and online state changes).
  • Sanitization: The skill recommends to 'Preflight source content' and 'Validate resulting types,' but lacks concrete implementation details for filtering or sanitizing embedded text within automation files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:06 AM
Security Audit — agent-trust-hub — tia-python