tia-python
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for installing local Python wheel files using pip and dynamically loading the Siemens scripting module by modifying the system path (
sys.path) based on theTIA_SCRIPTINGenvironment variable. These patterns are standard for manual SDK integration but involve executing code from variable filesystem paths. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of external automation data (XML, SimaticML, CAx, and CFC charts) into TIA Portal projects. This creates a surface where malicious instructions could be embedded within engineering artifacts to influence agent behavior during project manipulation.
- Ingestion points: Methods such as
portal.open_project,hmi.import_hmi_tags,plc.import_blocks,plc.import_cfc_charts, andproject.import_cax_dataacross various reference files. - Boundary markers: The instructions emphasize mandatory 'explicit mutation authorization' and 'exact selectors' to maintain control, though they do not specify technical delimiters for the data content itself.
- Capability inventory: Extensive capabilities including project lifecycle management (creation/deletion), file system writes (exports), and live industrial PLC operations (downloads and online state changes).
- Sanitization: The skill recommends to 'Preflight source content' and 'Validate resulting types,' but lacks concrete implementation details for filtering or sanitizing embedded text within automation files.
Audit Metadata