tia-simatic-drives

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill enables the agent to process data from TIA Portal projects, which may contain untrusted strings.
  • Ingestion points: Data is ingested from the TIA Portal environment via project.Devices.Find and property access such as DriveParameter.ParameterText (in references/drives-overview.md).
  • Boundary markers: The instructions do not define delimiters or specific "ignore" instructions for content retrieved from the project objects.
  • Capability inventory: The skill provides access to high-impact capabilities including hardware configuration modification (HardwareProjection), telegram insertion, security encryption activation (DriveDataEncryption.Activate), and local file system writes for report generation (SafetyAcceptanceTestReport.CreateProtocol).
  • Sanitization: No evidence of input validation or sanitization is present to mitigate instructions potentially embedded in device or parameter metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 07:56 AM
Security Audit — agent-trust-hub — tia-simatic-drives