tia-testsuite

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface where external files are ingested using the LoadFromFile methods described in references/application-test.md, references/style-guide.md, and references/system-test.md. To mitigate this, the skill includes explicit instructions for the agent to treat these external files as untrusted, validate their provenance, and verify the resulting project identities before performing save operations.
  • [COMMAND_EXECUTION]: The skill interacts with the TIA Portal environment and PLCSIM through the Siemens.Engineering.TestSuite API. These operations, while capable of modifying industrial automation projects, are governed by instructions requiring explicit user authorization and specific project-level user rights ('Edit Test Suite data'). This ensures that all mutations to the TIA Portal project are performed under human oversight and within defined security contexts.
  • [DATA_EXFILTRATION]: The skill facilitates network communication via the OPC UA protocol to interact with Simatic controllers. The documentation in references/system-test.md mandates that the agent must not assume simulation and must obtain explicit authorization before connecting to any live controller or production endpoint specified in the OPCUAServerAddress property, preventing unauthorized network operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:06 AM
Security Audit — agent-trust-hub — tia-testsuite