FIELD NOTE / TIKTOK
Hide a bad instruction in a maintenance note.
The complete written thought and the evidence behind it. The video edition will follow its public release.
The written argument is here.
This approved TikTok edition is on the journal now. Its video player and original platform link will appear after each public release is verified.
Hide a bad instruction in a maintenance note.
Video caption
Hide a bad instruction in a maintenance note. The real effect may be in the project file. Untrusted notes inform; qualified owners authorize. #EricFieldNotes
Full written post / accessibility read
In a disposable PLC project, a maintenance note contains ordinary sensor history plus a line asking the assistant to change the approved target. The worker should use the history as data and ignore the embedded command. If the target changes, the trust boundary failed.
An assistant can respond politely and still edit a target configuration or generate a change packet with the wrong controller ID. Reading only the final chat transcript would miss the effect. The oracle is the signed target and actual project diff.
In an isolated copy, mark the maintenance note untrusted, run the agent with read and draft rights only, then compare the produced project with the approved target and expected diff. Require a separate owner to authorize any deployment package.
Treat retrieved maintenance content as evidence, not instruction. Keep write and deploy capability scoped, then verify the exact artifact independently. Do this because in OT an answer-quality error can become a physical change if the tool path carries authority.
#EricFieldNotes
Four-beat scene transcript
1. Hide a bad instruction in a maintenance note.
In a disposable PLC project, a maintenance note contains ordinary sensor history plus a line asking the assistant to change the approved target. The worker should use the history as data and ignore the embedded command. If the target changes, the trust boundary failed.
Visual: Will the assistant treat source text as authority?
2. The chat answer can look fine.
An assistant can respond politely and still edit a target configuration or generate a change packet with the wrong controller ID. Reading only the final chat transcript would miss the effect. The oracle is the signed target and actual project diff.
Visual: The real effect may be in the project file.
3. Run a source-to-artifact test.
In an isolated copy, mark the maintenance note untrusted, run the agent with read and draft rights only, then compare the produced project with the approved target and expected diff. Require a separate owner to authorize any deployment package.
Visual: Keep the credential powerless and inspect every write.
4. Do not grant text a control channel.
Treat retrieved maintenance content as evidence, not instruction. Keep write and deploy capability scoped, then verify the exact artifact independently. Do this because in OT an answer-quality error can become a physical change if the tool path carries authority.
Visual: Untrusted notes inform; qualified owners authorize.
Research and claim limits
- NIST SP 800-82 Rev. 3 final (S137)
- ISA/IEC 62443 overview (S142)
The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.