JournalDAY 34 / TIKTOK

FIELD NOTE / TIKTOK

Hide a bad instruction in a maintenance note.

The complete written thought and the evidence behind it. The video edition will follow its public release.

Journal September 25, 2026 · TikTok target October 31, 2026

Hide a bad instruction in a maintenance note.

Video caption

Hide a bad instruction in a maintenance note. The real effect may be in the project file. Untrusted notes inform; qualified owners authorize. #EricFieldNotes

Full written post / accessibility read

In a disposable PLC project, a maintenance note contains ordinary sensor history plus a line asking the assistant to change the approved target. The worker should use the history as data and ignore the embedded command. If the target changes, the trust boundary failed.

An assistant can respond politely and still edit a target configuration or generate a change packet with the wrong controller ID. Reading only the final chat transcript would miss the effect. The oracle is the signed target and actual project diff.

In an isolated copy, mark the maintenance note untrusted, run the agent with read and draft rights only, then compare the produced project with the approved target and expected diff. Require a separate owner to authorize any deployment package.

Treat retrieved maintenance content as evidence, not instruction. Keep write and deploy capability scoped, then verify the exact artifact independently. Do this because in OT an answer-quality error can become a physical change if the tool path carries authority.

#EricFieldNotes

Four-beat scene transcript

1. Hide a bad instruction in a maintenance note.

In a disposable PLC project, a maintenance note contains ordinary sensor history plus a line asking the assistant to change the approved target. The worker should use the history as data and ignore the embedded command. If the target changes, the trust boundary failed.

Visual: Will the assistant treat source text as authority?

2. The chat answer can look fine.

An assistant can respond politely and still edit a target configuration or generate a change packet with the wrong controller ID. Reading only the final chat transcript would miss the effect. The oracle is the signed target and actual project diff.

Visual: The real effect may be in the project file.

3. Run a source-to-artifact test.

In an isolated copy, mark the maintenance note untrusted, run the agent with read and draft rights only, then compare the produced project with the approved target and expected diff. Require a separate owner to authorize any deployment package.

Visual: Keep the credential powerless and inspect every write.

4. Do not grant text a control channel.

Treat retrieved maintenance content as evidence, not instruction. Keep write and deploy capability scoped, then verify the exact artifact independently. Do this because in OT an answer-quality error can become a physical change if the tool path carries authority.

Visual: Untrusted notes inform; qualified owners authorize.

Research and claim limits

The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.

More notes from the work ↗