Spoken Prompt Injection
A user or background speaker says instructions that try to override policy, reveal private context, or change tool behavior.
Hidden answer: strong mitigation
Treat ASR output as untrusted user input. Keep system and tool policy outside the transcript, classify tool intent separately, require explicit confirmations for sensitive actions, evaluate retrieval grounding, and log sanitized decision traces rather than raw audio by default.