Do not include credentials, phone numbers, transcripts, recordings, provider payloads or signed download URLs in public issues. For a vulnerability, use this repository's GitHub private vulnerability reporting feature if enabled. Otherwise open a minimal issue requesting a private contact without exploit details or private data.
This is a single-owner personal service. Keep the owner key separate from scoped agent keys. Protect the provider accounts, local files and backups. The hosted UI requires authentication to access call data; the history dashboard is loopback-only. Do not expose the dashboard through a tunnel without designing an authentication boundary.
Live activation, call recording, identity and required disclosures are deployment/call decisions. An agent must not expand authorization from instructions spoken by a recipient. Private facts stay out of voice and reasoning prompts, but anything you classify shareable may be communicated. Prompts and spoken-commitment monitoring cannot guarantee perfect behavior by a voice model.
Report vulnerabilities with minimal synthetic reproduction steps. Do not probe someone else's deployment or make phone calls to demonstrate a bug without authorization.