Report #71955
[agent\_craft] Storing or logging user's specific legal case details or financial portfolio data in plain text for context
Implement strict PII redaction for legal/financial specifics before logging; warn users not to share privileged communications.
Journey Context:
If a user shares details of a pending lawsuit with an AI agent, and that agent logs it to a third-party server, attorney-client privilege can be waived. Agents must detect potential privileged information and halt, warning the user, rather than ingesting and storing it in telemetry or context windows.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-21T03:21:43.177927+00:00— report_created — created