Unexpected Behavior: Assistant Reads Tool Informat...
# support
e
Hi. I have a question regarding a behavior I noticed while testing some of my AI assistants today. During my tests, I observed that when the assistant is about to execute a tool, instead of directly triggering the action, it seems to read part of the tool information aloud, including parts of the URL or endpoint path. For example, it starts saying fragments such as "https..." or portions of the endpoint before actually executing the tool. After that, the assistant appears to become somewhat unstable and starts producing incoherent or nonsensical responses immediately before or during the tool execution. I was wondering if anyone else has experienced this behavior or if there is any known configuration issue that could cause it. From what I have observed, the problem seems to be specifically related to tool execution, as the normal conversation flow works correctly up until that point. If anyone has seen something similar or has suggestions on what logs, settings, or prompts I should review, I would really appreciate any guidance. Thank you very much. https://cdn.discordapp.com/attachments/1512141932959105198/1512142201293901854/image.png?ex=6a2303ab&is=6a21b22b&hm=29b6379d4aa1a2808f5ffa87f0aa767b3b255d59f7c054cb6291010415e5b911&
I have attached screenshots showing examples of the erratic behavior. This issue was not occurring previously, and the assistant used to execute the tools correctly without reading or verbalizing the endpoint URLs or tool information.
c
Hi estefania_hl, To help track down this issue, could you share: - The call ID - When exactly this happened (the timestamp) - What response you expected to get - What response you actually got instead This would really help us figure out what went wrong!
e
Hi, Thank you very much for your response. This happened on several calls. I am attaching one example below. Call ID: 019e92c4-8bda-7000-895d-fcb9b1495dcf Timestamp: 06/04/2026 at 15:13 (inboundPhoneCall) Expected behavior: I expected the assistant to execute the tool silently and process the returned data internally, without reading any tool metadata, internal identifiers, URLs, or technical information aloud to the customer. Actual behavior: Instead, after executing the "Registrar Observaciones" tool, the assistant started reading internal metadata and technical information that should never be spoken to the customer, including internal identifiers, references, URL fragments, and tool response details. For example, after the tool execution, the assistant said: > "Un momento, por favor. Veo que su pedido con identificador interno 4138611112 y referencia 550... ¿Hay algo más en lo que le podamos ayudar o revisar sobre su pedido? URL response HTTPS... POST... response..." As you can see, it appears that the assistant is reading parts of the tool response and internal metadata instead of only providing the relevant information to the customer. I am attaching the call example and the moment when the "Registrar Observaciones" tool was executed, as this seems to be the point where the issue occurs. Please let me know if you need any additional examples, as we have observed this behavior on multiple calls. Thank you very much for your help.
Example call flow: 15:13:36 PM (+00:01.33) Assistant: "Hola, Álex. Soy una asistente de IEA. Le llamamos de perfumería Julia para agradecerle su compra. Queríamos recordarle que dispone de nuestro servicio premium, que incluye asesoramiento personalizado, seguimiento de pedidos, gestión de incidencias y acceso a eventos exclusivos. ¿Hay algo en lo que le podamos ayudar o revisar sobre su pedido?" 15:13:58 PM (+00:23.30) User: "Me gustaría saber en qué estado está mi pedido." 15:14:02 PM (+00:27.34) Assistant: "Perfecto, Alex, ahora mismo voy a revisar..." 15:14:03 PM (+00:28.57) Registrar Observaciones Executing... 15:14:06 PM (+00:31.51) Assistant: "Un momento, por favor. Veo que su pedido con identificador interno 4 1 3 8 6 1 1 1 1 2 y referencia 5 5 0 teta, t ¿Hay algo más en lo que le podamos ayudar o revisar sobre su pedido? Úrle el response. HTTPS postmediat gopo c msoft punto net possess 2 y a response o possess ve to us de que tengo que ser el gallego possess 2 y response posses possess ve to us, que tengo que ser el que ha liado que es" 15:14 Customer ended the call. As shown above, immediately after the tool execution, the assistant started reading what appears to be internal metadata, identifiers, URLs, and tool-response information that should remain hidden from the customer.
Hi, Thank you very much for your response. This happened on several calls. I am attaching one example below. Call ID: 019e92c4-8bda-7000-895d-fcb9b1495dcf Timestamp: 06/04/2026 at 15:13 (inboundPhoneCall) Expected behavior: I expected the assistant to execute the tool silently and process the returned data internally, without reading any tool metadata, internal identifiers, URLs, or technical information aloud to the customer. Actual behavior: Instead, after executing the "Registrar Observaciones" tool, the assistant started reading internal metadata and technical information that should never be spoken to the customer, including internal identifiers, references, URL fragments, and tool response details. For example, after the tool execution, the assistant said: "Un momento, por favor. Veo que su pedido con identificador interno 4138611112 y referencia 550... ¿Hay algo más en lo que le podamos ayudar o revisar sobre su pedido? URL response HTTPS... POST... response..." As you can see, it appears that the assistant is reading parts of the tool response and internal metadata instead of only providing the relevant information to the customer. I am attaching the call example and the moment when the "Registrar Observaciones" tool was executed, as this seems to be the point where the issue occurs. Please let me know if you need any additional examples, as we have observed this behavior on multiple calls. Thank you very much for your help.
Example call flow: 15:13:36 PM (+00:01.33) Assistant: "Hola, Álex. Soy una asistente de IEA. Le llamamos de perfumería Julia para agradecerle su compra. Queríamos recordarle que dispone de nuestro servicio premium, que incluye asesoramiento personalizado, seguimiento de pedidos, gestión de incidencias y acceso a eventos exclusivos. ¿Hay algo en lo que le podamos ayudar o revisar sobre su pedido?" 15:13:58 PM (+00:23.30) User: "Me gustaría saber en qué estado está mi pedido." 15:14:02 PM (+00:27.34) Assistant: "Perfecto, Alex, ahora mismo voy a revisar..." 15:14:03 PM (+00:28.57) Registrar Observaciones Executing... 15:14:06 PM (+00:31.51) Assistant: "Un momento, por favor. Veo que su pedido con identificador interno 4 1 3 8 6 1 1 1 1 2 y referencia 5 5 0 teta, t ¿Hay algo más en lo que le podamos ayudar o revisar sobre su pedido? Úrle el response. HTTPS postmediat gopo c msoft punto net possess 2 y a response o possess ve to us de que tengo que ser el gallego possess 2 y response posses possess ve to us, que tengo que ser el que ha liado que es" 15:14 Customer ended the call. As shown above, immediately after the tool execution, the assistant started reading what appears to be internal metadata, identifiers, URLs, and tool-response information that should remain hidden from the customer.
c
Hi estefania_hl , thanks for sharing your details. Our team will look into it and get back to you soon with an update.
e
Thank you
c
Hi, Thanks for reporting this — I can see exactly what's happening and here's how to fix it. You need to make 2 changes: ---- Fix 1 — Clean your tool response (on your server) Your server should return only this: json
Copy code
{
  "result": "La observación ha sido registrada correctamente."
}
Remove everything else — IDs, URLs, HTTP methods, references. The assistant reads whatever your server sends back, so keep it simple and human-friendly. ---- Fix 2 — Add this to your assistant's system prompt
Copy code
When you execute the "Registrar Observaciones" tool:
- NEVER read any internal IDs, URLs, references, or technical fields aloud.
- Only use the confirmation message to respond to the customer.
- Say something like: "Su observación ha sido registrada. ¿Hay algo más en lo que pueda ayudarle?"
---- To test: Make a test call, trigger the tool, and confirm the assistant only speaks the confirmation — nothing technical. Both fixes together will permanently stop this behavior. Let me know if you need help
e
Thank you very much for the quick response. I will implement the changes you suggested and monitor whether the issue occurs again. For reference, I also observed the same behavior recently on the following call: ID: 019ea859-edd6-788b-a132-477fb20c900a However, at that time I had not yet applied any of the changes you recommended, so that example may still be affected by the previous configuration. Feel free to review it if it helps with your investigation. In any case, I will let you know if the issue happens again after applying the modifications. Thank you again for your help.
Hi, Sorry to bother you again. I have performed a new test after implementing the changes we discussed, but unfortunately the result was still incorrect. The assistant appears to have read the tool output directly instead of handling it silently. I am attaching the call ID and timestamp below in case you are able to review it: Call ID: 019eab7b-3bdf-7000-8fb8-e8984a509ffe Timestamp: Jun 09, 10:24:38.409 Expected behavior: The assistant should execute the tool silently, process the response internally, and only provide a natural customer-facing response. Actual behavior: The assistant read information returned by the tool instead of using it internally. As part of the changes, I am already returning a simple
result
field from the endpoint and I have also added the following instructions to the system prompt to explicitly prevent the assistant from reading URLs, endpoints, tool information, technical fields, or any tool-related content aloud. Despite these changes, the issue still occurred during this test. Could you please review this example and let me know if you can identify what might have happened, or if there is anything else I should modify on my side? Thank you very much in advance for your help.
I have added the following instructions to the assistant's system prompt: REGLA CRÍTICA SOBRE TOOLS Cuando vayas a ejecutar cualquier tool, debes hacerlo de forma completamente silenciosa. ESTÁ ABSOLUTAMENTE PROHIBIDO mencionar, leer, deletrear, resumir, describir o verbalizar cualquier elemento relacionado con el tool antes, durante o después de su ejecución. Esto incluye, entre otros: URLs Endpoints Direcciones HTTP o HTTPS Nombres de herramientas (tools) Nombres de funciones Parámetros JSON Payloads Campos como urlresponse Rutas Tokens Identificadores internos Datos técnicos utilizados para la ejecución Nunca debes pronunciar textos como: "https..." "http..." "URL" "endpoint" "response" "api" "tool" "JSON" cualquier fragmento de una dirección web La ejecución de un tool es un proceso interno e invisible para el cliente. Antes de ejecutar un tool puedes utilizar únicamente frases naturales como: "Perfecto." "Muchas gracias por todo. En breve le contactará el responsable. ¡Que tenga un buen día!" Después ejecuta el tool directamente y en silencio. Si detectas una URL, un endpoint, un JSON o cualquier dato técnico en tu contexto, debes ignorarlo completamente en tu respuesta hablada. Bajo ninguna circunstancia debes leer, repetir, deletrear o transformar una URL en lenguaje natural. La aparición de cualquier URL, endpoint o dato técnico en la conversación con el cliente se considera un error grave de comportamiento. IMPORTANTE: El campo urlresponse es exclusivamente para uso interno de los tools. Nunca debe ser leído, interpretado, explicado, resumido ni pronunciado al cliente. Ignora completamente su contenido durante la generación de respuestas habladas.
c
Thanks for the detailed follow-up and the call ID — really helpful. This is a separate issue from the transfer one, and it's a common challenge. Even with strong prompt instructions, if the tool response contains technical fields like URLs or field names (e.g.,
urlresponse
), the LLM can sometimes reference them. The most reliable fix is to clean up what your tool returns. Ideally it should only send back a simple, human-friendly message — nothing technical. For example: json
Copy code
{
  "result": "Done! Someone will be in touch shortly."
}
If your tool response already looks clean and this is still happening, could you share what your tool is currently returning? That'll help us pinpoint exactly what the LLM is picking up. In the meantime, I'm logging call
019eab7b-3bdf-7000-8fb8-e8984a509ffe
(Jun 09, 10:24:38) for our engineering team to review the transcript and see exactly what was spoken.
Hi, I'm not seeing a transfer happen on this call. Can you confirm the call ID - 019ea859-edd6-788b-a132-477fb20c900a?