Uploaded June 2026 | Updated September 2026, 3 weeks ago
Shadow Data in Tool Calls: The Privacy Leak Hiding in Plain Sight
Shabista Shabista and Ravi Gupta, Independent; Mayank Kumar Raunak, Intel Corporation
"Run it locally and your data stays private." This assumption is dangerously wrong.
When an AI agent calls external tools—weather APIs, calendars, maps, search—the request itself leaks user data. A local agent asking "What's the weather at my doctor's office?" sends exact coordinates to a third party. The agent may be local, but your medical visit pattern isn't.
We are analyzing tool calls from a prototype smart home agent. Preliminary testing indicates that the majority leak personally identifiable or sensitive contextual information in the request parameters alone—before any response is processed. Location, health indicators, financial patterns, and relationship data routinely escape through tool call payloads.
This talk presents a working Tool Call Sanitizer deployed on Raspberry Pi that intercepts, analyzes, and generalizes outbound requests in real-time. We target significant reduction in data leakage with minimal degradation in task utility. Privacy engineering must extend beyond the agent to the entire tool ecosystem.
View the full PEPR '26 program at usenix.org/conference/pepr26/program
Shadow Data in Tool Calls: The Privacy Leak Hiding in Plain Sight
Shabista Shabista and Ravi Gupta, Independent; Mayank Kumar Raunak, Intel Corporation
"Run it locally and your data stays private." This assumption is dangerously wrong.
When an AI agent calls external tools—weather APIs, calendars, maps, search—the request itself leaks user data. A local agent asking "What's the weather at my doctor's office?" sends exact coordinates to a third party. The agent may be local, but your medical visit pattern isn't.
We are analyzing tool calls from a prototype smart home agent. Preliminary testing indicates that the majority leak personally identifiable or sensitive contextual information in the request parameters alone—before any response is processed. Location, health indicators, financial patterns, and relationship data routinely escape through tool call payloads.
This talk presents a working Tool Call Sanitizer deployed on Raspberry Pi that intercepts, analyzes, and generalizes outbound requests in real-time. We target significant reduction in data leakage with minimal degradation in task utility. Privacy engineering must extend beyond the agent to the entire tool ecosystem.
View the full PEPR '26 program at usenix.org/conference/pepr26/program










