# Agent spoke its system prompt aloud to the caller at a transfer\_call node (gpt-4.1 conversation flow)

**URL:** <https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478>\
**Category:** Support Help\
**Tags:** bug\
**Created:** [August 7, 2026, 10:04pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478 "2026-08-07T22:04:35Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrew3](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/andrew3/32/1713_2.png) [@andrew3](https://community.retellai.com/u/andrew3)\
**Post date:** [August 7, 2026, 10:04pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/1 "2026-08-07T22:04:35Z")

</div>

Hi Retell team,

We had a production call where the agent read its entire system prompt out loud  
to the caller in English, instead of generating the node’s utterance.

Call details

- call\_id: call\_de5959a912f7c4245a7c57e3e23
- agent\_id: agent\_6d3fe306d1e8b2ecb516126f46 (agent\_version 0)
- conversation\_flow\_id: conversation\_flow\_f5e65a0e6a1d
- component: conversation\_flow\_component\_44941051c505
- node: transfer\_dest\_1781597713272 (“Transfer to 予約センター”),  
type transfer\_call, speak\_during\_execution: true
- model\_choice: {“type”: “cascading”, “model”: “gpt-4.1”}
- agent language: ja-JP
- public log: [https://dxc03zgurdly9.cloudfront.net/33753a0aa4299b3aab8fc01c2ded5bf6a5405d9e4a7fff4de8ece7ca20ebae3f/public.log](https://dxc03zgurdly9.cloudfront.net/33753a0aa4299b3aab8fc01c2ded5bf6a5405d9e4a7fff4de8ece7ca20ebae3f/public.log)

What happened  
The flow transitioned into the transfer node at 2026-08-07 02:05:31.005 UTC.  
From 53.05s to 80.79s into the call (~28 seconds), the agent spoke this to the  
caller, in English, on a Japanese-language call:

“You are a helpful hotel receptionist. Always respond in Japanese. Never  
answer factual questions yourself; let the knowledge-base lookup step handle  
them. Never say you are checking or confirming before the lookup step. Never  
accept or process requests yourself unless a tool step does so. Never state  
staff availability.Always use keigo. Never switch languages. Keep responses  
concise and natural. Never use filler words. Never repeat yourself. Follow  
the task instruction closely.\n\n—\n\n”

This is a condensed paraphrase of our global\_prompt, and it ends with the  
“\n\n—\n\n” separator — which suggests the model was reproducing the system  
prompt scaffold itself rather than generating a response.

The transfer\_call tool then fired normally at 02:06:03.589 UTC and the transfer  
succeeded, so only the announcement utterance was affected.

Expected behavior  
The node’s instruction is:  
{“type”: “prompt”, “text”: “Briefly and naturally tell the user that you will  
now transfer them to someone who can help. Do not name the destination.  
Match the user’s language. Do not ask any further questions — only  
acknowledge the transfer.”}  
We expected a short Japanese transfer acknowledgement.

Scope and onset  
We scanned our full production call history for this signature:

- Jul 8 – Jul 31: 9,735 calls, 0 occurrences
- Jul 31 – Aug 8: 6,088 calls, 1 occurrence (this call)  
So it appears to be new as of early August and very rare, but it is severe when  
it happens — the caller hears our internal prompt read aloud.

Questions

1. Was there any change to gpt-4.1 serving or to how the system prompt is  
assembled for cascading conversation flows around Aug 6?
2. Is there any guard on your side against the model emitting the system prompt  
as an utterance?
3. Would you recommend a different model\_choice, or switching this node’s  
instruction to static\_text, to eliminate the risk on transfer announcements?

Happy to provide the recording or any other call data.

Thanks,  
Andrew

---

<div class="post-metadata">

**Author:** ![Shah-Fazal](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/shah-fazal/32/2522_2.png) [@Shah-Fazal](https://community.retellai.com/u/Shah-Fazal)\
**Post date:** [August 7, 2026, 10:15pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/2 "2026-08-07T22:15:30Z")

</div>

Hello @andrew3 Thanks for sharing the Call ID. I’m checking it with the team and will get back to you as soon as I have an update.

Thank You

---

<div class="post-metadata">

**Author:** ![Shah-Fazal](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/shah-fazal/32/2522_2.png) [@Shah-Fazal](https://community.retellai.com/u/Shah-Fazal)\
**Post date:** [August 8, 2026, 1:34pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/3 "2026-08-08T13:34:50Z")

</div>

Hello @andrew3 we reproduced your timeline against the call record and internal log.

What we see:

- On this call the transfer-announcement turn was generated by gpt-4.1 on your `transfer_dest_1781597713272` node (`type: transfer_call`, `speak_during_execution: true`, `instruction.type: prompt`). What the model emitted was an English paraphrase of your `globalPrompt`, terminated by the internal `\n\n---\n\n` scaffold separator. The `transfer_call` tool then fired normally ~30s later and connected, matching what you saw.

- Our internal log does not show a first-token timeout or a cascade fallback at node entry, so this doesn’t look like a leak from a fallback model rendering a wrapper template — it looks like a rare model instruction-following slip on gpt-4.1 for this specific short-announcement node.

On your three questions:

1. We don’t have a confirmed Retell-side change to gpt-4.1 or to prompt assembly for cascading conversation flows around Aug 6 that would explain a new regression here. We also can’t confirm or rule out a provider-side serving drift from our side.
2. There is no pre-TTS server-side guard today that inspects assistant content for “looks like the system prompt” and suppresses it.
3. For a transfer-announcement utterance we recommend switching this node’s `instruction` from `{type: "prompt", ...}` to `{type: "static_text", text: "少々お待ちください。担当におつなぎいたします。"}` (or your preferred one-liner). `static_text` is read verbatim with no LLM generation step, so this failure mode is structurally impossible there — and it removes the ~1–2s of LLM latency on the transfer seam. If you’d rather keep it dynamic, an alternative is pinning a stronger instruction-following model on that specific node and adding 1–2 finetune examples showing the desired short Japanese output — but `static_text` is the definitive fix for the “must never say the prompt” property.

Thank You

---

<div class="post-metadata">

**Author:** ![andrew3](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/andrew3/32/1713_2.png) [@andrew3](https://community.retellai.com/u/andrew3)\
**Post date:** [August 9, 2026, 10:06pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/4 "2026-08-09T22:06:06Z")

</div>

Thanks! This seems rare so we’ll monitor things on our side and use the static\_text option if we keep seeing it.

---

<div class="post-metadata">

**Author:** ![andrew3](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/andrew3/32/1713_2.png) [@andrew3](https://community.retellai.com/u/andrew3)\
**Post date:** [August 10, 2026, 12:35am UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/5 "2026-08-10T00:35:49Z")

</div>

Follow-up — same failure class, different node (private handoff message)

We hit this again two days later on the same agent LLM, and static\_text isn’t available  
as a workaround on this path.

Call: call\_1a9770ac6f2438e21e9c02a74f6  
Agent: agent\_b0c4d8513d561b8eebe58bfdb1  
2026-08-08 17:58:29 JST  
Log: [https://dxc03zgurdly9.cloudfront.net/49999783eb9c2e40201b3ea3904b1730d148a0291b8cce8ece02f9a881f7ccd2/public.log](https://dxc03zgurdly9.cloudfront.net/49999783eb9c2e40201b3ea3904b1730d148a0291b8cce8ece02f9a881f7ccd2/public.log)

Not speak\_during\_execution this time — it’s the private handoff message on a warm  
transfer (privateHandoffOption.type: “prompt”). Our prompt asks for a fixed opening  
sentence plus a 1–2 sentence Japanese summary for the staff member.

What it produced: the call transcript reformatted as a bilingual “Agent:/Customer:”  
dialogue, repeated four times, wrapped in chat-assistant filler — “Certainly! Here is the  
conversation you provided, formatted as a dialogue between an agent and a customer…” /  
“If you need this in a different format or with additional context, please let me know!”  
None of our prompt was followed.

Three things that make this worse than the first case:

1. It never terminated. public.log: “Speaking private handoff message” 17:59:51.971 →  
“Ending call” 18:01:56.241 — 124 seconds, 4,311 characters.
2. The caller sat on hold music for those two minutes and hung up. The transfer never  
completed.
3. The recited dialogue is fabricated. It has the agent telling the caller  
「デイユースでご利用の場合でも、プールの利用が可能です。」 and a full closing exchange.  
None of it happened — our rag\_lookup returned could\_not\_answer: true at 60.4s, which is  
why the call was being transferred at all. The staff member was read an invented  
conversation containing a wrong answer.

Questions:

- Can you look at this call and tell us what the root cause was?
- Is it the same underlying issue as the first report, or something different?
- Both incidents landed on transfer nodes within three days, and we’ve seen nothing  
comparable elsewhere in our call volume. Does that pattern mean anything from your side?
- What do you recommend we do about it, given static\_text isn’t an option on this path?
- Is there anything that limits how long a generated message like this can run?

Any interim mitigation would be appreciated — a single slip on this path currently costs  
the caller the transfer and hands staff false information.

---

<div class="post-metadata">

**Author:** ![Shah-Fazal](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/shah-fazal/32/2522_2.png) [@Shah-Fazal](https://community.retellai.com/u/Shah-Fazal)\
**Post date:** [August 10, 2026, 2:12pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/6 "2026-08-10T14:12:41Z")

</div>

Hello @andrew3 Checking it with the team.

---

<div class="post-metadata">

**Author:** ![andrew3](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/andrew3/32/1713_2.png) [@andrew3](https://community.retellai.com/u/andrew3)\
**Post date:** [August 10, 2026, 5:52pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/7 "2026-08-10T17:52:42Z")

</div>

We’ve seen an uptick in issues like this recently (PT times):

call\_4a5de65fb26d23cb5d931ea8dac 2026-08-09 18:03:04  
call\_22edc9f51a61f9f4c1403681617 2026-08-09 19:03:04  
call\_b202d49ad862f2aef9ed76a9aed 2026-08-09 21:43:40  
call\_ed677b82881ee724b1425ae4a9e 2026-08-09 23:09:20  
call\_f63426077cd0edbf89fdb22dd3e 2026-08-10 00:21:53  
call\_98a135ed76bb90857ffbd05d8a6 2026-08-10 01:32:11

Please let us know as soon as you know something.

Thanks,

Andrew

---

<div class="post-metadata">

**Author:** ![Shah-Fazal](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/shah-fazal/32/2522_2.png) [@Shah-Fazal](https://community.retellai.com/u/Shah-Fazal)\
**Post date:** [August 10, 2026, 6:06pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/8 "2026-08-10T18:06:38Z")

</div>

Hey @andrew3 We’ve reviewed the second call and agree this is a serious recurrence: the private handoff generated a fabricated, lengthy transcript, preventing the transfer from completing.

It appears related to the earlier transfer-path failure, though we have not confirmed the root cause yet. We’re escalating both incidents and investigating safeguards for generated transfer/handoff messages, including preventing unsafe output and limiting runaway generation.

Since `static_text` is not available for private handoffs, please keep that prompt as short and constrained as possible for now. We’ll follow up with findings and a concrete mitigation.

Thank You

---

<div class="post-metadata">

**Author:** ![Shah-Fazal](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/shah-fazal/32/2522_2.png) [@Shah-Fazal](https://community.retellai.com/u/Shah-Fazal)\
**Post date:** [August 11, 2026, 1:08pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/9 "2026-08-11T13:08:54Z")

</div>

Hello @andrew3 this might be related to some problem of our internal problem,Team is sending out a PR to fix it.

Thank You

---

<div class="post-metadata">

**Author:** ![andrew3](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/andrew3/32/1713_2.png) [@andrew3](https://community.retellai.com/u/andrew3)\
**Post date:** [August 11, 2026, 1:57pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/10 "2026-08-11T13:57:32Z")

</div>

Thanks! Please let me know once the fix has been released.

Andrew

---

<div class="post-metadata">

**Author:** ![trevor](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/trevor/32/466_2.png) [@trevor](https://community.retellai.com/u/trevor)\
**Post date:** [August 17, 2026, 8:30pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/11 "2026-08-17T20:30:16Z")

</div>

Same issue on 2026-08-17.

call\_e73bc57336bb24ac64d9ab9d385

Agentic warm transfer. public\_handoff\_option type prompt. After the destination answered, the handoff spoke the generation prompt (Knowledge cutoff, “You are an expert in performing a warm transfer”, few-shot example) instead of the one-line handoff. Transfer still completed.

1 of 21 transfers today. Only occurrence we found in the last week.

Was the Aug 11 fix released? If so it did not catch this path.

---

<div class="post-metadata">

**Author:** ![Shah-Fazal](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.retellai.com/shah-fazal/32/2522_2.png) [@Shah-Fazal](https://community.retellai.com/u/Shah-Fazal)\
**Post date:** [August 18, 2026, 1:09pm UTC](https://community.retellai.com/t/agent-spoke-its-system-prompt-aloud-to-the-caller-at-a-transfer-call-node-gpt-4-1-conversation-flow/3478/12 "2026-08-18T13:09:48Z")

</div>

Hello @trevor we do have another improvement that’s being gradually rolled out.

Thank You
