Sent to the selected LLM together with the STT transcript of the whole call. The placeholders are filled in per run.
Changes apply from the next analysis run. Detections already on the page keep the prompt they were made with.
The caller's clip carries a synthetic-voice signature (deepfake, 93%) while the script applies urgency pressure — a vishing pattern. The audio evidence is invisible to a text-only pipeline: the stack missed this moment and only flagged the later, text-visible push.
A scripted urgency push in the words themselves — a named five-figure transfer plus time pressure — matches the vishing playbook, so this one is visible to a text-only pipeline. The synthetic-voice probe at 0:05 left no trace in the transcript and went unflagged.
“You can hear it's me” — the caller asserts identity by voice alone and pushes an unverified contact change: the core of an account-takeover impersonation. The stack caught it too, from the transcript (64%).
The caller repeats the agent's name back and challenges their identity (“Alex, you said?”). The language model read this as an impersonation attempt; the reference marks no impersonation here — the caller is threatening escalation, not posing as someone else.
A threat to escalate to a supervisor to force the change, on top of a sharp emotion shift to angry in the voice. Also caught by STT+LLM from the transcript alone (61%).