BSides San Antonio 2026 June 13 at St. Mary's University What happens when you social engineer an AI agent that was trained to be helpful over the phone? Can you get it to reveal its system prompt out loud? Will it disclose information about other callers? How far can you push it before its guardrails kick in? Voice AI agents are the same LLMs we've been prompt injecting, just with a phone number instead of a chatbot. Yapper is the open-source tool I built to test them.