Research questionHow can tool-using agents prevent sensitive conclusions assembled from individually non-revealing tool outputs?A tool result may be harmless in isolation yet reveal a sensitive conclusion when combined with other returns and the agent’s reasoning. Per-output privacy checks therefore may miss disclosures that emerge across an agent’s tool-use sequence.