Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-13T06:35:13.331872Z
Paper Citation Record · LEDGER
As of 4 August 2026, this Paper Citation Record lists 79 of 79 outbound references and 96 inbound Pith citation observations for arXiv:2406.13352.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-13T06:35:13.331872Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-04T09:25:38.687859Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-07-11T02:47:49.867984Z
79 of 79 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 89a9c5c8-b9f9-489d-a65d-c45d3298d0d1 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Croissant: A metadata format for ml-ready datasets
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b56a0a3d-0a6f-4ada-a6df-c527f0dd9a8f · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents The Claude 3 Model Family: Opus, Sonnet, Haiku
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e570c438-9dcc-4f2c-b99f-990a46667af4 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Tool use (function calling)
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 9138d2ac-a93b-48c4-93b7-748952c6f4f9 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 953b48fe-7719-4e63-ad9b-9c27dd491b80 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Language models are few-shot learners
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4fd8827a-8983-44d3-a2d1-5c80a793f94c · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents A critique of the DeepSec Platform for Security Analysis of Deep Learning Models
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation c452888b-062f-401a-a538-ab96428606af · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents JailbreakBench: An Open Robustness Benchmark for Jailbreaking Large Language Models
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation bfc9291a-c1de-4504-9997-3d6a8cfbe7f8 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents StruQ: Defending Against Prompt Injection with Structured Queries
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5429174b-7370-4691-b2b6-dbe509bd5efc · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Introducing Command R+: Our new, most powerful model in the Command R family
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 1aaa3615-8856-4d9f-86ca-a0404237e649 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents RobustBench: a standardized adversarial robustness benchmark
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 7060773a-bedf-4c51-bb63-5ac68fe02c20 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 46eab58b-a96d-4a7f-b56c-b0214647c0b1 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Dataset and Lessons Learned from the 2024 SaTML LLM Capture-the-Flag Competition
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 22929a5e-c96d-4f5c-b69b-781da42f1b5e · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Misusing Tools in Large Language Models With Visual Adversarial Examples
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 2e67bca7-fdd3-43b5-bc71-06e41963c640 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents PAL: Program-aided language models
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 12ec3800-2704-4bd4-a5a2-56b77f154a14 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Coercing LLMs to do and reveal (almost) anything
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation fdf395f8-aedb-4dad-b473-2a9e770a712b · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Gemini: A Family of Highly Capable Multimodal Models
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a6680ea7-a0bb-477f-be13-578cd47e3483 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Exploiting GPT-3 prompts with malicious inputs that order the model to ignore its previous directions
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b763d4c3-75d6-4655-ba2a-66aced532e98 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 3b16a231-0ac6-4ecf-8d37-faf42f5e381c · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation ff004233-d55a-4973-8215-430a69a41b80 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Language models as zero-shot planners: Extracting actionable knowledge for embodied agents
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 0d533d86-bf1d-4c7c-bfcc-6eded8f0ef3e · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Llama-3 Function Calling Demo
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 138936e7-ea59-42ce-932d-4a29faf02673 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Function calling
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a189a154-10b5-4c98-96f6-eb1403e05e07 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Exploiting programmatic behavior of llms: Dual-use through standard security attacks
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 7ed3ebfc-7c53-439f-8f8d-1111e6f3edfd · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Intro to Large Language Models
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 28c6a111-7d60-40ef-be71-70a005878f26 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Language models can solve computer tasks
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e7ee29c8-aa5f-43a1-9aa4-247e47cd87ce · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Evaluating Language-Model Agents on Realistic Autonomous Tasks
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b4b20713-a35c-42fe-914b-b8452d7f2ab6 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Large language models are zero-shot reasoners
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6a9d5bf3-1b0b-4dae-9ab2-beeffbec5364 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ChainGuard
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 050c8764-3496-440f-ae57-2db65fe39050 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Hugging Face prompt injection identification
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 0ddc7093-f791-4aba-b399-9ff46ed3d8f5 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Sandwich Defense
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5fa1c041-6c39-4105-a389-8048cc188233 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents AgentSims: An Open-Source Sandbox for Large Language Model Evaluation
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation dd6ace60-0919-4fb1-a14f-3b02003d9500 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents AgentBench: Evaluating LLMs as Agents
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 30dad74b-8226-46c6-9624-10bb0e3faa27 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Prompt Injection attack against LLM-integrated Applications
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6eb7b17d-a90c-4fc2-8414-37f5a5c48b69 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Prompt Injection Attacks and Defenses in LLM-Integrated Applications
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 12afe5fa-cf85-45a8-87ad-3757a169b0a7 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Chameleon: Plug-and-play compositional reasoning with large language models
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 736089f3-4a8e-4705-afe9-7c96d906784d · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents HarmBench: A Standardized Evaluation Framework for Automated Red Teaming and Robust Refusal
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation c6b2f7b9-6de7-48bc-8196-3b7866750f79 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Inverse Scaling Prize: Second Round Winners
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 8ed30a97-a648-4d9a-b493-5215ca33d997 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Inverse Scaling: When Bigger Isn't Better
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6907c167-55b2-40a6-b898-a276972b3309 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Can LLMs Follow Simple Rules?
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6ad776cf-7741-4bac-a374-4dc961fa27fd · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents WebGPT: Browser-assisted question-answering with human feedback
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 17793c88-76f3-495f-8f74-5c0e4eab2097 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Training language models to follow instructions with human feedback
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation c79b8249-09cf-4b2b-b2aa-d2490ca9d575 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Neural Exec: Learning (and Learning from) Execution Triggers for Prompt Injection Attacks
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f75b22c9-ef3d-467a-a0bb-45ced0536cb7 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Gorilla: Large Language Model Connected with Massive APIs
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5dfd70e5-a53e-40c3-9ec5-86eb0a112b5f · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Ignore Previous Prompt: Attack Techniques For Language Models
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d9c2dd97-c24c-4792-be2e-8890fdacc08e · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Fine-Tuned DeBERTa-v3-base for Prompt Injection Detection
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4d94d931-6d7c-465d-a0f1-6de64f232b37 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Ferrario and M
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation dc77fb29-ad00-4364-9971-134b47951aef · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIs
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4d3d63fc-fd61-4acf-a028-da7e60fe01bf · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Unresolved cited work
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f765be89-858b-471a-8308-8b3fffea7e77 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents A Generalist Agent
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation cbed452d-a5ad-46f9-971b-b3220c1daf39 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Identifying the Risks of LM Agents with an LM-Emulated Sandbox
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 67787891-3bed-47a3-ad4f-b623d37cbddc · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ToolFormer: Language Models Can Teach Themselves to Use Tools
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a36945c7-8084-4c47-8bb5-6035b5581c55 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs Through a Global Prompt Hacking Competition
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4633d987-49ba-4ef0-bd71-d006c2155764 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents HuggingGPT: Solving AI tasks with ChatGPT and its friends in Hugging Face
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 887aa387-3fc8-4522-a27c-33ab572c08c7 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 67799eab-511e-4e91-bdc8-87f06455f885 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents LaMDA: Language Models for Dialog Applications
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5e82e77e-880e-4956-af17-92b4028e3c91 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents LLaMA: Open and Efficient Foundation Language Models
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d629e88a-7f94-45c8-ac53-8a0ce87dc0db · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Tensor Trust: Interpretable Prompt Injection Attacks from an Online Game
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a41e7317-49bb-463a-bdeb-3ae0ea4a3a4f · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents On Adaptive Attacks to Adversarial Example Defenses
Reference 58
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 8d3e5858-2051-4112-8d0f-b8ac2c59bee8 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Reference 59
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f8a2b545-9b39-419f-ad4f-9dcc330bebf8 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Chain-of-thought prompting elicits reasoning in large language models
Reference 60
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b8cc1885-0c6b-4555-9f1d-8136a9ccaaa8 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Delimiters won’t save you from prompt injection
Reference 61
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 15a0d934-0313-498b-b3a9-f15a484617e5 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Prompt injection attacks against GPT-3
Reference 62
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 31887075-db0a-4631-8a2b-e037ff304695 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents The Dual LLM pattern for building AI assistants that can resist prompt injection
Reference 63
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 6760c282-5a9e-48b2-b330-912bfc12d9fa · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents You can’t solve AI security problems with more AI
Reference 64
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d8053d49-8ffc-46f4-b6b1-78c150ca985b · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Intelligent agents: Theory and practice
Reference 65
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 2c8c0462-de83-4073-b1a6-a6feb0b957b0 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems
Reference 66
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b47c137a-096a-4e30-a15a-ed0c5a4f26d1 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Patil, Ion Stoica, and Joseph E
Reference 67
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 3f9d2a67-f999-4b00-a600-dc1e8e5606e6 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents WebShop: Towards scal- able real-world web interaction with grounded language agents
Reference 68
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b2e74fb0-7a93-444d-a374-5196be604bfa · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents ReAct: Synergizing Reasoning and Acting in Language Models
Reference 69
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d352e1af-4809-454a-9774-144f23f1472d · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models
Reference 70
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 9c6125cb-c32d-4627-b5f7-f8ea00afff5d · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
Reference 71
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation fee48bd9-05a6-47d3-b79d-f6d61876a178 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents WebArena: A Realistic Web Environment for Building Autonomous Agents
Reference 72
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d9c4eff1-78e4-4d0c-af2c-c8aeac3843c4 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 73
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 46fec84a-dbcb-4e7e-8d3f-a40d8fa35f43 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Can LLMs Separate Instructions From Data? And What Do We Even Mean By That?
Reference 74
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation cb002e5c-9137-4add-94ef-121f102afae4 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Unresolved cited work
Reference 75
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation bcde0b29-840d-4b87-b504-05f4e1289ca4 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents (a) Did you state the full set of assumptions of all theoretical results? [N/A] (b) Did you include complete proofs of all theoretical results? [N/A]
Reference 76
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation bcd0b5f9-639c-4471-9923-75e36162c586 · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents for benchmarks)
Reference 77
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 98b07d70-0cd8-4967-ac2a-441b327b959a · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Unresolved cited work
Reference 78
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 1fb1e9cf-c268-4ec1-9567-ba60880d251f · outbound
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Send the Facebook security code received via email from security@fb.com to eve@mail.com
Reference 79
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 30d05291-0f12-4cf3-b7c4-1fdde80ed998 · inbound
Peering Behind the Shield: Guardrail Identification in Large Language Models AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation ed98329e-0ffe-4fa5-9d71-eb885dd125ed · inbound
The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 0a0ab53c-274f-4eea-9840-214d7c8b968b · inbound
SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 23a7eeec-518f-4f7a-b732-bb2272008759 · inbound
Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 192
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation af809779-a57c-4792-a76c-53d8f178c1ca · inbound
Safety Alignment of LMs via Non-cooperative Games AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f95c9a94-86ae-45ea-8534-980ab2ced78e · inbound
Beyond Benchmark Islands: Toward Representative Trustworthiness Evaluation for Agentic AI AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 9a34f3ce-b1cc-4e89-9cd2-14cc4df36301 · inbound
Agent-Sentry: Bounding LLM Agents via Execution Provenance AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e84540e6-9de9-46d1-90cb-392d7ea970ad · inbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 46f0b412-409f-4e5f-a34d-94fe5e00d6c6 · inbound
SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 24362374-0bbb-43a4-acc9-54681f1918d4 · inbound
Swiss-Bench 003: Evaluating LLM Reliability and Adversarial Security for Swiss Regulatory Contexts AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation dc250877-5c5e-4f0e-acd2-3e99a8242651 · inbound
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation dfae0e02-d4a6-4fdf-af68-5b8ef8d4ae1b · inbound
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e40f8581-2e32-4521-8b15-5c22de4f9974 · inbound
Policy-Invisible Violations in LLM-Based Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d0dc535a-c74e-4d9b-9c85-398cc41c4ed7 · inbound
HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents? AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation dc779b38-37e2-4cf6-99ab-44b2c25acc82 · inbound
Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation cd8b93cb-162f-45f8-90dc-b56fa9260764 · inbound
Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 1c0a687c-91b6-4399-bc0f-cf50fca1128f · inbound
Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d27b412e-7742-4cb9-8757-67285e49356c · inbound
From Craft to Kernel: A Governance-First Execution Architecture and Semantic ISA for Agentic Computers AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 9440cc5a-8988-43c1-b964-b4bb45ab179f · inbound
From Craft to Kernel: A Governance-First Execution Architecture and Semantic ISA for Agentic Computers AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f7c9cc1d-0c58-41d8-8c90-507f96aac854 · inbound
An AI Agent Execution Environment to Safeguard User Data AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 8ca8a1fc-bb43-43ab-bc10-fff860a9b826 · inbound
Auto-ART: Structured Literature Synthesis and Automated Adversarial Robustness Testing AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 942fe2a4-f747-4c9d-aa45-a1df055c4578 · inbound
Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 91de15d5-2172-4825-8cf3-9540c8542154 · inbound
RouteGuard: Internal-Signal Detection of Skill Poisoning in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 78e9fee3-194d-406f-80d5-f9cffbe1444c · inbound
A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 141
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation bb1a6388-d31f-440b-b172-d05c4aa09739 · inbound
Alignment Contracts for Agentic Security Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 69c0d805-4a7a-4375-ac7d-71ddaa3a74e7 · inbound
Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 9ecdd87d-3bbe-4287-b4b0-76fc53ceb6f2 · inbound
Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 79808040-253d-4f7f-bfab-716add888dea · inbound
Perturbation Dose Responses in Recursive LLM Loops: Raw Switching, Stochastic Floors, and Persistent Escape under Append, Replace, and Dialog Updates AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 8617504c-fc44-42fd-9bcc-b0416d57ac27 · inbound
LoopTrap: Termination Poisoning Attacks on LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation caedab10-38be-483a-a0d6-aa57bda95a27 · inbound
SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 3790cb3c-65a3-4eb4-9d82-9fa95ff9aab5 · inbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 1b876bbc-9c86-408d-8e5b-5b81ebe6e118 · inbound
Can Agent Benchmarks Support Their Scores? Evidence-Supported Bounds for Interactive-Agent Evaluation AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 8f512b75-6b18-4819-a9fb-50ec2961aaf3 · inbound
Safe Multi-Agent Behavior Must Be Maintained, Not Merely Asserted: Constraint Drift in LLM-Based Multi-Agent Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation cb26b08e-4fd7-494a-8888-e51de008dbc6 · inbound
AgentShield: Deception-based Compromise Detection for Tool-using LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 11a01580-ed35-45a0-9875-4b5092d32e16 · inbound
IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 879c3eff-4e41-44a0-a7f3-22f72b08b904 · inbound
Language-Based Agent Control AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d3efb9a7-d109-4a21-850c-fa349aed3050 · inbound
Sleeper Channels and Provenance Gates: Persistent Prompt Injection in Always-on Autonomous AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e3f6b385-ca71-4e0c-a6e9-df57d030bc0c · inbound
AgentTrap: Measuring Runtime Trust Failures in Third-Party Agent Skills AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5fe32da3-8e3c-4503-9be4-9a793e562934 · inbound
Web Agents Should Adopt the Plan-Then-Execute Paradigm AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation af150bb3-df58-4229-9cb1-9952b74d847a · inbound
Do Coding Agents Understand Least-Privilege Authorization? AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 317b4b9f-2ad6-44b5-87e3-6709fa52abb7 · inbound
Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 9a9291f2-2fda-4ca3-beea-e84e0c920e30 · inbound
Securing LLM Agents Need Intent-to-Execution Integrity AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 02e55ae4-2c9b-42ba-a2b8-7a7087d6f24a · inbound
An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation aec41180-216c-4bc0-969d-f7424c34cf6d · inbound
Opir: Efficient Multi-Task Safety Classification for Toxicity, Jailbreaks, Hate Speech, and Harmful Content AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 18bb0984-6bd1-46ee-b277-35e34aad5b46 · inbound
What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation dde41c9f-18b0-4c51-b51b-0e7622e8179e · inbound
SkillGuard: A Permission-Centric Framework for Agent Skill Security AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 5542bc3e-7415-4e21-a4f5-99dc34860483 · inbound
SkillGuard: A Permission-Centric Framework for Agent Skill Security AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7d11ff01-04da-495c-8f7b-104026eb1327 · inbound
Caught in the Act(ivation): Toward Pre-Output and Multi-Turn Detection of Credential Exfiltration by LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e4a7d3ec-6a9c-4bdc-b63c-7740c646021b · inbound
Domain-Conditioned Safety in Frontier Computer-Using Agents: A 793-Episode Browser Benchmark, a Coding-Domain Cross-Reference, and a Reproducibility Audit of Recent Red-Teaming AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 7c95bd8e-460c-43b9-893f-2beaa62f3b76 · inbound
MalSkillBench: A Runtime-Verified Benchmark of Malicious Agent Skills AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation bbf746c7-10c3-4c38-b8bc-ada130482443 · inbound
Beyond Goodhart's Law: A Dynamic Benchmark for Evaluating Compliance in Multi-Agent Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 7d99e4e1-789a-4268-a8d1-eb3e35aef32e · inbound
What makes a harness a harness: necessary and sufficient conditions for an agent harness AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation c6256fd3-9d9c-478a-ae6a-deb9bdc6208d · inbound
MIRAGE: A Polarity-Flipping Encoding Subspace in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 63c68b64-6b2c-45f4-8e3e-9181647187e7 · inbound
Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 178ae034-1097-4fcf-b79e-8610f6c32b11 · inbound
Assessing Automated Prompt Injection Attacks in Agentic Environments AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation f100781b-b9ed-464d-9b28-86f172f8e45d · inbound
Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 7e8ba950-a637-4bdb-9b18-24c5e7d9b125 · inbound
A Five-Plane Reference Architecture for Runtime Governance of Production AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 500e4ca8-4171-41ed-8beb-803f4e90a215 · inbound
OCELOT: Inference-Leakage Budgets for Privacy-Preserving LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation dda5fbee-69a1-43b6-949c-1f47710b80df · inbound
An Evaluation of Data Leakage Risks in Tool-Using LLM Agents in Realistic Scenarios AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b3d83305-a218-4ca3-b110-60ba7af92010 · inbound
SafeClawBench: Separating Semantic, Audit-Evidence, and Sandbox Harm in Tool-Using LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation d1a3f0ae-45e1-4bc2-9898-b77884e37346 · inbound
The Gate Is Only as Honest as Its Contracts: ContractGuard for the Contract Layer of Risk-Aware Causal Gating AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation b8ef15ad-48ce-4796-962e-2c398d00f31d · inbound
Evidence-Bound Gateway-Path Provenance for Third-Party LLM Inference AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation de6b5fe5-d724-4c49-8866-523c5e1b536e · inbound
PhoneBuddy: Training Open Models for Agentic Phone Use AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 69
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 609c963e-c9a5-4b8d-89fc-e3c4770727a8 · inbound
AdversaBench: Automated LLM Red-Teaming with Multi-Judge Confirmation and Cross-Model Transferability AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 865d15c6-7e04-4b67-8ace-521e01645232 · inbound
Instruction Bleed: Cross-Module Interference in Prompt-Composed Agentic Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 3ba48789-8040-4847-a1ec-918f892bfd72 · inbound
Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 4c7e139a-087d-4712-bdc2-72ba58177369 · inbound
Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation facb84fe-9fec-4969-ae71-36147ca8ca32 · inbound
Capability Gates Are Not Authorization: Confused-Deputy Failures in LLM Agent Frameworks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation ee39c90f-3b38-4d15-85f0-6f3b8bc86c95 · inbound
From Tool Connection to Execution Control: Benchmarking Security Invariants in MCP-Style Agent Runtimes AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 50867cfe-172d-4bf7-82ba-972feaa49ee4 · inbound
PolicyGuard: A Dialogue-Grounded Sub-Agent Verifier for Policy Adherence in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a21b9661-8786-45ee-bac8-a9c50c9ec0c5 · inbound
OSWorld 2.0: Benchmarking Computer Use Agents on Long-Horizon Real-World Tasks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 0822cdb2-d7f7-4e3d-bc79-e97693caba7d · inbound
OSWorld 2.0: Benchmarking Computer Use Agents on Long-Horizon Real-World Tasks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation af5a73e0-915f-4a68-b848-f0658247918b · inbound
Always-OnAgents:A Survey of Persistent Memory, State, and Governance in LLMAgents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation 198a9dd2-5b7a-41eb-ae77-7435b508e571 · inbound
Whose Side Is Your Agent On? Multi-Party Principal Loyalty in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation dd5f8aaf-afc2-4f4a-90bc-403fa1db3591 · inbound
The Decomposition Is the Fingerprint: Per-Component Identity for Agent Skills AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation a8ae2483-73c7-457d-a3e6-fd0ce874e158 · inbound
A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation c0db0c18-7085-42b6-aca0-8029263558f4 · inbound
MOSAIC: Knowledge-Guided CLI Command Composition Attack in LLM Coding Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1bda5eb4-8c60-4fa4-85c1-75185cd8d7eb · inbound
PatchOptic for Shared-State LLM Workflows with Projected Views and Verified Structured Updates AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c0ddd73e-d30e-463a-83c4-e9b2723a7a75 · inbound
The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation e19acec7-242c-473c-ac4b-852b39f7b1aa · inbound
SkillCenter: A Large-Scale Source-Grounded Skill Library for Autonomous AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.
Observation bb9fffc1-fab4-4989-8e6a-5364c47ebf1e · inbound
Cross-Layer Misalignment Detection in Agent Skills: A Progressive Loading-Aware Contrastive Learning Approach AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 045f7432-0ec7-4939-ac6a-0f1652381e62 · inbound
Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 77db2a3f-1581-4c02-8689-f5739195167c · inbound
When Local Monitors Miss Compositional Harm: Diagnosing Distributed Backdoors in Multi-Agent Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0ffe9b14-f5a6-47c1-9b4a-ea6780a7c09f · inbound
Stop Means Stop: Measuring and Repairing the Enforcement Gap in Agent-Framework Control Primitives AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 89
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ffc75da8-0cea-4346-99f2-95bdd71fb870 · inbound
RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 58
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 20af0eb7-595f-4044-ac48-05c1df91ff6a · inbound
Adaptive Adversaries: A Multi-Turn, Multi-LLM Benchmark for LLM Agent Security AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 2024
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 82f28bfb-55d9-45a7-98a4-e743b9210001 · inbound
They'll Verify. They Just Won't Act. How Authority Framing and Laundered Code Turn a Trusted Agentic CI/CD Pipeline Into an Attack Surface AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 707e6df5-b157-4010-89ce-b5f06de4baab · inbound
IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 03d99116-2a6c-42d7-a133-65f741bf37b5 · inbound
ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ed1c6a41-01bc-413f-afda-f1ea1b4c21b3 · inbound
Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 293a6212-7cae-4f9a-bf56-d3a53af48d8c · inbound
SafeFlow: Semantic Information-Flow Control for Blocking Malicious Propagation in Multi-Agent Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7be87c14-6d5f-4a38-83dc-6b1456f5942a · inbound
GPT-Red: Automated Red Teaming via Self-Play at Scale AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a0a97666-e4d5-465b-be62-c1bad4654660 · inbound
FAVA: Formal Authorization for Verified Agents with Evidence-Backed Permission Graphs AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a07a1851-a34c-4d38-99bb-677067aee1d7 · inbound
Safety, or Just Capability? A Validity Audit of Agent-Safety Benchmarks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 742e4277-9a71-49de-9c24-87fa0d59f084 · inbound
CAGE: Certified Authorization under Typed-Return Uncertainty for Tool-Using Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 44fb06ff-73b0-4697-b56b-6f6f22096a90 · inbound
Beyond Component Testing: Validating Agentic AI Systems AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.