Pith. sign in

Paper Citation Record · LEDGER

Imprompter: Tricking LLM Agents into Improper Tool Use

As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 26 inbound Pith citation observations for arXiv:2410.14923.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2410.14923 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 26 of 26 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 26 of 26 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T15:37:51.603999Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

2
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 66e6083f-e437-47c3-874b-88c06a6b83e7 · inbound

Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions cites this paper.

Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-13T09:02:40.411688Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-13T09:02:40.294491Z digest=sha256:70abe8991984ad08ac65549f34d2a4b4e22b7fafed6388b7d3bbff6d96eb1690

Observation aab7e631-2d14-4b0c-921c-5c3990c973cf · inbound

Lessons from Defending Gemini Against Indirect Prompt Injections cites this paper.

Lessons from Defending Gemini Against Indirect Prompt Injections Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-07T15:37:51.603999Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:37:51.603999Z digest=sha256:b497d0ba4783517fc0b484f01f30342986d07b839cd63fda3cee6bd310299def

Observation ac2626e6-3ed5-47fa-8f37-4d423204ba59 · inbound

Data-Centric Safety and Ethical Measures for Data and AI Governance cites this paper.

Data-Centric Safety and Ethical Measures for Data and AI Governance Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T04:34:08.000242Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T04:34:08.000242Z digest=sha256:48bdbbe1c0edc69e2227f82c2030c5789e2ff2700c2e6b148457b3aba067ac34

Observation 87ea844c-4b84-4efe-b22f-b0f8cc12c09b · inbound

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems cites this paper.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.507283Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.507283Z digest=sha256:adf322d400f2324ca72ace93cd72577cf5781b81bc6148eaed0efde490c0a8c0

Observation ef7e3098-7e36-4660-b5c1-1aa73879559b · inbound

FaSTA$^*$: Fast-Slow Toolpath Agent with Subroutine Mining for Efficient Multi-turn Image Editing cites this paper.

FaSTA$^*$: Fast-Slow Toolpath Agent with Subroutine Mining for Efficient Multi-turn Image Editing Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-05-19T08:17:10.746601Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-19T08:17:08.223736Z digest=sha256:14c95ddf47599aed53a0c472fa853363a1264420368a13103e94957123fb15ce

Observation b8580e78-b2fc-44d8-ad47-fd96cdb4f583 · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 122

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:45.093922Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:45.093922Z digest=sha256:11eb3df8dfcf302041cbe99d680b579e45b2fd92252bb545537e8f911ed0cded

Observation 757c4528-ba1f-4594-9e0b-f07bfcbb87e9 · inbound

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree cites this paper.

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-06T15:52:56.510579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T15:52:56.510579Z digest=sha256:0e5e53d698e307fd6a14c1037b9a6dfc6cf0c158fe8968387b3fffb5a39add1a

Observation 4a7c8dd4-d55a-448e-aa63-0896643f70a5 · inbound

On the Future of Software Reuse in the Era of AI Native Software Engineering cites this paper.

On the Future of Software Reuse in the Era of AI Native Software Engineering Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T15:29:05.783421Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T15:29:05.783421Z digest=sha256:bd0034498e2bad0493a60a3eabcdcfdc98827d0241ac0780365af113dac9ab1f

Observation dc60bca4-8180-45eb-ab43-56784df000e4 · inbound

AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents cites this paper.

AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-04T21:44:12.278474Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T21:44:12.278474Z digest=sha256:0442214e58247c27445dce548b70effd8cd9c4bdbd960e35ff04071dcfc0e396

Observation 02c1bb54-0bef-4954-b47c-dde9e019eabb · inbound

AgentBound: Securing Execution Boundaries of AI Agents cites this paper.

AgentBound: Securing Execution Boundaries of AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
metadata mismatch
arxiv_id, observed 2026-05-18T05:15:54.156005Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-18T05:12:23.542793Z digest=sha256:a990aacc6d093ef14ad5b423d3562cc73645dd5d4dbea617d498c15227dd564f

Observation 8fae375b-c2cf-4058-b1bf-1bed57620730 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 45

Resolution
metadata mismatch
arxiv_id, observed 2026-05-18T03:42:22.516285Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:0155753e2770d522efbd32b7ebcb757b3c666003918c9acbed4fc6ab247581e0

Observation 2f4b6a39-39f6-49ec-80b1-3cfe183eaf56 · inbound

GUIGuard-Bench: Toward a General Evaluation for Privacy-Preserving GUI Agents cites this paper.

GUIGuard-Bench: Toward a General Evaluation for Privacy-Preserving GUI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 56

Resolution
metadata mismatch
arxiv_id, observed 2026-05-16T11:32:48.257431Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-16T11:31:16.087579Z digest=sha256:d5d9839c14f2ba627caff885c937b7a5e09d82a181168d5c00b00f16f01bc31a

Observation 5d05004d-b4bb-4c5f-ad2c-0db093425c95 · inbound

Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP cites this paper.

Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 71

Resolution
verified exact
arxiv_id, observed 2026-05-16T05:07:20.812637Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-16T05:05:16.370606Z digest=sha256:5fb6336adb4848e48e4558f13e3096f49630e1c604888b4a3c7062e21546f434

Observation fe22c24f-fdc2-4fff-94a8-7539659ed8de · inbound

From Storage to Steering: Memory Control Flow Attacks on LLM Agents cites this paper.

From Storage to Steering: Memory Control Flow Attacks on LLM Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 1

Resolution
unresolved
no resolver link, observed 2026-07-14T20:40:43.875392Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-14T20:40:43.875392Z digest=sha256:72a39e044b647b65ccc8e7ff6554f44410e623e2a5ba91f031948d22d78d2401

Observation f631d8a7-2d9a-4229-aa2a-57fef3addcd8 · inbound

How Your Credentials Are Leaked by LLM Agent Skills: An Empirical Study cites this paper.

How Your Credentials Are Leaked by LLM Agent Skills: An Empirical Study Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 18

Resolution
verified exact
arxiv_id, observed 2026-05-13T19:53:11.688398Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-13T19:51:29.230241Z digest=sha256:26fb3fcbfa140848d38377b296201fc81ef3ff5da7106d5b318f69e4f1f89263

Observation 1fe5a63e-6a84-41a7-bcfe-92c99bfd40c2 · inbound

HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents? cites this paper.

HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents? Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-05-10T10:34:29.224645Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-10T10:32:37.967401Z digest=sha256:95ccab7e5b2780211995b1ce8a44d98cc3f6a59cdf47227cbc83d8b6edcccf5c

Observation bb9e389e-d419-4939-bb20-1b698435fbbf · inbound

WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections cites this paper.

WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 21

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T14:45:49.558073Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-30T20:16:13.413064Z digest=sha256:0ff05ec53e1339a64f124300d3383d87e21fd1359ad858d0ce75bac82acbc8e4

Observation 432be1f4-7116-4eb1-a1ec-aeef85c35e84 · inbound

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety cites this paper.

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-05-22T05:51:07.946360Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-22T05:50:28.114140Z digest=sha256:f2e60a3fa402512dcd82c4aa8fd9ede7c4a93b3d26fbf02601fbc38b6c48a4c1

Observation f4c8e78c-002a-4c01-bf51-b6d2680fb3ee · inbound

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety cites this paper.

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-05-25T06:06:43.046681Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-25T06:05:27.736494Z digest=sha256:be4dbf79a1b996da7033862866de0d82af81a3082671a4a2b8519993a8a9934d

Observation a32cd385-442e-4221-ae45-5eeb7ecd29dd · inbound

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents cites this paper.

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 127

Resolution
verified exact
arxiv_id, observed 2026-06-28T19:42:36.161487Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-06-28T18:53:41.420255Z digest=sha256:4548422e602fcb189f521ebb5dcb0c15867915c796e08a68fbf5d5b8708f643a

Observation 79b665f1-26d8-4d01-bda8-fcab0f5f660b · inbound

Assessing Automated Prompt Injection Attacks in Agentic Environments cites this paper.

Assessing Automated Prompt Injection Attacks in Agentic Environments Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.981522Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:0a2893a618a9c9ac6d07a48d087adf6f50d0c760eb5f991fc4ab746eab1baaf1

Observation 5486ad3f-d5bb-4798-af87-ff92b493f921 · inbound

SAIGuard: Communication-State Simulation for Proactive Defense of LLM Multi-Agent Systems cites this paper.

SAIGuard: Communication-State Simulation for Proactive Defense of LLM Multi-Agent Systems Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 17

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T13:28:18.842251Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-06-27T08:04:15.004591Z digest=sha256:45fd059f12b269228c4c5675a1062163d6d2cf475ebe2a5e4830388ef1c97fbb

Observation 8a2bfdbd-ac6d-49fe-a55a-265fd27b1e89 · inbound

AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents cites this paper.

AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 42

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T16:48:40.495135Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-27T04:57:54.827932Z digest=sha256:f86aeb60d86c6e3084a126515f16cea40a6193327c5aa0c826310b7e0160fd8b

Observation c52f5f5f-d966-4c28-9e05-07c50195f8c3 · inbound

DualView: Preventing Indirect Prompt Injection in Personal AI Agents cites this paper.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 58

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:1e5346bf28b1c3533a9b5d695e9c39139f08001f8ca10983b7e7dcdb2b38866b

Observation aa3314d3-c3fa-4027-98e2-0b3b8e754aea · inbound

Agent Data Injection Attacks are Realistic Threats to AI Agents cites this paper.

Agent Data Injection Attacks are Realistic Threats to AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 8

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:50436d8b3c883e9dc3ccc49e92798b74501057a0dd2657b717e8ab35e7cca234

Observation 61022b50-8da0-46cb-85f6-ca54b0432b68 · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 269

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.607188Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.607188Z digest=sha256:d6047d53369914c46c6a65257cb422f17d57006dbe35a191310ff93269e67529