{"as_of":"2026-08-07T08:16:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:83dff0e9247b50c9146df0872b1d03f750eb044ec188f44ed6ed6298fce7e26d","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":6,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":6,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-07T06:34:17.273281+00:00","state":"measured"},{"denominator":6,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":6,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-06T21:16:25.979328Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":1,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2502.09809","last_updated":"2025-02-13T23:00:33Z","snapshot_observed_at":"2026-08-07T02:30:41.970309Z","submitted_at":"2025-02-13T23:00:33Z","title":"AgentGuard: Repurposing Agentic Orchestrator for Safety Evaluation of Tool Orchestration","version":1},"cited_work":{"arxiv_id":"2502.09809","doi":"10.48550/arxiv.2502.09809","metadata_source":"arxiv_reference","pith_arxiv_id":"2502.09809","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentguard: Repurposing agentic orchestrator for safety evaluation of tool orchestration","venue":"ArXiv.org","work_id":"27b98927-2fa7-4d69-ad47-fbe3148a686f","year":2025},"citing_paper":{"arxiv_id":"2503.23278","last_updated":"2025-10-07T07:13:32Z","snapshot_observed_at":"2026-07-06T21:00:55.979837Z","submitted_at":"2025-03-30T01:58:22Z","title":"Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions","version":3},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-05-13T09:02:40.294491Z"},"links":{"cited_paper":"/paper/2502.09809","citing_paper":"/paper/2503.23278"},"observation_digest":"sha256:10609521b1098a41be08282ad0becc6362ec864d19c3a241e301590d556d3465","observation_id":"ee8888f1-10c7-40d6-8a58-65a99a74cd92","resolution":{"observed_at":"2026-05-13T09:02:40.332250Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2502.09809","last_updated":"2025-02-13T23:00:33Z","snapshot_observed_at":"2026-08-07T02:30:41.970309Z","submitted_at":"2025-02-13T23:00:33Z","title":"AgentGuard: Repurposing Agentic Orchestrator for Safety Evaluation of Tool Orchestration","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2502.09809","snapshot_observed_at":"2026-08-06T21:16:25.979328Z","title":"Agentguard: Repurposing agentic orchestrator for safety evaluation of tool orchestration","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2507.02986","last_updated":"2025-07-08T15:44:49Z","snapshot_observed_at":"2026-08-06T21:08:26.227267Z","submitted_at":"2025-07-01T10:01:21Z","title":"GAF-Guard: An Agentic Framework for Risk Management and Governance in Large Language Models","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-06T21:16:25.979328Z"},"links":{"cited_paper":"/paper/2502.09809","citing_paper":"/paper/2507.02986"},"observation_digest":"sha256:a8e3ac9b351aa3c5138dd131d89da25ecb80027bb7b21055397d246ab89899e4","observation_id":"e1012037-ce4f-4196-9ac4-4961c806a089","resolution":{"observed_at":"2026-08-06T21:16:25.979328Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.09809","last_updated":"2025-02-13T23:00:33Z","snapshot_observed_at":"2026-08-07T02:30:41.970309Z","submitted_at":"2025-02-13T23:00:33Z","title":"AgentGuard: Repurposing Agentic Orchestrator for Safety Evaluation of Tool Orchestration","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2502.09809","snapshot_observed_at":"2026-08-06T16:12:47.563041Z","title":"Agentguard: Repurposing agentic orchestrator for safety evaluation of tool orchestration","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2507.14293","last_updated":"2025-07-18T18:06:27Z","snapshot_observed_at":"2026-08-06T15:57:20.673152Z","submitted_at":"2025-07-18T18:06:27Z","title":"WebGuard: Building a Generalizable Guardrail for Web Agents","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-06T16:12:47.563041Z"},"links":{"cited_paper":"/paper/2502.09809","citing_paper":"/paper/2507.14293"},"observation_digest":"sha256:567051c151fe687e49d6dfe5ee626e04bc9beeaf5e609dcbe57ef51e5130e1a7","observation_id":"a8d481dd-6c7e-4b82-9855-b9dc97a5beb5","resolution":{"observed_at":"2026-08-06T16:12:47.563041Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.09809","last_updated":"2025-02-13T23:00:33Z","snapshot_observed_at":"2026-08-07T02:30:41.970309Z","submitted_at":"2025-02-13T23:00:33Z","title":"AgentGuard: Repurposing Agentic Orchestrator for Safety Evaluation of Tool Orchestration","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2502.09809","snapshot_observed_at":"2026-08-04T21:44:12.255241Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2509.07764","last_updated":"2025-09-09T13:59:00Z","snapshot_observed_at":"2026-08-04T21:44:11.122043Z","submitted_at":"2025-09-09T13:59:00Z","title":"AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-04T21:44:12.255241Z"},"links":{"cited_paper":"/paper/2502.09809","citing_paper":"/paper/2509.07764"},"observation_digest":"sha256:df3a26a75670a1e7398ed6b01ba367c1d1fb4f7f7ae2667c2613b4b2523fb95e","observation_id":"1a5b4932-8627-4a94-9cac-450a8a5096e3","resolution":{"observed_at":"2026-08-04T21:44:12.255241Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.09809","last_updated":"2025-02-13T23:00:33Z","snapshot_observed_at":"2026-08-07T02:30:41.970309Z","submitted_at":"2025-02-13T23:00:33Z","title":"AgentGuard: Repurposing Agentic Orchestrator for Safety Evaluation of Tool Orchestration","version":1},"cited_work":{"arxiv_id":"2502.09809","doi":"10.48550/arxiv.2502.09809","metadata_source":"arxiv_reference","pith_arxiv_id":"2502.09809","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentguard: Repurposing agentic orchestrator for safety evaluation of tool orchestration","venue":"ArXiv.org","work_id":"27b98927-2fa7-4d69-ad47-fbe3148a686f","year":2025},"citing_paper":{"arxiv_id":"2603.09002","last_updated":"2026-04-26T14:13:48Z","snapshot_observed_at":"2026-07-06T22:48:26.306802Z","submitted_at":"2026-03-09T22:46:27Z","title":"Security Considerations for Multi-agent Systems","version":2},"reference_index":300,"source":"pdf_text","source_observed_at":"2026-05-15T14:12:14.160789Z"},"links":{"cited_paper":"/paper/2502.09809","citing_paper":"/paper/2603.09002"},"observation_digest":"sha256:68bf364e0aabfd81f88ebf498329f52e0691fc15c20aa7f1edf9e9069be988fa","observation_id":"bf1c9516-6c0f-4798-8168-4f881ed04cdc","resolution":{"observed_at":"2026-05-15T14:15:55.719083Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2502.09809","last_updated":"2025-02-13T23:00:33Z","snapshot_observed_at":"2026-08-07T02:30:41.970309Z","submitted_at":"2025-02-13T23:00:33Z","title":"AgentGuard: Repurposing Agentic Orchestrator for Safety Evaluation of Tool Orchestration","version":1},"cited_work":{"arxiv_id":"2502.09809","doi":"10.48550/arxiv.2502.09809","metadata_source":"arxiv_reference","pith_arxiv_id":"2502.09809","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentguard: Repurposing agentic orchestrator for safety evaluation of tool orchestration","venue":"ArXiv.org","work_id":"27b98927-2fa7-4d69-ad47-fbe3148a686f","year":2025},"citing_paper":{"arxiv_id":"2606.10749","last_updated":"2026-06-09T12:01:07Z","snapshot_observed_at":"2026-07-31T21:35:18.696472Z","submitted_at":"2026-06-09T12:01:07Z","title":"Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-06-27T12:55:22.831264Z"},"links":{"cited_paper":"/paper/2502.09809","citing_paper":"/paper/2606.10749"},"observation_digest":"sha256:79f3b37599d27407314dce6ba2a23876344f8e9e3c90e6c72cd7957d7c2a26d0","observation_id":"b8e86c0e-7c05-4626-bed0-5059e592910f","resolution":{"observed_at":"2026-06-27T13:20:56.690720Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2502.09809/citation-record","integrity":"/paper/2502.09809/integrity","json":"/paper/2502.09809/citation-record.json","paper":"/paper/2502.09809"},"outbound":[],"paper":{"arxiv_id":"2502.09809","last_updated":"2025-02-13T23:00:33Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-07T02:30:41.970309Z","submitted_at":"2025-02-13T23:00:33Z","title":"AgentGuard: Repurposing Agentic Orchestrator for Safety Evaluation of Tool Orchestration"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"thesis":"As of 7 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 6 inbound Pith citation observations for arXiv:2502.09809."}