Pith. sign in

Paper Citation Record · LEDGER

AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

As of 7 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 16 inbound Pith citation observations for arXiv:2505.05849.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.05849 v4

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 16 of 16 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 16 of 16 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-06T15:42:01.058771Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-04T10:09:45.177863Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 1b69edd8-c974-46b4-8663-438abb005067 · inbound

Progent: Securing AI Agents with Privilege Control cites this paper.

Progent: Securing AI Agents with Privilege Control AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 64

Resolution
verified exact
arxiv_id, observed 2026-05-22T21:12:08.484176Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-22T21:09:51.782808Z digest=sha256:d26f8bfa4f371e08f45faa02083b1e3531870f29e33ea8cfa2e8bbcb2abf177e

Observation 3f6dbd46-137c-4c4a-b0c3-bd62c8ba26ba · inbound

PromptArmor: Simple yet Effective Prompt Injection Defenses cites this paper.

PromptArmor: Simple yet Effective Prompt Injection Defenses AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-06T15:42:01.058771Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T15:42:01.058771Z digest=sha256:012efd859a187912e1ac565a8afc65b327a10a94d5b33fd057482296d154c516

Observation 59e59dd2-a947-4309-b9b2-8a72a1bf3145 · inbound

Agentic Web: Weaving the Next Web with AI Agents cites this paper.

Agentic Web: Weaving the Next Web with AI Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 224

Resolution
unresolved
no resolver link, observed 2026-08-06T13:05:40.367994Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T13:05:40.367994Z digest=sha256:a78eeafbfdac5b54021d96b231330489d70347b941bb90952e2eb28a54b4b689

Observation e01b55d3-0550-41b1-b9e0-7a7aaf50e233 · inbound

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation cites this paper.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 52

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.054246Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:1b7a847dc34c680962476cae11c803559b298dcb8f8ec67f1677bf2fca5424a2

Observation 3ef61d7f-ae1b-4ee4-92bc-5f80b0238b63 · inbound

Agent Security is a Systems Problem cites this paper.

Agent Security is a Systems Problem AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 75

Resolution
verified exact
arxiv_id, observed 2026-05-20T09:03:09.842181Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-20T09:02:59.719090Z digest=sha256:5d63766d22263330c3b5bf430e00de4987eefab5846f5c0f4410a9e82f578366

Observation f3353e1c-a6ab-42ad-94a8-a09152700dd7 · inbound

Agent Security is a Systems Problem cites this paper.

Agent Security is a Systems Problem AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 75

Resolution
verified exact
arxiv_id, observed 2026-05-21T07:44:02.914269Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-05-21T07:43:14.250188Z digest=sha256:74774e15d5fe2c2a1776b317e9243ad70480b5cfb50e3bd8ecc10f59a25068a2

Observation 403464f2-3a56-4ea4-ac84-709e17e2fe54 · inbound

Hallucination as Exploit: Evidence-Carrying Multimodal Agents cites this paper.

Hallucination as Exploit: Evidence-Carrying Multimodal Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-20T09:48:11.589903Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=arxiv_source observed=2026-05-20T09:46:42.413501Z digest=sha256:6a662cf4b5837436a887a031ab0a8067cec93751f65370f6bc84d968e13c6b87

Observation d44f66e0-cfef-4cdc-b84b-b769a5bd773c · inbound

Hallucination as Exploit: Evidence-Carrying Multimodal Agents cites this paper.

Hallucination as Exploit: Evidence-Carrying Multimodal Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-22T09:01:19.894756Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=arxiv_source observed=2026-05-22T08:57:29.491043Z digest=sha256:74fb84822fdd8626cb1604a9e3b8dd8ef3286cb0d8e1529ba03a4201215ea23b

Observation eb3ef02b-eb9b-4acb-8c6b-1a6272bf5342 · inbound

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models cites this paper.

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 21

Resolution
metadata mismatch
arxiv_id, observed 2026-06-28T19:22:34.394638Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=arxiv_source observed=2026-06-28T19:19:17.673497Z digest=sha256:39f143be3b38ad8949f1dc16ff2a8d7f8aaca05beafa89e04da602b26cafe427

Observation 412cde2d-a5bb-4fc3-bbf5-52bb12fd7d8a · inbound

Assessing Automated Prompt Injection Attacks in Agentic Environments cites this paper.

Assessing Automated Prompt Injection Attacks in Agentic Environments AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.945423Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:9f0058a358ebbe47a42916000a6fbac1d41e46b85cd9e967f96d792221589b71

Observation d3594358-41db-416a-ba7e-17f323c11cce · inbound

PI-Hunter: Automated Red-Teaming for Exposing and Localizing Prompt Injections cites this paper.

PI-Hunter: Automated Red-Teaming for Exposing and Localizing Prompt Injections AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 28

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T12:38:07.269748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=arxiv_source observed=2026-06-27T08:56:12.882653Z digest=sha256:82c139e240ceac14036dae573acef1497169879745a111f0b72deb0de57a4c23

Observation f47fff1d-8f9a-4b0b-a561-ff066adb7b40 · inbound

Same-Origin Policy for Agentic Browsers cites this paper.

Same-Origin Policy for Agentic Browsers AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-07-01T07:35:29.017390Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-07-01T07:29:08.355105Z digest=sha256:ec1d4176198ebd19ed0e8d2bb659de4376a5db76cf969c79fc47e4fe9823ccd9

Observation 92e8edb9-0134-4a58-9b27-8bcfe956fd8a · inbound

When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents cites this paper.

When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-07-04T10:09:45.179850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-26T09:05:22.096955Z digest=sha256:f0b4e39eae7f988d4e06fadac02a4fa79764e8e056fff8c3e09de4db22102657

Observation fc937447-2d5a-4b84-b05b-49bdfdbedfc9 · inbound

CONTRA: Red-Teaming Configurations of Personalizable Agents cites this paper.

CONTRA: Red-Teaming Configurations of Personalizable Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 13

Resolution
unresolved
no resolver link, observed 2026-07-12T04:03:40.067404Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-07-12T04:03:40.067404Z digest=sha256:39bda7ff7a89ad4fe10d993825ac2b8de7954918cefe4fe6600ab0b9f6505a0c

Observation 1b17e9f1-3daf-4a2b-ae26-da210751b368 · inbound

Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents cites this paper.

Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T11:38:19.674889Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T11:38:19.674889Z digest=sha256:27522d0df22b1fa7d31b5bce6e78ae1c87f9a4c7500f6386fe0cf4ae70b48fb0

Observation c76f5e9b-e5d3-4311-b3ff-1e806e38fac5 · inbound

GPT-Red: Automated Red Teaming via Self-Play at Scale cites this paper.

GPT-Red: Automated Red Teaming via Self-Play at Scale AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T01:12:44.169745Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T01:12:44.169745Z digest=sha256:21e9f88279c8491c72d7ff1b064904e9641d3497a9b6d80ced7e3a363e45ca0d