Pith. sign in

Paper Citation Record · LEDGER

Design Patterns for Securing LLM Agents against Prompt Injections

As of 4 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 32 inbound Pith citation observations for arXiv:2506.08837.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.08837 v3

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 32 of 32 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-04T06:34:03.388597+00:00

measured 32 of 32 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-04T08:06:09.223677Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-07-10T12:27:04.097770Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 3035d91c-4bf4-4a01-b1b6-44cd415829a1 · inbound

Prompt Injection Attack to Tool Selection in LLM Agents cites this paper.

Prompt Injection Attack to Tool Selection in LLM Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 73

Resolution
metadata mismatch
arxiv_id, observed 2026-05-16T17:08:29.063576Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-16T17:08:28.933831Z digest=sha256:4d666b78b717096d7f7a8d3f761d67276168161abef5f4a5abaa1fa99cd93d04

Observation 557428b5-3b14-4f23-8503-e7b4b2f00627 · inbound

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents cites this paper.

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-04T08:06:09.223677Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T08:06:09.223677Z digest=sha256:7651755338b8b3724eb2699e215a127eb3e09bc22c6b758f650f118cd46c80ba

Observation 421e278b-f1e9-433b-a767-52f1e0f20db0 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Design Patterns for Securing LLM Agents against Prompt Injections

Reference 59

Resolution
metadata mismatch
arxiv_id, observed 2026-05-18T03:42:22.528614Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:f9b34e95b0f35f4638436388d239fee7255da59601e8306fea7e2f2408b87644

Observation ca0e399b-891b-47bc-8350-aca7d93946ee · inbound

Prevalence of Security and Privacy Risk-Inducing Usage of AI-based Conversational Agents cites this paper.

Prevalence of Security and Privacy Risk-Inducing Usage of AI-based Conversational Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-04T07:01:14.483509Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:01:14.483509Z digest=sha256:a708de53be8b827cf7b4bef8770c610cd5c3b98fb6083cfad8f5a7dec0b72e1a

Observation fcd2aeea-d216-45cd-9b46-e6ef4820eb08 · inbound

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation cites this paper.

Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation Design Patterns for Securing LLM Agents against Prompt Injections

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-22T12:51:33.451649Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-22T12:46:44.819224Z digest=sha256:8fcf6e914a1bc16d30671b492fac79124af793aa0b82786b4c3e9b970e967ed0

Observation 349bed18-f6e7-40a0-865b-88bc47d9813f · inbound

Tracking Capabilities for Safer Agents cites this paper.

Tracking Capabilities for Safer Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-15T18:36:29.247485Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-15T18:31:34.181629Z digest=sha256:f344b0933ec23f47ba84ada2f2ec47cba3e5f431379627f999455d02cfbb2293

Observation f47ad6d8-a9d1-4e8f-9fd3-bd17c9c387a4 · inbound

LogJack: Indirect Prompt Injection Through Cloud Logs Against LLM Debugging Agents cites this paper.

LogJack: Indirect Prompt Injection Through Cloud Logs Against LLM Debugging Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 1

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T13:55:29.084211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-10T13:51:49.515947Z digest=sha256:5d74c82c70472b2f2e45eb7f79ef882ea2a3cbe1c9d75e1a22d2e7a4a5082c50

Observation bbefcaaa-25ed-46d3-8971-260da12cc5e5 · inbound

Alignment Contracts for Agentic Security Systems cites this paper.

Alignment Contracts for Agentic Security Systems Design Patterns for Securing LLM Agents against Prompt Injections

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-05-11T15:01:04.910407Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-09T20:47:28.506174Z digest=sha256:2d084ec886866ca645ac4008d9abefc27f0bc123b5a0b032018ef394c4c730f8

Observation d3f339d7-4ece-4549-8ea7-e862d4488316 · inbound

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration cites this paper.

Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration Design Patterns for Securing LLM Agents against Prompt Injections

Reference 6

Resolution
metadata mismatch
arxiv_id, observed 2026-05-19T17:32:41.588564Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-19T17:30:22.481943Z digest=sha256:6f23002ecfe96a7801d1790e62b151d45b8533f106d6ebad4708611e03702301

Observation fbe41ca5-0fc7-48cf-935c-9ebc11b9416d · inbound

IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection cites this paper.

IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection Design Patterns for Securing LLM Agents against Prompt Injections

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-05-13T05:47:21.309927Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-13T05:46:07.132408Z digest=sha256:ebac1f14e903576d34f1fe27717f0051e08ade236c01be2b0447c2181e34ca78

Observation 89d9bc78-ec48-46d0-b108-58bea1a2e519 · inbound

Web Agents Should Adopt the Plan-Then-Execute Paradigm cites this paper.

Web Agents Should Adopt the Plan-Then-Execute Paradigm Design Patterns for Securing LLM Agents against Prompt Injections

Reference 3

Resolution
metadata mismatch
arxiv_id, observed 2026-05-15T02:43:33.372927Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-15T02:42:05.644536Z digest=sha256:07b5e21837eb59a1c982f9e708875d2e9208d45b2cb77ae14b80a40f11202d09

Observation 6a4a398c-ba3c-4d78-baae-139ba393d87d · inbound

The Insurability Frontier of AI Risk: Mapping Threats to Affirmative Coverage, Silent Exposures, and Exclusions cites this paper.

The Insurability Frontier of AI Risk: Mapping Threats to Affirmative Coverage, Silent Exposures, and Exclusions Design Patterns for Securing LLM Agents against Prompt Injections

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-20T23:33:50.920592Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-05-20T23:30:39.514339Z digest=sha256:e7ba6871c23970b67f6ca5493bf32789a085769d061920b17a87cc55c9e6714a

Observation ffd7a805-ebec-4f09-9b6c-9e37d5f969bc · inbound

Agentic-J: An AI Agent for Biological Microscopy Image Analysis cites this paper.

Agentic-J: An AI Agent for Biological Microscopy Image Analysis Design Patterns for Securing LLM Agents against Prompt Injections

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-07-02T01:36:25.311723Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-28T11:48:11.033570Z digest=sha256:9ea4d183eba4e8a00ddc1777a9a6a865d203b7a7a9ba7b539264510735cedcc5

Observation fed40526-eb57-4b76-8c65-afe923f74566 · inbound

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents cites this paper.

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 18

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T23:36:22.921717Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-28T14:12:38.815852Z digest=sha256:42d2f3eb0bbfe5be218510a2fe0cd9b7ca572907d2f0779bbb3a6b81f69d9ec9

Observation 529405dc-6e36-4f9c-b92c-19ed75aaf16e · inbound

Data Flow Control: Data Safety Policies for AI Agents cites this paper.

Data Flow Control: Data Safety Policies for AI Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 7

Resolution
verified exact
arxiv_id, observed 2026-07-02T15:47:06.357233Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T23:28:47.480408Z digest=sha256:47417432472a539e258b2e5634369e68fec302dff2b0d1ab5a72fcae902c4c3e

Observation 8a55b5ac-366f-45b3-a23c-3a2fafee5c79 · inbound

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs cites this paper.

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs Design Patterns for Securing LLM Agents against Prompt Injections

Reference 22

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T05:47:41.197854Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T13:05:57.618969Z digest=sha256:756551e5a9f6e7b30247f5f75d83e5d944eb0f6dbe5ac541dd3cec00044c7c80

Observation d22383bd-4dfc-4893-ba75-e1253cb95ee9 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation Design Patterns for Securing LLM Agents against Prompt Injections

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-06-27T13:20:57.094470Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:13182aa07579131ca2b985dd3744916d45379d2942502782065f074beb3aefea

Observation 175a722a-4c15-427e-a3a4-068bbe2d7335 · inbound

Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents cites this paper.

Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 5

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T09:19:43.605487Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-26T10:13:31.405238Z digest=sha256:202d194af39a7a2f8d401b4cfae8d246cd9bfedff9e98ac6b1b97b7ffb381355

Observation b459f59e-ff63-4e41-8a1d-357c3c82495c · inbound

GIF: Locally Sound Geometric Information Flow Control for LLMs cites this paper.

GIF: Locally Sound Geometric Information Flow Control for LLMs Design Patterns for Securing LLM Agents against Prompt Injections

Reference 13

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T10:49:46.741547Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-26T08:24:49.908288Z digest=sha256:802f0fe72be62678c975da6d3f83387e2dad3448cb9cc0f731b14f327bf3aabd

Observation 7dcc35be-7d05-4c3f-9094-c9f53153b919 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 23

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T13:39:51.328735Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:4479da7785787e2b26ff077f4db5eea466e0d09fbbeb350bfac0f1883eee85f3

Observation 808a4815-8a81-4ea8-9eaf-80a9b706cf7f · inbound

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents cites this paper.

Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-07-04T14:09:53.262547Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-06-26T04:29:16.386339Z digest=sha256:a8cb103b95d0fa8bdd901b064d8d1f52613c38b778ad1481ac1d8fc0aa6dcbfa

Observation 2f4644b6-c99c-416d-b7c3-1d0252e42811 · inbound

Janus: a Playground for User-Involved Agentic Permission Management cites this paper.

Janus: a Playground for User-Involved Agentic Permission Management Design Patterns for Securing LLM Agents against Prompt Injections

Reference 2

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T20:08:54.778632Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-07-03T20:06:32.891096Z digest=sha256:f4c692e6562bd026f6a0bb4ca8fe042583dedfad9ee6b7d8f70cb10ca541c251

Observation a45d9e9d-2c75-464b-8052-b1b799c2e4ff · inbound

Beyond Self-Resolution: Settlement Factorization for Robust Natural Language Mechanism cites this paper.

Beyond Self-Resolution: Settlement Factorization for Robust Natural Language Mechanism Design Patterns for Securing LLM Agents against Prompt Injections

Reference 1

Resolution
unresolved
no resolver link, observed 2026-07-11T19:34:52.611804Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T19:34:52.611804Z digest=sha256:98ffa03584d21262eff95fb907bb987d7e296e6b064b3d2c4f2d71b8e247566b

Observation 9eb4f866-d0b6-498b-bfa0-d98b81f35732 · inbound

Agent Data Injection Attacks are Realistic Threats to AI Agents cites this paper.

Agent Data Injection Attacks are Realistic Threats to AI Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 37

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:ab35c40368cac38a19ac8e61ec956a4e688239d0ace43da96b6bb2064118848a

Observation bfd5d8d7-340e-4927-ae45-9a02af7cf509 · inbound

Prismata: Confining Cross-Site Prompt Injection in Web Agents cites this paper.

Prismata: Confining Cross-Site Prompt Injection in Web Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 7

Resolution
verified exact
local_arxiv, observed 2026-07-10T12:27:04.099528Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-04T06:34:03.388597+00:00.

source=pdf_text observed=2026-07-10T12:20:03.672480Z digest=sha256:76d9c5d697b233f8a12b156fd306965cbf86a8607b417442a1227bf69f3bf3bd

Observation ecb94da7-7e5f-41c0-91a9-11c532e3b281 · inbound

Adversarial Prompting Framework for AI Safety Assessment cites this paper.

Adversarial Prompting Framework for AI Safety Assessment Design Patterns for Securing LLM Agents against Prompt Injections

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T05:10:09.289891Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T05:10:09.289891Z digest=sha256:b3738d0e981a43da7aa5d2e369118cc441ab266d6a580e2ec4993ddf158205fc

Observation f09d9082-5519-4344-9b07-828395f81160 · inbound

Specifying the Delegated-Autonomy Boundary: Requirements Engineering for Agentic AI cites this paper.

Specifying the Delegated-Autonomy Boundary: Requirements Engineering for Agentic AI Design Patterns for Securing LLM Agents against Prompt Injections

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T18:40:55.397024Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T18:40:55.397024Z digest=sha256:44de439f598df8f77869f4d1e857f14dd485a9f749ccf80f31f1ab5e23f91794

Observation 77f03a05-7c8b-4407-a4f2-162945b4802f · inbound

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests cites this paper.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Design Patterns for Securing LLM Agents against Prompt Injections

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:52.016053Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:52.016053Z digest=sha256:258d0ea3816309b4b2fe159e04e1f329a3fe3dfbe7d11e6fa75855d0ef68bf9e

Observation b169d889-a5d9-4a70-a222-129b8d5ea01f · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework Design Patterns for Securing LLM Agents against Prompt Injections

Reference 197

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.261016Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.261016Z digest=sha256:18d59bde1d8a793b8ff4e07b25282ba35fc5ad5b592d372d78f0af644a507f19

Observation 4a235574-ca91-4afd-836c-fa9a52b7f157 · inbound

Are You Still the Agent I Authorized? Earned Authority under a Fixed Ceiling for Evolving Agents cites this paper.

Are You Still the Agent I Authorized? Earned Authority under a Fixed Ceiling for Evolving Agents Design Patterns for Securing LLM Agents against Prompt Injections

Reference 15

Resolution
unresolved
no resolver link, observed 2026-07-30T18:16:45.183096Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-30T18:16:45.183096Z digest=sha256:fce12b621cd0c106021100c206997fcfee281a0b36aee66e97c486bd70b86b7f

Observation 77238753-6243-414d-9a2a-f05a02807625 · inbound

How Context Attribution Handles What the Model Already Knows cites this paper.

How Context Attribution Handles What the Model Already Knows Design Patterns for Securing LLM Agents against Prompt Injections

Reference 54

Resolution
unresolved
no resolver link, observed 2026-07-30T12:03:18.274762Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-07-30T12:03:18.274762Z digest=sha256:ef7b771e2190efc4a878a48aa673018ee8b3ad8a746213d2c1fa11658fdfe1d1

Observation 372f391f-490e-4885-a115-6d34b9a4b96a · inbound

AISPA: User-Centric System Prompt Auditing for Large Language Model Applications cites this paper.

AISPA: User-Centric System Prompt Auditing for Large Language Model Applications Design Patterns for Securing LLM Agents against Prompt Injections

Reference 2026

Resolution
unresolved
no resolver link, observed 2026-07-31T02:04:06.710922Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T02:04:06.710922Z digest=sha256:ff40eda79c00faec2772429a6feb4d7587859cc59f062b14646f6ede661cfdbd