Pith. sign in

Paper Citation Record · LEDGER

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

As of 10 August 2026, this Paper Citation Record lists 100 of 107 outbound references and 10 inbound Pith citation observations for arXiv:2506.13666.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.13666 v1

Coverage vector

measured 100 of 107 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T00:32:36.760608Z

measured 110 of 110 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 10 of 10 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-06T21:44:54.864170Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

100 of 107 outbound references displayed

  • verified exact0
  • verified fuzzy13
  • unresolved87
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation cab8fd2c-7197-4197-b0fc-fef0587b23a5 · outbound

This paper cites Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.443050Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.443050Z digest=sha256:d314f1bba8f774799ea23bf4f348870e6a0ee99677448eed13a0001938db6d47

Observation da9cb528-7157-4b44-8b73-00c0227eb123 · outbound

This paper cites Introducing the model context protocol.https://www.anthropic.com/news/ model-context-protocol, November 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Introducing the model context protocol.https://www.anthropic.com/news/ model-context-protocol, November 2024

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.447486Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.447486Z digest=sha256:b9ecdd511b8eb199ccd51d96328432c997fe163d241f8d0ffaaf195b61894c2d

Observation e62633f9-e83d-4a72-b74f-41265a3c4fd3 · outbound

This paper cites Foundational Challenges in Assuring Alignment and Safety of Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Foundational Challenges in Assuring Alignment and Safety of Large Language Models

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.451035Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.451035Z digest=sha256:86ffa872444dbf1d303ded7bef9eef6a4720ef946e84030cd405bfae48f2ebd3

Observation db8f1793-bf40-42a1-9c1f-9efc77144c16 · outbound

This paper cites Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.454938Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.454938Z digest=sha256:9bf5352bcc2df9572ab906057f73b1fd8f55c0d0819970f67398fc52e6c2b84c

Observation e8dd5d7a-7962-493e-b320-9fbace30b48a · outbound

This paper cites Safety-tuned LLaMAs: Lessons from improving the safety of large language models that follow instructions.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety-tuned LLaMAs: Lessons from improving the safety of large language models that follow instructions

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.458413Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.458413Z digest=sha256:27824395e242bf7136575afd777c0c9bb166703dc650f71003af797d1a82a4e9

Observation 1a387885-bd0a-4de2-9931-609e4c15616b · outbound

This paper cites an unresolved cited work.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Unresolved cited work

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.461485Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.461485Z digest=sha256:70a3912ad39677ac5d9c2d6a20d57338d4cb08ee2534db80661b929f4aebccbc

Observation 89437d5c-6824-41ee-9761-7ae1f94654d8 · outbound

This paper cites Highlights from lex fridman’s interview of yann lecun, March.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Highlights from lex fridman’s interview of yann lecun, March

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.464997Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.464997Z digest=sha256:58129b07af4f689c4aca1f68b91660813a847d61dae926729a54b717e0a421ec

Observation c256f18c-5b5b-4146-88f5-2b3a8045b973 · outbound

This paper cites A survey on evaluation of large language models.ACM transactions on intelligent systems and technology, 15(3):1–45, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey on evaluation of large language models.ACM transactions on intelligent systems and technology, 15(3):1–45, 2024

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.471713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.471713Z digest=sha256:4f50f8cfd3a0770fb62f5ab3c68191d8493a1f37ba0cace91b609b1d688a90ca

Observation 11cc4119-caec-474e-968a-138ed5374a77 · outbound

This paper cites Pappas, Florian Tramèr, Hamed Hassani, and Eric Wong.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Pappas, Florian Tramèr, Hamed Hassani, and Eric Wong

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.474958Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.474958Z digest=sha256:b10a7828c842d38a4944ea7b0c9615fb2dc7dc1cad7237c4a265c9580f765f37

Observation 4c2d0d40-1d6a-4979-80f0-8940a1819874 · outbound

This paper cites Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2025

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.477590Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.477590Z digest=sha256:f6650767f465f0d60c5d3ada5c8dbd8da95598c7bfd43d53c5109c1c7735df78

Observation 599af7df-89b2-426a-9af3-6f744f976cd4 · outbound

This paper cites Safety-aware fine-tuning of large language models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety-aware fine-tuning of large language models

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.480493Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.480493Z digest=sha256:9920b8a4b69025fd13476e00023f59e595eb50e4b8bf5c6ffb6ec2e43e66a112

Observation 349a1758-8d22-4163-8e06-8da4d2fdd95d · outbound

This paper cites Scaling instruction-finetuned language models.Journal of Machine Learning Research, 25(70):1–53, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Scaling instruction-finetuned language models.Journal of Machine Learning Research, 25(70):1–53, 2024

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.483792Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.483792Z digest=sha256:339c7c7bec7794809fea74809365db1f01a6b7f5cf642512fca9f6721ba0def6

Observation 4cb8a155-06a1-4f7e-ac1c-f3da080f6365 · outbound

This paper cites Textworld: A learning environment for text-based games.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Textworld: A learning environment for text-based games

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.486870Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.486870Z digest=sha256:770ded21da99589929c7a8a803bf602d5f7fc677efb82962f66f9d2db24226fc

Observation 47c933f4-d52b-4cd3-a619-3aae05a6b0ad · outbound

This paper cites DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.489432Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.489432Z digest=sha256:6400cfd65f32169764b58473b0f7299acb846829d6bc1dce34cb633233e2ec3c

Observation b12f1fb7-e970-4920-862b-1ac01661ce5c · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Ai agents under threat: A survey of key security challenges and future pathways

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.492579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.492579Z digest=sha256:4fbb037afd024e9b3c0c8e1798b559ac9a899b15afd314ba84d0a572dc60ea63

Observation 5d55cfb2-91e3-4329-b16a-8462d561c64c · outbound

This paper cites Bert: Pre-training of deep bidirectional transformers for language understanding.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Bert: Pre-training of deep bidirectional transformers for language understanding

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.495577Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.495577Z digest=sha256:b81b22bba378d9a7bdd9ebb738d26cdb046cd1398d37ed0ff3333ad65b424e72

Observation e7069162-a4b2-4c9d-8d8a-ab81d166a0c9 · outbound

This paper cites A Wolf in Sheep's Clothing: Generalized Nested Jailbreak Prompts can Fool Large Language Models Easily.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Wolf in Sheep's Clothing: Generalized Nested Jailbreak Prompts can Fool Large Language Models Easily

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.498449Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.498449Z digest=sha256:9aa2517a9b6aa6a5b8fb85d4d24f61caae71e4d8292dd89d33cbf67036cde846

Observation 8888b506-9c6e-4569-bb1b-e1f604fda046 · outbound

This paper cites A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP).

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.501355Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.501355Z digest=sha256:9f3b98b9d98cae8bb3fa022248637100b234c3a91d54a5374246ffe54c0e37b7

Observation 82bac543-6e04-41e9-8fa1-0d01ddab0f31 · outbound

This paper cites Pawan Kumar, and Adel Bibi.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Pawan Kumar, and Adel Bibi

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.504729Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.504729Z digest=sha256:62718e2ca6963250d2d61131da46ae0f3475fe5c83e20b342e3d4a80c7b5ab99

Observation 87ea844c-4b84-4efe-b22f-b0f8cc12c09b · outbound

This paper cites Imprompter: Tricking LLM Agents into Improper Tool Use.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.507283Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.507283Z digest=sha256:adf322d400f2324ca72ace93cd72577cf5781b81bc6148eaed0efde490c0a8c0

Observation b2baea63-0248-4742-94a6-3ba85ab31972 · outbound

This paper cites Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.510129Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.510129Z digest=sha256:9ffdd723bdf332d91f03202dec9a80aa73347ae5216263e7c9f74bfaa9896134

Observation 71d669d1-12cd-4a41-869c-ffc4f118f42d · outbound

This paper cites Textbooks Are All You Need.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Textbooks Are All You Need

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.512749Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.512749Z digest=sha256:0ac50beb29b115ae86fe49bf3aae79276c4e1bd21875ce0f60c6f66813994575

Observation 6338beed-56ee-4479-b1ce-ca417488e76c · outbound

This paper cites Large Language Model based Multi-Agents: A Survey of Progress and Challenges.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Large Language Model based Multi-Agents: A Survey of Progress and Challenges

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.515911Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.515911Z digest=sha256:f3a4e84971dbd8ca5032937560b1d0f2769ad28b0fba91dc4c02600bda303db6

Observation 15daf63a-56cd-4b96-afdb-15cb2ff8a771 · outbound

This paper cites Regulating chatgpt and other large generative ai models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Regulating chatgpt and other large generative ai models

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.519516Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.519516Z digest=sha256:9ab3002ad9548b3e0129e09134d50a2a45a30c36ca79986abe5ef205bed3536b

Observation 74fbc7fb-4214-4ff9-92f1-0361627e54d6 · outbound

This paper cites A survey on large language models: Applications, challenges, limitations, and practical usage.Authorea Preprints, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey on large language models: Applications, challenges, limitations, and practical usage.Authorea Preprints, 2023

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.522302Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.522302Z digest=sha256:b32782bd7901f62d3992e28bda70c3851bf89035b4f12c0489201f406fcbc4ff

Observation c9306aa5-16ba-4a9d-985a-e15869da3867 · outbound

This paper cites What is in Your Safe Data? Identifying Benign Data that Breaks Safety.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems What is in Your Safe Data? Identifying Benign Data that Breaks Safety

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.525213Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.525213Z digest=sha256:f1e8c50fcccb4f0fce331c3bcdb1f733a7011f4852c709bb44df566a277c29ca

Observation 73b9fd81-05b3-489c-b34b-cac9663ac932 · outbound

This paper cites Red-Teaming LLM Multi-Agent Systems via Communication Attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Red-Teaming LLM Multi-Agent Systems via Communication Attacks

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.528134Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.528134Z digest=sha256:22be16f59b3dc60a140f0bd2fe537c6cc7b0be9f2eaae664e3f4376f17c4959f

Observation ed2a81ee-4b17-4cac-8223-bbed55d65379 · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.535179Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.535179Z digest=sha256:589c308a7f8ef7559f21f103fe2b0fdbf08d74e9ea1112b6b8aeca05d8a2a57b

Observation ecd65069-43f6-4e93-b30d-fac8feff78d3 · outbound

This paper cites T1: Advancing Language Model Reasoning through Reinforcement Learning and Inference Scaling.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems T1: Advancing Language Model Reasoning through Reinforcement Learning and Inference Scaling

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.538291Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.538291Z digest=sha256:2d4543386f76260f5e77003a20f1385ab098f32235f5f878258adf2431d188ba

Observation 3ed7c96d-4758-44d2-816c-28d632e2b569 · outbound

This paper cites Scaling Trends in Language Model Robustness.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Scaling Trends in Language Model Robustness

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.541321Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.541321Z digest=sha256:d7a39b71905d958e511e3e91574ef8cc5561a0f713df500b6f5d22be54cd6fb4

Observation 740059a3-efc9-4b55-8bda-5f99777f08ed · outbound

This paper cites A survey of safety and trustworthiness of large language models through the lens of verification and validation.Artificial Intelligence Review, 57(7):175, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey of safety and trustworthiness of large language models through the lens of verification and validation.Artificial Intelligence Review, 57(7):175, 2024

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.544502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.544502Z digest=sha256:2f98e43dc6a3fef4fff4278cccd0663f8d1162c0e8760f75b7c1827d10e0d6f4

Observation abacfcb5-873b-48ac-93bf-9f014ab7eb00 · outbound

This paper cites Babyai 1.1, 2020.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Babyai 1.1, 2020

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.547224Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.547224Z digest=sha256:098f09b530b35c2147bba32e5e771d1906f8244b068c78acf685810128d79142

Observation 427cf786-071f-45a2-b516-8bde402013dc · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.550081Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.550081Z digest=sha256:677fb21e0c2baa653a597ffeba265b58d43d11b971c5734226c36dd2aea69443

Observation ec439bd0-f2ff-4c1a-a184-71b64c84c100 · outbound

This paper cites Mcp security notification: Tool poisoning attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Mcp security notification: Tool poisoning attacks

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.553330Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.553330Z digest=sha256:0fb6a0a34180ea33f327c9b6b254846a6d97c63720faa5dba15486ab420b05e9

Observation 1244253f-4154-4114-bd33-9b4ed1d2517d · outbound

This paper cites SafeChain: Safety of Language Models with Long Chain-of-Thought Reasoning Capabilities.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems SafeChain: Safety of Language Models with Long Chain-of-Thought Reasoning Capabilities

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.556165Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.556165Z digest=sha256:c301b459a2f6a2fa2cd2e3dd1c783cc47941fa9c36d9b382f1e71913fe62cf61

Observation bdb8422b-033e-43a6-89cf-c0bda4e306b9 · outbound

This paper cites Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.559678Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.559678Z digest=sha256:a06a25588aa8a58cf3407bcd1082d9d6735613f18b40ee15dbea2a8996eb1fbb

Observation 19c5409f-c863-4e40-9a1b-ee970cc44425 · outbound

This paper cites Llm-mod: Can large language models assist content moderation? InExtended Abstracts of the CHI Conference on Human Factors in Computing Systems.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Llm-mod: Can large language models assist content moderation? InExtended Abstracts of the CHI Conference on Human Factors in Computing Systems

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.563012Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.563012Z digest=sha256:0231a3e81c8c24c20e4c42c359f8a1277f316937f2f3bfd64633527d20f6c7db

Observation 7f1e61ea-52c3-40fa-a6f5-62f2bf479779 · outbound

This paper cites Watch your language: Investigating content moderation with large language models.Proceedings of the International AAAI Conference on Web and Social Media, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Watch your language: Investigating content moderation with large language models.Proceedings of the International AAAI Conference on Web and Social Media, 2024

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.565644Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.565644Z digest=sha256:0c15720e0feacd4715c3d90d2f60cc23a76e50308d65475953eb35bdaaa8bcc9

Observation 511c0034-a37f-4235-b47d-765d0119c364 · outbound

This paper cites MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.568714Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.568714Z digest=sha256:fd8c2e73142b1cca758e89074f510a88eed453710e30d19c957b27b1951be4d1

Observation 1d46beab-1ba3-4821-9853-c92ee7fc1333 · outbound

This paper cites How not to be stupid about ai, with yann lecun.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems How not to be stupid about ai, with yann lecun

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.571929Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.571929Z digest=sha256:c1a1be993d8f5e6f3548d48f5ce2ebaa5412ff8553304db021023cd57939fd44

Observation 4a01d0f6-66ab-4bb4-bdc9-77680eb4f755 · outbound

This paper cites Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.575227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.575227Z digest=sha256:73c34799c36b98533bd6d51d2887b7126a09332f90781c1ab74efb1c4ec998d9

Observation 59802d7a-0a03-4b0c-9a71-8ec832f81fca · outbound

This paper cites Common 7B Language Models Already Possess Strong Math Capabilities.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Common 7B Language Models Already Possess Strong Math Capabilities

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.578494Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.578494Z digest=sha256:c33efa5bcecb954c0acd89d1bd9630c5374822608eae561d7a86d0c9b0a03320

Observation c8132a73-f252-428c-96ae-e33004d5b5c2 · outbound

This paper cites Camel: Communicative agents for" mind" exploration of large language model society.Advances in Neural Information Processing Systems, 36:51991–52008, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Camel: Communicative agents for" mind" exploration of large language model society.Advances in Neural Information Processing Systems, 36:51991–52008, 2023

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.581487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.581487Z digest=sha256:9786cb349db6e6c77e6ba00bb7e2f9b153f7b8c7cbbd7796e554a90989d33ded

Observation 9a00be52-d04d-4e03-ab77-9f90bda7a673 · outbound

This paper cites DeepInception: Hypnotize Large Language Model to Be Jailbreaker.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems DeepInception: Hypnotize Large Language Model to Be Jailbreaker

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.584165Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.584165Z digest=sha256:b534346704a5a22071cb79e9625112c78a82f963f4fc4016adf69da867e663f5

Observation a299b3ba-ca64-428c-a5f5-87a036e037af · outbound

This paper cites The Unlocking Spell on Base LLMs: Rethinking Alignment via In-Context Learning.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The Unlocking Spell on Base LLMs: Rethinking Alignment via In-Context Learning

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.587266Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.587266Z digest=sha256:0c05ecf533b542fc768e55366d136b5b9134184cbc85bcdb0b0a94721d1cb6a2

Observation feffbfcf-e616-4ee4-a8e2-f837a306ebf3 · outbound

This paper cites Understanding and enhancing the transferability of jailbreaking attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Understanding and enhancing the transferability of jailbreaking attacks

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.590175Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.590175Z digest=sha256:10bf1f4f6a726e7123e4b20ba48cb1fc9b45eb50475993572b6940529241a7cb

Observation 5f27bde5-03c1-4068-bc86-5710b3f6facc · outbound

This paper cites ToolACE: Winning the Points of LLM Function Calling.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ToolACE: Winning the Points of LLM Function Calling

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.593020Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.593020Z digest=sha256:70210ed51bf430ac55c30722966b585daaa55cff5df4f5321eb4461fb293bd5a

Observation 64067349-a619-4bd7-b98d-afd287c03953 · outbound

This paper cites Autodan: Generating stealthy jailbreak prompts on aligned large language models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Autodan: Generating stealthy jailbreak prompts on aligned large language models

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.595996Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.595996Z digest=sha256:365420c3e35b6f747e366d03a49a04460c0c948d0b6d8b48e082971ea4315b97

Observation f578c017-50af-4261-9762-8f77c9152e97 · outbound

This paper cites Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.598721Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.598721Z digest=sha256:6d5d680322692e021ce6a8d2c6ab70131ced30c175f234e8cbfd81d94e14c348

Observation bbfc070e-c4aa-4838-bdd6-01e020769a5f · outbound

This paper cites RobustFT: Robust Supervised Fine-tuning for Large Language Models under Noisy Response.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems RobustFT: Robust Supervised Fine-tuning for Large Language Models under Noisy Response

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.601660Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.601660Z digest=sha256:7b61e9b70faf36762e09fc110d32323013727ff8b4215808b5702bb5d36c73c4

Observation f700f20c-b668-4c99-a7fc-334e65e65551 · outbound

This paper cites CodeChameleon: Personalized Encryption Framework for Jailbreaking Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems CodeChameleon: Personalized Encryption Framework for Jailbreaking Large Language Models

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.604717Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.604717Z digest=sha256:6a1e2a7ade60f2229296f6d76c1e7cda56ade560ddd0abcdfba2dcc6f9bc9b13

Observation 7954f0b0-91d6-43a7-8bd6-2edf9f2652f8 · outbound

This paper cites Agentboard: An analytical evaluation board of multi-turn llm agents, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Agentboard: An analytical evaluation board of multi-turn llm agents, 2024

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.607632Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.607632Z digest=sha256:c1f6f05678d318bbe5171da2c381cc04e162dd1cc94d5c65b64c09659303b5f7

Observation f5dc2dfc-0fac-4b1a-b621-b202218ea1a0 · outbound

This paper cites Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.610249Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.610249Z digest=sha256:6fc94d24239e510477c333303628975f5c1d07ee57a39433891d42b46f2edd4a

Observation 7b9f233f-ddce-4c8d-9b52-39901c78a083 · outbound

This paper cites AgentSafe: Safeguarding Large Language Model-based Multi-agent Systems via Hierarchical Data Management.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems AgentSafe: Safeguarding Large Language Model-based Multi-agent Systems via Hierarchical Data Management

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.613450Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.613450Z digest=sha256:75c6bc0e77bb51bd1de41a487b26768238d9727600d0cb0244ea2ab42bea3b19

Observation c7de98e6-ed07-46f7-a216-adaf5a45e658 · outbound

This paper cites an unresolved cited work.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Unresolved cited work

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.617161Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.617161Z digest=sha256:24f97484815344d641d98c928012e50fcdd3c85e8a50d62881c98bccfbeab2ed

Observation 4540d3ec-8f76-41be-b476-e4d565fa9ffe · outbound

This paper cites A Comprehensive Overview of Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Comprehensive Overview of Large Language Models

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.619901Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.619901Z digest=sha256:445724a6a92856294ecefd3d3ad613096a07be6d8e4f6090e8a5afca076c4a96

Observation 26ca70b2-80f0-4e90-9655-1d19342371e8 · outbound

This paper cites GPT-4 technical report.CoRR, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems GPT-4 technical report.CoRR, 2023

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.623242Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.623242Z digest=sha256:cad71d25ca030238f83900253f0a467e07417a15d23e69e5b543db8f3fd5850e

Observation 93a25dfa-c201-4bb1-aaef-b423ed7d83e6 · outbound

This paper cites Training language models to follow instructions with human feedback.Advances in neural information processing systems, 35:27730–27744, 2022.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Training language models to follow instructions with human feedback.Advances in neural information processing systems, 35:27730–27744, 2022

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.626365Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.626365Z digest=sha256:ef23b3b1fbbb6b893c50ad5563683fb9b03e2cf8bbc881906c7fb68a4c3b1c26

Observation 5153d8fc-048f-4b5a-a9a7-4b814de674f6 · outbound

This paper cites Self-alignment of large language models via monopolylogue-based social scene sim- ulation.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Self-alignment of large language models via monopolylogue-based social scene sim- ulation

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.618797Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.629215Z digest=sha256:f59add0f8e33edc535016699e350c81ad5564646a5cc60bcdb8e57cb9ba9266e

Observation 9e7ec986-2242-46b0-b1ce-329bf2db8fb7 · outbound

This paper cites A survey on agent-based modelling assisted by machine learning.Expert Systems, 42(1):e13325, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey on agent-based modelling assisted by machine learning.Expert Systems, 42(1):e13325, 2025

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.608506Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.632627Z digest=sha256:355cb58c226b0439fc7fdaa2e2fd8d0765f56776dc06f710c5faf4bc7c25e97a

Observation b9f45d87-fa24-49cb-852f-836ec4551680 · outbound

This paper cites ADaPT: As-Needed Decomposition and Planning with Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ADaPT: As-Needed Decomposition and Planning with Language Models

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.635903Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.635903Z digest=sha256:77280f0ac89779dda9c5eee20a0f40f79a78f52ffc6e3862c87e3189e4f8e7bf

Observation bfe99cd4-0424-4e95-bcd6-a7d4a6e6dd80 · outbound

This paper cites Fine-tuning Aligned Language Models Compromises Safety, Even When Users Do Not Intend To!.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Fine-tuning Aligned Language Models Compromises Safety, Even When Users Do Not Intend To!

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.639515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.639515Z digest=sha256:360506594bf2c1433eb16391650e0d20378cee67284e5719f0ff9ddca32aeb23

Observation fc79b600-34e2-42f3-bf03-69748daac3d7 · outbound

This paper cites Safety alignment should be made more than just a few tokens deep.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety alignment should be made more than just a few tokens deep

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.598823Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.642841Z digest=sha256:2e3236e6cb95070f34d7d01a6ef3c10c6511ba6eb5ca6f38bc852a6bdb732787

Observation 54ba21df-c8af-47e0-a521-de0985373cb3 · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.645879Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.645879Z digest=sha256:22b3276ba59826f46ba71807f0bb236ed81d8a2f0789f39ec7777bb9db819751

Observation a26c16fc-22fc-46ef-83f1-d36f03a32ea9 · outbound

This paper cites Tptu: Task planning and tool usage of large language model-based ai agents.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Tptu: Task planning and tool usage of large language model-based ai agents

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.588649Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.648975Z digest=sha256:b078cc3d8e07a7004cbddca147d8a9ae48af94d6b58c6b1f178f86aeda7419c2

Observation eee225d5-1ecd-48db-83f4-59c3f3eb83e2 · outbound

This paper cites Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36: 68539–68551, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36: 68539–68551, 2023

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.651630Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.651630Z digest=sha256:c81bb476045ebdfdff60eae867a76ae66dfafaafcd626650ee356d61d39b4015

Observation 95941cb5-c39b-4245-9ab4-f38416c441f1 · outbound

This paper cites Large Language Model Safety: A Holistic Survey.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Large Language Model Safety: A Holistic Survey

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.657747Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.657747Z digest=sha256:ce071b2ccf62f0f80527ebc68226a1f91e1397aa430498d6e088af34d4102ee6

Observation e38e1f26-8af7-43dc-846e-f22688ba3362 · outbound

This paper cites Welcome to the era of experience.Google AI, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Welcome to the era of experience.Google AI, 2025

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.572748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.660554Z digest=sha256:56bc40cac416c67d9248b85b48ae1c285203f64db42cc1cecb04b97f6dffe56c

Observation bc18e7db-d374-4fb0-bf7f-cce0c18a9f5c · outbound

This paper cites Large language model (chatgpt) as a support tool for breast tumor board.NPJ Breast Cancer, 9(1):44, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Large language model (chatgpt) as a support tool for breast tumor board.NPJ Breast Cancer, 9(1):44, 2023

Reference 71

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.563133Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.663467Z digest=sha256:e87e610ddf2347f1cc847e48ab5f3e884d620d1ed47a54c6f7850644123cf96a

Observation 068ee5fd-9a41-438b-bcaa-82dc516b2131 · outbound

This paper cites ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.666302Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.666302Z digest=sha256:1c3fe6082e6dd320fdf739586592b8bde1121dca0eddf2d836047fb3c790e0b4

Observation f034a09e-e2fa-4274-ab49-808463f0e4b1 · outbound

This paper cites A Survey on Post-training of Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Survey on Post-training of Large Language Models

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.669532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.669532Z digest=sha256:e930366b12143f2775dc9f08877275462aa3c9ec67de41bf18f96d1f75acb695

Observation e49dc2bf-5595-4833-a4fd-4f0d3ee92e48 · outbound

This paper cites Multi-Agent Collaboration Mechanisms: A Survey of LLMs.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Multi-Agent Collaboration Mechanisms: A Survey of LLMs

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.672515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.672515Z digest=sha256:fee2da6fa683d80710a16e7dde7a3c7337da0ba472e6c8d07ee98227723a9300

Observation 036f6ddd-16e2-4554-a054-a056ef1b0c3c · outbound

This paper cites House Committee on Oversight and Accountability.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems House Committee on Oversight and Accountability

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.553788Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.675669Z digest=sha256:49de5200cde73b8b1ad9c37f532dd72c5573112f5e51476e9b8abe724cf8846e

Observation 6ba5b7ab-5472-4f04-ba3b-bd5d1c00b471 · outbound

This paper cites From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.678358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.678358Z digest=sha256:e49beec5a2b9a4aada043545c1dbc7bdcdc03fcee1af25a12bceeb22d2ac8754

Observation 6fe0c16b-c9c5-4686-b103-ddb0ced94a13 · outbound

This paper cites Backdooralign: Mitigating fine-tuning based jailbreak attack with backdoor enhanced safety alignment.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Backdooralign: Mitigating fine-tuning based jailbreak attack with backdoor enhanced safety alignment

Reference 77

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.544261Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.682146Z digest=sha256:322de27a72b1a06e6dce2a6754d16e3bcda9d553e395389aa45d184e5625820f

Observation 1cd39cb2-ad4d-4097-9cd9-44ea269ef0ba · outbound

This paper cites A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.685699Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.685699Z digest=sha256:537035ab502471dc302187d9e992bfc155545289751f435db1ccb43e584d5eb1

Observation be9ee4a7-10a0-4f4b-a793-d24b6bec5b18 · outbound

This paper cites ScienceWorld: Is your Agent Smarter than a 5th Grader?.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ScienceWorld: Is your Agent Smarter than a 5th Grader?

Reference 79

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.689405Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.689405Z digest=sha256:f03afec988a62b763034c17b36373d884689cd94ec8cef4a6b7e977475099f77

Observation 785cfa32-51aa-4d6f-ad78-502d0157a6af · outbound

This paper cites G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent Systems.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent Systems

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.692682Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.692682Z digest=sha256:a03f64ce2eb9ccf968f9bd5537ec41e48455cfbb4d4897e12c1e778f6124e74d

Observation b61d1d5a-cf4b-4993-a884-8647f3aef8da · outbound

This paper cites Augmenting language models with long-term memory.Advances in Neural Information Processing Systems, 36:74530–74543, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Augmenting language models with long-term memory.Advances in Neural Information Processing Systems, 36:74530–74543, 2023

Reference 81

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.695853Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.695853Z digest=sha256:a0051adc256dba3ec0013bc002930d1f2aa84ffe9a9575710c7b6763ada7a330

Observation c81ab498-e158-400f-84ac-8be0fcd0581e · outbound

This paper cites AgentGym: Evolving Large Language Model-based Agents across Diverse Environments.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems AgentGym: Evolving Large Language Model-based Agents across Diverse Environments

Reference 82

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.698999Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.698999Z digest=sha256:5d70aed5aeff9083f9d1d4dc96a13ba4598e807ee0b9ae63defd3f39ec71dbb7

Observation e48af40e-acf2-42d8-b9d9-dd4fc079521b · outbound

This paper cites The rise and potential of large language model based agents: A survey.Science China Information Sciences, 68(2):121101, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The rise and potential of large language model based agents: A survey.Science China Information Sciences, 68(2):121101, 2025

Reference 83

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.702156Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.702156Z digest=sha256:2a40904f39c14dd045215358bf41bc8cdffdc0e73b1acd87e6e81e4f764c12fe

Observation f96d077d-7cfb-4ecc-949e-513f4ebb4f35 · outbound

This paper cites Certifiably robust rag against retrieval corruption.arXiv preprint arXiv:2405.15556, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Certifiably robust rag against retrieval corruption.arXiv preprint arXiv:2405.15556, 2024

Reference 84

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.704889Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.704889Z digest=sha256:231e26a4d342d65a60f02fe2fd0d632aacdc86ea39730b9637d7dd938aa895ee

Observation 380e6eee-66c5-484b-86ee-9f201f1e5933 · outbound

This paper cites Bag of tricks: Benchmarking of jailbreak attacks on llms.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Bag of tricks: Benchmarking of jailbreak attacks on llms

Reference 85

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.521751Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.707657Z digest=sha256:e1211c4cdaecfb62dc492c76aa76a93d241f95d07f263c2ff2ea56d6f51d98fc

Observation 74828f52-df54-443a-8638-be1165b46fcd · outbound

This paper cites Qwen3 Technical Report.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Qwen3 Technical Report

Reference 86

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.710457Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.710457Z digest=sha256:b02763a8fb27910686dcfcd6d1fefe4145c2916ee39b4cff5f15f2f2d25b4677

Observation 95703251-2882-404c-9a50-c7e497ae4a07 · outbound

This paper cites Gpt4tools: Teaching large language model to use tools via self-instruction.Advances in Neural Information Processing Systems, 36:71995–72007, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Gpt4tools: Teaching large language model to use tools via self-instruction.Advances in Neural Information Processing Systems, 36:71995–72007, 2023

Reference 87

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.713245Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.713245Z digest=sha256:11d1bb325cd0e9d4cd0b8e5731712d832a4c73dc685e9cebf7cdf6be466a958e

Observation a19666c5-0f5d-45e7-a5fb-c9349549add3 · outbound

This paper cites The second half.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The second half

Reference 88

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.506455Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.716985Z digest=sha256:d31f3844f67856e3320a56013ab934e894156eafd7f7ad6589a71b907818304a

Observation 7f61f150-b491-4527-9a47-b62e72b3d17d · outbound

This paper cites Webshop: Towards scalable real-world web interaction with grounded language agents.Advances in Neural Information Processing Systems, 35:20744–20757, 2022.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Webshop: Towards scalable real-world web interaction with grounded language agents.Advances in Neural Information Processing Systems, 35:20744–20757, 2022

Reference 89

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.719731Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.719731Z digest=sha256:be2d58e14c46cdadb8405ea77c46fb087903d01170adab276b6490b250249fac

Observation fea6eceb-7aa5-4c7c-b05d-1c583cb0e5d6 · outbound

This paper cites On the vulnerability of safety alignment in open-access llms.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems On the vulnerability of safety alignment in open-access llms

Reference 90

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.490297Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.722464Z digest=sha256:6a1da5cd8bd33993b879ccb4d987845a67a13331765395ebefa0286cd5349367

Observation adf6ba7d-7317-400d-a0e8-27f41b4d2700 · outbound

This paper cites NetSafe: Exploring the Topological Safety of Multi-agent Networks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems NetSafe: Exploring the Topological Safety of Multi-agent Networks

Reference 91

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.725488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.725488Z digest=sha256:38df8bc45df1828bb87237cba547409be53f97cc6007173183faea9b0d656682

Observation 658a354a-f690-49f2-985f-f7672cd019dc · outbound

This paper cites A Survey on Trustworthy LLM Agents: Threats and Countermeasures.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Survey on Trustworthy LLM Agents: Threats and Countermeasures

Reference 92

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.728262Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.728262Z digest=sha256:4ad8c29ec96d17d93e3203fc282dbff700969064e444c1f7ad8b588149f76c00

Observation 1524d6e6-286a-43ba-93ef-3b2fef453951 · outbound

This paper cites GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher

Reference 93

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.731379Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.731379Z digest=sha256:0acac83158f5a0ce84a8aef012b355da07e07cb1870dcb1a8ffb9f931aa80df2

Observation 00c62709-3317-40a3-b346-442a63fdae42 · outbound

This paper cites The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG).

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG)

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.734755Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.734755Z digest=sha256:7511d13b6f10e3100fe6c5ede1d186925557b11bc525364361ca868b960e02b8

Observation f589ac32-fc8d-4d1b-96e3-5b2e30bd4aa3 · outbound

This paper cites Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 95

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.737890Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.737890Z digest=sha256:8dc7d975cdca75435c824b78c3a3287aa6a9802b35f531eaccb17a0deb8ce2f6

Observation ab6de568-c470-4aab-88e5-dea0578791ba · outbound

This paper cites Cut the Crap: An Economical Communication Pipeline for LLM-based Multi-Agent Systems.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Cut the Crap: An Economical Communication Pipeline for LLM-based Multi-Agent Systems

Reference 96

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.740954Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.740954Z digest=sha256:42b168fcfc4425934c0ee894a72b25f09e4177ca3009e6d6691ca6e05b19024e

Observation e4edd56d-f9ec-49a4-953c-f24c4b7be12c · outbound

This paper cites G-Designer: Architecting Multi-agent Communication Topologies via Graph Neural Networks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems G-Designer: Architecting Multi-agent Communication Topologies via Graph Neural Networks

Reference 97

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.744658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.744658Z digest=sha256:1c0e92c2aab727447a4ac7e24cee2c8584df81ae61f028b39dc6133fa4dcdda8

Observation 957146b2-5704-4b00-aba6-c0e9972dae84 · outbound

This paper cites Multi-agent Architecture Search via Agentic Supernet.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Multi-agent Architecture Search via Agentic Supernet

Reference 98

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.747826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.747826Z digest=sha256:5eb8b9f021a48cb72095d0d68644de62473a8676f340408c5585f47c567e7bf7

Observation 135758a2-101f-46b2-b1b3-b9f34e775ef4 · outbound

This paper cites On large language models safety, security, and privacy: A survey.Journal of Electronic Science and Technology, page 100301, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems On large language models safety, security, and privacy: A survey.Journal of Electronic Science and Technology, page 100301, 2025

Reference 99

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.480624Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.751306Z digest=sha256:a3dce98810d25ed2f3eb980851e34a6c1fbc46a952b4df715223bb55928ac201

Observation 345cee46-9e13-41d1-b269-df216f2781e7 · outbound

This paper cites A Survey on the Memory Mechanism of Large Language Model based Agents.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Survey on the Memory Mechanism of Large Language Model based Agents

Reference 100

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.754225Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.754225Z digest=sha256:2881f80458734d68f9932a3d3e21d4bb8f45673fef21833d9d647ed137c7c9cb

Observation 076583d6-15c9-4396-a3d0-44469bf491fb · outbound

This paper cites Agent-SafetyBench: Evaluating the Safety of LLM Agents.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Agent-SafetyBench: Evaluating the Safety of LLM Agents

Reference 101

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.757251Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.757251Z digest=sha256:4c893c3c065394b151c49402ab9550b034f38c7c6f69f1e993acdb75adbbc48a

Observation 3a8ecb07-4fc3-4a68-ab6a-ff2bac3b1b42 · outbound

This paper cites Weak-to-strong jailbreaking on large language models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Weak-to-strong jailbreaking on large language models

Reference 102

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.470778Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:32:36.760608Z digest=sha256:5a9a5fc1bb93c82642f910dada81b9ea2f5fba436e55287d69ff95ec3de8e34b

Pith citing papers

Observation 90e1e1ed-8764-4e66-a8d9-6960ea2c0b21 · inbound

A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis cites this paper.

A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T21:44:54.864170Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:44:54.864170Z digest=sha256:a6c9135d7c6fe37a0c1477adc5f3837c43e63f7d02b5d77ee776954e04234f13

Observation cfe0e7e8-93f6-4771-ad9f-5e537f17e30b · inbound

A Survey of Context Engineering for Large Language Models cites this paper.

A Survey of Context Engineering for Large Language Models We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 268

Resolution
verified exact
arxiv_id, observed 2026-05-13T20:58:45.454680Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-13T20:58:45.060041Z digest=sha256:ec66bb7e6c91b14be7ff33d6381d105f2d2abe502904578408cca2916c933c9b

Observation e0d13b95-ba3d-45c4-a254-a4f2d61dcdb2 · inbound

Quantifying Conversation Drift in MCP via Latent Polytope cites this paper.

Quantifying Conversation Drift in MCP via Latent Polytope We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-05T22:51:28.082763Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T22:51:28.082763Z digest=sha256:9f7e3b1ed764e9b2a26bb4e8cee07c5af4287d1bc71c8f9424ce0f4098dfb1e7

Observation 20c9401e-5b28-422d-ba1a-9243586357e2 · inbound

SafeSearch: Automated Red-Teaming of LLM-Based Search Agents cites this paper.

SafeSearch: Automated Red-Teaming of LLM-Based Search Agents We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-04T14:43:49.514734Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T14:43:49.514734Z digest=sha256:b7061cf21b73fadbc053afc062e9f0921aa439bc5793439c91e06e17a31c3b99

Observation fefa0c54-1a93-4642-b570-953c2be5843e · inbound

AgentBound: Securing Execution Boundaries of AI Agents cites this paper.

AgentBound: Securing Execution Boundaries of AI Agents We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-18T05:15:54.194195Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-18T05:12:23.542793Z digest=sha256:5e24aab9ecbb1e4a8e2f2c8fd6356d3cfc72d3dfa7d8e653ec9210f598598a22

Observation 3124087a-1487-43c7-acf0-c3166b8bb612 · inbound

BalDRO: A Distributionally Robust Optimization based Framework for Large Language Model Unlearning cites this paper.

BalDRO: A Distributionally Robust Optimization based Framework for Large Language Model Unlearning We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-03T10:45:41.323277Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T10:45:41.323277Z digest=sha256:6f3752e22bfc8cc33abcab2c02834b8e8f7ae4d332bb8de6bb894630f1e55368

Observation 99d5a936-f809-49ba-9bd3-93cff40c539c · inbound

Combating Data Laundering in LLM Training cites this paper.

Combating Data Laundering in LLM Training We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 16

Resolution
unresolved
no resolver link, observed 2026-07-13T14:08:35.474488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-13T14:08:35.474488Z digest=sha256:7caa3a4df9d0119fb1d57477e28411dc5a8d6972ef6d4d88767f0c3c2f467502

Observation 480a69b4-2b84-4ec8-a628-112915abefca · inbound

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers cites this paper.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.943736Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:cfa188f57e29797f61459b59840cc972881446ed003f65ba0ceac53fa6bde09f

Observation 90f557b0-dd05-47fa-bd65-952d9dc1467e · inbound

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security cites this paper.

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-10T21:10:46.722140Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-05-10T17:10:50.283791Z digest=sha256:69f737cd86eebb620fd534be0c36c8998b2ba8ef457a743dd8f2d4ca98eb6ee0

Observation 6bfb7f42-7003-402d-9b36-9ebc80aaad4c · inbound

"What Happens Locally, Leaks Globally": Detecting Privacy Leakage Risks in MCP Servers cites this paper.

"What Happens Locally, Leaks Globally": Detecting Privacy Leakage Risks in MCP Servers We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 9

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T06:49:38.283917Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-06-26T14:07:59.170493Z digest=sha256:d683de27e6c2c2debf3f2a704fada12828b13d2f82671d2b368025df9d539e81