{"as_of":"2026-08-10T17:40:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:2f0ca7d2923e848ce6702efe7fe2cfad3bc2527bb931632cd37a2612f42200bf","coverage":[{"denominator":107,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":100,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T00:32:36.760608Z","state":"measured"},{"denominator":110,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":110,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-10T06:31:04.303077+00:00","state":"measured"},{"denominator":10,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":10,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-06T21:44:54.864170Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":0,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-08-06T21:44:54.864170Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.23474","last_updated":"2025-06-30T02:37:27Z","snapshot_observed_at":"2026-08-09T18:44:17.312239Z","submitted_at":"2025-06-30T02:37:27Z","title":"A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-06T21:44:54.864170Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2506.23474"},"observation_digest":"sha256:a6c9135d7c6fe37a0c1477adc5f3837c43e63f7d02b5d77ee776954e04234f13","observation_id":"90e1e1ed-8764-4e66-a8d9-6960ea2c0b21","resolution":{"observed_at":"2026-08-06T21:44:54.864170Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":"2506.13666","doi":"10.48550/arxiv.2506.13666","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"We should identify and mitigate third-party safety risks in mcp-powered agent systems","venue":"ArXiv.org","work_id":"b22353cd-1606-4671-a46c-a3a4e0f90410","year":2025},"citing_paper":{"arxiv_id":"2507.13334","last_updated":"2025-07-21T17:48:18Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-07-17T17:50:36Z","title":"A Survey of Context Engineering for Large Language Models","version":2},"reference_index":268,"source":"pdf_text","source_observed_at":"2026-05-13T20:58:45.060041Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2507.13334"},"observation_digest":"sha256:d9dd411ed936c4f52f4c020e5ddd80049727ea1d845e0f9ffa856bb6a81f107b","observation_id":"cfe0e7e8-93f6-4771-ad9f-5e537f17e30b","resolution":{"observed_at":"2026-05-13T20:58:45.454680Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-08-05T22:51:28.082763Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2508.06418","last_updated":"2025-08-08T16:05:27Z","snapshot_observed_at":"2026-08-08T12:59:56.859606Z","submitted_at":"2025-08-08T16:05:27Z","title":"Quantifying Conversation Drift in MCP via Latent Polytope","version":1},"reference_index":10,"source":"arxiv_source","source_observed_at":"2026-08-05T22:51:28.082763Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2508.06418"},"observation_digest":"sha256:9f7e3b1ed764e9b2a26bb4e8cee07c5af4287d1bc71c8f9424ce0f4098dfb1e7","observation_id":"e0d13b95-ba3d-45c4-a254-a4f2d61dcdb2","resolution":{"observed_at":"2026-08-05T22:51:28.082763Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-08-04T14:43:49.514734Z","title":"We should identify and mitigate third-party safety risks in mcp-powered agent systems","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2509.23694","last_updated":"2026-06-03T04:13:57Z","snapshot_observed_at":"2026-08-04T14:43:33.365212Z","submitted_at":"2025-09-28T07:05:17Z","title":"SafeSearch: Automated Red-Teaming of LLM-Based Search Agents","version":6},"reference_index":11,"source":"arxiv_source","source_observed_at":"2026-08-04T14:43:49.514734Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2509.23694"},"observation_digest":"sha256:b7061cf21b73fadbc053afc062e9f0921aa439bc5793439c91e06e17a31c3b99","observation_id":"20c9401e-5b28-422d-ba1a-9243586357e2","resolution":{"observed_at":"2026-08-04T14:43:49.514734Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":"2506.13666","doi":"10.48550/arxiv.2506.13666","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"We should identify and mitigate third-party safety risks in mcp-powered agent systems","venue":"ArXiv.org","work_id":"b22353cd-1606-4671-a46c-a3a4e0f90410","year":2025},"citing_paper":{"arxiv_id":"2510.21236","last_updated":"2026-04-24T09:59:19Z","snapshot_observed_at":"2026-07-06T22:33:58.663508Z","submitted_at":"2025-10-24T08:10:36Z","title":"AgentBound: Securing Execution Boundaries of AI Agents","version":3},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-05-18T05:12:23.542793Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2510.21236"},"observation_digest":"sha256:86e3067fe11b7a642f14fbcd48c43f64360ad2baefdf714dfbf4a82898cf38dd","observation_id":"fefa0c54-1a93-4642-b570-953c2be5843e","resolution":{"observed_at":"2026-05-18T05:15:54.194195Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-08-03T10:45:41.323277Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2601.09172","last_updated":"2026-07-12T18:25:55Z","snapshot_observed_at":"2026-08-09T00:06:09.623252Z","submitted_at":"2026-01-14T05:15:10Z","title":"BalDRO: A Distributionally Robust Optimization based Framework for Large Language Model Unlearning","version":3},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-03T10:45:41.323277Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2601.09172"},"observation_digest":"sha256:6f3752e22bfc8cc33abcab2c02834b8e8f7ae4d332bb8de6bb894630f1e55368","observation_id":"3124087a-1487-43c7-acf0-c3166b8bb612","resolution":{"observed_at":"2026-08-03T10:45:41.323277Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-07-13T14:08:35.474488Z","title":"We should identify and mitigate third-party safety risks in mcp-powered agent systems.arXiv preprint arXiv:2506.13666, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2604.01904","last_updated":"2026-06-16T07:34:03Z","snapshot_observed_at":"2026-08-06T20:46:41.012304Z","submitted_at":"2026-04-02T11:19:49Z","title":"Combating Data Laundering in LLM Training","version":3},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-07-13T14:08:35.474488Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2604.01904"},"observation_digest":"sha256:7caa3a4df9d0119fb1d57477e28411dc5a8d6972ef6d4d88767f0c3c2f467502","observation_id":"99d5a936-f809-49ba-9bd3-93cff40c539c","resolution":{"observed_at":"2026-07-13T14:08:35.474488Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":"2506.13666","doi":"10.48550/arxiv.2506.13666","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"We should identify and mitigate third-party safety risks in mcp-powered agent systems","venue":"ArXiv.org","work_id":"b22353cd-1606-4671-a46c-a3a4e0f90410","year":2025},"citing_paper":{"arxiv_id":"2604.01905","last_updated":"2026-05-19T08:31:57Z","snapshot_observed_at":"2026-07-06T22:51:40.181565Z","submitted_at":"2026-04-02T11:22:07Z","title":"From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers","version":2},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-05-21T10:41:17.307952Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2604.01905"},"observation_digest":"sha256:3dc87a1f6e678a16cfc58c849c16c0b93880a0ffb12a9deb6a2dc75a02364489","observation_id":"480a69b4-2b84-4ec8-a628-112915abefca","resolution":{"observed_at":"2026-05-21T10:44:07.943736Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":"2506.13666","doi":"10.48550/arxiv.2506.13666","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"We should identify and mitigate third-party safety risks in mcp-powered agent systems","venue":"ArXiv.org","work_id":"b22353cd-1606-4671-a46c-a3a4e0f90410","year":2025},"citing_paper":{"arxiv_id":"2604.07551","last_updated":"2026-04-08T19:53:26Z","snapshot_observed_at":"2026-07-06T22:55:46.307881Z","submitted_at":"2026-04-08T19:53:26Z","title":"MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-05-10T17:10:50.283791Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2604.07551"},"observation_digest":"sha256:93e8ef99c199cfb3a478e43d74c7617e84af608d0b391fe9f9297b090c0a001e","observation_id":"90f557b0-dd05-47fa-bd65-952d9dc1467e","resolution":{"observed_at":"2026-05-10T21:10:46.722140Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"cited_work":{"arxiv_id":"2506.13666","doi":"10.48550/arxiv.2506.13666","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.13666","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"We should identify and mitigate third-party safety risks in mcp-powered agent systems","venue":"ArXiv.org","work_id":"b22353cd-1606-4671-a46c-a3a4e0f90410","year":2025},"citing_paper":{"arxiv_id":"2606.21338","last_updated":"2026-06-19T11:35:41Z","snapshot_observed_at":"2026-07-06T23:56:21.824303Z","submitted_at":"2026-06-19T11:35:41Z","title":"\"What Happens Locally, Leaks Globally\": Detecting Privacy Leakage Risks in MCP Servers","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-06-26T14:07:59.170493Z"},"links":{"cited_paper":"/paper/2506.13666","citing_paper":"/paper/2606.21338"},"observation_digest":"sha256:c1c57791c3a884e9e5a3090efe67cf690700ef402085552ede15559ec471a21a","observation_id":"6bfb7f42-7003-402d-9b36-9ebc80aaad4c","resolution":{"observed_at":"2026-07-04T06:49:38.283917Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2506.13666/citation-record","integrity":"/paper/2506.13666/integrity","json":"/paper/2506.13666/citation-record.json","paper":"/paper/2506.13666"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2405.20446","last_updated":"2025-02-04T14:35:38Z","snapshot_observed_at":"2026-08-10T04:06:38.482153Z","submitted_at":"2024-05-30T19:46:36Z","title":"Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2405.20446","snapshot_observed_at":"2026-08-07T00:32:36.443050Z","title":"Is my data in your retrieval database? membership inference attacks against retrieval augmented generation.arXiv preprint arXiv:2405.20446, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.443050Z"},"links":{"cited_paper":"/paper/2405.20446","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:d314f1bba8f774799ea23bf4f348870e6a0ee99677448eed13a0001938db6d47","observation_id":"cab8fd2c-7197-4197-b0fc-fef0587b23a5","resolution":{"observed_at":"2026-08-07T00:32:36.443050Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.447486Z","title":"Introducing the model context protocol.https://www.anthropic.com/news/ model-context-protocol, November 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.447486Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:b9ecdd511b8eb199ccd51d96328432c997fe163d241f8d0ffaaf195b61894c2d","observation_id":"da9cb528-7157-4b44-8b73-00c0227eb123","resolution":{"observed_at":"2026-08-07T00:32:36.447486Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.09932","last_updated":"2024-09-06T00:46:40Z","snapshot_observed_at":"2026-07-06T18:00:30.424554Z","submitted_at":"2024-04-15T16:58:28Z","title":"Foundational Challenges in Assuring Alignment and Safety of Large Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.09932","snapshot_observed_at":"2026-08-07T00:32:36.451035Z","title":"Foundational challenges in assuring alignment and safety of large language models.arXiv preprint arXiv:2404.09932, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.451035Z"},"links":{"cited_paper":"/paper/2404.09932","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:86ffa872444dbf1d303ded7bef9eef6a4720ef946e84030cd405bfae48f2ebd3","observation_id":"e62633f9-e83d-4a72-b74f-41265a3c4fd3","resolution":{"observed_at":"2026-08-07T00:32:36.451035Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2204.05862","last_updated":"2022-04-12T15:02:38Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2022-04-12T15:02:38Z","title":"Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2204.05862","snapshot_observed_at":"2026-08-07T00:32:36.454938Z","title":"Training a helpful and harmless assistant with reinforcement learning from human feedback.arXiv preprint arXiv:2204.05862, 2022","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.454938Z"},"links":{"cited_paper":"/paper/2204.05862","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:9bf5352bcc2df9572ab906057f73b1fd8f55c0d0819970f67398fc52e6c2b84c","observation_id":"db8f1793-bf40-42a1-9c1f-9efc77144c16","resolution":{"observed_at":"2026-08-07T00:32:36.454938Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.458413Z","title":"Safety-tuned LLaMAs: Lessons from improving the safety of large language models that follow instructions","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.458413Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:27824395e242bf7136575afd777c0c9bb166703dc650f71003af797d1a82a4e9","observation_id":"e8dd5d7a-7962-493e-b320-9fbace30b48a","resolution":{"observed_at":"2026-08-07T00:32:36.458413Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.461485Z","title":null,"venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.461485Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:70a3912ad39677ac5d9c2d6a20d57338d4cb08ee2534db80661b929f4aebccbc","observation_id":"1a387885-bd0a-4de2-9931-609e4c15616b","resolution":{"observed_at":"2026-08-07T00:32:36.461485Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.464997Z","title":"Highlights from lex fridman’s interview of yann lecun, March","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.464997Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:58129b07af4f689c4aca1f68b91660813a847d61dae926729a54b717e0a421ec","observation_id":"89437d5c-6824-41ee-9761-7ae1f94654d8","resolution":{"observed_at":"2026-08-07T00:32:36.464997Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.471713Z","title":"A survey on evaluation of large language models.ACM transactions on intelligent systems and technology, 15(3):1–45, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.471713Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:4f50f8cfd3a0770fb62f5ab3c68191d8493a1f37ba0cace91b609b1d688a90ca","observation_id":"c256f18c-5b5b-4146-88f5-2b3a8045b973","resolution":{"observed_at":"2026-08-07T00:32:36.471713Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.474958Z","title":"Pappas, Florian Tramèr, Hamed Hassani, and Eric Wong","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.474958Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:b10a7828c842d38a4944ea7b0c9615fb2dc7dc1cad7237c4a265c9580f765f37","observation_id":"11cc4119-caec-474e-968a-138ed5374a77","resolution":{"observed_at":"2026-08-07T00:32:36.474958Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.477590Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.477590Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:f6650767f465f0d60c5d3ada5c8dbd8da95598c7bfd43d53c5109c1c7735df78","observation_id":"4c2d0d40-1d6a-4979-80f0-8940a1819874","resolution":{"observed_at":"2026-08-07T00:32:36.477590Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.480493Z","title":"Safety-aware fine-tuning of large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.480493Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:9920b8a4b69025fd13476e00023f59e595eb50e4b8bf5c6ffb6ec2e43e66a112","observation_id":"599af7df-89b2-426a-9af3-6f744f976cd4","resolution":{"observed_at":"2026-08-07T00:32:36.480493Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.483792Z","title":"Scaling instruction-finetuned language models.Journal of Machine Learning Research, 25(70):1–53, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.483792Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:339c7c7bec7794809fea74809365db1f01a6b7f5cf642512fca9f6721ba0def6","observation_id":"349a1758-8d22-4163-8e06-8da4d2fdd95d","resolution":{"observed_at":"2026-08-07T00:32:36.483792Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.486870Z","title":"Textworld: A learning environment for text-based games","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.486870Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:770ded21da99589929c7a8a803bf602d5f7fc677efb82962f66f9d2db24226fc","observation_id":"4cb8a155-06a1-4f7e-ac1c-f3da080f6365","resolution":{"observed_at":"2026-08-07T00:32:36.486870Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2501.12948","last_updated":"2026-01-04T03:57:36Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-01-22T15:19:35Z","title":"DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2501.12948","snapshot_observed_at":"2026-08-07T00:32:36.489432Z","title":"DeepSeek-R1: Incentivizing reasoning capability in llms via reinforcement learning","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.489432Z"},"links":{"cited_paper":"/paper/2501.12948","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:6400cfd65f32169764b58473b0f7299acb846829d6bc1dce34cb633233e2ec3c","observation_id":"47c933f4-d52b-4cd3-a619-3aae05a6b0ad","resolution":{"observed_at":"2026-08-07T00:32:36.489432Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.492579Z","title":"Ai agents under threat: A survey of key security challenges and future pathways","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.492579Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:4fbb037afd024e9b3c0c8e1798b559ac9a899b15afd314ba84d0a572dc60ea63","observation_id":"b12f1fb7-e970-4920-862b-1ac01661ce5c","resolution":{"observed_at":"2026-08-07T00:32:36.492579Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.495577Z","title":"Bert: Pre-training of deep bidirectional transformers for language understanding","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.495577Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:b81b22bba378d9a7bdd9ebb738d26cdb046cd1398d37ed0ff3333ad65b424e72","observation_id":"5d55cfb2-91e3-4329-b16a-8462d561c64c","resolution":{"observed_at":"2026-08-07T00:32:36.495577Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2311.08268","last_updated":"2024-04-07T03:04:10Z","snapshot_observed_at":"2026-07-06T16:47:24.765597Z","submitted_at":"2023-11-14T16:02:16Z","title":"A Wolf in Sheep's Clothing: Generalized Nested Jailbreak Prompts can Fool Large Language Models Easily","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.08268","snapshot_observed_at":"2026-08-07T00:32:36.498449Z","title":"A wolf in sheep’s clothing: Generalized nested jailbreak prompts can fool large language models easily.arXiv preprint arXiv:2311.08268, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.498449Z"},"links":{"cited_paper":"/paper/2311.08268","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:9aa2517a9b6aa6a5b8fb85d4d24f61caae71e4d8292dd89d33cbf67036cde846","observation_id":"e7069162-a4b2-4c9d-8d8a-ab81d166a0c9","resolution":{"observed_at":"2026-08-07T00:32:36.498449Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2505.02279","last_updated":"2025-05-23T00:28:09Z","snapshot_observed_at":"2026-08-07T15:56:34.289224Z","submitted_at":"2025-05-04T22:18:27Z","title":"A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2505.02279","snapshot_observed_at":"2026-08-07T00:32:36.501355Z","title":null,"venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.501355Z"},"links":{"cited_paper":"/paper/2505.02279","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:9f3b98b9d98cae8bb3fa022248637100b234c3a91d54a5374246ffe54c0e37b7","observation_id":"8888b506-9c6e-4569-bb1b-e1f604fda046","resolution":{"observed_at":"2026-08-07T00:32:36.501355Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.504729Z","title":"Pawan Kumar, and Adel Bibi","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.504729Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:62718e2ca6963250d2d61131da46ae0f3475fe5c83e20b342e3d4a80c7b5ab99","observation_id":"82bac543-6e04-41e9-8fa1-0d01ddab0f31","resolution":{"observed_at":"2026-08-07T00:32:36.504729Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.14923","last_updated":"2024-10-22T00:53:48Z","snapshot_observed_at":"2026-08-08T01:05:56.776964Z","submitted_at":"2024-10-19T01:00:57Z","title":"Imprompter: Tricking LLM Agents into Improper Tool Use","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.14923","snapshot_observed_at":"2026-08-07T00:32:36.507283Z","title":"Imprompter: Tricking llm agents into improper tool use.arXiv preprint arXiv:2410.14923, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.507283Z"},"links":{"cited_paper":"/paper/2410.14923","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:adf322d400f2324ca72ace93cd72577cf5781b81bc6148eaed0efde490c0a8c0","observation_id":"87ea844c-4b84-4efe-b22f-b0f8cc12c09b","resolution":{"observed_at":"2026-08-07T00:32:36.507283Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2209.07858","last_updated":"2022-11-22T19:12:57Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2022-08-23T23:37:14Z","title":"Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2209.07858","snapshot_observed_at":"2026-08-07T00:32:36.510129Z","title":"Red teaming language models to reduce harms: Methods, scaling behaviors, and lessons learned.arXiv preprint arXiv:2209.07858, 2022","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.510129Z"},"links":{"cited_paper":"/paper/2209.07858","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:9ffdd723bdf332d91f03202dec9a80aa73347ae5216263e7c9f74bfaa9896134","observation_id":"b2baea63-0248-4742-94a6-3ba85ab31972","resolution":{"observed_at":"2026-08-07T00:32:36.510129Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2306.11644","last_updated":"2023-10-02T06:12:30Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-06-20T16:14:25Z","title":"Textbooks Are All You Need","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2306.11644","snapshot_observed_at":"2026-08-07T00:32:36.512749Z","title":"Textbooks are all you need.arXiv preprint arXiv:2306.11644, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.512749Z"},"links":{"cited_paper":"/paper/2306.11644","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:0ac50beb29b115ae86fe49bf3aae79276c4e1bd21875ce0f60c6f66813994575","observation_id":"71d669d1-12cd-4a41-869c-ffc4f118f42d","resolution":{"observed_at":"2026-08-07T00:32:36.512749Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.01680","last_updated":"2024-04-19T01:15:16Z","snapshot_observed_at":"2026-08-10T13:10:07.804621Z","submitted_at":"2024-01-21T23:36:14Z","title":"Large Language Model based Multi-Agents: A Survey of Progress and Challenges","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.01680","snapshot_observed_at":"2026-08-07T00:32:36.515911Z","title":"Large language model based multi-agents: A survey of progress and challenges.arXiv preprint arXiv:2402.01680, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.515911Z"},"links":{"cited_paper":"/paper/2402.01680","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:b68bff5dfd3d402b93c6406cf8d780a0aa93419b7495a37e5ecdb3ea9f6fb14a","observation_id":"6338beed-56ee-4479-b1ce-ca417488e76c","resolution":{"observed_at":"2026-08-07T00:32:36.515911Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.519516Z","title":"Regulating chatgpt and other large generative ai models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.519516Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:9ab3002ad9548b3e0129e09134d50a2a45a30c36ca79986abe5ef205bed3536b","observation_id":"15daf63a-56cd-4b96-afdb-15cb2ff8a771","resolution":{"observed_at":"2026-08-07T00:32:36.519516Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.522302Z","title":"A survey on large language models: Applications, challenges, limitations, and practical usage.Authorea Preprints, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.522302Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:b32782bd7901f62d3992e28bda70c3851bf89035b4f12c0489201f406fcbc4ff","observation_id":"74fbc7fb-4214-4ff9-92f1-0361627e54d6","resolution":{"observed_at":"2026-08-07T00:32:36.522302Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.01099","last_updated":"2024-08-20T17:54:08Z","snapshot_observed_at":"2026-08-10T16:25:21.386068Z","submitted_at":"2024-04-01T13:12:30Z","title":"What is in Your Safe Data? Identifying Benign Data that Breaks Safety","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.01099","snapshot_observed_at":"2026-08-07T00:32:36.525213Z","title":"What is in your safe data? identifying benign data that breaks safety.arXiv preprint arXiv:2404.01099, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.525213Z"},"links":{"cited_paper":"/paper/2404.01099","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:5dfb39086c98d14375cde8105547492f32984c1da35ec3cb87eb641cd46153cb","observation_id":"c9306aa5-16ba-4a9d-985a-e15869da3867","resolution":{"observed_at":"2026-08-07T00:32:36.525213Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.14847","last_updated":"2025-06-02T01:51:09Z","snapshot_observed_at":"2026-08-07T18:01:00.658329Z","submitted_at":"2025-02-20T18:55:39Z","title":"Red-Teaming LLM Multi-Agent Systems via Communication Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2502.14847","snapshot_observed_at":"2026-08-07T00:32:36.528134Z","title":"Red-teaming llm multi-agent systems via communication attacks.arXiv preprint arXiv:2502.14847, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.528134Z"},"links":{"cited_paper":"/paper/2502.14847","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:22be16f59b3dc60a140f0bd2fe537c6cc7b0be9f2eaae664e3f4376f17c4959f","observation_id":"73b9fd81-05b3-489c-b34b-cac9663ac932","resolution":{"observed_at":"2026-08-07T00:32:36.528134Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2503.23278","last_updated":"2025-10-07T07:13:32Z","snapshot_observed_at":"2026-07-06T21:00:55.979837Z","submitted_at":"2025-03-30T01:58:22Z","title":"Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2503.23278","snapshot_observed_at":"2026-08-07T00:32:36.535179Z","title":"Model context protocol (mcp): Landscape, security threats, and future research directions.arXiv preprint arXiv:2503.23278, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.535179Z"},"links":{"cited_paper":"/paper/2503.23278","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:589c308a7f8ef7559f21f103fe2b0fdbf08d74e9ea1112b6b8aeca05d8a2a57b","observation_id":"ed2a81ee-4b17-4cac-8223-bbed55d65379","resolution":{"observed_at":"2026-08-07T00:32:36.535179Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2501.11651","last_updated":"2025-06-13T16:15:45Z","snapshot_observed_at":"2026-08-08T22:57:04.484148Z","submitted_at":"2025-01-20T18:33:33Z","title":"T1: Advancing Language Model Reasoning through Reinforcement Learning and Inference Scaling","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2501.11651","snapshot_observed_at":"2026-08-07T00:32:36.538291Z","title":"Advancing language model reasoning through reinforcement learning and inference scaling.arXiv preprint arXiv:2501.11651, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.538291Z"},"links":{"cited_paper":"/paper/2501.11651","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:2d4543386f76260f5e77003a20f1385ab098f32235f5f878258adf2431d188ba","observation_id":"ecd65069-43f6-4e93-b30d-fac8feff78d3","resolution":{"observed_at":"2026-08-07T00:32:36.538291Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.18213","last_updated":"2025-06-05T08:11:43Z","snapshot_observed_at":"2026-08-06T20:29:52.745778Z","submitted_at":"2024-07-25T17:26:41Z","title":"Scaling Trends in Language Model Robustness","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.18213","snapshot_observed_at":"2026-08-07T00:32:36.541321Z","title":"Effects of scale on language model robustness.arXiv preprint arXiv:2407.18213, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.541321Z"},"links":{"cited_paper":"/paper/2407.18213","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:d7a39b71905d958e511e3e91574ef8cc5561a0f713df500b6f5d22be54cd6fb4","observation_id":"3ed7c96d-4758-44d2-816c-28d632e2b569","resolution":{"observed_at":"2026-08-07T00:32:36.541321Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.544502Z","title":"A survey of safety and trustworthiness of large language models through the lens of verification and validation.Artificial Intelligence Review, 57(7):175, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.544502Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:2f98e43dc6a3fef4fff4278cccd0663f8d1162c0e8760f75b7c1827d10e0d6f4","observation_id":"740059a3-efc9-4b55-8bda-5f99777f08ed","resolution":{"observed_at":"2026-08-07T00:32:36.544502Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.547224Z","title":"Babyai 1.1, 2020","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.547224Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:098f09b530b35c2147bba32e5e771d1906f8244b068c78acf685810128d79142","observation_id":"abacfcb5-873b-48ac-93bf-9f014ab7eb00","resolution":{"observed_at":"2026-08-07T00:32:36.547224Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.06674","last_updated":"2023-12-07T19:40:50Z","snapshot_observed_at":"2026-07-06T17:00:00.321552Z","submitted_at":"2023-12-07T19:40:50Z","title":"Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.06674","snapshot_observed_at":"2026-08-07T00:32:36.550081Z","title":"Llama guard: Llm-based input-output safeguard for human-ai conversations.CoRR, abs/2312.06674, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.550081Z"},"links":{"cited_paper":"/paper/2312.06674","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:677fb21e0c2baa653a597ffeba265b58d43d11b971c5734226c36dd2aea69443","observation_id":"427cf786-071f-45a2-b516-8bde402013dc","resolution":{"observed_at":"2026-08-07T00:32:36.550081Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.553330Z","title":"Mcp security notification: Tool poisoning attacks","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.553330Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:0fb6a0a34180ea33f327c9b6b254846a6d97c63720faa5dba15486ab420b05e9","observation_id":"ec439bd0-f2ff-4c1a-a184-71b64c84c100","resolution":{"observed_at":"2026-08-07T00:32:36.553330Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.12025","last_updated":"2025-02-17T16:57:56Z","snapshot_observed_at":"2026-08-07T18:11:43.608954Z","submitted_at":"2025-02-17T16:57:56Z","title":"SafeChain: Safety of Language Models with Long Chain-of-Thought Reasoning Capabilities","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2502.12025","snapshot_observed_at":"2026-08-07T00:32:36.556165Z","title":"Safechain: Safety of language models with long chain-of-thought reasoning capabilities.CoRR, abs/2502.12025, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.556165Z"},"links":{"cited_paper":"/paper/2502.12025","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:c301b459a2f6a2fa2cd2e3dd1c783cc47941fa9c36d9b382f1e71913fe62cf61","observation_id":"1244253f-4154-4114-bd33-9b4ed1d2517d","resolution":{"observed_at":"2026-08-07T00:32:36.556165Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.07791","last_updated":"2024-07-23T01:59:54Z","snapshot_observed_at":"2026-07-06T18:44:20.262496Z","submitted_at":"2024-07-10T16:08:46Z","title":"Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.07791","snapshot_observed_at":"2026-08-07T00:32:36.559678Z","title":"Flooding spread of manipulated knowl- edge in llm-based multi-agent communities.arXiv preprint arXiv:2407.07791, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.559678Z"},"links":{"cited_paper":"/paper/2407.07791","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:a06a25588aa8a58cf3407bcd1082d9d6735613f18b40ee15dbea2a8996eb1fbb","observation_id":"bdb8422b-033e-43a6-89cf-c0bda4e306b9","resolution":{"observed_at":"2026-08-07T00:32:36.559678Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.563012Z","title":"Llm-mod: Can large language models assist content moderation? InExtended Abstracts of the CHI Conference on Human Factors in Computing Systems","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.563012Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:0231a3e81c8c24c20e4c42c359f8a1277f316937f2f3bfd64633527d20f6c7db","observation_id":"19c5409f-c863-4e40-9a1b-ee970cc44425","resolution":{"observed_at":"2026-08-07T00:32:36.563012Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.565644Z","title":"Watch your language: Investigating content moderation with large language models.Proceedings of the International AAAI Conference on Web and Social Media, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.565644Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:0c15720e0feacd4715c3d90d2f60cc23a76e50308d65475953eb35bdaaa8bcc9","observation_id":"7f1e61ea-52c3-40fa-a6f5-62f2bf479779","resolution":{"observed_at":"2026-08-07T00:32:36.565644Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.12757","last_updated":"2025-05-19T08:48:07Z","snapshot_observed_at":"2026-08-07T16:01:32.883939Z","submitted_at":"2025-04-17T08:49:10Z","title":"MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.12757","snapshot_observed_at":"2026-08-07T00:32:36.568714Z","title":"Mcp guardian: A security-first layer for safeguarding mcp-based ai system.arXiv preprint arXiv:2504.12757, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.568714Z"},"links":{"cited_paper":"/paper/2504.12757","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:fd8c2e73142b1cca758e89074f510a88eed453710e30d19c957b27b1951be4d1","observation_id":"511c0034-a37f-4235-b47d-765d0119c364","resolution":{"observed_at":"2026-08-07T00:32:36.568714Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.571929Z","title":"How not to be stupid about ai, with yann lecun","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.571929Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:c1a1be993d8f5e6f3548d48f5ce2ebaa5412ff8553304db021023cd57939fd44","observation_id":"1d46beab-1ba3-4821-9853-c92ee7fc1333","resolution":{"observed_at":"2026-08-07T00:32:36.571929Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.08586","last_updated":"2025-02-12T17:19:36Z","snapshot_observed_at":"2026-08-08T23:24:16.398221Z","submitted_at":"2025-02-12T17:19:36Z","title":"Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2502.08586","snapshot_observed_at":"2026-08-07T00:32:36.575227Z","title":"Commercial llm agents are already vulnerable to simple yet dangerous attacks.arXiv preprint arXiv:2502.08586, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.575227Z"},"links":{"cited_paper":"/paper/2502.08586","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:73c34799c36b98533bd6d51d2887b7126a09332f90781c1ab74efb1c4ec998d9","observation_id":"4a01d0f6-66ab-4bb4-bdc9-77680eb4f755","resolution":{"observed_at":"2026-08-07T00:32:36.575227Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.04706","last_updated":"2024-03-07T18:00:40Z","snapshot_observed_at":"2026-08-07T09:14:55.529271Z","submitted_at":"2024-03-07T18:00:40Z","title":"Common 7B Language Models Already Possess Strong Math Capabilities","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.04706","snapshot_observed_at":"2026-08-07T00:32:36.578494Z","title":"Common 7b language models already possess strong math capabilities","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.578494Z"},"links":{"cited_paper":"/paper/2403.04706","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:c33efa5bcecb954c0acd89d1bd9630c5374822608eae561d7a86d0c9b0a03320","observation_id":"59802d7a-0a03-4b0c-9a71-8ec832f81fca","resolution":{"observed_at":"2026-08-07T00:32:36.578494Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.581487Z","title":"Camel: Communicative agents for\" mind\" exploration of large language model society.Advances in Neural Information Processing Systems, 36:51991–52008, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.581487Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:9786cb349db6e6c77e6ba00bb7e2f9b153f7b8c7cbbd7796e554a90989d33ded","observation_id":"c8132a73-f252-428c-96ae-e33004d5b5c2","resolution":{"observed_at":"2026-08-07T00:32:36.581487Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2311.03191","last_updated":"2024-11-28T13:43:50Z","snapshot_observed_at":"2026-08-04T19:12:56.970085Z","submitted_at":"2023-11-06T15:29:30Z","title":"DeepInception: Hypnotize Large Language Model to Be Jailbreaker","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.03191","snapshot_observed_at":"2026-08-07T00:32:36.584165Z","title":"Deepin- ception: Hypnotize large language model to be jailbreaker.arXiv preprint arXiv:2311.03191, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.584165Z"},"links":{"cited_paper":"/paper/2311.03191","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:b534346704a5a22071cb79e9625112c78a82f963f4fc4016adf69da867e663f5","observation_id":"9a00be52-d04d-4e03-ab77-9f90bda7a673","resolution":{"observed_at":"2026-08-07T00:32:36.584165Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2312.01552","last_updated":"2023-12-04T00:46:11Z","snapshot_observed_at":"2026-08-07T00:42:49.627314Z","submitted_at":"2023-12-04T00:46:11Z","title":"The Unlocking Spell on Base LLMs: Rethinking Alignment via In-Context Learning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2312.01552","snapshot_observed_at":"2026-08-07T00:32:36.587266Z","title":"The unlocking spell on base llms: Rethinking alignment via in-context learning.arXiv preprint arXiv:2312.01552, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.587266Z"},"links":{"cited_paper":"/paper/2312.01552","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:0c05ecf533b542fc768e55366d136b5b9134184cbc85bcdb0b0a94721d1cb6a2","observation_id":"a299b3ba-ca64-428c-a5f5-87a036e037af","resolution":{"observed_at":"2026-08-07T00:32:36.587266Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.590175Z","title":"Understanding and enhancing the transferability of jailbreaking attacks","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.590175Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:10bf1f4f6a726e7123e4b20ba48cb1fc9b45eb50475993572b6940529241a7cb","observation_id":"feffbfcf-e616-4ee4-a8e2-f837a306ebf3","resolution":{"observed_at":"2026-08-07T00:32:36.590175Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2409.00920","last_updated":"2025-07-25T08:26:54Z","snapshot_observed_at":"2026-08-07T03:58:38.931628Z","submitted_at":"2024-09-02T03:19:56Z","title":"ToolACE: Winning the Points of LLM Function Calling","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2409.00920","snapshot_observed_at":"2026-08-07T00:32:36.593020Z","title":"Toolace: Winning the points of llm function calling.arXiv preprint arXiv:2409.00920, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.593020Z"},"links":{"cited_paper":"/paper/2409.00920","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:70210ed51bf430ac55c30722966b585daaa55cff5df4f5321eb4461fb293bd5a","observation_id":"5f27bde5-03c1-4068-bc86-5710b3f6facc","resolution":{"observed_at":"2026-08-07T00:32:36.593020Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.595996Z","title":"Autodan: Generating stealthy jailbreak prompts on aligned large language models","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.595996Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:365420c3e35b6f747e366d03a49a04460c0c948d0b6d8b48e082971ea4315b97","observation_id":"64067349-a619-4bd7-b98d-afd287c03953","resolution":{"observed_at":"2026-08-07T00:32:36.595996Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.13860","last_updated":"2024-03-10T13:58:08Z","snapshot_observed_at":"2026-07-06T15:31:18.144952Z","submitted_at":"2023-05-23T09:33:38Z","title":"Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.13860","snapshot_observed_at":"2026-08-07T00:32:36.598721Z","title":"Jailbreaking chatgpt via prompt engineering: An empirical study.arXiv preprint arXiv:2305.13860, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.598721Z"},"links":{"cited_paper":"/paper/2305.13860","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:6d5d680322692e021ce6a8d2c6ab70131ced30c175f234e8cbfd81d94e14c348","observation_id":"f578c017-50af-4261-9762-8f77c9152e97","resolution":{"observed_at":"2026-08-07T00:32:36.598721Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14922","last_updated":"2024-12-19T15:00:18Z","snapshot_observed_at":"2026-08-10T14:41:19.849597Z","submitted_at":"2024-12-19T15:00:18Z","title":"RobustFT: Robust Supervised Fine-tuning for Large Language Models under Noisy Response","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2412.14922","snapshot_observed_at":"2026-08-07T00:32:36.601660Z","title":"Robustft: Robust supervised fine-tuning for large language models under noisy response, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.601660Z"},"links":{"cited_paper":"/paper/2412.14922","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:b0ed06e3dae72b9fd7ef43f537d537502e11cea12a0a0826a177b8b19d1d58c7","observation_id":"bbfc070e-c4aa-4838-bdd6-01e020769a5f","resolution":{"observed_at":"2026-08-07T00:32:36.601660Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.16717","last_updated":"2024-02-26T16:35:59Z","snapshot_observed_at":"2026-08-10T11:33:27.635491Z","submitted_at":"2024-02-26T16:35:59Z","title":"CodeChameleon: Personalized Encryption Framework for Jailbreaking Large Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.16717","snapshot_observed_at":"2026-08-07T00:32:36.604717Z","title":"Codechameleon: Personalized encryption framework for jailbreaking large language models.arXiv preprint arXiv:2402.16717, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.604717Z"},"links":{"cited_paper":"/paper/2402.16717","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:58f4862185787d4668e193150921a15742604499b0ed0b6bb55d33c73d7752ed","observation_id":"f700f20c-b668-4c99-a7fc-334e65e65551","resolution":{"observed_at":"2026-08-07T00:32:36.604717Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.607632Z","title":"Agentboard: An analytical evaluation board of multi-turn llm agents, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.607632Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:c1f6f05678d318bbe5171da2c381cc04e162dd1cc94d5c65b64c09659303b5f7","observation_id":"7954f0b0-91d6-43a7-8bd6-2edf9f2652f8","resolution":{"observed_at":"2026-08-07T00:32:36.607632Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.05206","last_updated":"2026-04-14T16:10:41Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-02-02T05:14:22Z","title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2502.05206","snapshot_observed_at":"2026-08-07T00:32:36.610249Z","title":"Safety at scale: A comprehensive survey of large model safety.arXiv preprint arXiv:2502.05206, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.610249Z"},"links":{"cited_paper":"/paper/2502.05206","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:6fc94d24239e510477c333303628975f5c1d07ee57a39433891d42b46f2edd4a","observation_id":"f5dc2dfc-0fac-4b1a-b621-b202218ea1a0","resolution":{"observed_at":"2026-08-07T00:32:36.610249Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2503.04392","last_updated":"2025-07-08T04:14:01Z","snapshot_observed_at":"2026-08-07T17:24:54.525086Z","submitted_at":"2025-03-06T12:41:54Z","title":"AgentSafe: Safeguarding Large Language Model-based Multi-agent Systems via Hierarchical Data Management","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2503.04392","snapshot_observed_at":"2026-08-07T00:32:36.613450Z","title":"Agentsafe: Safeguarding large language model-based multi- agent systems via hierarchical data management.arXiv preprint arXiv:2503.04392, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.613450Z"},"links":{"cited_paper":"/paper/2503.04392","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:75c6bc0e77bb51bd1de41a487b26768238d9727600d0cb0244ea2ab42bea3b19","observation_id":"7b9f233f-ddce-4c8d-9b52-39901c78a083","resolution":{"observed_at":"2026-08-07T00:32:36.613450Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.617161Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.617161Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:24f97484815344d641d98c928012e50fcdd3c85e8a50d62881c98bccfbeab2ed","observation_id":"c7de98e6-ed07-46f7-a216-adaf5a45e658","resolution":{"observed_at":"2026-08-07T00:32:36.617161Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2307.06435","last_updated":"2024-10-17T01:10:40Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-07-12T20:01:52Z","title":"A Comprehensive Overview of Large Language Models","version":10},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2307.06435","snapshot_observed_at":"2026-08-07T00:32:36.619901Z","title":"A comprehensive overview of large language models.arXiv preprint arXiv:2307.06435, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.619901Z"},"links":{"cited_paper":"/paper/2307.06435","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:445724a6a92856294ecefd3d3ad613096a07be6d8e4f6090e8a5afca076c4a96","observation_id":"4540d3ec-8f76-41be-b476-e4d565fa9ffe","resolution":{"observed_at":"2026-08-07T00:32:36.619901Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.623242Z","title":"GPT-4 technical report.CoRR, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.623242Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:cad71d25ca030238f83900253f0a467e07417a15d23e69e5b543db8f3fd5850e","observation_id":"26ca70b2-80f0-4e90-9655-1d19342371e8","resolution":{"observed_at":"2026-08-07T00:32:36.623242Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.626365Z","title":"Training language models to follow instructions with human feedback.Advances in neural information processing systems, 35:27730–27744, 2022","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.626365Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:ef23b3b1fbbb6b893c50ad5563683fb9b03e2cf8bbc881906c7fb68a4c3b1c26","observation_id":"93a25dfa-c201-4bb1-aaef-b423ed7d83e6","resolution":{"observed_at":"2026-08-07T00:32:36.626365Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.615371Z","title":"Self-alignment of large language models via monopolylogue-based social scene sim- ulation","venue":null,"work_id":"3e870a8a-f35d-44b0-968b-4f063a2dc2dd","year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.629215Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:7d7b58ea73ac6e6912e675784a05c5a9530300c6a2d9aa2387df4821eeefcd3d","observation_id":"5153d8fc-048f-4b5a-a9a7-4b814de674f6","resolution":{"observed_at":"2026-08-07T00:32:37.618797Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.605150Z","title":"A survey on agent-based modelling assisted by machine learning.Expert Systems, 42(1):e13325, 2025","venue":null,"work_id":"279473c3-971e-4f19-9f57-5971c2f8ce54","year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":61,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.632627Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:86a8134729a42d907d45bdd19fbb58506041cf0a565ae2d6d1f2908f2b4980e8","observation_id":"9e7ec986-2242-46b0-b1ce-329bf2db8fb7","resolution":{"observed_at":"2026-08-07T00:32:37.608506Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2311.05772","last_updated":"2024-04-08T20:42:17Z","snapshot_observed_at":"2026-07-06T16:45:32.248661Z","submitted_at":"2023-11-08T17:59:15Z","title":"ADaPT: As-Needed Decomposition and Planning with Language Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2311.05772","snapshot_observed_at":"2026-08-07T00:32:36.635903Z","title":"Adapt: As-needed decomposition and planning with language models.arXiv preprint arXiv:2311.05772, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.635903Z"},"links":{"cited_paper":"/paper/2311.05772","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:77280f0ac89779dda9c5eee20a0f40f79a78f52ffc6e3862c87e3189e4f8e7bf","observation_id":"b9f45d87-fa24-49cb-852f-836ec4551680","resolution":{"observed_at":"2026-08-07T00:32:36.635903Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2310.03693","last_updated":"2023-10-05T17:12:17Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-10-05T17:12:17Z","title":"Fine-tuning Aligned Language Models Compromises Safety, Even When Users Do Not Intend To!","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.03693","snapshot_observed_at":"2026-08-07T00:32:36.639515Z","title":"Fine-tuning aligned language models compromises safety, even when users do not intend to!arXiv preprint arXiv:2310.03693, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":63,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.639515Z"},"links":{"cited_paper":"/paper/2310.03693","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:360506594bf2c1433eb16391650e0d20378cee67284e5719f0ff9ddca32aeb23","observation_id":"bfe99cd4-0424-4e95-bcd6-a7d4a6e6dd80","resolution":{"observed_at":"2026-08-07T00:32:36.639515Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.595302Z","title":"Safety alignment should be made more than just a few tokens deep","venue":null,"work_id":"42ae65cd-8e63-4d6f-99ae-c164d8924f5a","year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.642841Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:33384ad2b9a5f0131f6725fbb18bc869cd9aad6b79990c53cd0e9a1c405b4a10","observation_id":"fc79b600-34e2-42f3-bf03-69748daac3d7","resolution":{"observed_at":"2026-08-07T00:32:37.598823Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.03767","last_updated":"2025-04-11T16:59:05Z","snapshot_observed_at":"2026-08-09T15:33:11.934104Z","submitted_at":"2025-04-02T21:46:02Z","title":"MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.03767","snapshot_observed_at":"2026-08-07T00:32:36.645879Z","title":"Mcp safety audit: Llms with the model context protocol allow major security exploits.arXiv preprint arXiv:2504.03767, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.645879Z"},"links":{"cited_paper":"/paper/2504.03767","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:22b3276ba59826f46ba71807f0bb236ed81d8a2f0789f39ec7777bb9db819751","observation_id":"54ba21df-c8af-47e0-a521-de0985373cb3","resolution":{"observed_at":"2026-08-07T00:32:36.645879Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.585382Z","title":"Tptu: Task planning and tool usage of large language model-based ai agents","venue":null,"work_id":"7eb99849-9e5c-4258-8ae9-38e244e624cf","year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":66,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.648975Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:98b0645aac3893440d13fcddaee3327f97669b8dc8f97e712fdcf5566246ee13","observation_id":"a26c16fc-22fc-46ef-83f1-d36f03a32ea9","resolution":{"observed_at":"2026-08-07T00:32:37.588649Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.651630Z","title":"Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36: 68539–68551, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":67,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.651630Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:c81bb476045ebdfdff60eae867a76ae66dfafaafcd626650ee356d61d39b4015","observation_id":"eee225d5-1ecd-48db-83f4-59c3f3eb83e2","resolution":{"observed_at":"2026-08-07T00:32:36.651630Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2412.17686","last_updated":"2024-12-23T16:11:27Z","snapshot_observed_at":"2026-07-06T20:12:13.548098Z","submitted_at":"2024-12-23T16:11:27Z","title":"Large Language Model Safety: A Holistic Survey","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2412.17686","snapshot_observed_at":"2026-08-07T00:32:36.657747Z","title":"Large language model safety: A holistic survey","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":69,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.657747Z"},"links":{"cited_paper":"/paper/2412.17686","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:ce071b2ccf62f0f80527ebc68226a1f91e1397aa430498d6e088af34d4102ee6","observation_id":"95941cb5-c39b-4245-9ab4-f38416c441f1","resolution":{"observed_at":"2026-08-07T00:32:36.657747Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.569324Z","title":"Welcome to the era of experience.Google AI, 2025","venue":null,"work_id":"3fe461e8-e5c5-4201-baa6-885284907067","year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":70,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.660554Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:a3a1ee885c58a6ac4a9924c61b67cb5a28d8f372fcb86331bcf002b42d9cb0e0","observation_id":"e38e1f26-8af7-43dc-846e-f22688ba3362","resolution":{"observed_at":"2026-08-07T00:32:37.572748Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.560092Z","title":"Large language model (chatgpt) as a support tool for breast tumor board.NPJ Breast Cancer, 9(1):44, 2023","venue":null,"work_id":"3fc76449-843a-405e-880e-4bca578e2dca","year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":71,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.663467Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:5d31f74d31efc074ddc15fca6a5f7dcd1e31f31d85fe33b2f967ba7f45dd3e8f","observation_id":"bc18e7db-d374-4fb0-bf7f-cce0c18a9f5c","resolution":{"observed_at":"2026-08-07T00:32:37.563133Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2306.05301","last_updated":"2023-09-07T12:20:45Z","snapshot_observed_at":"2026-07-06T15:40:20.267344Z","submitted_at":"2023-06-08T15:46:32Z","title":"ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2306.05301","snapshot_observed_at":"2026-08-07T00:32:36.666302Z","title":"Toolalpaca: Generalized tool learning for language models with 3000 simulated cases.arXiv preprint arXiv:2306.05301, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":72,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.666302Z"},"links":{"cited_paper":"/paper/2306.05301","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:1c3fe6082e6dd320fdf739586592b8bde1121dca0eddf2d836047fb3c790e0b4","observation_id":"068ee5fd-9a41-438b-bcaa-82dc516b2131","resolution":{"observed_at":"2026-08-07T00:32:36.666302Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2503.06072","last_updated":"2025-08-01T01:52:05Z","snapshot_observed_at":"2026-08-09T18:57:28.644927Z","submitted_at":"2025-03-08T05:41:42Z","title":"A Survey on Post-training of Large Language Models","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2503.06072","snapshot_observed_at":"2026-08-07T00:32:36.669532Z","title":"A survey on post-training of large language models.arXiv preprint arXiv:2503.06072, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":73,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.669532Z"},"links":{"cited_paper":"/paper/2503.06072","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:e930366b12143f2775dc9f08877275462aa3c9ec67de41bf18f96d1f75acb695","observation_id":"f034a09e-e2fa-4274-ab49-808463f0e4b1","resolution":{"observed_at":"2026-08-07T00:32:36.669532Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2501.06322","last_updated":"2025-01-10T19:56:50Z","snapshot_observed_at":"2026-07-30T22:07:13.869232Z","submitted_at":"2025-01-10T19:56:50Z","title":"Multi-Agent Collaboration Mechanisms: A Survey of LLMs","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2501.06322","snapshot_observed_at":"2026-08-07T00:32:36.672515Z","title":"Multi-agent collaboration mechanisms: A survey of llms.arXiv preprint arXiv:2501.06322, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":74,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.672515Z"},"links":{"cited_paper":"/paper/2501.06322","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:fee2da6fa683d80710a16e7dde7a3c7337da0ba472e6c8d07ee98227723a9300","observation_id":"e49dc2bf-5595-4833-a4fd-4f0d3ee92e48","resolution":{"observed_at":"2026-08-07T00:32:36.672515Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.550918Z","title":"House Committee on Oversight and Accountability","venue":null,"work_id":"0f3557c3-d6ce-41d4-a2f5-503d973f05fc","year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":75,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.675669Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:5c7c49cf4223c3ed5b8b875ace67156ba68a015ae8170c5de60c96d16eac04d0","observation_id":"036f6ddd-16e2-4554-a054-a056ef1b0c3c","resolution":{"observed_at":"2026-08-07T00:32:37.553788Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2412.10198","last_updated":"2025-02-07T13:26:18Z","snapshot_observed_at":"2026-08-09T10:37:48.124404Z","submitted_at":"2024-12-13T15:15:24Z","title":"From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2412.10198","snapshot_observed_at":"2026-08-07T00:32:36.678358Z","title":"From allies to adversaries: Manipulating llm tool-calling through adversarial injection.arXiv preprint arXiv:2412.10198, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":76,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.678358Z"},"links":{"cited_paper":"/paper/2412.10198","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:e49beec5a2b9a4aada043545c1dbc7bdcdc03fcee1af25a12bceeb22d2ac8754","observation_id":"6ba5b7ab-5472-4f04-ba3b-bd5d1c00b471","resolution":{"observed_at":"2026-08-07T00:32:36.678358Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.540233Z","title":"Backdooralign: Mitigating fine-tuning based jailbreak attack with backdoor enhanced safety alignment","venue":null,"work_id":"8571157f-ef59-4f47-aac0-c924478d811f","year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":77,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.682146Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:97167324fb363df953cca16b77afeb8bb37a41e2f1d249f13acea7685ac868da","observation_id":"6fe0c16b-c9c5-4686-b103-ddb0ced94a13","resolution":{"observed_at":"2026-08-07T00:32:37.544261Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-08-09T14:46:30.842437Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-07T00:32:36.685699Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment.arXiv preprint arXiv:2504.15585, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":78,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.685699Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:537035ab502471dc302187d9e992bfc155545289751f435db1ccb43e584d5eb1","observation_id":"1cd39cb2-ad4d-4097-9cd9-44ea269ef0ba","resolution":{"observed_at":"2026-08-07T00:32:36.685699Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2203.07540","last_updated":"2022-11-14T17:52:27Z","snapshot_observed_at":"2026-08-06T07:25:42.562786Z","submitted_at":"2022-03-14T22:52:34Z","title":"ScienceWorld: Is your Agent Smarter than a 5th Grader?","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2203.07540","snapshot_observed_at":"2026-08-07T00:32:36.689405Z","title":"Science- world: Is your agent smarter than a 5th grader?, 2022","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":79,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.689405Z"},"links":{"cited_paper":"/paper/2203.07540","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:f03afec988a62b763034c17b36373d884689cd94ec8cef4a6b7e977475099f77","observation_id":"be9ee4a7-10a0-4f4b-a793-d24b6bec5b18","resolution":{"observed_at":"2026-08-07T00:32:36.689405Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.11127","last_updated":"2025-02-16T13:48:41Z","snapshot_observed_at":"2026-08-07T18:14:46.655001Z","submitted_at":"2025-02-16T13:48:41Z","title":"G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent Systems","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2502.11127","snapshot_observed_at":"2026-08-07T00:32:36.692682Z","title":"G-safeguard: A topology-guided security lens and treatment on llm-based multi-agent systems.arXiv preprint arXiv:2502.11127, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":80,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.692682Z"},"links":{"cited_paper":"/paper/2502.11127","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:a03f64ce2eb9ccf968f9bd5537ec41e48455cfbb4d4897e12c1e778f6124e74d","observation_id":"785cfa32-51aa-4d6f-ad78-502d0157a6af","resolution":{"observed_at":"2026-08-07T00:32:36.692682Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.695853Z","title":"Augmenting language models with long-term memory.Advances in Neural Information Processing Systems, 36:74530–74543, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":81,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.695853Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:a0051adc256dba3ec0013bc002930d1f2aa84ffe9a9575710c7b6763ada7a330","observation_id":"b61d1d5a-cf4b-4993-a884-8647f3aef8da","resolution":{"observed_at":"2026-08-07T00:32:36.695853Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2406.04151","last_updated":"2024-06-06T15:15:41Z","snapshot_observed_at":"2026-08-09T08:52:31.974183Z","submitted_at":"2024-06-06T15:15:41Z","title":"AgentGym: Evolving Large Language Model-based Agents across Diverse Environments","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2406.04151","snapshot_observed_at":"2026-08-07T00:32:36.698999Z","title":"Agentgym: Evolving large language model-based agents across diverse environments.arXiv preprint arXiv:2406.04151, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":82,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.698999Z"},"links":{"cited_paper":"/paper/2406.04151","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:5d70aed5aeff9083f9d1d4dc96a13ba4598e807ee0b9ae63defd3f39ec71dbb7","observation_id":"c81ab498-e158-400f-84ac-8be0fcd0581e","resolution":{"observed_at":"2026-08-07T00:32:36.698999Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.702156Z","title":"The rise and potential of large language model based agents: A survey.Science China Information Sciences, 68(2):121101, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":83,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.702156Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:2a40904f39c14dd045215358bf41bc8cdffdc0e73b1acd87e6e81e4f764c12fe","observation_id":"e48af40e-acf2-42d8-b9d9-dd4fc079521b","resolution":{"observed_at":"2026-08-07T00:32:36.702156Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.704889Z","title":"Certifiably robust rag against retrieval corruption.arXiv preprint arXiv:2405.15556, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":84,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.704889Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:231e26a4d342d65a60f02fe2fd0d632aacdc86ea39730b9637d7dd938aa895ee","observation_id":"f96d077d-7cfb-4ecc-949e-513f4ebb4f35","resolution":{"observed_at":"2026-08-07T00:32:36.704889Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.518621Z","title":"Bag of tricks: Benchmarking of jailbreak attacks on llms","venue":null,"work_id":"56f99711-186d-4b0c-81a7-ca02225cd9ff","year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":85,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.707657Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:8b6dc752a747af626dc4ed70552610d5e9d26acd1fb36a3194ac4ff784e7d933","observation_id":"380e6eee-66c5-484b-86ee-9f201f1e5933","resolution":{"observed_at":"2026-08-07T00:32:37.521751Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2505.09388","last_updated":"2025-05-14T13:41:34Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-05-14T13:41:34Z","title":"Qwen3 Technical Report","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2505.09388","snapshot_observed_at":"2026-08-07T00:32:36.710457Z","title":"Qwen3 technical report.arXiv preprint arXiv:2505.09388, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":86,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.710457Z"},"links":{"cited_paper":"/paper/2505.09388","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:b02763a8fb27910686dcfcd6d1fefe4145c2916ee39b4cff5f15f2f2d25b4677","observation_id":"74828f52-df54-443a-8638-be1165b46fcd","resolution":{"observed_at":"2026-08-07T00:32:36.710457Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.713245Z","title":"Gpt4tools: Teaching large language model to use tools via self-instruction.Advances in Neural Information Processing Systems, 36:71995–72007, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":87,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.713245Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:11d1bb325cd0e9d4cd0b8e5731712d832a4c73dc685e9cebf7cdf6be466a958e","observation_id":"95703251-2882-404c-9a50-c7e497ae4a07","resolution":{"observed_at":"2026-08-07T00:32:36.713245Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.503604Z","title":"The second half","venue":null,"work_id":"47875808-7544-4bb9-9cdb-02b80c759cf6","year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":88,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.716985Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:45e8055c76c0acd66153fa513da62e1943a24e209093487728b77e1e7eabffd4","observation_id":"a19666c5-0f5d-45e7-a5fb-c9349549add3","resolution":{"observed_at":"2026-08-07T00:32:37.506455Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:36.719731Z","title":"Webshop: Towards scalable real-world web interaction with grounded language agents.Advances in Neural Information Processing Systems, 35:20744–20757, 2022","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":89,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.719731Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:be2d58e14c46cdadb8405ea77c46fb087903d01170adab276b6490b250249fac","observation_id":"7f61f150-b491-4527-9a47-b62e72b3d17d","resolution":{"observed_at":"2026-08-07T00:32:36.719731Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.487221Z","title":"On the vulnerability of safety alignment in open-access llms","venue":null,"work_id":"f63bad74-cf5d-4eb9-8cf9-3a694dae7d2f","year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":90,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.722464Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:1458a0467014b3b242b173b30cf619c5546ac0f3610cfd98cd1408f13417cce9","observation_id":"fea6eceb-7aa5-4c7c-b05d-1c583cb0e5d6","resolution":{"observed_at":"2026-08-07T00:32:37.490297Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.15686","last_updated":"2024-10-21T06:54:27Z","snapshot_observed_at":"2026-08-04T07:28:02.629995Z","submitted_at":"2024-10-21T06:54:27Z","title":"NetSafe: Exploring the Topological Safety of Multi-agent Networks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.15686","snapshot_observed_at":"2026-08-07T00:32:36.725488Z","title":"Netsafe: Exploring the topological safety of multi-agent networks.arXiv preprint arXiv:2410.15686, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":91,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.725488Z"},"links":{"cited_paper":"/paper/2410.15686","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:38df8bc45df1828bb87237cba547409be53f97cc6007173183faea9b0d656682","observation_id":"adf6ba7d-7317-400d-a0e8-27f41b4d2700","resolution":{"observed_at":"2026-08-07T00:32:36.725488Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2503.09648","last_updated":"2025-03-12T08:42:05Z","snapshot_observed_at":"2026-08-07T17:10:45.463485Z","submitted_at":"2025-03-12T08:42:05Z","title":"A Survey on Trustworthy LLM Agents: Threats and Countermeasures","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2503.09648","snapshot_observed_at":"2026-08-07T00:32:36.728262Z","title":"A survey on trustworthy llm agents: Threats and countermeasures.arXiv preprint arXiv:2503.09648, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":92,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.728262Z"},"links":{"cited_paper":"/paper/2503.09648","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:4ad8c29ec96d17d93e3203fc282dbff700969064e444c1f7ad8b588149f76c00","observation_id":"658a354a-f690-49f2-985f-f7672cd019dc","resolution":{"observed_at":"2026-08-07T00:32:36.728262Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T00:32:36.731379Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher.arXiv preprint arXiv:2308.06463, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":93,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.731379Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:0acac83158f5a0ce84a8aef012b355da07e07cb1870dcb1a8ffb9f931aa80df2","observation_id":"1524d6e6-286a-43ba-93ef-3b2fef453951","resolution":{"observed_at":"2026-08-07T00:32:36.731379Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.16893","last_updated":"2024-02-23T18:35:15Z","snapshot_observed_at":"2026-08-09T00:18:43.208790Z","submitted_at":"2024-02-23T18:35:15Z","title":"The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG)","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.16893","snapshot_observed_at":"2026-08-07T00:32:36.734755Z","title":"The good and the bad: Exploring privacy issues in retrieval- augmented generation (rag).arXiv preprint arXiv:2402.16893, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":94,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.734755Z"},"links":{"cited_paper":"/paper/2402.16893","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:7511d13b6f10e3100fe6c5ede1d186925557b11bc525364361ca868b960e02b8","observation_id":"00c62709-3317-40a3-b346-442a63fdae42","resolution":{"observed_at":"2026-08-07T00:32:36.734755Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2407.20859","last_updated":"2024-07-30T14:35:31Z","snapshot_observed_at":"2026-07-06T18:53:57.980865Z","submitted_at":"2024-07-30T14:35:31Z","title":"Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2407.20859","snapshot_observed_at":"2026-08-07T00:32:36.737890Z","title":"Breaking agents: Compromising autonomous llm agents through malfunction amplification.arXiv preprint arXiv:2407.20859, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":95,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.737890Z"},"links":{"cited_paper":"/paper/2407.20859","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:8dc7d975cdca75435c824b78c3a3287aa6a9802b35f531eaccb17a0deb8ce2f6","observation_id":"f589ac32-fc8d-4d1b-96e3-5b2e30bd4aa3","resolution":{"observed_at":"2026-08-07T00:32:36.737890Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.02506","last_updated":"2024-10-03T14:14:31Z","snapshot_observed_at":"2026-08-06T07:05:30.821556Z","submitted_at":"2024-10-03T14:14:31Z","title":"Cut the Crap: An Economical Communication Pipeline for LLM-based Multi-Agent Systems","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.02506","snapshot_observed_at":"2026-08-07T00:32:36.740954Z","title":"Cut the crap: An economical communication pipeline for llm-based multi-agent systems.arXiv preprint arXiv:2410.02506, 2024","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":96,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.740954Z"},"links":{"cited_paper":"/paper/2410.02506","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:42b168fcfc4425934c0ee894a72b25f09e4177ca3009e6d6691ca6e05b19024e","observation_id":"ab6de568-c470-4aab-88e5-dea0578791ba","resolution":{"observed_at":"2026-08-07T00:32:36.740954Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.11782","last_updated":"2025-02-06T15:37:52Z","snapshot_observed_at":"2026-08-04T04:02:29.838505Z","submitted_at":"2024-10-15T17:01:21Z","title":"G-Designer: Architecting Multi-agent Communication Topologies via Graph Neural Networks","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.11782","snapshot_observed_at":"2026-08-07T00:32:36.744658Z","title":"G-designer: Architecting multi-agent communication topologies via graph neural networks.arXiv preprint arXiv:2410.11782, 2024","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":97,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.744658Z"},"links":{"cited_paper":"/paper/2410.11782","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:1c0e92c2aab727447a4ac7e24cee2c8584df81ae61f028b39dc6133fa4dcdda8","observation_id":"e4edd56d-f9ec-49a4-953c-f24c4b7be12c","resolution":{"observed_at":"2026-08-07T00:32:36.744658Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2502.04180","last_updated":"2025-06-09T05:15:47Z","snapshot_observed_at":"2026-08-08T23:12:45.901049Z","submitted_at":"2025-02-06T16:12:06Z","title":"Multi-agent Architecture Search via Agentic Supernet","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2502.04180","snapshot_observed_at":"2026-08-07T00:32:36.747826Z","title":"Multi-agent architecture search via agentic supernet.arXiv preprint arXiv:2502.04180, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":98,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.747826Z"},"links":{"cited_paper":"/paper/2502.04180","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:5eb8b9f021a48cb72095d0d68644de62473a8676f340408c5585f47c567e7bf7","observation_id":"957146b2-5704-4b00-aba6-c0e9972dae84","resolution":{"observed_at":"2026-08-07T00:32:36.747826Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.477099Z","title":"On large language models safety, security, and privacy: A survey.Journal of Electronic Science and Technology, page 100301, 2025","venue":null,"work_id":"fb169810-8176-4725-babb-df7addae6473","year":2025},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":99,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.751306Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:092d097278817cbf00f2064bf75cec7198a3f0349bbc189fffdbe46dc594aeab","observation_id":"135758a2-101f-46b2-b1b3-b9f34e775ef4","resolution":{"observed_at":"2026-08-07T00:32:37.480624Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.13501","last_updated":"2024-04-21T01:49:46Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-04-21T01:49:46Z","title":"A Survey on the Memory Mechanism of Large Language Model based Agents","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.13501","snapshot_observed_at":"2026-08-07T00:32:36.754225Z","title":"A survey on the memory mechanism of large language model based agents.arXiv preprint arXiv:2404.13501, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":100,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.754225Z"},"links":{"cited_paper":"/paper/2404.13501","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:2881f80458734d68f9932a3d3e21d4bb8f45673fef21833d9d647ed137c7c9cb","observation_id":"345cee46-9e13-41d1-b269-df216f2781e7","resolution":{"observed_at":"2026-08-07T00:32:36.754225Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14470","last_updated":"2025-05-20T05:58:23Z","snapshot_observed_at":"2026-08-06T12:35:19.109481Z","submitted_at":"2024-12-19T02:35:15Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2412.14470","snapshot_observed_at":"2026-08-07T00:32:36.757251Z","title":"Agent-safetybench: Evaluating the safety of llm agents.arXiv preprint arXiv:2412.14470, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":101,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.757251Z"},"links":{"cited_paper":"/paper/2412.14470","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:4c893c3c065394b151c49402ab9550b034f38c7c6f69f1e993acdb75adbbc48a","observation_id":"076583d6-15c9-4396-a3d0-44469bf491fb","resolution":{"observed_at":"2026-08-07T00:32:36.757251Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T00:32:37.467498Z","title":"Weak-to-strong jailbreaking on large language models","venue":null,"work_id":"8862197d-b57b-40e4-8fbb-f43f77e0ab13","year":2024},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":102,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.760608Z"},"links":{"citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:9a5b0a4db4cec457554ee6f7d67c21801765b0e62f38d52793990abff15492cc","observation_id":"3a8ecb07-4fc3-4a68-ab6a-ff2bac3b1b42","resolution":{"observed_at":"2026-08-07T00:32:37.470778Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","latest_version":1,"primary_category":"cs.LG","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems"},"reference_resolution":{"displayed":100,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":87,"verified_exact":0,"verified_fuzzy":13},"total_outbound_references":107},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-10T06:31:04.303077+00:00","source":"crossref"},{"observed_at":"2026-08-10T06:30:57.382061+00:00","source":"retraction_watch"}],"thesis":"As of 10 August 2026, this Paper Citation Record lists 100 of 107 outbound references and 10 inbound Pith citation observations for arXiv:2506.13666."}