{"as_of":"2026-08-21T23:28:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:1db97a1f32e177de79b731e795d01be56eb8b645698512ee058fc08f012b3442","coverage":[{"denominator":76,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":76,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-06T20:29:46.464523Z","state":"measured"},{"denominator":77,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":77,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-21T06:32:19.484+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-05-20T10:51:19.555985Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-20T10:53:13.363465Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"cited_work":{"arxiv_id":"2507.02699","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2507.02699","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"arXiv preprint arXiv:2507.02699 , year=","venue":null,"work_id":"eb58737e-3b3b-4147-ac87-2b3b1713c426","year":null},"citing_paper":{"arxiv_id":"2605.17830","last_updated":"2026-05-18T04:06:34Z","snapshot_observed_at":"2026-08-15T04:24:56.358655Z","submitted_at":"2026-05-18T04:06:34Z","title":"Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents","version":1},"reference_index":24,"source":"arxiv_source","source_observed_at":"2026-05-20T10:51:19.555985Z"},"links":{"cited_paper":"/paper/2507.02699","citing_paper":"/paper/2605.17830"},"observation_digest":"sha256:52c6b2ba41339752aea7f00c4c1af308c86e3150711c8aa75d57bb675aec1ffa","observation_id":"97c55fa5-8be5-47a3-84d6-6f63219e8a96","resolution":{"observed_at":"2026-05-20T10:53:13.365092Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2507.02699/citation-record","integrity":"/paper/2507.02699/integrity","json":"/paper/2507.02699/citation-record.json","paper":"/paper/2507.02699"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.195171Z","title":"infosecurity-magazine.com/news/ 91-of-apt-attacks-start-with-a-spear-phishing/ , 2012","venue":null,"work_id":"921dc32d-c0db-4477-830e-5329a57d1b27","year":2012},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:39.959006Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:5ebc552cd9a20b2a6158dac410e22c8986a922a2e3425ef278979081bed72e48","observation_id":"6325995f-bcba-4904-9719-c869eddb0d9f","resolution":{"observed_at":"2026-08-06T20:29:57.200866Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.177764Z","title":"https://www.paubox.com/blog/ the-email-connection-with-atp-attacks , 2023","venue":null,"work_id":"8b86bd3d-fa6f-45a8-970e-07594a33daae","year":2023},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.061302Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:1e824bac51497b07c6bac1322a03b2a11bfc8275b855a14207cfbc80a63d1052","observation_id":"2fb8f170-7167-45c9-a293-09886f92b949","resolution":{"observed_at":"2026-08-06T20:29:57.184103Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.161115Z","title":"https://github.com/ transitive-bullshit/agentic, 2025","venue":null,"work_id":"4e9b4a45-9e57-4325-a2ac-28db1a924036","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.135382Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:a4a530baab1450efe22384635920298f38110642ff47ca0060868a0dd63744da","observation_id":"0bb9c941-fb87-4299-8cef-6fc719a3d2d5","resolution":{"observed_at":"2026-08-06T20:29:57.166448Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.144160Z","title":"https://github.com/ aiwaves-cn/agents, 2025","venue":null,"work_id":"89e7998b-eeda-4134-8131-6fdaa06da5b6","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.214054Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:75509f3e2ba4a48aa43d2a740de45c080ed25bae163ddafed3372de4b876c620","observation_id":"a3e333ff-e6b7-477f-82cd-5937bcabf11f","resolution":{"observed_at":"2026-08-06T20:29:57.149457Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.129493Z","title":"https://docs","venue":null,"work_id":"de23e96e-073b-47de-8ef7-7d2433900e06","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.285134Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:8da66ea1d46bd16ea40f6a4cf2cc7f682fd0897845db664a74274daf22b6ca45","observation_id":"b37628b6-6efd-4ba5-836d-7edf0ac29f85","resolution":{"observed_at":"2026-08-06T20:29:57.133888Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.115380Z","title":"https://github.com/HKUDS/ AutoAgent, 2025","venue":null,"work_id":"508a7784-42b7-4ed4-8e11-fd5c6014d2a3","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.369271Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:add4ebd6bebb8bcd438557eac30816cc71f909e5020f5f85cff61218027c6534","observation_id":"337266e5-4e21-4224-ac68-eadb16b0bb87","resolution":{"observed_at":"2026-08-06T20:29:57.119874Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.098646Z","title":"https://github.com/ deepseek-ai/DeepSeek-R1, 2025","venue":null,"work_id":"95f9ab7d-5b60-4f44-a801-abc7771c23d9","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.471796Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:42a9dab7e6019cd0b29eef4a87183425056e199af686f3ee475877e085d9bee4","observation_id":"c31d47cb-e53f-4048-8ae0-da64d5f57be2","resolution":{"observed_at":"2026-08-06T20:29:57.103738Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.082732Z","title":"https://github.com/ deepseek-ai/DeepSeek-V3, 2025","venue":null,"work_id":"8e519fa4-3aef-4d8f-9f31-0c4aa98d9599","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.557561Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:cf9c5471376cc7bc27cc20aeff605b4fa2b4981b80d960f7913ffc5257109c4b","observation_id":"00df22cf-646e-4139-9857-8b9cd7b6dde4","resolution":{"observed_at":"2026-08-06T20:29:57.087541Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.065948Z","title":"https://ai.google.dev/ gemini-api/docs/models?authuser=1# gemini-1.5-pro, 2025","venue":null,"work_id":"c23ccbf9-0ffd-41bb-acd7-d5a1d52d253e","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.633975Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:25b980c2e5e7441bdd4c09c96fae3b78e593443d4cd9be6e0c2cd13ae4d10533","observation_id":"c4759c04-b8b6-494b-9e21-5f13db739875","resolution":{"observed_at":"2026-08-06T20:29:57.071198Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.050336Z","title":"https://ai.google.dev/ gemini-api/docs/models?authuser=1# gemini-2.0-flash, 2025","venue":null,"work_id":"48cdf361-521e-4a18-abf9-6a9a639b8724","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.711855Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:c428b1073a5d09a1b1f17ef51c6077f3441558febe3b43ca2d81d41880b324a6","observation_id":"ba818543-c5ad-4c39-b1e4-55883bef6a99","resolution":{"observed_at":"2026-08-06T20:29:57.055478Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.033079Z","title":"https://github.com/, 2025","venue":null,"work_id":"ebfe6bac-6412-4e34-9663-9b085bd37c64","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.790902Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:d30099a8d67adcb128517af6f13e37bb1322ef8fdf87d67c6ade2ec1a399cee1","observation_id":"43acee7e-2371-4ffe-ad92-ef800d56c240","resolution":{"observed_at":"2026-08-06T20:29:57.037870Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.017563Z","title":"https://github.com/griptape-ai/ griptape, 2025","venue":null,"work_id":"6f83dd2a-f9a1-4c8a-a814-434e56d1ddec","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.867170Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:8f25e5be788f6578d5e13461a38752f5869add3f2c222b2b76d0f7a329e0a003","observation_id":"e59f635a-055b-4158-8b83-97bc395cfeca","resolution":{"observed_at":"2026-08-06T20:29:57.022706Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:57.001653Z","title":"https://github.com/deepset-ai/ haystack, 2025","venue":null,"work_id":"50c6d651-8c14-4162-8d98-89e349428907","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.942749Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:b853075452c1fbc122dfe6e3fe26be7fb738fef6087ba6aea91237836f469157","observation_id":"d6377911-5b69-4071-a8f6-ada44c15ba9d","resolution":{"observed_at":"2026-08-06T20:29:57.006723Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:56.987091Z","title":"https://huggingface.co/, 2025","venue":null,"work_id":"ccacae69-fcf8-4cef-93b7-025148c55a12","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:40.987812Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:6cfaa3c7061d68e762150fd72116418c5f319d21b6ad4f81d1769c8739bdeced","observation_id":"65c9a792-6ac1-498b-93ee-f3342b48a841","resolution":{"observed_at":"2026-08-06T20:29:56.991661Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:56.970804Z","title":"https://github.com/InternLM/ lagent, 2025","venue":null,"work_id":"6c05385b-fced-4290-bcb4-152c889df281","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.122183Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:38d69b1c789bbf85ff4853d72f670b488f9d14843522d5d5a47ea8f89ef7556e","observation_id":"38379a74-07ae-4628-9e8f-bac969167e68","resolution":{"observed_at":"2026-08-06T20:29:56.975802Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:56.845968Z","title":"https://github.com/ langchain-ai/langchain, 2025","venue":null,"work_id":"dd4f0670-5623-4fe1-b7c0-e7e1be160f77","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.247853Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:d2ca57be8a7fd8921fbeb8d24352eacb09e3e160399c408e1060517d60797264","observation_id":"ac9ab31a-59aa-4c05-b1d2-ef1e8eac7fe8","resolution":{"observed_at":"2026-08-06T20:29:56.959184Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:56.612787Z","title":"https://smith.langchain","venue":null,"work_id":"945983d9-f551-477f-92d8-8159ecf9e41c","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.375746Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:cb7694a266a9c5063ae7fb9e4bbac862364b394916bf336c9579d8a823689d64","observation_id":"c4b42c7d-0607-4fb7-a58b-57977d943f40","resolution":{"observed_at":"2026-08-06T20:29:56.680071Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:56.370772Z","title":"https://github.com/langflow-ai/ langflow, 2025","venue":null,"work_id":"a80202f6-e5bb-4c2d-ad3d-2b144744a310","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.530606Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:0e7c647b90f8dfbbb0638415a2f953091fcd927956b0cec9db0b89aeca989a9d","observation_id":"fd510ae5-9a4f-45ff-87b9-2880b2328439","resolution":{"observed_at":"2026-08-06T20:29:56.537349Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:56.037726Z","title":"https://github.com/langroid/ langroid, 2025","venue":null,"work_id":"8de16971-bcee-44f6-a6b8-9c5c6f78e4f7","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.610299Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:dbe1dabb4aaf60b185729cbccec88bcc4cfae0950ed53cfaed1c4bbea28bc3b1","observation_id":"3caa2be8-a194-4254-9a1e-2113c9034922","resolution":{"observed_at":"2026-08-06T20:29:56.155932Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:55.710908Z","title":"https://github.com/letta-ai/letta, 2025","venue":null,"work_id":"c2e6971b-eaec-436c-9721-7569be6ff296","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.671570Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:b24c4b28c03d136fc1581da3b1c2852c9c9764a7d8da84f1dd03b9bf9c230d97","observation_id":"01bcf1c5-64f9-43f0-af4b-541025c769f5","resolution":{"observed_at":"2026-08-06T20:29:55.864637Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:55.473808Z","title":"https://ollama.com/library/ llama3, 2025","venue":null,"work_id":"558294c3-51df-4c83-b293-598e06c08ac0","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.729559Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:56f34d87f745fcb5914798d65933fa8506a34f6c18bc62f68a38d9e531ddc2fb","observation_id":"38880e9b-03fa-43da-a984-ab025b1572c6","resolution":{"observed_at":"2026-08-06T20:29:55.594134Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:55.281304Z","title":"https://ollama.com/library/ llama3.1, 2025","venue":null,"work_id":"6566d9ce-a97e-403a-b578-cfb110b123ce","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.787679Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:f381927f73da2d0b97cb08f9df9909c37301078cb3462259a32c10f3e191f4cf","observation_id":"774fb88d-fe6f-4edb-a053-bc88d3cd2c6f","resolution":{"observed_at":"2026-08-06T20:29:55.355031Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:55.178107Z","title":"https://ollama.com/library/ llama3.3, 2025","venue":null,"work_id":"06d927db-eed1-4581-9b4d-0cbfef787543","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.843105Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:8d9b8875318c937c976586e50836ceba52f2b3a378bf0f3b09a2514267df6e77","observation_id":"bea1b2e8-b021-42bd-90a9-0d0424e4133c","resolution":{"observed_at":"2026-08-06T20:29:55.224468Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:55.033938Z","title":"https://github.com/ run-llama/llama_index, 2025","venue":null,"work_id":"d2f7a25f-ae3d-4f3a-82bc-53aeda01b2d5","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.920513Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:1139fc1f784613612393c8abae50c4f3d60362f8d011d8611e62ba0741255329","observation_id":"5dff1aad-8de1-4b4b-a9bd-6f2ecbebfb1d","resolution":{"observed_at":"2026-08-06T20:29:55.093764Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:54.909937Z","title":"https://github.com/geekan/ MetaGPT, 2025","venue":null,"work_id":"346b0a73-c623-47b1-ba54-322870535466","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:41.988145Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:deaf2d4dbdd42c29f685e800bd0f69547dff36cbd7c40ee214da42565a9b9f92","observation_id":"f560ce3f-5cb2-49b2-b965-662037b18a0d","resolution":{"observed_at":"2026-08-06T20:29:54.966057Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:54.779869Z","title":"https://github.com/ modelscope/modelscope-agent, 2025","venue":null,"work_id":"fe1b318d-a4b5-4f76-85fa-3a5624b488dc","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.080663Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:4ab5f7202cc7bf3bc737c7bafa1d47eb7fab46af67531b59d2d2484ce01a1b4a","observation_id":"331e9879-3cfb-42c6-bc72-15c6f2bbccc9","resolution":{"observed_at":"2026-08-06T20:29:54.835577Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:54.658281Z","title":"https://github.com/ openai/openai-agents-python, 2025","venue":null,"work_id":"d6d9be68-b804-4bda-b827-5f46ff7b8d03","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.158867Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:07a02178dc3468057367f28922d0556d35b52f74a051ccdcd88156ee363811d1","observation_id":"b6c73ce3-92b6-4b32-aff2-36df355b3ee0","resolution":{"observed_at":"2026-08-06T20:29:54.715219Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:54.538498Z","title":"https://platform.openai.com/docs/ models/gpt-3.5-turbo, 2025","venue":null,"work_id":"41516400-5a56-4ced-b60d-7c51cafb3bdd","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.230677Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:30e502ac35974e9759f066a2e62c4f6425342e747f0259127346fbd7d65bb9c5","observation_id":"0bce9e23-2835-4030-926d-d028ee04c4db","resolution":{"observed_at":"2026-08-06T20:29:54.596039Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:54.421683Z","title":"https://platform","venue":null,"work_id":"0621b004-3835-4d79-9acb-3e7b24cfe53a","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.283132Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:9f586118676201c2b04abbe8270572f44690c72549c298df7cd1208422b7f0d3","observation_id":"8527c0bf-9b8a-4209-9c7f-d05b6bd568d8","resolution":{"observed_at":"2026-08-06T20:29:54.473543Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:54.298039Z","title":"Ackerman and Nina Panickssery","venue":null,"work_id":"b53a8b9b-4d4a-4314-aa0f-19d04d0962c7","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.353329Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:78b555ccf09b6884eb288f480e5a71f3d805e904b37b3f16a7192695cdab31c6","observation_id":"28bd2bc9-173b-41c9-af0e-7a66edf6af81","resolution":{"observed_at":"2026-08-06T20:29:54.353565Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:54.165243Z","title":"Many-shot jail- breaking","venue":null,"work_id":"dd8f6051-de2b-4f68-996c-d8e5e89f896d","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.413177Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:3780787ecb804de48f80189e2ebd969c0775ce28863431f35bd0e0964fd087ba","observation_id":"58a7e9f8-9ba4-426e-8abc-a23f8db8a107","resolution":{"observed_at":"2026-08-06T20:29:54.223491Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:54.043301Z","title":"Encrypted prompt: Securing llm applications against unauthorized actions, 2025","venue":null,"work_id":"a9163595-1247-400d-abc2-2ec17f783e4f","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.471174Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:db976ef1d5f9d5461e9a56b51c2d27a121800b2aad1560020ea643c15ebd1101","observation_id":"cc430696-05d6-4676-8570-a877ef986f86","resolution":{"observed_at":"2026-08-06T20:29:54.092528Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:53.939219Z","title":"The obvious invisible threat: Llm-powered gui agents’ vulnerability to fine-print injections, 2025","venue":null,"work_id":"d862ff02-6fbd-41ec-9911-a004bfd3e843","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.547687Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:73911e004eefbc5f6321431acee55dc6847610cab08aacb82b0b03900dc7ce53","observation_id":"3e565e81-465f-446c-8cbd-c6f4da856a0a","resolution":{"observed_at":"2026-08-06T20:29:53.985800Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:53.796357Z","title":"Struq: Defending against prompt injection with structured queries, 2024","venue":null,"work_id":"b9a3a074-10fe-443d-b82c-021d50fced5e","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.623373Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:1572c64562bfccaa4d97ad55c59d3ea684921939c20c4bb0bdd477800264e260","observation_id":"3cd1eda8-e905-493b-ad6f-1e7677a8f15e","resolution":{"observed_at":"2026-08-06T20:29:53.879562Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:42.698878Z","title":"Secalign: Defending against prompt injection with preference optimization, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.698878Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:89770ccbc98e5b0685051d87d20ecf32a0cc09f4116c10904bad890414ccf0ea","observation_id":"76bd1828-0218-462d-8737-aa3c0025ec07","resolution":{"observed_at":"2026-08-06T20:29:42.698878Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:42.762552Z","title":"Can indirect prompt injection attacks be detected and removed? arXiv preprint arXiv:2502.16580, 2025","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.762552Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:7cea012450dc6b6b20ed9f955a29031b1d60f0bd30dcf22c258c3bd8a9c12263","observation_id":"dbaaacc6-72b5-485a-9f17-57ad00d65d9f","resolution":{"observed_at":"2026-08-06T20:29:42.762552Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:53.629219Z","title":"Masterkey: Automated jail- breaking of large language model chatbots","venue":null,"work_id":"78bd17f1-aac7-4c5e-8595-d0bc089aa670","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.830385Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:6747df23e76545ec56af8e3c8c6514ff6be2bbf54728b273578385515c73b2f6","observation_id":"fd5fa52d-0cce-4114-b75d-a6121d7e76ac","resolution":{"observed_at":"2026-08-06T20:29:53.692485Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:53.456957Z","title":"The philosopher’s stone: Trojaning plugins of large language models, 2024","venue":null,"work_id":"3d609976-a1cb-4e16-bfda-63e93841d08b","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.902031Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:88fc74b1545f027234a6a84298d232aab0bdc8fe5a43c5a4dc604521cceb6652","observation_id":"7212e946-f51d-4d77-aec2-a859e482d917","resolution":{"observed_at":"2026-08-06T20:29:53.546757Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:53.264139Z","title":"Feature-aware mali- cious output detection and mitigation, 2025","venue":null,"work_id":"a9cbaf6f-68e0-4405-9d57-62aaeef3adb7","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:42.966656Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:6c744ccbf01135ad39121f50f7b8b6adbf2d276e5ff574094ddef6061c028db4","observation_id":"3675e98e-101b-42b6-a65d-b12b8f88ca0b","resolution":{"observed_at":"2026-08-06T20:29:53.353399Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:53.078331Z","title":"Struphantom: Evo- lutionary injection attacks on black-box tabular agents powered by large language models, 2025","venue":null,"work_id":"aa95be00-f090-4eb8-b7be-32697f1598ad","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.039729Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:4e7e72287ea1976eba64a1acc6e04ce28c162d3ffd13cd726b7dbcb0221d6ba6","observation_id":"1993f9fb-3a22-488e-9ff7-887d5ddd11db","resolution":{"observed_at":"2026-08-06T20:29:53.161565Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:52.898397Z","title":"From assistants to agents in the llm era","venue":null,"work_id":"4d4d335a-820b-45e6-ab60-889d448cf6fe","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.116733Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:e2acfefabc85cbcc6e19423e7423a0577d66931dbdd9b87396dacd2af67ed98d","observation_id":"1ec37b72-d1b2-4469-ac11-d096bc0e9d8d","resolution":{"observed_at":"2026-08-06T20:29:52.976226Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:52.716370Z","title":"Jbfuzz: Jailbreaking llms efficiently and effectively using fuzzing, 2025","venue":null,"work_id":"aafb0614-a5e6-4d65-9c4b-845edf6d943e","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.174126Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:9b4690875629f5ab238b17591481099815867f2a85aa5b0a4d3e290ea3b960a2","observation_id":"68b1a2c1-d589-42f8-9cc2-abe895d9eea8","resolution":{"observed_at":"2026-08-06T20:29:52.796476Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:52.552888Z","title":"Safety mis- alignment against large language models","venue":null,"work_id":"6ae4e269-3a55-45b1-a35e-67115db91d37","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.257553Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:9d302703505e10698b6f57d31def1ad66d628d081ca8fd83d4de256f6c1dd3cf","observation_id":"6c00e9a3-881b-49cb-a6f7-454fe4817775","resolution":{"observed_at":"2026-08-06T20:29:52.643089Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:52.375573Z","title":"Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection","venue":null,"work_id":"65d78cce-22f4-4632-b531-6603c65a81fc","year":2023},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.302921Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:5c357ba714f7a8b028cd36142dd1cde03449d9d51abb738900caccc46fde93d6","observation_id":"9359093f-91d3-431a-b0b8-019c3f96d4b9","resolution":{"observed_at":"2026-08-06T20:29:52.438121Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:52.224097Z","title":"Bypassing prompt injection and jailbreak detection in llm guardrails, 2025","venue":null,"work_id":"693fd804-e9c0-4aac-b495-843494c96c6d","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.307961Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:3b6c240ae55c6bd76c10384f2d37e1f26fdef8ba896eae41fa046e87dce9c582","observation_id":"1a92068a-1488-49d7-af50-b7e8402adefe","resolution":{"observed_at":"2026-08-06T20:29:52.299856Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:52.066078Z","title":"Iterative prompting with persuasion skills in jailbreaking large language models, 2025","venue":null,"work_id":"31bb5c36-a565-49f9-8541-f515a7d81e09","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.312915Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:89e263b0e3cf6d3e2aad7b2cf9655280a47b8dcc20add7d49d640a51d803fcae","observation_id":"1e5ae241-bfc9-46e4-a51c-82545cb68c5a","resolution":{"observed_at":"2026-08-06T20:29:52.144885Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:51.876688Z","title":"xjailbreak: Representation space guided reinforce- ment learning for interpretable llm jailbreaking, 2025","venue":null,"work_id":"99bf7347-9808-4cf7-9513-93e2c7bc1425","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.321535Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:d71ad1f06cfaae08f4f41f21ea565b9e1e655d73cf74c5034b61ce8a3d5c9f34","observation_id":"567dc867-d669-4c51-9e67-ec1fe3fe60e0","resolution":{"observed_at":"2026-08-06T20:29:51.962477Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:51.710884Z","title":"Multi- step jailbreaking privacy attacks on chatgpt, 2023","venue":null,"work_id":"22b07764-dbaf-4462-8b31-64a92b4ae96c","year":2023},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.487076Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:968664c05a07f2ecc7e403ec4d5f2abf9489f7ef562fccdc02fdf2129fbb1781","observation_id":"fdf92076-e0e8-4924-bc8f-353d12be5035","resolution":{"observed_at":"2026-08-06T20:29:51.787327Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:51.544301Z","title":"Separator injection attack: Uncovering dialogue bi- ases in large language models caused by role sepa- rators, 2025","venue":null,"work_id":"e7bc12ba-c844-4c70-b9e7-24b96bda0635","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.597757Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:83380d23d10568d483bf603d678d86ec9f5f88db31b81a8bc0a19af3a48f97a7","observation_id":"b5bda01e-3335-406a-828e-2ec43b2bb0f8","resolution":{"observed_at":"2026-08-06T20:29:51.629786Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:51.357076Z","title":"Pico: Jailbreaking multimodal large language models via Pictorial Code contextu- alization, 2025","venue":null,"work_id":"0970c13b-4aaf-4826-a4fd-5f485c7ffd3c","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.737401Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:b0961889c3396bbcde0a7f33cb6f83d4d8932a302de81be1d95a37ccb744e60f","observation_id":"97dfebd2-8523-436b-b47a-4cb616b04a95","resolution":{"observed_at":"2026-08-06T20:29:51.447062Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:51.179716Z","title":"Token-level constraint bound- ary search for jailbreaking text-to-image models, 2025","venue":null,"work_id":"122c8478-59e4-43b3-b485-3ba2f98a9629","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:43.906523Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:96deaf93450310bd13b15636931517550db0f78ed9a0687143423bd724bbde53","observation_id":"2a7b2de6-f4f2-4289-b7cd-31c969ff61da","resolution":{"observed_at":"2026-08-06T20:29:51.253691Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:51.019993Z","title":"Demystifying rce vulnerabil- ities in llm-integrated apps","venue":null,"work_id":"ded8c42b-887a-4050-b036-ef242e783904","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:44.080880Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:245d1aa2955d16ad6b8af986fe2602a957e4d68b742609ffde88acbf95efe45f","observation_id":"1740c6d6-dc88-40e8-94d8-aa6d04e59478","resolution":{"observed_at":"2026-08-06T20:29:51.095063Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:50.796126Z","title":"Prompt injection attack against llm-integrated ap- plications, 2024","venue":null,"work_id":"309f94f8-39d2-496f-a191-c1f796d728b1","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:44.235076Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:43f16af62d79d5c9198cafa85202dc94e55d0320af91b0e56cb84bedb2a1467a","observation_id":"df3427e0-fa28-4fcc-bae9-c4db0edd6c3b","resolution":{"observed_at":"2026-08-06T20:29:50.888421Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:50.590274Z","title":"Formalizing and bench- marking prompt injection attacks and defenses, 2024","venue":null,"work_id":"7831e73f-7519-44cb-a5b3-63527746fd1e","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:44.394416Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:98760ef07b4f814fa0e83bbbeffae6773df2d19da8890c0098465e9d66e49afb","observation_id":"40c9801e-07f1-4885-96dd-84ec5d5d3409","resolution":{"observed_at":"2026-08-06T20:29:50.658678Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:50.392533Z","title":"Saro: Enhancing llm safety through reasoning- based alignment, 2025","venue":null,"work_id":"8f976a11-8588-4e2f-aa6d-5628e2ad0858","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:44.575081Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:b7f479d52c45ac7c24691b7d446a09e459e1563226bf7c3875db5590c4d4d3b0","observation_id":"0fe7c87b-91b5-40d4-9ab9-d7b153f000b0","resolution":{"observed_at":"2026-08-06T20:29:50.482598Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:50.236107Z","title":"From prompt injections to sql injec- tion attacks: How protected is your llm-integrated web application?, 2025","venue":null,"work_id":"d56eaf1e-5155-47dc-be71-e136c967b6be","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:44.731561Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:7a0884d6279445e6b9a353537d6e0d9151bcb54b16c7797d0517ec8140f3c918","observation_id":"07fa3256-f73c-4154-b81f-5dc740010e0a","resolution":{"observed_at":"2026-08-06T20:29:50.302309Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:50.045572Z","title":"Ignore previous prompt: Attack techniques for language models, 2022","venue":null,"work_id":"8fff24fe-1063-4059-ba80-2603f1dbe02e","year":2022},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:44.897942Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:f44c5088d029638a573309d763c751dd4725d489a6fffb582c53fa0f67fd8cb1","observation_id":"2f368d73-52b3-4171-9242-a776c8310e1d","resolution":{"observed_at":"2026-08-06T20:29:50.132083Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:45.022255Z","title":"do anything now","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.022255Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:90c9239557aa992cc43072af8ad51f50052f775c8bf8f9afc8389acc917f159b","observation_id":"98aa6921-b5c0-48a2-a1f7-b80e57bc40b6","resolution":{"observed_at":"2026-08-06T20:29:45.022255Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:49.826840Z","title":"Yurascanner: Leveraging llms for task-driven web app scanning","venue":null,"work_id":"9fdc0117-82a4-4a5b-92b4-ae3595c27d46","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.162549Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:ad9d7a82fe24f0768cfdd7e75e4bdc02e06d6e8621343fa91513b15a711b0b06","observation_id":"3ff28be2-30ac-40ee-b2a7-5f860b628710","resolution":{"observed_at":"2026-08-06T20:29:49.892278Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:49.630298Z","title":"Signed-prompt: A new approach to prevent prompt injection attacks against llm- integrated applications, 2024","venue":null,"work_id":"39bd8ba7-57e9-4632-a3f9-6ae54d69f796","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.259762Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:ba1b6cb5769ead88502127940601eaee1377e439fdd426bdf0dcbc337c9af101","observation_id":"2770a61e-afd2-4bbc-bacb-e3a6d55156bd","resolution":{"observed_at":"2026-08-06T20:29:49.743513Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:49.340744Z","title":"Email spoofing with smtp smuggling: How the shared email infrastructures magnify this vul- nerability","venue":null,"work_id":"d63715bb-e541-4241-b1c4-776736017015","year":null},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":61,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.322347Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:693997f3c304e65913ac935a18ef93d818b00303b823ebb7a75baa362c7c6bc4","observation_id":"ca85aaf5-dc65-4e4c-8bae-159225f744f0","resolution":{"observed_at":"2026-08-06T20:29:49.455967Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:49.157754Z","title":"Unity is strength: Collaborative llm-based agents for code reviewer recommendation","venue":null,"work_id":"c70cba2c-8d13-4f14-96c3-9da39ec42532","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.401040Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:3179ab43861abf8a4728b4a221d4da59f4e6eaa932a7ead00bade81361e77378","observation_id":"66654049-a55d-47a4-9268-f6e8dcb8456c","resolution":{"observed_at":"2026-08-06T20:29:49.254390Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:48.980250Z","title":"Geneshift: Impact of different scenario shift on jailbreaking llm, 2025","venue":null,"work_id":"1155103a-b16c-4438-ba4f-865b5ad5f6f0","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":63,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.493784Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:6168951dd38b345a60458f3a7f9cdfd00ef3240165c5e3ee82093f93fc09c5f6","observation_id":"420d02d8-212b-450e-be02-532d989229e1","resolution":{"observed_at":"2026-08-06T20:29:49.077460Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:48.681593Z","title":"Isolategpt: An exe- cution isolation architecture for llm-based agentic systems, 2025","venue":null,"work_id":"5fd08bde-e87d-4532-8b50-3775cea9348f","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.575250Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:65253a3737697c08618bc6f73df9a5977079e1d24c18c961c2017d79d1e6f190","observation_id":"865a1c7f-6f5d-4a34-88a1-7508db99206b","resolution":{"observed_at":"2026-08-06T20:29:48.790571Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:48.496477Z","title":"Sneakyprompt: Jailbreaking text-to- image generative models, 2023","venue":null,"work_id":"814ce040-8d7d-4438-8f15-e548ec154c6d","year":2023},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.642214Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:ed155f11daca83c1a847a2dd52c2477123c33be9b741ef0694b6d2d80f382eaf","observation_id":"02f6f7fc-17ff-437b-bc69-8975d2d0be6e","resolution":{"observed_at":"2026-08-06T20:29:48.568558Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:48.234233Z","title":"Lightdefense: A lightweight uncertainty-driven defense against jailbreaks via shifted token distribution, 2025","venue":null,"work_id":"5900bd90-9c12-4950-8c45-bc5e1587e5a3","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":66,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.709709Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:4c10be5a4ef936a78f38d6cf2114a478b626f06ea26c722d345cf72015743a63","observation_id":"65d2f12b-a647-4e6b-9d70-b340a8604391","resolution":{"observed_at":"2026-08-06T20:29:48.369862Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:48.016169Z","title":"Poster: Repairing bugs with the introduction of new variables: A multi-agent large language model","venue":null,"work_id":"5063c0af-faac-4076-a942-89a6d22d137a","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":67,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.770925Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:e5d3cad8ce4920b57ff67accafc89e411123474f8f7c2b4a37e1f66b46171836","observation_id":"4110b923-f0b8-4f1c-b6bc-dbcbbf45c732","resolution":{"observed_at":"2026-08-06T20:29:48.090922Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:47.821510Z","title":"Agent security bench (asb): Formalizing and benchmarking attacks and de- fenses in llm-based agents, 2025","venue":null,"work_id":"99d89715-df17-43f9-a021-08ebf0717ff1","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":68,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.905738Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:d662d9279f08a5d102ab8d3d24a2a2e2c2b858fb3fac26d5172eec9a03675b69","observation_id":"bc87a13f-3c4b-420e-bc3d-e9bb14c7b73d","resolution":{"observed_at":"2026-08-06T20:29:47.918350Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:47.603424Z","title":"TrojanSQL: SQL injection against natural language interface to database","venue":null,"work_id":"ad5c95c1-e7e6-4834-817f-6dbb21de5570","year":2023},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":69,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.983465Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:f131833a94822d1d76aed7c1d9391fde93f3e3733c219068a9c6ecac06123485","observation_id":"0d2f0ea6-0c43-4bea-917e-4f4caa148c3c","resolution":{"observed_at":"2026-08-06T20:29:47.712482Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:47.295234Z","title":"Im- perceptible content poisoning in llm-powered ap- plications","venue":null,"work_id":"c1d605f2-8480-4fa6-ae04-ff6dadc438f8","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":70,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:46.127398Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:b07e98e1d223cfd65870fa898cbf6d7c894fa192acf34ef6c824bc16fc1d7a65","observation_id":"4f4e8509-459a-40be-bc90-9fbef5a3554d","resolution":{"observed_at":"2026-08-06T20:29:47.428850Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:47.145061Z","title":"Defense against prompt injection attacks via mixture of encodings, 2025","venue":null,"work_id":"2f4968cf-aa08-46a2-9116-cd25b7f70bba","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":71,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:46.221554Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:9b433c7fd87751bfee9a1270e3cfbc52445b125c41c8ca3e298895b2d9fd6546","observation_id":"e081e15d-0047-4019-9041-beef43bafbfd","resolution":{"observed_at":"2026-08-06T20:29:47.222555Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:47.004670Z","title":"On large lan- guage models’ resilience to coercive interrogation","venue":null,"work_id":"70632242-512e-41ad-bd5f-7a0b459ef707","year":2024},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":72,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:46.315650Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:9082ec7d59b59b240065408677f7853e0720bfe37bddca09d9fa9611d57e17a9","observation_id":"8dfd4b89-4f76-4898-83f9-af1da43350a3","resolution":{"observed_at":"2026-08-06T20:29:47.066157Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:46.851326Z","title":"Adasteer: Your aligned llm is inherently an adaptive jailbreak defender, 2025","venue":null,"work_id":"cd277ea4-cf15-412d-bd1a-2c04c4ccfad4","year":2025},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":73,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:46.403794Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:b8541342b24128e44e50e1dcd39bec1a682f2ff20264d724651c2244e0f39048","observation_id":"d447a5c3-abd9-4602-b2e8-fc2008f2aca0","resolution":{"observed_at":"2026-08-06T20:29:46.936132Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:46.683716Z","title":"[AGENT_NAME]","venue":null,"work_id":"5d8baab3-f35a-458a-abe9-902998ea09f4","year":2023},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":74,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:46.464523Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:dc7a3bf3973523ffb1f8327eb4b81d4f47fd07b6904258c2857007be58a2fed1","observation_id":"58d8b4bb-de90-4ebd-94c3-71d9b7da2cd2","resolution":{"observed_at":"2026-08-06T20:29:46.758523Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:46.060837Z","title":null,"venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":2023,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:46.060837Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:761e05c76501a4d63c67e6c2bb53b33425be4cdf7a7731874f97f447f8185db7","observation_id":"88a1f251-e6d5-49d6-944e-6fb98bc18a56","resolution":{"observed_at":"2026-08-06T20:29:46.060837Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-06T20:29:45.840643Z","title":null,"venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","version":1},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-06T20:29:45.840643Z"},"links":{"citing_paper":"/paper/2507.02699"},"observation_digest":"sha256:9d13a766143e7e295d9142391f7c1848ecacd9508411457817e936d5f25a8818","observation_id":"e0d95ebe-01c9-4a61-bb29-f48f17396fcb","resolution":{"observed_at":"2026-08-06T20:29:45.840643Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2507.02699","last_updated":"2025-07-03T15:09:40Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-15T23:33:50.029304Z","submitted_at":"2025-07-03T15:09:40Z","title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents"},"reference_resolution":{"displayed":76,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":5,"verified_exact":0,"verified_fuzzy":71},"total_outbound_references":76},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-21T06:32:19.484+00:00","source":"crossref"},{"observed_at":"2026-08-21T06:32:16.066871+00:00","source":"retraction_watch"}],"thesis":"As of 21 August 2026, this Paper Citation Record lists 76 of 76 outbound references and 1 inbound Pith citation observation for arXiv:2507.02699."}