Pith. sign in

Paper Citation Record · LEDGER

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

As of 14 August 2026, this Paper Citation Record lists 49 of 49 outbound references and 11 inbound Pith citation observations for arXiv:2509.05755.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2509.05755 v6

Coverage vector

measured 49 of 49 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T05:09:40.020584Z

measured 60 of 60 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-14T06:32:32.682623+00:00

measured 11 of 11 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-04T08:06:16.098981Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

49 of 49 outbound references displayed

  • verified exact2
  • verified fuzzy28
  • unresolved19
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation e9995044-7870-47d3-81cc-d43ac03c5082 · outbound

This paper cites https://jfrog.com/blog/p rompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://jfrog.com/blog/p rompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/, 2024

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.530979Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.717409Z digest=sha256:3679d829d3bf4416d0aab2be55e67e6c45fac90e5c55d00b2177e8727e7c9fd3

Observation 908d4b2e-401b-408b-ac44-14ea48069655 · outbound

This paper cites https://thehackernews.com/2024 /06/prompt-injection-flaw-in-vanna-ai.html, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://thehackernews.com/2024 /06/prompt-injection-flaw-in-vanna-ai.html, 2024

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.511326Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.724902Z digest=sha256:b595cfb53ebcc82eedf65b35cc18a35c78dbc1883c33b73d52c4ba4bcdc7fe34

Observation 97061c38-caf8-4dd3-952b-00931101f7fe · outbound

This paper cites https://www.cherry-ai.com/, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://www.cherry-ai.com/, 2025

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.485868Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.731021Z digest=sha256:482f9e3f0a7574cb4b9e0c36c5df01ff6ed1d8d6a8b67b34a78fd4a4f8bc0429

Observation 62abf537-44cd-430f-976e-e005c318ed76 · outbound

This paper cites https://docs.anthropic.com/en/docs/claude-code/overview , 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.anthropic.com/en/docs/claude-code/overview , 2025

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.456265Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.737081Z digest=sha256:242c4c9f1b073d99af03bd762a6f5f10edf8b0e032410b5957410f018c0f27d1

Observation cd49c8f8-9c8d-4051-9592-a3964d41fb86 · outbound

This paper cites https://docs.github.com/en/copil ot/using-github-copilot/copilot-chat, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.github.com/en/copil ot/using-github-copilot/copilot-chat, 2025

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.428727Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.743955Z digest=sha256:37ca7bba760a96db467b8997533c2604489bce684a4a55790129d068359fd4e7

Observation ad5068f1-0cd3-4a4d-ab91-481c6f494f4e · outbound

This paper cites https://owasp.org/www-proje ct-top-10-for-large-language-model-applications/, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://owasp.org/www-proje ct-top-10-for-large-language-model-applications/, 2025

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.400243Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.749409Z digest=sha256:1805a99eac1eb50da85708ec9e2b5fde9f2c6a011d29b97978b566c7350096c3

Observation 3588386c-dd77-41c4-8838-5966f11ef3dd · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.375616Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.755742Z digest=sha256:34863ded552e02766e77741935f4386fa6b009bf66235a8ed7a74b2cc9fc172d

Observation 28026c98-05e1-415c-81ca-2b32d8c036a9 · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.352428Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.762358Z digest=sha256:af5618306a0e8722478d656ac56be55b1bf91a91022a7569b7e753881b844470

Observation 89f1ba3c-72ac-4fc3-b6d0-8f58e83df1ea · outbound

This paper cites Anthropic tool use and function calling.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Anthropic tool use and function calling

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.327200Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.768821Z digest=sha256:19d624d5cf35d5dab2e24e1b2db19ce52c68096224d6337655bef9348dae95c2

Observation 9a0f2e10-81c2-45a2-83b3-573ddea70a5e · outbound

This paper cites Model context protocol.https://docs.anthropic.com/docs/mcp/, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Model context protocol.https://docs.anthropic.com/docs/mcp/, 2024

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.305113Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.776491Z digest=sha256:bfdb13054df8c30a23640a07dc5f037113231e242e1877acfe9ba8f6ada26ee5

Observation c9179a97-7fa6-44f1-8062-1426bbf4cf12 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.782564Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.782564Z digest=sha256:847c2a7173a6316c2dd2fa3e8ea0766eff5f98807f646564f2c09db9a8d1add9

Observation 407c5235-9481-478b-9021-979d2501ae22 · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.278728Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.789182Z digest=sha256:bad98eaf5e253a070983cf03deca8385e625206059ff9b56c767a9941e78d020

Observation 07079539-cf03-4ffe-a02d-24f475836e0e · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.256452Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.795361Z digest=sha256:6f7ee69d90d4e6eab25974c381b3e0eab61d7b943cf9c9e1d53352b292f98f03

Observation f3762e53-3c9e-461c-a296-2888f147cbac · outbound

This paper cites The Llama 3 Herd of Models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment The Llama 3 Herd of Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.800933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.800933Z digest=sha256:e2568a5eb48535934714d53f2c39f94157ecca3b4532693b85b96fc5a408a91f

Observation 2a3bf3fe-ac71-45a1-bfe0-02f925a4b86e · outbound

This paper cites Conversational Prompt Engineering.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Conversational Prompt Engineering

Reference 15

Resolution
verified exact
local_arxiv, observed 2026-08-05T05:09:40.777379Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.806899Z digest=sha256:d13460f85418bf05fdcc0cfa06a25bc4e48b64b5e486ae05c0ed221e6637492c

Observation 0e8dfd11-281a-4c09-91c8-f6ef868ce623 · outbound

This paper cites WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.813876Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.813876Z digest=sha256:1013dfc12f5fd7c2a0dac3b8d266a8b82031cffd678f960d83e9abbee8ebf542

Observation ef92fb38-1d05-47b3-8b4d-4afed1b45398 · outbound

This paper cites An Empirical Categorization of Prompting Techniques for Large Language Models: A Practitioner's Guide.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment An Empirical Categorization of Prompting Techniques for Large Language Models: A Practitioner's Guide

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.820844Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.820844Z digest=sha256:d919a1b0082a662641471b1dc123597df61b3ec1fcaa685f0ed8fdd8a51329be

Observation d868d79c-af93-469e-887d-e8428f51f636 · outbound

This paper cites What is prompt engineering? https://cloud.google.com/discover/what-is-promp t-engineering?hl=en#what-is-prompt-engineering, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is prompt engineering? https://cloud.google.com/discover/what-is-promp t-engineering?hl=en#what-is-prompt-engineering, 2025

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.232493Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.828635Z digest=sha256:f7fa22022031bf6d423dce977206202633728aa8c796ab71ab8344d481162d19

Observation b4656a5e-5286-4acb-a1d8-2dd5e5a89746 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.835452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.835452Z digest=sha256:e89869791d1dc49977f83aca2d339020e3f04c7c80d7309fbeae19b75dfe6ee6

Observation a43c34b6-1182-4430-99b8-28e4822e7418 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.841874Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.841874Z digest=sha256:0998fefe566e0cb15ba89f99b1bef3a7e7793f82c10ddea318ec2e5e81891476

Observation 85e9ee6f-d778-4a05-a24d-147cab8a50b9 · outbound

This paper cites Promptshield: Deploy- able detection for prompt injection attacks.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Promptshield: Deploy- able detection for prompt injection attacks

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.193369Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.848575Z digest=sha256:7b612f3f41c2963ec86685526a495de314f60322b190fcbda9fd6c817e0ff320

Observation 27b5fa44-5b19-4017-9c30-566884e56539 · outbound

This paper cites Kpmg ai quarterly pulse survey: From agent experimentation to rapid scale and deployment.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Kpmg ai quarterly pulse survey: From agent experimentation to rapid scale and deployment

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.172873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.855633Z digest=sha256:9d202ba884abee62e47ed47fbf6cc2b976737fac0ff89de64b4e476467ec23ba

Observation a3a3005c-09d3-4bc1-ac61-76dc3459c4f4 · outbound

This paper cites How to use chat models to call tools.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment How to use chat models to call tools

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.150660Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.861201Z digest=sha256:2b537847486ab329a58b4de86fb9137b25913d53093e10b5615b2a7f271a6622

Observation ae5f12df-493f-4ed9-ba60-7c71131e3ff7 · outbound

This paper cites EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.868193Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.868193Z digest=sha256:1e751b12a41b141a7367f56bd7e677b5066404a14f468e4f0bdf99e06189babb

Observation d7881e67-b55b-4f0a-a74f-5b1944d62543 · outbound

This paper cites Self-Reflection Makes Large Language Models Safer, Less Biased, and Ideologically Neutral.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Self-Reflection Makes Large Language Models Safer, Less Biased, and Ideologically Neutral

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.874576Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.874576Z digest=sha256:940166beae274ba00c89e3e9d140f9e0bc857c894d63a19e74fa51eaa3a924dc

Observation 4119c212-c675-408a-81e9-0e99ba7fe945 · outbound

This paper cites Demystifying rce vulnerabilities in llm-integrated apps.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Demystifying rce vulnerabilities in llm-integrated apps

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.126476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.879992Z digest=sha256:c9986746a9745d3c65c38ad1e89c7f4c31fe3e1132e8f34a16f44ee7d80f634c

Observation c568f671-1bbd-4ccd-8da4-85eea6062524 · outbound

This paper cites What do you want? user-centric prompt generation for text-to-image synthesis via multi-turn guidance.arXiv preprint arXiv:2408.12910, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What do you want? user-centric prompt generation for text-to-image synthesis via multi-turn guidance.arXiv preprint arXiv:2408.12910, 2024

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.887000Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.887000Z digest=sha256:d7bce50099d2e857ac381a2758f19a1d22ef9646c1ae3d38429f01b2deac48bd

Observation d6f45d43-3a6d-4e11-bf11-4700c819a7f0 · outbound

This paper cites Formalizing and bench- marking prompt injection attacks and defenses.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Formalizing and bench- marking prompt injection attacks and defenses

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.098378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.892467Z digest=sha256:82c3d04c10525503db696fbc89dd28100913ff7134203433bc620097cb4f4514

Observation 6f1910d5-5138-4ac3-8888-c7e150c90193 · outbound

This paper cites LLM In-Context Recall is Prompt Dependent.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment LLM In-Context Recall is Prompt Dependent

Reference 29

Resolution
verified exact
local_arxiv, observed 2026-08-05T05:09:40.275758Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.897444Z digest=sha256:5df75853567eb5ed2962f432a90c8f3f721553e4b941d8cc413a2df2ea00e00b

Observation 71f603de-062e-4ca4-a6b1-0630cb42a9d4 · outbound

This paper cites Large Language Models Know Your Contextual Search Intent: A Prompting Framework for Conversational Search.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Large Language Models Know Your Contextual Search Intent: A Prompting Framework for Conversational Search

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.903821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.903821Z digest=sha256:64b0d8a2401dd9fa1c20e3a1ed2e0a6747c09559bcf7aa9f0f1cccb6fba06bbc

Observation 579ea73d-e38b-4363-bf91-7ade07ccf287 · outbound

This paper cites Llama-prompt-guard-2-22m.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama-prompt-guard-2-22m

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.073052Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.909568Z digest=sha256:b042121ebc351e2dc12dde61026097b058bcf6238cc62cff168f87dfc6671046

Observation c5410c68-8013-4137-b1be-d3555ec15528 · outbound

This paper cites Augmented Language Models: a Survey.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Augmented Language Models: a Survey

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.915182Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.915182Z digest=sha256:ad555e96ebccf55761bf161dfc5e3e149285d094b206a0b0acea46be79b13c1b

Observation 39e175ac-9b83-4922-9ee4-5ad3e26f625a · outbound

This paper cites A Closer Look at System Prompt Robustness.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment A Closer Look at System Prompt Robustness

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.921172Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.921172Z digest=sha256:16c836d8c6077873b1e6e11d6f658eac84bd47ff47baa60840844827c9f221be

Observation 7b8a8328-08ce-48a9-b6d4-25206be9f2d5 · outbound

This paper cites Position is power: System prompts as a mechanism of bias in large language models (llms).

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Position is power: System prompts as a mechanism of bias in large language models (llms)

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.046186Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.926761Z digest=sha256:8dd2b6d006fd58c13d1bea88bda2b2734ec0e40ef07801a85d15985c02521888

Observation 51e69f08-bc38-41a7-9027-b8bb4893e81b · outbound

This paper cites What is agentic ai? https://blogs.nvidia.com/blog/what-is-agentic-ai/ , 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is agentic ai? https://blogs.nvidia.com/blog/what-is-agentic-ai/ , 2024

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.025647Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.933155Z digest=sha256:853d1b65321d328f52ab0a2c26265f57d6952d47930c38d6a05c52f906dabbc9

Observation 85c1f51f-3a59-46e4-8458-194e521ee7ac · outbound

This paper cites Function Calling with LLMs.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Function Calling with LLMs

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.005989Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.939751Z digest=sha256:980f66f8efdd48580d345a342c7127e3185ba4b93f50ca8a361b9e2c82c4191d

Observation c045c9d2-502b-4728-a01e-b20d81f1ed24 · outbound

This paper cites Openai assistants and tool use documentation.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Openai assistants and tool use documentation

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.984125Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.945109Z digest=sha256:44f3e260ec49fb23aabffd68c53dd36cc06634362e4020bdc7d1edb78d985e5f

Observation d8150135-e2ca-4871-9c30-2ee3b1997c5e · outbound

This paper cites Pwc’s ai agent survey.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Pwc’s ai agent survey

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.964097Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.950807Z digest=sha256:530438e44eef939cb8b607de8b6fe9d21a728516d85bf053e9bc2526dea53050

Observation ea544374-55c9-45f2-8a42-10ee93d2d637 · outbound

This paper cites Tool learning with large language models: A survey.Frontiers of Computer Science, 19(8):198343, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Tool learning with large language models: A survey.Frontiers of Computer Science, 19(8):198343, 2025

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.957253Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.957253Z digest=sha256:44274ad1e89bfb588f85ec3bfc2575e507f411bb2f45c9a32d8e804363ce3923

Observation 0caf3c5a-5e4a-4ec4-91c4-462359a1756b · outbound

This paper cites Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36:68539–68551, 2023.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36:68539–68551, 2023

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.933641Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.963689Z digest=sha256:33c14c2f117c5889e8bc256629d33f13ae73f503555e1d8a59a103935b6d5818

Observation fe7e9087-75fb-4593-a0a9-62ffbe2bfc75 · outbound

This paper cites Cline — ai coding, open source and uncompromised.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Cline — ai coding, open source and uncompromised

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.911858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.969422Z digest=sha256:f32ee288b4f697ba88615cb369ca628c7cdcab3f86a03beb432c0fc034eb688a

Observation 9c655096-f07b-42c1-b1cc-3548e9f88d27 · outbound

This paper cites AdvAgent: Controllable Blackbox Red-teaming on Web Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment AdvAgent: Controllable Blackbox Red-teaming on Web Agents

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.975185Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.975185Z digest=sha256:88dbc74da224ea67a55a8a85bd157af2c5f1b79e838c5be71406c8348d4470a9

Observation aa5368bd-9afc-4180-b2ac-059056983a7a · outbound

This paper cites React: Synergizing reasoning and acting in language models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment React: Synergizing reasoning and acting in language models

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.981410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.981410Z digest=sha256:adb9d9a6432878954fa9533ce47eaba78091efe009c54cc1f2f971824bb4f6dd

Observation 9acb4cc3-cf41-47ab-a028-ae5e1faf9068 · outbound

This paper cites Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.987143Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.987143Z digest=sha256:d7b0b8cbc79f1d3053bca422cfeaf20630806994b8b0fd10ebba48a6f4211b96

Observation d981f5bf-91c7-408e-8196-88cd0ac27398 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated llm agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Injecagent: Benchmarking indirect prompt injections in tool-integrated llm agents

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.876491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:39.993267Z digest=sha256:9560ad3cb165854415dc153a58068e2d15444eddd50c2f66a3b20a9d84d2f7ae

Observation 06f34892-dbc4-47f3-a2d6-a25f7954bf0a · outbound

This paper cites SPRIG: Improving Large Language Model Performance by System Prompt Optimization.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment SPRIG: Improving Large Language Model Performance by System Prompt Optimization

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.998742Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.998742Z digest=sha256:771c02d4bb3c3050c475eb7124dc893587dc932d798ef8de92f2e784aca178bc

Observation 7a67a165-bd3d-411e-82f6-82ce4ba28d9c · outbound

This paper cites a helpful assistant.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment a helpful assistant

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.850748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-08-05T05:09:40.007399Z digest=sha256:8954c40417416f46dda1c3cb0e3034caa7dca7f014b71dc23dc2086f78699e73

Observation 439ec31b-2370-422d-a5ee-527c586cfa08 · outbound

This paper cites Context-faithful Prompting for Large Language Models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Context-faithful Prompting for Large Language Models

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.014381Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.014381Z digest=sha256:b2d1647bdaa8fcf6d62c91760c6bbb7dd996ddde5af469009cb370b43c36b15d

Observation cf50d8e3-a96a-4a81-9b6d-0591876bad5e · outbound

This paper cites MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.020584Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.020584Z digest=sha256:b7539b40eabff72facf91f866a9e16189a904c2c844e6e9cb71f751b2dbdd1c9

Pith citing papers

Observation 9d74020d-4276-44f4-972a-d140ebd224d1 · inbound

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem cites this paper.

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 50

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-18T18:43:35.072919Z digest=sha256:886732007c3a04bb26b962e2f30eca90fb7c97ec0a437fceec90daa79b048dc6

Observation b2f37388-ce84-46df-a93e-5317fdf8e087 · inbound

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents cites this paper.

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-04T08:06:16.098981Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T08:06:16.098981Z digest=sha256:51eab3885741e8eacb82a4582d58b79c41b35348b86698399d2e9f69faf4caed

Observation 647942dc-86f7-4c34-b8d2-3c4975cffa7d · inbound

Verifiable Manifest Signing and Transparency Enforcement for Secure MCP-Based LLM Pipelines cites this paper.

Verifiable Manifest Signing and Transparency Enforcement for Secure MCP-Based LLM Pipelines Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-03T06:18:06.545883Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T06:18:06.545883Z digest=sha256:a44bfff74fc762fdf8b0f85d2dd25bb833732a75f6e5db163bbdb78b79592922

Observation aaad7391-b404-488a-bdc8-97f7d54d5713 · inbound

Security Considerations for Multi-agent Systems cites this paper.

Security Considerations for Multi-agent Systems Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 279

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-15T14:12:14.160789Z digest=sha256:c964f43a283774bb30fd38bc2bb6c0d26d4a89c2700187df3272dc944ef782e3

Observation ca03258d-9fd1-4e78-b649-060698daa6bc · inbound

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents cites this paper.

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-05-08T18:42:06.418583Z digest=sha256:e917713be2567cdd6029f80981e793db4f71d92d933c571f327e7be82b231996

Observation ae2b9919-6ccc-4980-96d2-63039ece1e71 · inbound

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents cites this paper.

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T15:04:20.284238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T15:04:20.284238Z digest=sha256:352687c9b363dbe114ae455c36c5c91d596e163edc3f2fb7129f8cdd20f245cd

Observation e3a483f2-a692-4cf3-af23-03f439f78a3d · inbound

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents cites this paper.

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-06-30T16:24:55.067215Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-30T16:22:23.857438Z digest=sha256:affc67d9c77d1f8b94869daf4e462c3dc68b0bda548bac377e5058cdc5db6def

Observation eef9bcc5-a2fe-485b-ab8c-85086b0598ad · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 208

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:0e18dbe24941d18a7bb8096d39875b17cf918837b6518e0d45639f14ddc4c7b0

Observation 09dc7c45-d270-4e7a-aa73-62ff2e95d091 · inbound

Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study cites this paper.

Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 100

Resolution
verified exact
local_arxiv, observed 2026-07-03T12:08:07.100919Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-27T09:06:12.868791Z digest=sha256:405aef51ae1f683fd338f7b88858968ab7ae12ddfa1939cdf00fd11aa9c680dd

Observation 71ce2c75-eb1f-4265-a68f-6b6c27a541bd · inbound

ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP cites this paper.

ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 30

Resolution
verified exact
local_arxiv, observed 2026-07-04T14:19:54.256550Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.

source=pdf_text observed=2026-06-26T04:07:14.506108Z digest=sha256:3c6fb9ad79bf2b6ad91c5833cc34f21e9918385ae3149b2b5f27ee6d329cf2e9

Observation 0c219119-2ba5-4ca1-8932-b9a863d5a04d · inbound

Where Is the Cost of Third-Party API Routers in Agentic Software Development? cites this paper.

Where Is the Cost of Third-Party API Routers in Agentic Software Development? Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 25

Resolution
unresolved
no resolver link, observed 2026-07-30T17:25:46.962117Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-30T17:25:46.962117Z digest=sha256:c357469eb41610c066bb26ce23b6d539e27dd2020c5ab5cd53a68991de5ccb0f