Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-05T05:09:40.020584Z
Paper Citation Record · LEDGER
As of 14 August 2026, this Paper Citation Record lists 49 of 49 outbound references and 11 inbound Pith citation observations for arXiv:2509.05755.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-05T05:09:40.020584Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-14T06:32:32.682623+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-04T08:06:16.098981Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-08-05T02:28:24.338817Z
49 of 49 outbound references displayed
External citation measurements
0
pith, observed 2026-08-05T02:28:24.338817Z
Observation e9995044-7870-47d3-81cc-d43ac03c5082 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://jfrog.com/blog/p rompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/, 2024
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 908d4b2e-401b-408b-ac44-14ea48069655 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://thehackernews.com/2024 /06/prompt-injection-flaw-in-vanna-ai.html, 2024
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 97061c38-caf8-4dd3-952b-00931101f7fe · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://www.cherry-ai.com/, 2025
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 62abf537-44cd-430f-976e-e005c318ed76 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.anthropic.com/en/docs/claude-code/overview , 2025
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation cd49c8f8-9c8d-4051-9592-a3964d41fb86 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.github.com/en/copil ot/using-github-copilot/copilot-chat, 2025
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation ad5068f1-0cd3-4a4d-ab91-481c6f494f4e · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://owasp.org/www-proje ct-top-10-for-large-language-model-applications/, 2025
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 3588386c-dd77-41c4-8838-5966f11ef3dd · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 28026c98-05e1-415c-81ca-2b32d8c036a9 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 89f1ba3c-72ac-4fc3-b6d0-8f58e83df1ea · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Anthropic tool use and function calling
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 9a0f2e10-81c2-45a2-83b3-573ddea70a5e · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Model context protocol.https://docs.anthropic.com/docs/mcp/, 2024
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation c9179a97-7fa6-44f1-8062-1426bbf4cf12 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 407c5235-9481-478b-9021-979d2501ae22 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 07079539-cf03-4ffe-a02d-24f475836e0e · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation f3762e53-3c9e-461c-a296-2888f147cbac · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment The Llama 3 Herd of Models
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2a3bf3fe-ac71-45a1-bfe0-02f925a4b86e · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Conversational Prompt Engineering
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 0e8dfd11-281a-4c09-91c8-f6ef868ce623 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ef92fb38-1d05-47b3-8b4d-4afed1b45398 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment An Empirical Categorization of Prompting Techniques for Large Language Models: A Practitioner's Guide
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d868d79c-af93-469e-887d-e8428f51f636 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is prompt engineering? https://cloud.google.com/discover/what-is-promp t-engineering?hl=en#what-is-prompt-engineering, 2025
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation b4656a5e-5286-4acb-a1d8-2dd5e5a89746 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a43c34b6-1182-4430-99b8-28e4822e7418 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 85e9ee6f-d778-4a05-a24d-147cab8a50b9 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Promptshield: Deploy- able detection for prompt injection attacks
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 27b5fa44-5b19-4017-9c30-566884e56539 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Kpmg ai quarterly pulse survey: From agent experimentation to rapid scale and deployment
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation a3a3005c-09d3-4bc1-ac61-76dc3459c4f4 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment How to use chat models to call tools
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation ae5f12df-493f-4ed9-ba60-7c71131e3ff7 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d7881e67-b55b-4f0a-a74f-5b1944d62543 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Self-Reflection Makes Large Language Models Safer, Less Biased, and Ideologically Neutral
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4119c212-c675-408a-81e9-0e99ba7fe945 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Demystifying rce vulnerabilities in llm-integrated apps
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation c568f671-1bbd-4ccd-8da4-85eea6062524 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What do you want? user-centric prompt generation for text-to-image synthesis via multi-turn guidance.arXiv preprint arXiv:2408.12910, 2024
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d6f45d43-3a6d-4e11-bf11-4700c819a7f0 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Formalizing and bench- marking prompt injection attacks and defenses
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 6f1910d5-5138-4ac3-8888-c7e150c90193 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment LLM In-Context Recall is Prompt Dependent
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 71f603de-062e-4ca4-a6b1-0630cb42a9d4 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Large Language Models Know Your Contextual Search Intent: A Prompting Framework for Conversational Search
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 579ea73d-e38b-4363-bf91-7ade07ccf287 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama-prompt-guard-2-22m
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation c5410c68-8013-4137-b1be-d3555ec15528 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Augmented Language Models: a Survey
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 39e175ac-9b83-4922-9ee4-5ad3e26f625a · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment A Closer Look at System Prompt Robustness
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7b8a8328-08ce-48a9-b6d4-25206be9f2d5 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Position is power: System prompts as a mechanism of bias in large language models (llms)
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 51e69f08-bc38-41a7-9027-b8bb4893e81b · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is agentic ai? https://blogs.nvidia.com/blog/what-is-agentic-ai/ , 2024
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 85c1f51f-3a59-46e4-8458-194e521ee7ac · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Function Calling with LLMs
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation c045c9d2-502b-4728-a01e-b20d81f1ed24 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Openai assistants and tool use documentation
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation d8150135-e2ca-4871-9c30-2ee3b1997c5e · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Pwc’s ai agent survey
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation ea544374-55c9-45f2-8a42-10ee93d2d637 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Tool learning with large language models: A survey.Frontiers of Computer Science, 19(8):198343, 2025
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0caf3c5a-5e4a-4ec4-91c4-462359a1756b · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36:68539–68551, 2023
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation fe7e9087-75fb-4593-a0a9-62ffbe2bfc75 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Cline — ai coding, open source and uncompromised
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 9c655096-f07b-42c1-b1cc-3548e9f88d27 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment AdvAgent: Controllable Blackbox Red-teaming on Web Agents
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aa5368bd-9afc-4180-b2ac-059056983a7a · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment React: Synergizing reasoning and acting in language models
Reference 43
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9acb4cc3-cf41-47ab-a028-ae5e1faf9068 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents
Reference 44
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d981f5bf-91c7-408e-8196-88cd0ac27398 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Injecagent: Benchmarking indirect prompt injections in tool-integrated llm agents
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 06f34892-dbc4-47f3-a2d6-a25f7954bf0a · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment SPRIG: Improving Large Language Model Performance by System Prompt Optimization
Reference 46
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7a67a165-bd3d-411e-82f6-82ce4ba28d9c · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment a helpful assistant
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 439ec31b-2370-422d-a5ee-527c586cfa08 · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Context-faithful Prompting for Large Language Models
Reference 48
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cf50d8e3-a96a-4a81-9b6d-0591876bad5e · outbound
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9d74020d-4276-44f4-972a-d140ebd224d1 · inbound
Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation b2f37388-ce84-46df-a93e-5317fdf8e087 · inbound
When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 94
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 647942dc-86f7-4c34-b8d2-3c4975cffa7d · inbound
Verifiable Manifest Signing and Transparency Enforcement for Secure MCP-Based LLM Pipelines Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aaad7391-b404-488a-bdc8-97f7d54d5713 · inbound
Security Considerations for Multi-agent Systems Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 279
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation ca03258d-9fd1-4e78-b649-060698daa6bc · inbound
Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation ae2b9919-6ccc-4980-96d2-63039ece1e71 · inbound
Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e3a483f2-a692-4cf3-af23-03f439f78a3d · inbound
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation eef9bcc5-a2fe-485b-ab8c-85086b0598ad · inbound
Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 208
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 09dc7c45-d270-4e7a-aa73-62ff2e95d091 · inbound
Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 100
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 71ce2c75-eb1f-4265-a68f-6b6c27a541bd · inbound
ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.
Observation 0c219119-2ba5-4ca1-8932-b9a863d5a04d · inbound
Where Is the Cost of Third-Party API Routers in Agentic Software Development? Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.