{"as_of":"2026-08-13T19:11:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:9ea89b31140540735aa85a690cbec38591e78e2497e605a81a9870dce1a2adaf","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":14,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":14,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-13T06:32:02.005865+00:00","state":"measured"},{"denominator":14,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":14,"source":"paper_references, paper_reference_links","source_observed_at":"2026-07-10T12:20:03.672480Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":1,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2602.17753","last_updated":"2026-05-06T13:43:46Z","snapshot_observed_at":"2026-08-06T12:13:42.632788Z","submitted_at":"2026-02-19T18:57:43Z","title":"The 2025 AI Agent Index: Documenting Technical and Safety Features of Deployed Agentic AI Systems","version":2},"reference_index":139,"source":"pdf_text","source_observed_at":"2026-05-15T20:41:49.137745Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2602.17753"},"observation_digest":"sha256:f9e1d129f3252c30449f2d34db0bcfb96c4db51b1d66a92ad630ca820e20bfb5","observation_id":"ec163114-becf-44a3-93ab-fe9b0a9c4a98","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2603.09002","last_updated":"2026-04-26T14:13:48Z","snapshot_observed_at":"2026-08-11T02:37:54.478569Z","submitted_at":"2026-03-09T22:46:27Z","title":"Security Considerations for Multi-agent Systems","version":2},"reference_index":128,"source":"pdf_text","source_observed_at":"2026-05-15T14:12:14.160789Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2603.09002"},"observation_digest":"sha256:09363aaea0f05724194c829e6fae575b79657392cf1af6c8e1134abe71c8c1ba","observation_id":"baf82be7-dfea-4b6b-8cd6-4670ce1b7429","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2603.12230","last_updated":"2026-04-05T08:33:19Z","snapshot_observed_at":"2026-08-04T04:27:19.804842Z","submitted_at":"2026-03-12T17:49:39Z","title":"Security Considerations for Artificial Intelligence Agents","version":2},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-05-15T12:37:27.153365Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2603.12230"},"observation_digest":"sha256:09d296b6ba44fcbb5b74a011cdc38b0c7ecdfa08ea6417d64fbeddad43dbc88b","observation_id":"da654f9d-7022-4680-9295-d23daa2bc74c","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2604.07536","last_updated":"2026-04-08T19:18:11Z","snapshot_observed_at":"2026-08-11T08:57:39.275363Z","submitted_at":"2026-04-08T19:18:11Z","title":"TRUSTDESC: Preventing Tool Poisoning in LLM Applications via Trusted Description Generation","version":1},"reference_index":76,"source":"pdf_text","source_observed_at":"2026-05-10T17:16:35.875601Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2604.07536"},"observation_digest":"sha256:a482438aec682bba079e1d1a86c32adac058fe8c56c14b086fbe70ffbb97fc36","observation_id":"d7e137b8-c2d8-4911-adc2-736c8e256432","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2604.27202","last_updated":"2026-04-29T21:09:21Z","snapshot_observed_at":"2026-08-11T13:56:31.818773Z","submitted_at":"2026-04-29T21:09:21Z","title":"Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives","version":1},"reference_index":97,"source":"pdf_text","source_observed_at":"2026-05-07T08:55:39.589773Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2604.27202"},"observation_digest":"sha256:7962ee04ae746ae049c77ac3fb3786dfdcc89d3b3275183245b47674273c9218","observation_id":"773fa62e-314f-4ca0-8b5b-8efa398cc30a","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.01644","last_updated":"2026-05-02T23:34:32Z","snapshot_observed_at":"2026-08-11T15:49:43.658949Z","submitted_at":"2026-05-02T23:34:32Z","title":"Toward a Principled Framework for Agent Safety Measurement","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-05-09T13:59:04.866706Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.01644"},"observation_digest":"sha256:692add1fd0793b02ce650cabab1513497811ceb8efd91eb951edb589457e0027","observation_id":"d0eae604-3357-4766-a29f-6d9294fc6bb5","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.05509","last_updated":"2026-05-06T23:19:38Z","snapshot_observed_at":"2026-08-12T21:27:11.076034Z","submitted_at":"2026-05-06T23:19:38Z","title":"WAAA! Web Adversaries Against Agentic Browsers","version":1},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-05-08T16:08:51.850890Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.05509"},"observation_digest":"sha256:5134e89a43a240a1acb16ff3bda5f3518bf692856af1345c1809f7761f8e72ef","observation_id":"7b423caf-0233-4add-b9cb-150bac94caa5","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.07110","last_updated":"2026-05-08T01:38:46Z","snapshot_observed_at":"2026-07-06T23:19:30.387067Z","submitted_at":"2026-05-08T01:38:46Z","title":"Securing Computer-Use Agents: A Unified Architecture-Lifecycle Framework for Deployment-Grounded Reliability","version":1},"reference_index":191,"source":"pdf_text","source_observed_at":"2026-05-11T01:15:19.239355Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.07110"},"observation_digest":"sha256:065c391f6467f3ed54423b4a6bc3cdbc2a7b509869e7fd090dc46220ccc3d43d","observation_id":"27dd033b-ee7d-416e-8881-03289350d7e4","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.14290","last_updated":"2026-05-14T02:48:57Z","snapshot_observed_at":"2026-08-12T19:39:09.848387Z","submitted_at":"2026-05-14T02:48:57Z","title":"Web Agents Should Adopt the Plan-Then-Execute Paradigm","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-05-15T02:42:05.644536Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.14290"},"observation_digest":"sha256:c2eaedc2b8ca396bf97e43fbfb0364acab646711a1bb32cde567ea2c3cfc90f3","observation_id":"e903b718-ddd9-484f-8d4d-39f3ae39dbc1","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.15030","last_updated":"2026-05-14T16:26:27Z","snapshot_observed_at":"2026-08-13T15:20:39.475290Z","submitted_at":"2026-05-14T16:26:27Z","title":"WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections","version":1},"reference_index":78,"source":"pdf_text","source_observed_at":"2026-06-30T20:16:13.413064Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.15030"},"observation_digest":"sha256:f8cb1dd93c7036df46b84806ae29ae8a03ca7699579baf2b8bd6f8a98fa2fc7f","observation_id":"a9f8880c-dfec-4ced-aff0-e506b530688d","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.17453","last_updated":"2026-05-17T13:51:34Z","snapshot_observed_at":"2026-08-02T00:37:59.573957Z","submitted_at":"2026-05-17T13:51:34Z","title":"Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-05-19T23:26:15.658106Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.17453"},"observation_digest":"sha256:6dc444de8b51e34eb9186608e3486ed829730e71f1fcb4076cb288db4a157581","observation_id":"6a8e7267-cf47-44be-b914-0f8d010ee7d7","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2606.14027","last_updated":"2026-06-30T01:10:08Z","snapshot_observed_at":"2026-08-02T09:41:26.926011Z","submitted_at":"2026-06-12T02:01:38Z","title":"Same-Origin Policy for Agentic Browsers","version":3},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-07-01T07:29:08.355105Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2606.14027"},"observation_digest":"sha256:01ee4e8bd6d1e2cee7f41cdf51b1f1afa25a7e86c0c14ac90f9d4d7926d8a717","observation_id":"beaaeae9-eb3c-42f4-9656-2dfc7c89dad6","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2606.30783","last_updated":"2026-06-29T18:11:17Z","snapshot_observed_at":"2026-08-13T06:58:39.597212Z","submitted_at":"2026-06-29T18:11:17Z","title":"Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense","version":1},"reference_index":87,"source":"arxiv_source","source_observed_at":"2026-07-01T01:44:07.700127Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2606.30783"},"observation_digest":"sha256:0031e834b1e5172575afbab363db3d3d3134302bf4f04c7dab4cbeeffbb9a05a","observation_id":"a3f6ca82-9601-47c5-b96a-4c7e8323c4ab","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2607.08147","last_updated":"2026-07-09T06:37:52Z","snapshot_observed_at":"2026-08-07T03:47:57.753615Z","submitted_at":"2026-07-09T06:37:52Z","title":"Prismata: Confining Cross-Site Prompt Injection in Web Agents","version":1},"reference_index":97,"source":"pdf_text","source_observed_at":"2026-07-10T12:20:03.672480Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2607.08147"},"observation_digest":"sha256:3a1b887b31c27d3ef28f6c555591e19afdf1d55607769c61fdadb202109e07df","observation_id":"6267cd72-2123-43bd-a78a-12204f61f320","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2511.20597/citation-record","integrity":"/paper/2511.20597/integrity","json":"/paper/2511.20597/citation-record.json","paper":"/paper/2511.20597"},"outbound":[],"paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","latest_version":2,"primary_category":"cs.LG","snapshot_observed_at":"2026-08-13T18:42:58.633443Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"thesis":"As of 13 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 14 inbound Pith citation observations for arXiv:2511.20597."}