Pith. sign in

Paper Citation Record · LEDGER

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools

As of 11 August 2026, this Paper Citation Record lists 20 of 20 outbound references and 3 inbound Pith citation observations for arXiv:2601.01241.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2601.01241 v2

Coverage vector

measured 20 of 20 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-03T12:56:37.815027Z

measured 23 of 23 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-11T06:34:44.6726+00:00

measured 3 of 3 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-02T01:12:23.894152Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

20 of 20 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved20
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation 6c5b5c1a-e5af-48f2-852e-1f30ff8984c2 · outbound

This paper cites Introducing the model context protocol.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Introducing the model context protocol

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.757404Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.757404Z digest=sha256:3239a377a0da1534f218d7be37720cac6bbf72632d78e2cade5749946bf773bf

Observation dc2ce85d-f3d7-4003-8bb0-b165ef12929e · outbound

This paper cites Agent based modelling and simulation tools: A review of the state-of-art software,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Agent based modelling and simulation tools: A review of the state-of-art software,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.761151Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.761151Z digest=sha256:fa72ef7b5ca735f75430d469113ff0e62c2100d372a3fb490f98bb578b4cfec0

Observation 2a5e6bf6-46fc-45a3-9196-61a3f0614b78 · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.766883Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.766883Z digest=sha256:df693d2a95ff781acd45fb96e0326b0834753c67d55f4682c2aec7b21d567bb5

Observation 48247f33-2864-46e3-9dce-e3834ef283c8 · outbound

This paper cites MCIP: Protecting MCP safety via model contextual integrity protocol,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCIP: Protecting MCP safety via model contextual integrity protocol,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.770369Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.770369Z digest=sha256:800babc1fa80e0a6b3719de009ea63859d58b50a891e2c3c9ab4c428b2ff3948

Observation 7710cfb9-551a-46ed-83ea-bac9a10370ca · outbound

This paper cites Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.773738Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.773738Z digest=sha256:33ab22771d8b97d8aaaf89096c39afb2c16c1545326df85f5c49ea08e7d167a6

Observation 1e9127bc-7581-4138-8135-2b3b32451f1d · outbound

This paper cites Mcpscan,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Mcpscan,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.777268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.777268Z digest=sha256:8a3359016a1d4850a5ae546ae582e848eaa2403c6454cdb8c0ed1d49696cba95

Observation b816419c-d77d-4e91-914f-029cd2f04888 · outbound

This paper cites Scansat: Unlocking static and dynamic scan obfuscation,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Scansat: Unlocking static and dynamic scan obfuscation,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.780243Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.780243Z digest=sha256:8543c7d9c8e0d5b0959df87560693a13150e132188ec59eea0f3c6407eb18ec7

Observation af362f7a-3a24-41f5-b5e4-13e119abff33 · outbound

This paper cites Wave: a verifiably secure webassembly sandboxing runtime,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Wave: a verifiably secure webassembly sandboxing runtime,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.783379Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.783379Z digest=sha256:7e32397330486fe109fd914d7b501ec71337a5c01e370b5dc6ee9b7b0930af87

Observation 30e4925e-7a17-4116-aa3a-2b590c23223b · outbound

This paper cites Mcp-sandboxscan (anonymous github repository),.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Mcp-sandboxscan (anonymous github repository),

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.786645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.786645Z digest=sha256:c67e3273eaedafecde08c49427391d41e244acec7e5e92499e5a492cb328d846

Observation 280f776d-be11-4d24-ac11-78371288c7bd · outbound

This paper cites MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.789590Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.789590Z digest=sha256:b8bc549a42d9a95206b5ef328f304dc420bf0931f83d4ead6d2bccb13b0f752b

Observation 7444a582-fad4-4f66-bc9a-7bb07a5a207c · outbound

This paper cites (2025, May) Mcp: Untrusted servers and confused clients, plus a sneaky exploit.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools (2025, May) Mcp: Untrusted servers and confused clients, plus a sneaky exploit

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.792816Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.792816Z digest=sha256:8ee194ba140acc656cd0061cae44df28a600ca5932c11e02814c2c741a5452ae

Observation 6c9029d0-1fbb-491b-84c8-e4d153af2acc · outbound

This paper cites Model context protocol (mcp): Landscape, security threats, and future research directions,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Model context protocol (mcp): Landscape, security threats, and future research directions,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.795677Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.795677Z digest=sha256:7adc02b96232efc8601a282cff5173c952ab6b45a165697ffb5a405a68eecb17

Observation 904b91d8-d520-4a7c-8241-a59de5581ea2 · outbound

This paper cites Defeating prompt injections by design,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Defeating prompt injections by design,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.801880Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.801880Z digest=sha256:e2440634b634636b514a3fe801462a1754d7250d42d5409e80bd1b19f6db0da3

Observation 02695385-888e-48b7-afce-4879b6fd0d5c · outbound

This paper cites toxic flows,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools toxic flows,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.804547Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.804547Z digest=sha256:062ac53b886aca69881a378e579e9198b9c915c61f68b3846055446ede4e1ee3

Observation 915d489b-3776-463f-b502-91dc5ac9b88f · outbound

This paper cites Cheatsheet – a practical guide for securely using third-party mcp servers 1.0,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Cheatsheet – a practical guide for securely using third-party mcp servers 1.0,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.807218Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.807218Z digest=sha256:187f590147b5d4e3e1ad297e5a7628879a21dc5bb05a64e944b5929395ab54e4

Observation e22bce47-ee37-42bb-9e4c-1d939a477d19 · outbound

This paper cites Wasmbox: A lightweight wasm-based runtime for trustworthy multi-tenant embedded systems,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Wasmbox: A lightweight wasm-based runtime for trustworthy multi-tenant embedded systems,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.809750Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.809750Z digest=sha256:dd066ada15336398ea89b8ce738171c6127de63a03e87159d4217f2e353ec173

Observation 6d75229a-b35c-4666-9baf-573d65519fde · outbound

This paper cites Sledge: a serverless-first, light-weight wasm runtime for the edge,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Sledge: a serverless-first, light-weight wasm runtime for the edge,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.812388Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.812388Z digest=sha256:f37a5f3879164aec0aa1c2a282f819978a2bacfb2746f2f0d69acfda52f7be9a

Observation 9880b784-3879-4a9b-a146-10b28cb8d448 · outbound

This paper cites MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.815027Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.815027Z digest=sha256:fcd53975b7d350a760faa567ef0679fa0fa4edbf3ccdb569d9325285a8dcf79d

Observation 4fb683bb-6132-4a0d-8405-ca7826cc23ce · outbound

This paper cites Available: https://www.sciencedirect.com/science/articl e/pii/S1574013716301198.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Available: https://www.sciencedirect.com/science/articl e/pii/S1574013716301198

Reference 2017

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.764045Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.764045Z digest=sha256:e3e98db6fcbd4afa8602aa09fbd25e4fdbb7b7a1ba1175db04476cf4bd6732b5

Observation 81bdfb01-99dd-437e-83f5-5b5b4e47af74 · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.798775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.798775Z digest=sha256:e7c8927e7a7e4c15da3277112a66464140073eca88cf7b8a65bb9e5aee519fbd

Pith citing papers

Observation ed1db894-ad93-4d8e-83a0-b231967ef15b · inbound

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security cites this paper.

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools

Reference 49

Resolution
verified exact
arxiv_id, observed 2026-06-23T04:13:43.712185Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-05-10T17:10:50.283791Z digest=sha256:2d16fa612d997f5ceb16e9c96dd60aff29418218c09b234bc78049b4a683e889

Observation 5a41c41c-68f9-44bf-83ba-d80483b520d7 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools

Reference 166

Resolution
verified exact
local_arxiv, observed 2026-06-27T13:20:56.864193Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-11T06:34:44.6726+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:7ab41cf59bc08535cd5e8a8265b0b145c06f98dbc9d151dbcfaf776d047d12ff

Observation 70707f31-365b-4b5a-91ef-abab78b83267 · inbound

FlowGuard: From Signals to Evidence for MCP Security Detection cites this paper.

FlowGuard: From Signals to Evidence for MCP Security Detection MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-02T01:12:23.894152Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:12:23.894152Z digest=sha256:7abbc61527a9a69a19ca83927dd99ad0dc564d21befd7f7b8ec9594ca0f222be