{"as_of":"2026-08-16T05:19:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:407d1aff7109cb4a4683131f98e5f3e93febeade6bb30147b1f1015d387e316e","coverage":[{"denominator":24,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":24,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-03T06:48:33.255423Z","state":"measured"},{"denominator":25,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":25,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-15T06:32:42.880941+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-06-30T21:12:50.686474Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-06-30T21:15:04.163349Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"cited_work":{"arxiv_id":"2601.22136","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2601.22136","snapshot_observed_at":"2026-07-08T02:18:10.878626Z","title":"Stepshield: When, not whether to intervene on rogue agents","venue":null,"work_id":"8a798520-6541-4088-a0e3-57b9a56c5f18","year":2026},"citing_paper":{"arxiv_id":"2605.13631","last_updated":"2026-06-10T08:07:41Z","snapshot_observed_at":"2026-08-13T02:10:03.074086Z","submitted_at":"2026-05-13T14:58:24Z","title":"ProjGuard: Safety Monitoring for Computer-Use Agents via Low-Dimensional Projections","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-06-30T21:12:50.686474Z"},"links":{"cited_paper":"/paper/2601.22136","citing_paper":"/paper/2605.13631"},"observation_digest":"sha256:bc2e86f915b35bce4bb71b54473ba0e2cce4271d9de3511e9d884641d6b842e3","observation_id":"e3ccaed7-18a8-46ed-8ecc-dae40298f0c5","resolution":{"observed_at":"2026-07-08T02:18:10.878626Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2601.22136/citation-record","integrity":"/paper/2601.22136/integrity","json":"/paper/2601.22136/citation-record.json","paper":"/paper/2601.22136"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:30.823358Z","title":"AgentHarm : A benchmark for measuring harmfulness of LLM agents","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":1,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:30.823358Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:b717a95309450f23e50cc3fd9d1665bb9bb0e376a7fdb7a5c13538b1600f71f0","observation_id":"64bd849a-d9fa-43f1-b34e-893d1edc2cf7","resolution":{"observed_at":"2026-08-03T06:48:30.823358Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:30.930571Z","title":"ShieldAgent : Shielding agents via verifiable safety policy reasoning","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":2,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:30.930571Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:5034c2bb99c2b62f954fa27885244b18a3cf6f7b18e1f1169613bcb99907b58b","observation_id":"f5dfa6f7-bfcd-413f-b3c3-513ac6e6929f","resolution":{"observed_at":"2026-08-03T06:48:30.930571Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:31.111845Z","title":"AI coding tool wiped our database, says startup in catastrophic failure","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":3,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:31.111845Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:079314ebb8378e398155087b2f0c03afa75a22e08dc333838cef2876dd31d31d","observation_id":"fcc911a9-6e9a-4465-b246-efe51ee96d5e","resolution":{"observed_at":"2026-08-03T06:48:31.111845Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.05566","last_updated":"2024-01-17T20:26:01Z","snapshot_observed_at":"2026-08-15T14:10:05.296241Z","submitted_at":"2024-01-10T22:14:35Z","title":"Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.05566","snapshot_observed_at":"2026-08-03T06:48:31.340685Z","title":"Sleeper agents: Training deceptive LLMs that persist through safety training","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":4,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:31.340685Z"},"links":{"cited_paper":"/paper/2401.05566","citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:38d21167b07951a98a99cfb35cd0943cc93bf0440800e3362df3ce54c1d81c59","observation_id":"e4ad13b9-97c3-4c95-95a8-58816ee72d03","resolution":{"observed_at":"2026-08-03T06:48:31.340685Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:31.452397Z","title":"On the computational complexity of self-attention","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":5,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:31.452397Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:909e3cfab0b902025101cd9a0443883d602f883c6cc378520a0a0b5a7d7c04ff","observation_id":"9349ea88-b7a4-46f3-85e0-9ed3621696d6","resolution":{"observed_at":"2026-08-03T06:48:31.452397Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:31.595193Z","title":"Specification gaming: the flip side of AI ingenuity","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":6,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:31.595193Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:286ac0f27883065964b656f4b16596613f985531a6290f38c7134c9e84237274","observation_id":"912cb6c6-a9e0-4919-9895-00af93d91ec1","resolution":{"observed_at":"2026-08-03T06:48:31.595193Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15740","last_updated":"2025-07-08T21:23:22Z","snapshot_observed_at":"2026-08-15T19:47:17.558330Z","submitted_at":"2025-06-17T15:46:15Z","title":"SHADE-Arena: Evaluating Sabotage and Monitoring in LLM Agents","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2506.15740","snapshot_observed_at":"2026-08-03T06:48:31.664952Z","title":"SHADE-Arena : Evaluating sabotage and monitoring in LLM agents","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":7,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:31.664952Z"},"links":{"cited_paper":"/paper/2506.15740","citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:2e83c7342c5585544b25585f8cb0efb22fa493a837ac5c768ff2da6191af45c3","observation_id":"f2c1726a-0a9b-49b7-98d6-e8aacb93e39d","resolution":{"observed_at":"2026-08-03T06:48:31.664952Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:31.755426Z","title":"AgentBench : Evaluating LLMs as agents","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":8,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:31.755426Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:1650f362b60d271d2c7d38167bdfefebb7e15de5e9f13bcccf9c749798b31be8","observation_id":"8b2c6108-81db-4274-bf75-d3f63ad0e6d0","resolution":{"observed_at":"2026-08-03T06:48:31.755426Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:31.823861Z","title":"GAIA : A benchmark for general AI assistants","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":9,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:31.823861Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:379c8a1f61af3820e4f6c6c0768befb5922f1b0b6e74c18ae06112f9d8934d78","observation_id":"5fc275b6-2049-4bbe-9bbc-8bece699ce32","resolution":{"observed_at":"2026-08-03T06:48:31.823861Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2212.09251","last_updated":"2022-12-19T05:13:52Z","snapshot_observed_at":"2026-08-14T22:08:45.647927Z","submitted_at":"2022-12-19T05:13:52Z","title":"Discovering Language Model Behaviors with Model-Written Evaluations","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2212.09251","snapshot_observed_at":"2026-08-03T06:48:31.914327Z","title":"Discovering language model behaviors with model-written evaluations","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":10,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:31.914327Z"},"links":{"cited_paper":"/paper/2212.09251","citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:d8f85ed6fda54db579cde693f28272c7011ee4746d7a3494804eb99b31c7bd92","observation_id":"3ca2469a-38e3-4fd2-9e75-7eeda60a5d84","resolution":{"observed_at":"2026-08-03T06:48:31.914327Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:31.979160Z","title":"Identifying risks of LM agents with an LM -emulated sandbox","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":11,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:31.979160Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:737d90bb159c6fd6377fd92e59c9c5ec9517240bfb614f4960673d1a6c4d1645","observation_id":"738cb261-02f8-40c9-9be6-f77e14aaba5a","resolution":{"observed_at":"2026-08-03T06:48:31.979160Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:32.034384Z","title":"Toolformer: Language models can teach themselves to use tools","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":12,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:32.034384Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:1322ce9073d66ad8251f27370e5fba1bc81149b942150c76861147219e09c4e4","observation_id":"c277faaa-63a7-472b-a685-0c478c99983c","resolution":{"observed_at":"2026-08-03T06:48:32.034384Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:32.094844Z","title":"SafeArena : Evaluating the safety of autonomous web agents","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":13,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:32.094844Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:e0c9e297ea5d38860898b446cb3482e3600f3362bdd957cd4eccab7988454a92","observation_id":"a4928575-9cf5-4ef3-81db-a4143043e496","resolution":{"observed_at":"2026-08-03T06:48:32.094844Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:32.145784Z","title":"Gomez, Lukasz Kaiser, and Illia Polosukhin","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:32.145784Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:27fa13b31bf0599bcfbc9eb0b617213232b0807cdf712778e4c40871c7d147c1","observation_id":"d9a8c388-065a-4cd9-8fd9-f94e79554392","resolution":{"observed_at":"2026-08-03T06:48:32.145784Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:32.322808Z","title":"GuardAgent : Safeguard LLM agents via knowledge-enabled reasoning","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":15,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:32.322808Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:8ef3ea9a0b03ada73c5bc00615121b7654b6818d4bbc612cf9abab1b908425ea","observation_id":"a2a70930-fa0e-405e-9a3c-f74b81c056fc","resolution":{"observed_at":"2026-08-03T06:48:32.322808Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.07972","last_updated":"2024-05-30T08:55:12Z","snapshot_observed_at":"2026-08-14T22:26:00.902198Z","submitted_at":"2024-04-11T17:56:05Z","title":"OSWorld: Benchmarking Multimodal Agents for Open-Ended Tasks in Real Computer Environments","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.07972","snapshot_observed_at":"2026-08-03T06:48:32.428948Z","title":"OSWorld : Benchmarking multimodal agents for open-ended tasks in real computer environments","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":16,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:32.428948Z"},"links":{"cited_paper":"/paper/2404.07972","citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:a6017287828a94559e2f642024320289d5a4d5d4b0c7e23746aee8a217814042","observation_id":"d97c84ab-9c89-45ed-be05-c2d32f2cf919","resolution":{"observed_at":"2026-08-03T06:48:32.428948Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14161","last_updated":"2025-09-10T08:35:19Z","snapshot_observed_at":"2026-08-15T12:13:55.739245Z","submitted_at":"2024-12-18T18:55:40Z","title":"TheAgentCompany: Benchmarking LLM Agents on Consequential Real World Tasks","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2412.14161","snapshot_observed_at":"2026-08-03T06:48:32.516604Z","title":"Xu, Yufan Song, Boxuan Li, Yuxuan Ding, Jiayi Zou, Wangchunshu Zhao, Hao Peng, Daniel Fried, and Graham Neubig","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":17,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:32.516604Z"},"links":{"cited_paper":"/paper/2412.14161","citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:586e55b143b856b3f13d7832a8c1bd231746d504c770e33edcbfb12e268ca641","observation_id":"a63ded48-0b2e-4a79-8353-b5b4e0056a43","resolution":{"observed_at":"2026-08-03T06:48:32.516604Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:32.646810Z","title":"ReAct : Synergizing reasoning and acting in language models","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":18,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:32.646810Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:92afb23f01f68d37027ba0824d48024a6cfd6d2505d4093ba226af5b2671757e","observation_id":"03ed57ae-ac9b-4d76-9445-412142a8fcb8","resolution":{"observed_at":"2026-08-03T06:48:32.646810Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:32.798048Z","title":"SafeAgentBench : A benchmark for safe task planning of embodied LLM agents","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":19,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:32.798048Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:8308fff2058b4404656773e67fb8f5ac6f8d02e56a9443b1858f18c7a163abfb","observation_id":"852df4b5-06c0-47ef-bc11-7862bb19d395","resolution":{"observed_at":"2026-08-03T06:48:32.798048Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.10019","last_updated":"2024-10-05T06:50:15Z","snapshot_observed_at":"2026-08-15T13:54:08.703885Z","submitted_at":"2024-01-18T14:40:46Z","title":"R-Judge: Benchmarking Safety Risk Awareness for LLM Agents","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.10019","snapshot_observed_at":"2026-08-03T06:48:32.932827Z","title":"R-Judge : Benchmarking safety risk awareness","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":20,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:32.932827Z"},"links":{"cited_paper":"/paper/2401.10019","citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:fd786dda2fbcd21f48081038941c41a40357d1faf1e51d1f916267f6b696923d","observation_id":"6758dd8f-abbc-4e88-b0fa-2696c8c7aa84","resolution":{"observed_at":"2026-08-03T06:48:32.932827Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14470","last_updated":"2025-05-20T05:58:23Z","snapshot_observed_at":"2026-08-06T12:35:19.109481Z","submitted_at":"2024-12-19T02:35:15Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2412.14470","snapshot_observed_at":"2026-08-03T06:48:33.022088Z","title":"Agent-SafetyBench : Evaluating the safety of LLM agents","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":21,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:33.022088Z"},"links":{"cited_paper":"/paper/2412.14470","citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:085ca6aea46433caa6f50236f03086b05392a688ab836b14a326fd8ea806a9a7","observation_id":"a84379fe-a046-422c-8e31-03cd8df422ac","resolution":{"observed_at":"2026-08-03T06:48:33.022088Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2306.05685","last_updated":"2023-12-24T02:01:34Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-06-09T05:55:52Z","title":"Judging LLM-as-a-Judge with MT-Bench and Chatbot Arena","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2306.05685","snapshot_observed_at":"2026-08-03T06:48:33.095817Z","title":"Judging LLM -as-a-judge with MT-Bench and Chatbot Arena","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":22,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:33.095817Z"},"links":{"cited_paper":"/paper/2306.05685","citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:4af403efa4c46c3738fcff30b3537d8e330427e409324b37a9a4ebcd090425e5","observation_id":"c33a4aee-cdf4-4ea5-9312-67612fb98833","resolution":{"observed_at":"2026-08-03T06:48:33.095817Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:33.184945Z","title":"WebArena : A realistic web environment for building autonomous agents","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":23,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:33.184945Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:d4d5cd72d13759f2f53926649b956470597788b1bcc74b5c8e73b2395a4d9c20","observation_id":"85d149df-4e38-4b02-80a9-8311d60642dd","resolution":{"observed_at":"2026-08-03T06:48:33.184945Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-03T06:48:33.255423Z","title":"Agent-as-a-judge: Evaluate agents with agents","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents","version":2},"reference_index":24,"source":"arxiv_source","source_observed_at":"2026-08-03T06:48:33.255423Z"},"links":{"citing_paper":"/paper/2601.22136"},"observation_digest":"sha256:2b57e663fcd22296c74d67f50ada9e6740566b844c11f8d9ddcaf8759e362aaf","observation_id":"bd92b36d-2730-4f00-9d37-cc90ffe96690","resolution":{"observed_at":"2026-08-03T06:48:33.255423Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2601.22136","last_updated":"2026-07-07T06:58:47Z","latest_version":2,"primary_category":"cs.LG","snapshot_observed_at":"2026-08-14T22:09:19.972665Z","submitted_at":"2026-01-29T18:55:46Z","title":"StepShield: When, Not Whether to Intervene on Rogue Agents"},"reference_resolution":{"displayed":24,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":24,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":24},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"thesis":"As of 16 August 2026, this Paper Citation Record lists 24 of 24 outbound references and 1 inbound Pith citation observation for arXiv:2601.22136."}