Pith. sign in

Paper Citation Record · LEDGER

SoK: The Attack Surface of Agentic AI - Tools and Autonomy

As of 13 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 10 inbound Pith citation observations for arXiv:2603.22928.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2603.22928 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 10 of 10 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-13T06:32:02.005865+00:00

measured 10 of 10 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-07-11T02:41:24.813416Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-11T02:47:50.254511Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation d8c7c313-37c3-4a08-900c-4c6e96e30665 · inbound

SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems cites this paper.

SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-13T20:14:56.132341Z digest=sha256:8ed4247719c6eab2f4da0e3ad0b40d6fb221844ea48148c81322116bab2322b6

Observation b0cd2e70-8c58-432c-a4f2-2b8a17f50aa2 · inbound

A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms cites this paper.

A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-10T19:39:27.982512Z digest=sha256:398d772114423113185ad31640157788f5fd9cfcc168d94cc60ff0caafc9bddf

Observation 287fef8e-2eef-47bf-8305-0f94ee4cfeb9 · inbound

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments cites this paper.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:87740a12dd761213d97e9219a023bc6be7ba10c97e523f9dad47a3f0c8d70b83

Observation 3ca4c3cd-6b4d-45fd-94ef-b44b234b9aba · inbound

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback cites this paper.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:3c6bec9ee161722b4fc2a0fafa68d2697bd23ea60123051ae16018f280a853db

Observation 6ba71fd9-3176-440f-920a-78c49de5037b · inbound

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents cites this paper.

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-28T14:12:38.815852Z digest=sha256:02e5b3d0125ba861b37630d75c5fa8b17684e9f987664f60e808cec545119f31

Observation 46d78f36-85f8-460d-960a-beefad30dab0 · inbound

A Five-Plane Reference Architecture for Runtime Governance of Production AI Agents cites this paper.

A Five-Plane Reference Architecture for Runtime Governance of Production AI Agents SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-27T10:09:35.461423Z digest=sha256:8e388f4e479c72aace41b86fd840a352d9a7983fa5c0f368c802251e5fa468da

Observation 5dacf644-5d70-4bf7-b504-9cceeaa683a1 · inbound

Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies cites this paper.

Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-26T08:11:30.091859Z digest=sha256:4facf94d39b2023c47e85dffbe6f1a951cb105fe9fa3fa4dd306886c916ed338

Observation c61486d8-28f7-4389-bc83-76da6b4aaa84 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 32

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:b6aeea20a56d1128b085f36914885e3fd153989da0b0ad461c79133c590737c9

Observation 1cbc9a31-29ac-462c-ba18-8d4fd37b8fc8 · inbound

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems cites this paper.

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-01T04:44:23.543728Z digest=sha256:c56ef3b359bee29bca3440f7b9adc38e3d395735a798d11c4cf25927fda39940

Observation a1ba4bd8-ba67-4e25-817a-e8c036be8f5f · inbound

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities cites this paper.

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 1

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-11T02:41:24.813416Z digest=sha256:8d915ffc7426add84a5d2903db42ea1a222e98817865d24781ce8d1f93d190e7