Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-21T10:41:17.307952Z
Paper Citation Record · LEDGER
As of 1 August 2026, this Paper Citation Record lists 78 of 78 outbound references and 6 inbound Pith citation observations for arXiv:2604.01905.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-21T10:41:17.307952Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-01T06:32:01.292127+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-07-12T17:06:32.429160Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-07-02T14:37:03.245592Z
78 of 78 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 2192dcf6-10b3-41a4-8788-9a515de1430d · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers The work-averse cyberattacker model: theory and evidence from two million attack signatures
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 5b076f73-67fc-4324-a716-f5057198580e · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation d974657e-62c4-491a-bb1f-cda08b211498 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Introducing the model context protocol
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 190d6d1c-89dd-4dd9-8611-b51cacb5e869 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 04dcebb7-a223-47f7-a693-2f6f315df753 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers AgentBound: Securing Execution Boundaries of AI Agents
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation cf88cb01-1c1d-41f8-a5f7-9ceda4af6dff · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 6cb1a0d0-1510-4288-ba2b-5c8f6bcf1e9d · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Connect claude code to tools via mcp
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 1057eb7c-15da-4fd6-9555-dacb39523cd1 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Introducing claude 4
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 097d7d9f-6d32-4edd-adf1-bb0db9005fa8 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Introducing claude sonnet 4.5
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation ed718e72-705b-4a03-a35c-85707fc2cddc · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation f494db30-0fca-4313-b980-73ed35f981e8 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Cursor agent
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation b99abbb5-bf61-4b32-bd27-db743fbdb143 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Cursor directory - cursor rules & mcp servers
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation e6acea98-fcab-401f-8d3f-3c563c60a920 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model context protocol (mcp) | cursor docs
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 9e414ee2-0943-40d8-a528-8baa48fdae2a · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Deepseek-v3.1
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation d1f617fa-f6b7-4730-92bd-e13963270dbb · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 480a69b4-2b84-4ec8-a628-112915abefca · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation c8f490d6-4eca-43dc-89e4-0ed0090e3984 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Enhanced prompting framework for code summarization with large language models
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 0bd7ea9f-9fc7-4e64-9355-7744952aedcb · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcp json configuration
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 0e6f0b64-84eb-4c0e-ab11-966dc6d1abaa · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Trae Agent: An LLM-based Agent for Software Engineering with Test-time Scaling
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation f665a585-cf79-412e-a57f-bace9f2e3319 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Malguard: towards real-time, accurate, and actionable detection of malicious packages in pypi ecosystem
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 69abd670-8d92-4cf1-8a7f-2fa323291ef6 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Github copilot·your ai pair programmer
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation af9ac2a0-9b08-41b6-a2b1-9f38f37df736 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Extending github copilot coding agent with the model context protocol (mcp)
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation cc436108-e240-47ab-b1e5-7ecb56512c3a · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Popular mcp servers
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 49556769-5d8e-43f0-b056-6a58c97919fe · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Gemini 3
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation c6af10fd-2023-4290-93af-dd3a90c10fac · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Gtfobins
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 237775eb-2dfe-45c3-8314-d8a33dae2ce4 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A measurement study of model context protocol ecosystem
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation f4c4f5bd-186f-43eb-afda-a6d6de454b4f · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Large language model based multi-agents: A survey of progress and challenges
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation f42ca10a-0c9e-47a8-b160-17a65403343b · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers An empirical study of malicious code in pypi ecosystem
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 557f52d1-9262-408b-aa0d-617d2aa011a9 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers MCPXKIT: The Unified Toolkit for Analyzing Model Context Protocol Security
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 4bf2cacd-5007-4fee-a159-f45a7cbbd2e2 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers damn-vulnerable-mcp-server
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 1a6ac7e8-b7f1-4bf8-8a9f-b7abfae41d19 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation bb4db277-4916-498e-a4bf-bc350d7021dc · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model Context Protocol (MCP) Tool Descriptions Are Smelly! Towards Improving AI Agent Efficiency with Augmented MCP Tool Descriptions
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 374bd470-144f-4659-af45-96c6bce02cdd · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Automatic red teaming llm-based agents with model context protocol tools
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation ad3df134-ad3c-4cb7-b2e8-102e5387e8b1 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 0b855f7a-2327-449f-8479-aeb112e0fd22 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Donapi: Malicious npm packages detector using behavior sequence knowledge mapping
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation e5336804-7bf5-4983-8063-e0585855947a · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Spiderscan: Practical detection of malicious npm packages based on graph-based behavior modeling and matching
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 940bbfca-d0a4-4598-ac5c-25ca81a69d91 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Profmal: Detecting malicious npm packages by the synergy between static and dynamic analysis
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation ac8dbf75-a1bd-4f2f-a7ae-1b499f488392 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcp security notification: Tool poisoning attacks
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 2cc996c9-c7d4-47d4-82f5-841680381f60 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Whatsapp mcp exploited: Exfiltrating your message history via mcp
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation b93c7ea2-0e9e-4075-832d-76a49a6ac8d3 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers mcp-scan
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 8faed80e-5767-4f80-b2a6-42a48012c9d2 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcip: Protecting mcp safety via model contextual integrity protocol
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 5ff15277-1224-4569-b4e6-580f7e8257f9 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Joern - the bug hunter’s workbench
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation f5d8d013-bfe6-4b7a-aeb6-e7e98ec95b30 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers 3 malicious mcp servers found on pypi
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation d4a75edc-5d23-48c4-90e8-3ccd6f41ffae · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 0511f971-afff-4b99-837e-03200e6a44f2 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers First malicious mcp server found stealing emails in rogue postmark-mcp package
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation e0fe6fa6-cc55-4afd-a851-023ccc31768a · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers The platform for reliable agents
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation fd25793d-df60-426a-857d-d809ff0e2cce · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers We urgently need privilege management in mcp: A measurement of api usage in mcp ecosystems
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 7caaed62-d043-489e-922f-6ac0a34b1ef2 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Getting started with model context protocol part 2: Prompts and resources
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation f3df08c5-f9f8-4071-8816-02bdfaf7e621 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers From large to mammoth: A comparative evaluation of large language models in vulnerability detection
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation b9c9b25d-6e4f-4b2f-881a-4d81076ef73a · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 508818d3-bec9-4a0f-a9e8-bef50aba2370 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Model context protocol servers
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 20451973-ffc5-4e66-8a24-69b90a79aa7e · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 6b597d75-0048-4073-80d3-d50b82301b43 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Securing GenAI Multi-Agent Systems Against Tool Squatting: A Zero Trust Registry-Based Approach
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 759924c2-7e4d-4e2e-9f4f-f608a538c621 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Backstabber’s knife collection: A review of open source software supply chain attacks
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 33028c8a-beb2-48a2-8cee-d7f9e4289644 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Function calling
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 4378cc40-2157-4422-8e98-0704b9f3d1bf · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Introducing gpt-5
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation e82346e1-0c7e-4bc3-933c-d07b4ff14b9b · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A distributed vulnerability database for open source
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 55bd9afb-305a-4d82-9544-efcec9c496b3 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcp server directory
Reference 58
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation c9c1a46d-977e-4608-a790-68b1f28e8570 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Toolllm: Facilitating large language models to master 16000+ real-world apis
Reference 59
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 78cab1b6-7448-4f6e-b6e2-fb4641a7a53e · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits
Reference 60
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 03eaeeeb-163c-471c-bca4-1cb5fd48aaa5 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A survey on model context protocol: Architecture, state-of-the-art, challenges and future directions.Authorea Preprints
Reference 61
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 54548b34-58b5-414b-be75-0152c56d4a7f · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Benefits of using mcp over traditional integration methods
Reference 62
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 6f94083b-5363-4c64-ae68-4c3e9d4c7b5d · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers PromptArmor: Simple yet Effective Prompt Injection Defenses
Reference 63
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 8e9cd14e-7176-4805-9696-98998c5cc01f · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Smithery - turn scattered context into skills for ai
Reference 64
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 5cd76137-761b-4c22-b3bd-7ca4b19648dc · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
Reference 65
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 59d0a1f6-8ca3-4865-8682-9bfef1b3e135 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Ai-infra-guard
Reference 66
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation a6b45c99-62b5-4144-b3e0-40c6c33ad2b6 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcpguard: Automatically detecting vulnerabilities in mcp servers
Reference 67
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 7f0717bd-4da2-4e1c-926b-f2302777d49c · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Self-instruct: Aligning language models with self-generated instructions
Reference 68
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 25d30a3c-c9d9-4a3f-97f2-ada6f168dcee · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mpma: Preference manipulation attack against model context protocol
Reference 69
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation a9728051-ec2e-4682-b9db-977ce9237f25 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcp-guard: A defense framework for model context protocol integrity in large language model applications
Reference 70
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 38b68d2c-9635-452b-a294-4648e9dbd875 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers A Survey of AI Agent Protocols
Reference 71
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation c36df13c-fe5a-4d3c-a71d-1f949f3eaf95 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Mcpsecbench: A systematic security benchmark and playground for testing model context protocols
Reference 72
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 244e3ed8-d059-4794-890c-d539d3db37c5 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work
Reference 73
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation d2fff69f-aa24-4e05-922f-1dd85121f632 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Williams
Reference 74
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 0c0f68e9-a624-4852-9491-e7d14c8b7d0f · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Unresolved cited work
Reference 75
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation d49b879c-3882-4b6c-850e-eeb3ae5ff61a · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem
Reference 76
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation e4c9d553-941b-4b56-91ab-ea72816738bf · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers When mcp servers attack: Taxonomy, feasibility, and mitigation
Reference 77
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation feffcdfc-5d51-453c-be19-2ad36cfab178 · outbound
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers –” in the “ID
Reference 78
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 752c202b-71bb-45d6-8550-ba2b816a2398 · inbound
Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
Reference 63
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 5639f668-386b-4f04-a5a0-7b08325695da · inbound
On the dilaton gravity of analogue black holes From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4b4a796b-e468-4543-b6db-164ddba2081b · inbound
Red-Teaming Agent Execution Contexts: Open-World Security Evaluation on OpenClaw From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 4c5bf377-26d3-46e0-8e61-90717d3dd3ac · inbound
Behavioral Integrity Verification for AI Agent Skills From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation d62ceabc-b69f-4b78-91d6-66fb54856e84 · inbound
When Safe Skills Collide: Measuring Compositional Risk in Agent Skill Ecosystems From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.
Observation 5f52ee4b-68c4-4a30-86b3-b9eaf2d97f1a · inbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-01T06:32:01.292127+00:00.