Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-10T19:20:52.845052Z
Paper Citation Record · LEDGER
As of 6 August 2026, this Paper Citation Record lists 22 of 22 outbound references and 12 inbound Pith citation observations for arXiv:2604.04759.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-10T19:20:52.845052Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-06T06:34:29.942622+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-07-10T08:08:21.077290Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-08-05T02:28:24.338817Z
22 of 22 outbound references displayed
External citation measurements
0
pith, observed 2026-08-05T02:28:24.338817Z
Observation c15afb40-110d-44c0-ba64-e3e05a009e5d · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 001b5b4e-cb7a-4a58-90cc-94b4585e9216 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation e84540e6-9de9-46d1-90cb-392d7ea970ad · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation f8a1f2e7-a420-401e-adcb-0613e77d621e · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Yann Dubois, Balázs Galambosi, Percy Liang, and Tat- sunori B Hashimoto
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 164f1ff0-6ba0-4b39-a78d-ef2627e73184 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 76ab5808-34f9-436d-93f1-8deeb64949af · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Siwei Han, Kaiwen Xiong, Jiaqi Liu, Xinyu Ye, Yaofeng Su, Wenbo Duan, Xinyuan Liu, Cihang Xie, Mohit Bansal, Mingyu Ding, et al
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 93dd8247-19af-4461-8fa8-b3e580e54265 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw SkillJect: Effectively Automating Skill-Based Prompt Injection for Skill-Enabled Agents
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 38f9d78d-96bd-4d95-a5fc-19938868ad31 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Refusal-Trained LLMs Are Easily Jailbroken As Browser Agents
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 9759749a-e360-4fb3-b69d-16513a2b187c · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 19493644-8c33-47ad-b999-536a5f89d53a · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw "Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 2caec978-f9ca-4962-bf97-2c81a819149a · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw MemGPT: Towards LLMs as Operating Systems
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 0aa92f5b-73d8-4cbd-b609-3c4dd1d86405 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Identifying the Risks of LM Agents with an LM-Emulated Sandbox
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation de8577e4-ba35-4a31-8694-ba6429ab313f · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation b675c814-2f3b-44f0-a389-580a2a9482e0 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw arXiv preprint arXiv:2509.26354 , year=
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation fcf02fd4-dc69-4ff4-8284-be968e31be2f · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Vijayvargiya, A
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 707939fc-a688-48a8-bfea-2a1130d28c31 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Voyager: An Open-Ended Embodied Agent with Large Language Models
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation f07e0b5e-6a0b-4a0f-b2b8-b5390e8e0a91 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation afb4621c-02cb-4646-bf0c-d17c103a32a6 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw The Rise and Potential of Large Language Model Based Agents: A Survey
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 94cfb36d-2ce3-4251-b003-94e4acdc0c9e · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Zombie agents: Persistent control of self-evolving llm agents via self-reinforcing injections
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 43f11e62-6696-4cc7-a689-61b3f6024e1c · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 8ce834dd-2314-4dcf-9bef-42884f498a57 · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation c0172594-d89a-4d57-8fd3-11adc1815b4f · outbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 857b32e5-5f7b-45c6-a219-0997fc26a1a6 · inbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 9e3c66f2-e293-4a8f-b10f-94e15c1f2adf · inbound
When Routine Chats Turn Toxic: Unintended Long-Term State Poisoning in Personalized Agents Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation df7f8569-98de-49d4-9c64-f1644579edf0 · inbound
Towards Security-Auditable LLM Agents: A Unified Graph Representation Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation f77f0fea-168a-4bb1-9f72-fe82c0ec5b0e · inbound
Securing Computer-Use Agents: A Unified Architecture-Lifecycle Framework for Deployment-Grounded Reliability Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 129
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 68d8b81f-ef5f-4d8e-a9e1-f04011d7b669 · inbound
AgentTrap: Measuring Runtime Trust Failures in Third-Party Agent Skills Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 022b9e05-56d2-45dd-aacc-b6a02dc219a2 · inbound
Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 31dc9603-8746-420b-aa9a-2f94b7007ae1 · inbound
Triaging Threats to Specialized Guardrails Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation d60e1be1-0e7b-40bc-b673-f799fa033439 · inbound
SentGuard: Sentence-Level Streaming Guardrails for Large Language Models Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 97b307b2-1370-423b-8aba-d86c2f2bcc1c · inbound
RealClawBench: Live OpenClaw Benchmarks from Real Developer-Agent Sessions Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation bd65ac44-df28-43c6-941b-5a97c8e8f75e · inbound
Understanding and mitigating the risks of OpenClaw for non-technical users: A practical guide with Skill Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 3796e0f5-18e4-4029-bbd7-b552b6da6ff4 · inbound
Runtime Skill Audit: Targeted Runtime Probing for Agent Skill Security Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 15392d6f-5a54-41cf-8448-3330a8117018 · inbound
Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.