{"as_of":"2026-08-05T06:50:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:0cfbc06a6c9e491b34c0c18fa3310d90d3a2bbc6ef20dc3aa0dcc413d0632dae","coverage":[{"denominator":6,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":6,"source":"paper_references, paper_reference_links","source_observed_at":"2026-07-13T11:36:41.748710Z","state":"measured"},{"denominator":23,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":23,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-05T06:32:48.257954+00:00","state":"measured"},{"denominator":17,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":17,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-04T23:56:14.830929Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"pith","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":0,"observed_at":"2026-08-05T02:28:24.338817Z","source":"pith"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2604.24026","last_updated":"2026-05-04T16:52:56Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-04-27T04:25:15Z","title":"From Skill Text to Skill Structure: The Scheduling-Structural-Logical Representation for Agent Skills","version":4},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-05-08T04:05:49.308804Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2604.24026"},"observation_digest":"sha256:dc87a2367e7a77f4182433533d4ac78985c826a781ba1a2e4aba7c2bd5c9746f","observation_id":"552b4372-40e0-42ac-97e6-ce1c994f383c","resolution":{"observed_at":"2026-05-11T21:51:23.948379Z","resolver_source":"local_arxiv","status":"malformed_identifier"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2604.24026","last_updated":"2026-05-04T16:52:56Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-04-27T04:25:15Z","title":"From Skill Text to Skill Structure: The Scheduling-Structural-Logical Representation for Agent Skills","version":4},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-05-08T04:05:49.308804Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2604.24026"},"observation_digest":"sha256:9f69bf13e651fb31c2b93587a43872f28ff5fb8f0d1ef2552b4ffca94ebe8056","observation_id":"b1275cf9-9219-42c2-92f3-cd4f9b6ea61e","resolution":{"observed_at":"2026-05-09T00:14:27.110068Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2605.05868","last_updated":"2026-05-07T08:34:14Z","snapshot_observed_at":"2026-07-06T23:18:26.864785Z","submitted_at":"2026-05-07T08:34:14Z","title":"SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-05-08T09:33:30.464441Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2605.05868"},"observation_digest":"sha256:417a92511a5f27f5a83d287fa038dbf99c195503043f0efef6d0ddc98644b682","observation_id":"2b3321d3-5ba2-446e-87a1-4bfc9e6de600","resolution":{"observed_at":"2026-05-11T20:21:08.933343Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-07-12T17:06:32.429160Z","title":"Skillattack: Automated red teaming of agent skills through attack path refinement","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2605.11046","last_updated":"2026-07-06T14:50:31Z","snapshot_observed_at":"2026-07-12T17:06:30.437834Z","submitted_at":"2026-05-11T12:41:36Z","title":"On the dilaton gravity of analogue black holes","version":2},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-07-12T17:06:32.429160Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2605.11046"},"observation_digest":"sha256:316f6c9f81fe6ba217b11fb12a78dcfdc9c7fd72c28e13568b9e162fbc96be4e","observation_id":"ef609f95-b9ed-4c5e-9869-55039184eff6","resolution":{"observed_at":"2026-07-12T17:06:32.429160Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2605.11047","last_updated":"2026-05-11T13:20:02Z","snapshot_observed_at":"2026-07-06T23:22:57.012338Z","submitted_at":"2026-05-11T13:20:02Z","title":"Red-Teaming Agent Execution Contexts: Open-World Security Evaluation on OpenClaw","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-05-13T00:53:56.517406Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2605.11047"},"observation_digest":"sha256:fadf0bda08a055afd200e041c897fd2c58a4cebd5aaccb5013555787739ea5e4","observation_id":"4be056bf-d48f-4a73-938e-7458d355732b","resolution":{"observed_at":"2026-05-13T00:57:00.679223Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2605.12015","last_updated":"2026-05-27T06:26:15Z","snapshot_observed_at":"2026-07-06T23:23:44.276236Z","submitted_at":"2026-05-12T12:03:54Z","title":"SkillSafetyBench: Evaluating Agent Safety under Skill-Facing Attack Surfaces","version":1},"reference_index":54,"source":"arxiv_source","source_observed_at":"2026-05-13T05:10:04.763149Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2605.12015"},"observation_digest":"sha256:f032ec80898f96b7f791ae85ef5fd0bce336f298855e8412fb95b90a96890d63","observation_id":"bcf3304f-c08a-470c-8b00-74353f640417","resolution":{"observed_at":"2026-05-13T05:12:17.949635Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2605.12015","last_updated":"2026-05-27T06:26:15Z","snapshot_observed_at":"2026-07-06T23:23:44.276236Z","submitted_at":"2026-05-12T12:03:54Z","title":"SkillSafetyBench: Evaluating Agent Safety under Skill-Facing Attack Surfaces","version":2},"reference_index":8,"source":"arxiv_source","source_observed_at":"2026-06-30T22:30:59.927227Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2605.12015"},"observation_digest":"sha256:ad9ef6e62a647db60c70951ccaf9638e1ceaf8fafe1ffc97da6665b30412f830","observation_id":"cbcfb3c6-5914-4031-bc61-55fe07c6f74a","resolution":{"observed_at":"2026-07-01T13:55:46.274461Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2605.22634","last_updated":"2026-05-24T12:02:09Z","snapshot_observed_at":"2026-07-06T23:32:54.127514Z","submitted_at":"2026-05-21T15:40:05Z","title":"Contractual Skills: A GovernSpec Design Framework for Enterprise AI Agents","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-05-22T03:48:11.543797Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2605.22634"},"observation_digest":"sha256:170c58572196357e3dd3eaed9e9661408d8dc8b2dfb64dcdd274dcaaf607c964","observation_id":"e115d89f-9496-4632-8979-1df647675173","resolution":{"observed_at":"2026-05-22T03:51:02.021179Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2605.22634","last_updated":"2026-05-24T12:02:09Z","snapshot_observed_at":"2026-07-06T23:32:54.127514Z","submitted_at":"2026-05-21T15:40:05Z","title":"Contractual Skills: A GovernSpec Design Framework for Enterprise AI Agents","version":2},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-06-30T16:06:01.947184Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2605.22634"},"observation_digest":"sha256:851fd1e2adf04df62981f5cfb9bfefb9071c36173bbaa3d5724383a2b898dd52","observation_id":"0e5c6822-d251-4ce3-9541-a883f6433b3d","resolution":{"observed_at":"2026-06-30T16:14:53.518577Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2606.02540","last_updated":"2026-06-01T17:45:39Z","snapshot_observed_at":"2026-07-06T23:42:53.514946Z","submitted_at":"2026-06-01T17:45:39Z","title":"SkillHarm: Lifecycle-Aware Skill-Based Attacks via Automated Construction","version":1},"reference_index":47,"source":"arxiv_source","source_observed_at":"2026-06-28T15:00:59.241336Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2606.02540"},"observation_digest":"sha256:671497dface76f508dc90018b8f751f6b897c8b6913d8c749a1e913a1c5a40be","observation_id":"724d8a1b-a9e1-4cd9-86da-f84a3e2ca6dc","resolution":{"observed_at":"2026-07-01T22:46:19.938612Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2606.07943","last_updated":"2026-06-06T02:10:03Z","snapshot_observed_at":"2026-08-01T15:17:08.296282Z","submitted_at":"2026-06-06T02:10:03Z","title":"POISE: Position-Aware Undetectable Skill Injection on LLM Agents","version":1},"reference_index":25,"source":"arxiv_source","source_observed_at":"2026-06-27T19:52:23.006490Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2606.07943"},"observation_digest":"sha256:47c168523410b921b3e3dedaf03f3f7a0b93f929bf9b7f3a1520c6bdef0ba3a6","observation_id":"89e4173c-b014-4b51-9c52-910367057f5c","resolution":{"observed_at":"2026-07-02T21:17:24.388654Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2606.10749","last_updated":"2026-06-09T12:01:07Z","snapshot_observed_at":"2026-07-31T21:35:18.696472Z","submitted_at":"2026-06-09T12:01:07Z","title":"Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-06-27T12:55:22.831264Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2606.10749"},"observation_digest":"sha256:afcad0a5efa4f23ba6516b10fd87c783ec2cf73747e85e8852f81f22794b52d3","observation_id":"f1b962d7-0874-419f-8c1f-48949fb2c7cf","resolution":{"observed_at":"2026-06-27T13:20:56.713011Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2606.11671","last_updated":"2026-06-10T05:29:34Z","snapshot_observed_at":"2026-08-01T07:30:24.882086Z","submitted_at":"2026-06-10T05:29:34Z","title":"Runtime Skill Audit: Targeted Runtime Probing for Agent Skill Security","version":1},"reference_index":17,"source":"arxiv_source","source_observed_at":"2026-06-27T09:28:48.695776Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2606.11671"},"observation_digest":"sha256:5cb5373e363308c44728bc4dfbb737a06940750cbb12297306b284973185929e","observation_id":"a8eb1ac5-5c03-4cdd-bd21-3248354877e0","resolution":{"observed_at":"2026-06-27T09:30:46.539515Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":"2604.04989","doi":"10.48550/arxiv.2604.04989","metadata_source":"pith","pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","venue":"cs.CR","work_id":"34db1617-e04e-435d-8ee5-0cbdfbf07e16","year":2026},"citing_paper":{"arxiv_id":"2607.01136","last_updated":"2026-07-01T16:21:49Z","snapshot_observed_at":"2026-07-07T00:06:44.379624Z","submitted_at":"2026-07-01T16:21:49Z","title":"Skills Are Not Islands: Measuring Dependency and Risk in Agent Skill Supply Chains","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-07-02T08:07:09.648071Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2607.01136"},"observation_digest":"sha256:b44b93df19336ad3dc98a49eaaa876e3a1b13240ec76d2c9ba06e5cde9b5cd77","observation_id":"32cbb245-3e4f-4815-82c6-432dc79572a3","resolution":{"observed_at":"2026-07-02T08:16:47.231239Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-07-12T04:03:40.067404Z","title":"arXiv preprint arXiv:2604.04989 , year=","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.03220","last_updated":"2026-07-03T11:34:27Z","snapshot_observed_at":"2026-08-04T15:53:28.140739Z","submitted_at":"2026-07-03T11:34:27Z","title":"CONTRA: Red-Teaming Configurations of Personalizable Agents","version":1},"reference_index":20,"source":"arxiv_source","source_observed_at":"2026-07-12T04:03:40.067404Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2607.03220"},"observation_digest":"sha256:875b1909c23916dcc4a9389d014e6542d06993e4d70c4dea49ac160b4404bea3","observation_id":"a90599da-1cd8-476b-b2a2-16da1ef1f99a","resolution":{"observed_at":"2026-07-12T04:03:40.067404Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-04T01:22:31.310223Z","title":"SkillAttack: Automated Red Teaming of Agent Skills Through Attack Path Refinement,","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2608.00104","last_updated":"2026-07-31T00:24:06Z","snapshot_observed_at":"2026-08-05T06:20:46.030605Z","submitted_at":"2026-07-31T00:24:06Z","title":"Skillsets on the Chain: A Blockchain-based Zero-Trust Framework for Agentic AI Networking","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-04T01:22:31.310223Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2608.00104"},"observation_digest":"sha256:96ffcf7e5e6ec77cfe92fada6d716054394d29f0a4566ed786764ec895a9b6d8","observation_id":"7ff8298d-d546-41cd-be8c-5a8c5754b3f6","resolution":{"observed_at":"2026-08-04T01:22:31.310223Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.04989","snapshot_observed_at":"2026-08-04T23:56:14.830929Z","title":"arXiv preprint arXiv:2604.04989 , year=","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.01630","last_updated":"2026-08-03T03:00:43Z","snapshot_observed_at":"2026-08-05T06:31:23.332431Z","submitted_at":"2026-08-03T03:00:43Z","title":"RING: Retrieval-Internalized Generation for Continual Large-Scale Knowledge Injection","version":1},"reference_index":10,"source":"arxiv_source","source_observed_at":"2026-08-04T23:56:14.830929Z"},"links":{"cited_paper":"/paper/2604.04989","citing_paper":"/paper/2608.01630"},"observation_digest":"sha256:a096240f2359344286389cc750364f79592fd1ac6f7ce45d6077c4ef10ce528f","observation_id":"4709215b-7444-4788-ba22-669a2a63051b","resolution":{"observed_at":"2026-08-04T23:56:14.830929Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2604.04989/citation-record","integrity":"/paper/2604.04989/integrity","json":"/paper/2604.04989/citation-record.json","paper":"/paper/2604.04989"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2310.08419","last_updated":"2024-07-18T18:24:57Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-10-12T15:38:28Z","title":"Jailbreaking Black Box Large Language Models in Twenty Queries","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2310.08419","snapshot_observed_at":"2026-07-13T11:36:41.748710Z","title":"Edoardo Debenedetti, Daniel Paleka, Javier Siber, Robin Bachmann, Kilian Lieret, and Florian Tramèr","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-07-13T11:36:41.748710Z"},"links":{"cited_paper":"/paper/2310.08419","citing_paper":"/paper/2604.04989"},"observation_digest":"sha256:13e2f8fb08681301777315147c1b29f4cfd93782085e91f37d6eba00b3b0b2b9","observation_id":"68d0c596-8ca5-4d73-acc1-199a8883a74e","resolution":{"observed_at":"2026-07-13T11:36:41.748710Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2406.13352","last_updated":"2024-11-24T22:04:23Z","snapshot_observed_at":"2026-07-06T18:33:32.806635Z","submitted_at":"2024-06-19T08:55:56Z","title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2406.13352","snapshot_observed_at":"2026-07-13T11:36:41.748710Z","title":"Jingcheng Deng, Liang Pang, Zihao Wei, Shichen Xu, Zenghao Duan, Kun Xu, Yang Song, Huawei Shen, and Xueqi Cheng","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-07-13T11:36:41.748710Z"},"links":{"cited_paper":"/paper/2406.13352","citing_paper":"/paper/2604.04989"},"observation_digest":"sha256:761fee48cf29afd7c55517d8cdfe1af1cdebb774fe1f3f73bb4af6e0f7836846","observation_id":"46f0b412-409f-4e5f-a34d-94fe5e00d6c6","resolution":{"observed_at":"2026-07-13T11:36:41.748710Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2602.06547","last_updated":"2026-06-10T03:31:37Z","snapshot_observed_at":"2026-08-03T04:00:06.220291Z","submitted_at":"2026-02-06T09:52:27Z","title":"\"Do Not Mention This to the User\": Detecting and Understanding Malicious Agent Skills in the Wild","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2602.06547","snapshot_observed_at":"2026-07-13T11:36:41.748710Z","title":"Yi Liu, Zhihao Chen, Yanjun Zhang, Gelei Deng, Yuekang Li, Jianting Ning, and Leo Zhang","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-07-13T11:36:41.748710Z"},"links":{"cited_paper":"/paper/2602.06547","citing_paper":"/paper/2604.04989"},"observation_digest":"sha256:034fc2fa089f2f567604b317805f9acab75bdf6d30235dcb52c7dc96450908c8","observation_id":"8c2b7cc8-c607-4992-ae16-db14cae7537c","resolution":{"observed_at":"2026-07-13T11:36:41.748710Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2202.03286","last_updated":"2022-02-07T15:22:17Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2022-02-07T15:22:17Z","title":"Red Teaming Language Models with Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2202.03286","snapshot_observed_at":"2026-07-13T11:36:41.748710Z","title":"Mikayel Samvelyan, Sharath Chandra Raparthy, Luning Sun, Jack Parker-Holder, Minqi Hu, Tim Rocktäschel, Edward Grefenstette, and Emily Harber","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-07-13T11:36:41.748710Z"},"links":{"cited_paper":"/paper/2202.03286","citing_paper":"/paper/2604.04989"},"observation_digest":"sha256:cbc7bf41ad467983f377d56aee97d959efbc1d6bc24b1fd84ae645868e67e821","observation_id":"e1ad0971-5f5b-48d5-82ee-d8c75477919f","resolution":{"observed_at":"2026-07-13T11:36:41.748710Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.19793","last_updated":"2025-08-24T03:28:21Z","snapshot_observed_at":"2026-08-01T07:24:09.967062Z","submitted_at":"2025-04-28T13:36:43Z","title":"Prompt Injection Attack to Tool Selection in LLM Agents","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.19793","snapshot_observed_at":"2026-07-13T11:36:41.748710Z","title":"Huiyu Wang, Yibo Ma, and Kai Yu","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-07-13T11:36:41.748710Z"},"links":{"cited_paper":"/paper/2504.19793","citing_paper":"/paper/2604.04989"},"observation_digest":"sha256:bd4df35b5fb66e6d193d0c4ffa9dcd1a17cc9b68ffff90dd92a11f991bb54b75","observation_id":"744aa45f-9d21-4b35-9a20-6ee0f1d57e79","resolution":{"observed_at":"2026-07-13T11:36:41.748710Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.10019","last_updated":"2024-10-05T06:50:15Z","snapshot_observed_at":"2026-07-06T17:17:23.567885Z","submitted_at":"2024-01-18T14:40:46Z","title":"R-Judge: Benchmarking Safety Risk Awareness for LLM Agents","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2401.10019","snapshot_observed_at":"2026-07-13T11:36:41.748710Z","title":"InProceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-07-13T11:36:41.748710Z"},"links":{"cited_paper":"/paper/2401.10019","citing_paper":"/paper/2604.04989"},"observation_digest":"sha256:e47ffe89de0e3a23301eb0058fe3fc0cb3ee08de453c5fb1bd6e00b2b9307e13","observation_id":"d2f6e009-fa7a-4f8f-b378-29afc43db615","resolution":{"observed_at":"2026-07-13T11:36:41.748710Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2604.04989","last_updated":"2026-04-05T06:25:11Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-07-13T11:36:36.354754Z","submitted_at":"2026-04-05T06:25:11Z","title":"SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement"},"reference_resolution":{"displayed":6,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":6,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":6},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"thesis":"As of 5 August 2026, this Paper Citation Record lists 6 of 6 outbound references and 17 inbound Pith citation observations for arXiv:2604.04989."}