Pith. sign in

Paper Citation Record · LEDGER

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation

As of 2 August 2026, this Paper Citation Record lists 57 of 57 outbound references and 1 inbound Pith citation observation for arXiv:2605.06393.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2605.06393 v1

Coverage vector

measured 57 of 57 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-08T09:08:30.102711Z

measured 58 of 58 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-02T06:30:47.504484+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-01T16:35:17.406568Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

57 of 57 outbound references displayed

  • verified exact30
  • verified fuzzy16
  • unresolved2
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch9

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation a938718d-cbc8-489d-a4e0-4caf515480f5 · outbound

This paper cites (2026, Feb.) Openclaw vulnerability: Website-to-local agent takeover.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation (2026, Feb.) Openclaw vulnerability: Website-to-local agent takeover

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.773378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:d0338e47cae92fcdd8798ca2fd79b18ef7a297175ddadb7c199944d6a369bb16

Observation 0b4b4f70-bf74-4bfe-9329-d953a1068b27 · outbound

This paper cites (2026, Jan.) Openclaw/clawdbot has 1-click RCE via authentication token exfiltration from gatewayurl.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation (2026, Jan.) Openclaw/clawdbot has 1-click RCE via authentication token exfiltration from gatewayurl

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.764787Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:4ce6e56568842f270cb95929ef482377bd5a5d7b88768d2f3bc2f8ad171ce58a

Observation 5e1b04e0-c29f-4907-bbc3-6dae257b9c8c · outbound

This paper cites an unresolved cited work.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Unresolved cited work

Reference 3

Resolution
unresolved
raw_fallback, observed 2026-05-26T16:27:39.760093Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:4380392e53abb3101819caabe834ec6285ffadb34fb7cc85099884dd34ae1ae9

Observation 1d00f4a1-38ba-43f1-8026-d190f7616d74 · outbound

This paper cites an unresolved cited work.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Unresolved cited work

Reference 4

Resolution
unresolved
raw_fallback, observed 2026-05-26T16:27:39.769061Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:71c49b9a4b16e7feffc130e997085788585be8497cd45a4262fd1de2f2f80b0b

Observation fad4c65c-8e02-43f5-a36a-5e9154213b04 · outbound

This paper cites OP-TEE (Open Portable Trusted Ex- ecution Environment).

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation OP-TEE (Open Portable Trusted Ex- ecution Environment)

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.750852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:e7a6e2ccc6830b3743e8cbc1a415b3df5eec6864173bb08d40c9a4051b350884

Observation 729c4a5c-21ab-43ec-a6de-fe4de97459fa · outbound

This paper cites OP-TEE Documentation.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation OP-TEE Documentation

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.746149Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:f281cd70e18afdcdbde92b586bf98dea600e6b1b0b5e9d7bbd30cc94a6cb64d5

Observation 1e866452-8f82-480d-9b55-a219e09aaffa · outbound

This paper cites Keystone: An Open Framework for Architecting Trusted Execution Environments.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Keystone: An Open Framework for Architecting Trusted Execution Environments

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.731695Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:9eba80460f2449de65aea133def8df99ee1edf1d37fed4a76a15a1f1911477f1

Observation b791c4df-827c-42d6-89c3-d94ba8fd38b3 · outbound

This paper cites Keystone Enclave Documentation.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Keystone Enclave Documentation

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.736465Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:2afcca49846d012172c6a687fcf9a510c583fe41906c7dd3717542285066f475

Observation 83fa6f85-a065-4603-9992-8591b9515393 · outbound

This paper cites Enclave Application Cache for RISC-V Keystone.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Enclave Application Cache for RISC-V Keystone

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.741545Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:909d7a6dfffc9dd4d56c338f499cfceb12e49eb11720ff801a986312b6ae0c74

Observation 680bc1a0-c6e7-4d44-a5ef-231d5167017f · outbound

This paper cites (2026) Openclaw - personal AI assistant.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation (2026) Openclaw - personal AI assistant

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.755621Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:ba458e5fe5f028f2b3a2487ffb40cc73500cd57f217e8d8efd92b5f3badad11a

Observation e7a12b60-8192-4402-979c-f18fb8387449 · outbound

This paper cites Camels can use computers too: System-level security for computer use agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Camels can use computers too: System-level security for computer use agents

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.777394Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:fb24ba8dee3d4c4614856af294b98a55feb474e8c90d61d02f9ee8ca74db7a7a

Observation 80f11375-14d6-4b59-9f5b-2cbb42f59c25 · outbound

This paper cites CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-06-05T02:16:21.941428Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:5e0f362d181034518cd09bd4ee0c20e4e7188ac9a2f15ba76c0559c820b0779f

Observation 857b32e5-5f7b-45c6-a219-0997fc26a1a6 · outbound

This paper cites Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw

Reference 13

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.296295Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:fc067b7958ef111529700f25c9844456e0d8323af201c2c0a56b43604e053945

Observation 10e9b729-e369-4008-854b-f832dc2c4825 · outbound

This paper cites A systematic security evaluation of openclaw and its variants.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation A systematic security evaluation of openclaw and its variants

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.791050Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:8d2968835e9ad59fc39677c1d628743e206fd1d59246ce0cceacea32084d9045

Observation e68f8a17-c9fe-47c6-9705-c693cb3197ce · outbound

This paper cites A Systematic Security Evaluation of OpenClaw and Its Variants.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation A Systematic Security Evaluation of OpenClaw and Its Variants

Reference 15

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T20:26:11.278150Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:5995ca1296b72199ac2330a0a0cd3b60eec2d86bbcb05d2de45e96f682ca3778

Observation 39f98c1e-b1b9-4aca-87fa-7eb13a3daa37 · outbound

This paper cites Vpi-bench: Visual prompt injection attacks for computer-use agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Vpi-bench: Visual prompt injection attacks for computer-use agents

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.095045Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:3b73f335fb406ada3bbf749269b9e268b3322c11f4a4a9153e849c133695a7e5

Observation 45dd7915-755b-42d6-ac93-a71691def5e3 · outbound

This paper cites What Did It Actually Do?: Understanding risk awareness and traceability for computer-use agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation What Did It Actually Do?: Understanding risk awareness and traceability for computer-use agents

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.228751Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:23618caec223993f96871047c13161d704f340e299f450c1d540bd4c741955ec

Observation 8e28b5e1-9c8f-4e4f-96f1-bf64c5cc2a3e · outbound

This paper cites Don’t let the claw grip your hand: A security analysis and defense framework for openclaw.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Don’t let the claw grip your hand: A security analysis and defense framework for openclaw

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.781871Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:20d8a37f5cb2b1dee504d863593553aa2c2beae290162bec5179be40b7541f62

Observation 405030aa-437b-4afd-9d6d-a84e5ecb9e86 · outbound

This paper cites Don’t let the claw grip your hand: A security analysis and defense framework for OpenClaw.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Don’t let the claw grip your hand: A security analysis and defense framework for OpenClaw

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.236477Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:632d26edfd777881fcb1a9bacefd3830fc4615a1d6be92f946389d2196a9110a

Observation f3eea4e2-db26-40ad-9ede-4fb04cf25768 · outbound

This paper cites Uncovering security threats and architecting defenses in autonomous agents: A case study of OpenClaw.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Uncovering security threats and architecting defenses in autonomous agents: A case study of OpenClaw

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.247346Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:6b270cfe7db81766d63fcd7ff7f7c984e88dd321e355408f7007e9ecb4aa8d96

Observation febdfbe8-d7e8-4c79-bbf1-b6ed5bb54490 · outbound

This paper cites ClawLess: A Security Model of AI Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ClawLess: A Security Model of AI Agents

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.221742Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:c6ea2a8ece96d7dff380b18490d746363b4844aefefbab0ba4f872db65be0c5f

Observation c0e71a4c-64d8-4714-a732-03437511829a · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 22

Resolution
verified exact
arxiv_id, observed 2026-05-13T21:40:06.567267Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:64069d4058ac0821e6a61d3cd7a32dc284b0cb94933632da5ec4eeada31ec746

Observation 3790cb3c-65a3-4eb4-9d82-9fa95ff9aab5 · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:d9fcb8324392022662ef59768522c7518e0a43b3c05e35d5cf4bdb60187b68a3

Observation 60c9c6e5-77ac-428d-90fa-e0414e5d0b22 · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-12T13:36:57.477107Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:3554c25eee801c7d6a868224ad1b11983ec1b4ad717320be0f393881cf768989

Observation aff62ec5-9650-430a-bebc-7d87a21deba8 · outbound

This paper cites Os-harm: A benchmark for measuring safety of computer use agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Os-harm: A benchmark for measuring safety of computer use agents

Reference 25

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.272766Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:9ab332b0b7c43310a5493c8733e0d22e6d4c8fa7960942e4f8cb6f0dde60b490

Observation b6392458-5895-4aef-bb61-063e44d78daf · outbound

This paper cites WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-15T22:22:05.737978Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:9411206b8ccdead22f1130e526706d61250cf991c582ea15ff53da47f78943fb

Observation 1244999e-f9f3-488d-96d2-2b4c9c8f1b3d · outbound

This paper cites AgentHazard: A Benchmark for Evaluating Harmful Behavior in Computer-Use Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentHazard: A Benchmark for Evaluating Harmful Behavior in Computer-Use Agents

Reference 27

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.179617Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:d61f351c8f63e2476b7b021a3be0d1b4773264ffe7b1c18b8921baf32cd38a70

Observation 6515f193-6b6e-48af-b7ce-2993cb57e9fa · outbound

This paper cites ClawSafety: "Safe" LLMs, Unsafe Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ClawSafety: "Safe" LLMs, Unsafe Agents

Reference 28

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.194653Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:f1cdbdba6dfc601afe632017639818ac80498dfd868e2c5391b1b52526bfc5f9

Observation 124b7586-b60b-41bd-851d-d8c68926a21c · outbound

This paper cites Code agent can be an end-to-end system hacker: Benchmarking real-world threats of computer-use agent.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Code agent can be an end-to-end system hacker: Benchmarking real-world threats of computer-use agent

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.139612Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:ff89b328f7ce386f3b7bbc0876b45e4e633db6b6f9fa84ae62cd1b867fb60f38

Observation cfbda53c-fe70-4b69-8b8e-569fbd67782f · outbound

This paper cites ICON: Indirect prompt injection defense for agents based on inference-time correction.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ICON: Indirect prompt injection defense for agents based on inference-time correction

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.157152Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:380b660bc6678d55dff6c14bcb0de761d47442d11ed67cb447b251f66edba01d

Observation c5432059-af0f-467e-850f-7cddc4d5b4f5 · outbound

This paper cites Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.150157Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:3f71cc8f30fbeb4bf5b42c5c81d9426c42b3d6fdfde40d5b89500460acf596b4

Observation 7045ce5a-3719-4e0d-8e90-87a6f6e798dd · outbound

This paper cites arXiv preprint arXiv:2602.10453 , year=.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation arXiv preprint arXiv:2602.10453 , year=

Reference 32

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.164074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:183041f54bad6ed98a9790d395536115e8f640c96d4391e365302c65f24b0ded

Observation 83c79e3c-d9a9-4028-a6be-b095f6633a40 · outbound

This paper cites Memory poisoning attack and defense on memory based LLM-agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Memory poisoning attack and defense on memory based LLM-agents

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.726884Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:6177ce19541af69ba4236c3f00e4b9b1057f1f6bd2bf98cad149d784bd8bf041

Observation 07484e74-c5af-4bfb-b66b-1f63318bdd77 · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:24:32.777586Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:62f322a1cd9a7530bb8b2862b8ee912bea1bb2abcfeccb1cfb36906d10bb071a

Observation 1cf11920-0b88-401c-a02d-1639deeeda9b · outbound

This paper cites Formal Policy Enforcement for Real-World Agentic Systems.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Formal Policy Enforcement for Real-World Agentic Systems

Reference 35

Resolution
verified exact
arxiv_id, observed 2026-05-12T01:43:58.132331Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:11113a66561741a52af01f58406812d25cb3930336a3639baf7700f945b5f608

Observation 3a65c88d-70c8-4b4d-b8e2-96631ab50289 · outbound

This paper cites Wang, Trisha Singhal, Ameya Kelkar, and Jason Tuo.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Wang, Trisha Singhal, Ameya Kelkar, and Jason Tuo

Reference 36

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.289832Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:19a5f94924692abad30552d63ea04af59aa170f07ce7ba630b3d597f7b94d4f5

Observation 79808576-a662-47f2-8eb0-7586e30dd6d0 · outbound

This paper cites From Governance Norms to Enforceable Controls: A Layered Translation Method for Runtime Guardrails in Agentic AI.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation From Governance Norms to Enforceable Controls: A Layered Translation Method for Runtime Guardrails in Agentic AI

Reference 37

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.112259Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:cfb58198b69dda09c4594d93c4b8079aa7c2d93dc065016e86f55104c3804781

Observation 9c4d0216-016c-4e0c-b5eb-75b5c00c4ee2 · outbound

This paper cites Kaptein, V.-J.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Kaptein, V.-J

Reference 38

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.033709Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:3818c4e1dc1df5a3db294ed6b35d7368641eca505826521bc7485920aa79f37e

Observation 8ecb8f47-41c0-46c7-a2cb-fa8a78897c79 · outbound

This paper cites Uchibeke.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Uchibeke

Reference 39

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:10.998204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:c12abe3712987096eaab5fb81da0237a27ce075b70e4a2ced7c7265804f7000a

Observation 8ae5faa8-34a4-4369-8397-0a37b9e330da · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Progent: Securing AI Agents with Privilege Control

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-15T01:43:10.493453Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:ebb2cbb62f4f4c001bc64b4bf1d85c270b24dd9fd54debcc809c6b8eeee25623

Observation 46bff2a8-8ccb-4bd7-8772-b4def0492778 · outbound

This paper cites Pro2Guard: Proactive runtime enforcement of LLM agent safety via probabilistic model checking.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Pro2Guard: Proactive runtime enforcement of LLM agent safety via probabilistic model checking

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:10.978771Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:a7c4e03b555bf8bc4e37ffa30f132170fd7ebc8898619d56db955ec5ca41d420

Observation 8fce22f1-336f-4e23-aa2d-2f2d869a9b99 · outbound

This paper cites Agent Behavioral Contracts: Formal Specification and Runtime Enforcement.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Agent Behavioral Contracts: Formal Specification and Runtime Enforcement

Reference 42

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:10.961108Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:baf1dd545fa93f1c6bcef471b9fcc65070486c89022f793dc0374fa68bad78b5

Observation 00fb860b-50b0-46e9-824e-6493c1c3ed53 · outbound

This paper cites Evaluating Privilege Usage of Agents with Real-World Tools.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Evaluating Privilege Usage of Agents with Real-World Tools

Reference 43

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:10.968405Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:2e6fdc537aefe9683bf7783406646b9288397270bd02faf11510f9d8882537a2

Observation 86acbf06-b9b5-4128-b4e8-d914434b1ecf · outbound

This paper cites SafeClaw-R: Risk analysis and runtime enforcement for OpenClaw skills.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation SafeClaw-R: Risk analysis and runtime enforcement for OpenClaw skills

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:10.985007Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:cd745a70477d100d61c866aef38d009ac28f91306d352ee95762660ea90bfe55

Observation fbb5e2cf-877a-421f-995f-4aaa38147dd5 · outbound

This paper cites Security Considerations for Artificial Intelligence Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Security Considerations for Artificial Intelligence Agents

Reference 45

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.020770Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:3f1fafebb25fe2db2693c319f72af8ade56ca273c754da896db9d8a43aab20ef

Observation 0b7bd804-a764-4f99-b017-a16b441fc0fd · outbound

This paper cites Preventing privilege escala- tion.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Preventing privilege escala- tion

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.795252Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:9359f1f978b7c1ed5ca2783336c20e3f3b0579bd4249574e10a23a9f1950be64

Observation aaf89c1e-2d1b-40a6-92d3-be094afd834e · outbound

This paper cites Enforceable security policies.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Enforceable security policies

Reference 47

Resolution
verified exact
arxiv_id, observed 2026-05-08T22:24:19.059649Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:53da4be9492e17f131fefbf850bd65cff3176ccf29b558f3f4c5796e3ba7521b

Observation 18ac8001-21ab-4c87-a6d5-5765c533885b · outbound

This paper cites SC-11: Trusted Path.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation SC-11: Trusted Path

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.721928Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:c92e1af7b00bb74ba68c145acd74aaf9c49b1af33f8dcba95133f94009d72f9c

Observation 2b6a1e22-f50d-4448-ae00-ce754119e139 · outbound

This paper cites Evidence- based audit.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Evidence- based audit

Reference 49

Resolution
verified exact
doi, observed 2026-05-08T22:24:19.064342Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:77c0c6b6701e06ee45f47181b1ccdfdb2a3e11093f1567091f2450f337e84e01

Observation 37192e4b-2743-420c-b239-cf356377d326 · outbound

This paper cites Systems security foundations for agentic computing.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Systems security foundations for agentic computing

Reference 50

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.044363Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:18d91e54f7c473455fabd0656e856d86995d3a6d3556dc3db00447ad28dfe0f2

Observation 7e382754-e76c-4c4a-8122-4a3bc07887d8 · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Ai agents under threat: A survey of key security challenges and future pathways

Reference 51

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.067357Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:cc229d907c8eb10edbf8183fb036b18ea557b45c4a7ce392477dee452b71ce5c

Observation e01b55d3-0550-41b1-b9e0-7a7aaf50e233 · outbound

This paper cites AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 52

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.054246Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:4333f563ad59e6912aea659c4d2e86d5286d7883269312f8d78d4d6405eb013d

Observation feca86c2-699d-439c-862d-c539df9af9d4 · outbound

This paper cites AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 53

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.087888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:fe843ccbf541a9be1ed276444e1db75f3afbdc1af2c44279bcf4e4be09aa96b8

Observation 812bbb9c-6812-4222-8e0f-6b0884b22141 · outbound

This paper cites Poison once, exploit forever: Environment-injected memory poisoning attacks on web agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Poison once, exploit forever: Environment-injected memory poisoning attacks on web agents

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.717404Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:88d31b3cd166ff686cfbd16923cbeed9935bd57fa9f43b5cd6361488f97a2947

Observation ca9a4bb9-9268-419a-bee3-71963bd3fa48 · outbound

This paper cites Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents

Reference 55

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T20:26:11.122650Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:ad8fc1c0193a8530d977813c67d4d9fa21e1de753ce01d50ce46e010fe37988b

Observation ed97e1cc-5655-45ed-b989-7a0abf94d55a · outbound

This paper cites Maloyan and D.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Maloyan and D

Reference 56

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.009072Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:a53c6e3f538a84b79ef03dfb6ff8267474f51ba904b4665d3c6c42efe5585729

Observation dd7c609b-319f-4a4d-8f9d-500d6728a290 · outbound

This paper cites His research interests include trusted com- puting, confidential computing, system and network security.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation His research interests include trusted com- puting, confidential computing, system and network security

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.786529Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:2dd464351a795504d7da01847759645e07714086631074612aeaf6da7546fc42

Pith citing papers

Observation cdd1d98e-bac1-4a6a-99bc-586b5e77c7e5 · inbound

RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control cites this paper.

RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation

Reference 2026

Resolution
unresolved
no resolver link, observed 2026-08-01T16:35:17.406568Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T16:35:17.406568Z digest=sha256:c96ad96f72fbf0d7ef1c5572d48e0b2f9f5de61bc2f3287c7f3029b8451785fd