Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-08T09:08:30.102711Z
Paper Citation Record · LEDGER
As of 2 August 2026, this Paper Citation Record lists 57 of 57 outbound references and 1 inbound Pith citation observation for arXiv:2605.06393.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-08T09:08:30.102711Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-02T06:30:47.504484+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-01T16:35:17.406568Z
A source-named dated measurement, never combined with another source.
Source: cited_works
57 of 57 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation a938718d-cbc8-489d-a4e0-4caf515480f5 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation (2026, Feb.) Openclaw vulnerability: Website-to-local agent takeover
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 0b4b4f70-bf74-4bfe-9329-d953a1068b27 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation (2026, Jan.) Openclaw/clawdbot has 1-click RCE via authentication token exfiltration from gatewayurl
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 5e1b04e0-c29f-4907-bbc3-6dae257b9c8c · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Unresolved cited work
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 1d00f4a1-38ba-43f1-8026-d190f7616d74 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Unresolved cited work
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation fad4c65c-8e02-43f5-a36a-5e9154213b04 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation OP-TEE (Open Portable Trusted Ex- ecution Environment)
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 729c4a5c-21ab-43ec-a6de-fe4de97459fa · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation OP-TEE Documentation
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 1e866452-8f82-480d-9b55-a219e09aaffa · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Keystone: An Open Framework for Architecting Trusted Execution Environments
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation b791c4df-827c-42d6-89c3-d94ba8fd38b3 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Keystone Enclave Documentation
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 83fa6f85-a065-4603-9992-8591b9515393 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Enclave Application Cache for RISC-V Keystone
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 680bc1a0-c6e7-4d44-a5ef-231d5167017f · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation (2026) Openclaw - personal AI assistant
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation e7a12b60-8192-4402-979c-f18fb8387449 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Camels can use computers too: System-level security for computer use agents
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 80f11375-14d6-4b59-9f5b-2cbb42f59c25 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 857b32e5-5f7b-45c6-a219-0997fc26a1a6 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 10e9b729-e369-4008-854b-f832dc2c4825 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation A systematic security evaluation of openclaw and its variants
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation e68f8a17-c9fe-47c6-9705-c693cb3197ce · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation A Systematic Security Evaluation of OpenClaw and Its Variants
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 39f98c1e-b1b9-4aca-87fa-7eb13a3daa37 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Vpi-bench: Visual prompt injection attacks for computer-use agents
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 45dd7915-755b-42d6-ac93-a71691def5e3 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation What Did It Actually Do?: Understanding risk awareness and traceability for computer-use agents
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 8e28b5e1-9c8f-4e4f-96f1-bf64c5cc2a3e · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Don’t let the claw grip your hand: A security analysis and defense framework for openclaw
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 405030aa-437b-4afd-9d6d-a84e5ecb9e86 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Don’t let the claw grip your hand: A security analysis and defense framework for OpenClaw
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation f3eea4e2-db26-40ad-9ede-4fb04cf25768 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Uncovering security threats and architecting defenses in autonomous agents: A case study of OpenClaw
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation febdfbe8-d7e8-4c79-bbf1-b6ed5bb54490 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ClawLess: A Security Model of AI Agents
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation c0e71a4c-64d8-4714-a732-03437511829a · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 3790cb3c-65a3-4eb4-9d82-9fa95ff9aab5 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 60c9c6e5-77ac-428d-90fa-e0414e5d0b22 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation aff62ec5-9650-430a-bebc-7d87a21deba8 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Os-harm: A benchmark for measuring safety of computer use agents
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation b6392458-5895-4aef-bb61-063e44d78daf · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 1244999e-f9f3-488d-96d2-2b4c9c8f1b3d · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentHazard: A Benchmark for Evaluating Harmful Behavior in Computer-Use Agents
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 6515f193-6b6e-48af-b7ce-2993cb57e9fa · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ClawSafety: "Safe" LLMs, Unsafe Agents
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 124b7586-b60b-41bd-851d-d8c68926a21c · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Code agent can be an end-to-end system hacker: Benchmarking real-world threats of computer-use agent
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation cfbda53c-fe70-4b69-8b8e-569fbd67782f · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ICON: Indirect prompt injection defense for agents based on inference-time correction
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation c5432059-af0f-467e-850f-7cddc4d5b4f5 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 7045ce5a-3719-4e0d-8e90-87a6f6e798dd · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation arXiv preprint arXiv:2602.10453 , year=
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 83c79e3c-d9a9-4028-a6be-b095f6633a40 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Memory poisoning attack and defense on memory based LLM-agents
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 07484e74-c5af-4bfb-b66b-1f63318bdd77 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 1cf11920-0b88-401c-a02d-1639deeeda9b · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Formal Policy Enforcement for Real-World Agentic Systems
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 3a65c88d-70c8-4b4d-b8e2-96631ab50289 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Wang, Trisha Singhal, Ameya Kelkar, and Jason Tuo
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 79808576-a662-47f2-8eb0-7586e30dd6d0 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation From Governance Norms to Enforceable Controls: A Layered Translation Method for Runtime Guardrails in Agentic AI
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 9c4d0216-016c-4e0c-b5eb-75b5c00c4ee2 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Kaptein, V.-J
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 8ecb8f47-41c0-46c7-a2cb-fa8a78897c79 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Uchibeke
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 8ae5faa8-34a4-4369-8397-0a37b9e330da · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Progent: Securing AI Agents with Privilege Control
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 46bff2a8-8ccb-4bd7-8772-b4def0492778 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Pro2Guard: Proactive runtime enforcement of LLM agent safety via probabilistic model checking
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 8fce22f1-336f-4e23-aa2d-2f2d869a9b99 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Agent Behavioral Contracts: Formal Specification and Runtime Enforcement
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 00fb860b-50b0-46e9-824e-6493c1c3ed53 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Evaluating Privilege Usage of Agents with Real-World Tools
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 86acbf06-b9b5-4128-b4e8-d914434b1ecf · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation SafeClaw-R: Risk analysis and runtime enforcement for OpenClaw skills
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation fbb5e2cf-877a-421f-995f-4aaa38147dd5 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Security Considerations for Artificial Intelligence Agents
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 0b7bd804-a764-4f99-b017-a16b441fc0fd · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Preventing privilege escala- tion
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation aaf89c1e-2d1b-40a6-92d3-be094afd834e · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Enforceable security policies
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 18ac8001-21ab-4c87-a6d5-5765c533885b · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation SC-11: Trusted Path
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 2b6a1e22-f50d-4448-ae00-ce754119e139 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Evidence- based audit
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 37192e4b-2743-420c-b239-cf356377d326 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Systems security foundations for agentic computing
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 7e382754-e76c-4c4a-8122-4a3bc07887d8 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Ai agents under threat: A survey of key security challenges and future pathways
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation e01b55d3-0550-41b1-b9e0-7a7aaf50e233 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation feca86c2-699d-439c-862d-c539df9af9d4 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation 812bbb9c-6812-4222-8e0f-6b0884b22141 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Poison once, exploit forever: Environment-injected memory poisoning attacks on web agents
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation ca9a4bb9-9268-419a-bee3-71963bd3fa48 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation ed97e1cc-5655-45ed-b989-7a0abf94d55a · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Maloyan and D
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation dd7c609b-319f-4a4d-8f9d-500d6728a290 · outbound
Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation His research interests include trusted com- puting, confidential computing, system and network security
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-02T06:30:47.504484+00:00.
Observation cdd1d98e-bac1-4a6a-99bc-586b5e77c7e5 · inbound
RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation
Reference 2026
Source-reported events for the cited work
Unavailable: canonical work link unavailable.