Pith. sign in

Paper Citation Record · LEDGER

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments

As of 22 July 2026, this Paper Citation Record lists 54 of 54 outbound references and 0 inbound Pith citation observations for arXiv:2605.10779.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2605.10779 v1

Coverage vector

measured 54 of 54 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-12T04:08:05.893904Z

measured 54 of 54 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-07-21T06:31:05.380196+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

54 of 54 outbound references displayed

  • verified exact13
  • verified fuzzy39
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch2

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 25347ef8-f034-433d-82f4-0317f3b8a608 · outbound

This paper cites Agentharm: A benchmark for measuring harmfulness of llm agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Agentharm: A benchmark for measuring harmfulness of llm agents

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.228999Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:d56890d631b5e67436c9d8b09b2c72050ea353304d7225f511bc668b612148e5

Observation 7a04aab9-ac02-4a30-8e31-b425cedff576 · outbound

This paper cites System card: Claude Sonnet 4.6.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments System card: Claude Sonnet 4.6

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.249477Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:ab28a75f69b9cdd3e25c35fd95621b5647a74e10a6c5544cb4d91bdb59fcaf68

Observation fda9ff58-de75-42f5-861d-ad4916e81e84 · outbound

This paper cites OpenClaw 2026 security crisis: Protect your API keys now.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments OpenClaw 2026 security crisis: Protect your API keys now

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.171809Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:542c921d490b6da95cf42a86344b95907363dcc6d21f13da8560a087418bd775

Observation f17b7352-a605-41d7-be2f-cf80c44c2d32 · outbound

This paper cites Windows agent arena: Evaluating multi-modal os agents at scale.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Windows agent arena: Evaluating multi-modal os agents at scale

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.128527Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:d2c57dfb8290ca321548ca5d467f5d279e270bd61ab1fb22873db260583ffaec

Observation a8b99f5f-08e3-4e3e-ba1f-60660968ef3a · outbound

This paper cites Mind the gap: Text safety does not transfer to tool-call safety in llm agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Mind the gap: Text safety does not transfer to tool-call safety in llm agents

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-05-12T06:36:26.758976Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:397a8fedcf7ef51bf22e00ac342d90ec010008604487a6c7574b791e931a4efc

Observation 75b9a77b-fd56-4ca3-b28c-7d1710bb0bf0 · outbound

This paper cites Teleai-safety: A comprehensive llm jailbreaking benchmark towards attacks, defenses, and evaluations.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Teleai-safety: A comprehensive llm jailbreaking benchmark towards attacks, defenses, and evaluations

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-12T06:36:26.765247Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:4ac061ca406a40e4e7c3002c6b0b5b247a29a1fd03e7ab0c7e9c7c3a4657a76c

Observation d50e995d-1a9a-4250-a896-33517ebcf31d · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.180008Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:56b6e49c91ef1ca882a233990756ebccb3d8f8ec93c8ea56f9ea3ed6f387c6c6

Observation e03808e8-26fc-438b-ab90-759db19a0ec6 · outbound

This paper cites DeepSeek-V4: Towards highly efficient million-token context intelligence.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments DeepSeek-V4: Towards highly efficient million-token context intelligence

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.237138Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:40dbb229252ab16a72dbd72c933d9c89bb733f73e712731b4310a52f04cd4b5c

Observation d1507b5f-e09d-4e89-b4fb-ec738fcf91a0 · outbound

This paper cites DeepSeek-V3.2: Pushing the Frontier of Open Large Language Models.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments DeepSeek-V3.2: Pushing the Frontier of Open Large Language Models

Reference 9

Resolution
verified exact
local_arxiv, observed 2026-05-12T06:36:26.870498Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:0ecc3a162c77b35e78c14fda33c54c87b493f5594803740e005fb859ae277522

Observation 287fef8e-2eef-47bf-8305-0f94ee4cfeb9 · outbound

This paper cites Sok: The attack surface of agentic ai–tools, and autonomy.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Sok: The attack surface of agentic ai–tools, and autonomy

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-12T06:36:26.746191Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:16251671945f9502b330d082a75a03a677be10861dc0576419e8dcc630f72103

Observation 8865d338-5b76-4706-900b-6df475dbfcef · outbound

This paper cites Wasp: Benchmarking web agent security against prompt injection attacks.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Wasp: Benchmarking web agent security against prompt injection attacks

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.241892Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:da64062ea24ce6270f4ba5c79ee5ce9aedc58d5382737d911ffd973fd488b152

Observation ef8ede4c-3c49-4dbb-b7d2-898cb6af804d · outbound

This paper cites OpenClaw security issues include data leakage & prompt injection.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments OpenClaw security issues include data leakage & prompt injection

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.276107Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:bd0933604a6d466245e76b3585ee56c8d3ed9c1e2f6a4fa67cc449611050ed24

Observation 6f355e14-b6ac-42bf-a936-a9f769c8279d · outbound

This paper cites Security advisories for OpenClaw.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Security advisories for OpenClaw

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.200940Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:b9042f9f21bedf287e52fcda3a1b2f6956affc4b39365536a6666d64ce665238

Observation cd7f7159-18a2-4d29-995f-9c2232da4f9d · outbound

This paper cites SSRF in image tool remote fetch in OpenClaw.https://github .com/openclaw/openclaw/security/advisories/GHSA-56f2-hvwg-5743.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments SSRF in image tool remote fetch in OpenClaw.https://github .com/openclaw/openclaw/security/advisories/GHSA-56f2-hvwg-5743

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.197099Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:11ad65b5261385e3ed7621158ff41ad88f71717fb8f5f4b6ddbba083c9e8279d

Observation d843f2e7-b45a-44e7-b698-9b06b453eb5f · outbound

This paper cites OpenClaw nostr privateKey config redaction bypass leaks plaintext signing key via config.get.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments OpenClaw nostr privateKey config redaction bypass leaks plaintext signing key via config.get

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.205162Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:63a026ec8af24d7e37df7cf047a2990687685a0f73cdc72379e255d5b0643110

Observation 34dacf78-8f10-45d8-9809-62bbfb04e622 · outbound

This paper cites Gemini 3.1 Pro model card.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Gemini 3.1 Pro model card

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.208440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:733d16cc6bd5203bc3b6bef7a9328aac46d955164ee90d62656403da568d32c1

Observation 98ec8e2c-151d-46c8-b4d3-4be3a69c242c · outbound

This paper cites Safety Under Scaffolding: How Evaluation Conditions Shape Measured Safety.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Safety Under Scaffolding: How Evaluation Conditions Shape Measured Safety

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-06-04T03:08:16.834969Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:dcd22ca02a8e6fe210631e9eec65e0a506a025c1597d38749250b0d39590e41f

Observation fbe1e613-c4e2-4a2c-aeb0-8ca6f54c08a3 · outbound

This paper cites Researchers reveal six new OpenClaw vulnerabilities.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Researchers reveal six new OpenClaw vulnerabilities

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.217424Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:3a3ae0348a832357c923bcc588af91abc7911a8672a643b433a21849959baf35

Observation 591d3d8c-5b9a-45f5-82c2-16605617d6b7 · outbound

This paper cites Jiang, Y.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Jiang, Y

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-05-12T06:36:26.824950Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:473a3aa09507fc97db366a63607eab36d20f7b8b785e1fe81ab80478288b76ba

Observation e9ca5bb6-b05d-44e4-a8bd-79a41dbbeec4 · outbound

This paper cites Os-harm: A benchmark for measuring safety of computer use agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Os-harm: A benchmark for measuring safety of computer use agents

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.232994Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:921173eedab07585850303f51539d1c8ffaed4de4c0ecc295f2047ed716b6809

Observation f0a8a938-e0b2-43b7-bda1-42eb5809d47f · outbound

This paper cites Sec-bench: Automated bench- marking of llm agents on real-world software security tasks.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Sec-bench: Automated bench- marking of llm agents on real-world software security tasks

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.184208Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:299b33f1582f0d9d338880c733f4c8b72199ae2f8ff0e31900894caaf5ce8232

Observation 2db58369-1310-4a60-83d4-3cbf9dc76cbc · outbound

This paper cites Claw-Eval-Live: A Live Agent Benchmark for Evolving Real-World Workflows.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Claw-Eval-Live: A Live Agent Benchmark for Evolving Real-World Workflows

Reference 22

Resolution
verified exact
local_arxiv, observed 2026-05-12T06:36:26.733753Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:6f74a5098ceb503fc74b2977e7e9941705e359ae1151cf90c8eacae7c229d39a

Observation 0686fc54-fca5-421e-95d6-79a9bb105864 · outbound

This paper cites ClawsBench: Evaluating Capability and Safety of LLM Productivity Agents in Simulated Workspaces.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments ClawsBench: Evaluating Capability and Safety of LLM Productivity Agents in Simulated Workspaces

Reference 23

Resolution
verified exact
local_arxiv, observed 2026-05-12T06:36:26.861402Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:1bbda66b862cc408459c2b9a75bd81d72ba15e3fb86c7988d651c2c0cd8bf440

Observation ee976a74-c2e8-4c40-9e88-6af6a0b9c889 · outbound

This paper cites Besafe-bench: Unveiling behavioral safety risks of situated agents in functional environments.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Besafe-bench: Unveiling behavioral safety risks of situated agents in functional environments

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-12T06:36:26.807870Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:3dd87d99a169f7c503957739e95450deb196eb648aa9da269f1feb9177fe7f7c

Observation 6ef0844a-8a1b-4c52-a106-74b3fc8819aa · outbound

This paper cites Harmbench: A standardized evaluation framework for automated red teaming and robust refusal.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Harmbench: A standardized evaluation framework for automated red teaming and robust refusal

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.221422Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:56719caa60b9c77dfbb4ecd53bc89b0b99ac72200021e7aaa482258f7e250b29

Observation 912a0731-be66-4907-ac9f-bd6b05868032 · outbound

This paper cites Terminal-bench: Benchmarking agents on hard, realistic tasks in command line interfaces.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Terminal-bench: Benchmarking agents on hard, realistic tasks in command line interfaces

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.225238Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:dab67e0157fa26d4cca682129d7795b593eef8e3343108200e069bb5569b6169

Observation 955d3ad5-a082-4171-b960-c862ed561857 · outbound

This paper cites CVE-2026-26322: OpenClaw SSRF vulnerability in gateway tool via unrestricted gatewayUrl parameter.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments CVE-2026-26322: OpenClaw SSRF vulnerability in gateway tool via unrestricted gatewayUrl parameter

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.261556Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:c24ac1a0c795b0754cce7102217198b91319a7b790b1d14c395fdf01a2c01ad4

Observation 8e7cb622-bc14-437a-8acc-5c1aaf8ce550 · outbound

This paper cites CVE-2026-43528: OpenClaw security vulnerability.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments CVE-2026-43528: OpenClaw security vulnerability

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.160025Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:d82442ff8c491e157cc5bffe62dbe24822a21ccba31db0f268ce81fdc3d7a1e6

Observation 93f3511b-3c72-4da4-8445-113789dfcede · outbound

This paper cites CVE: Common vulnerabilities and exposures.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments CVE: Common vulnerabilities and exposures

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.147190Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:82456fdef571baeed803e5127bb7c9312df0f2b8da51a9a34c3fbd20adb97315

Observation 090fed7d-4139-465e-a357-9c52fa2a8e21 · outbound

This paper cites PinchBench: An independent benchmark for OpenClaw agent performance on complex real-world tasks.https://pinchbench.com/.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments PinchBench: An independent benchmark for OpenClaw agent performance on complex real-world tasks.https://pinchbench.com/

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.140141Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:305dd9685e6920c30ac7dbac5d5f0bf713fbbbd4719250d1f9c44aa73346be64

Observation fe37f0e3-d05b-4c4b-9de4-d24f2c0b8871 · outbound

This paper cites GPT-5.3-Codex system card.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments GPT-5.3-Codex system card

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.156006Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:ce32bb8f0775260cce8bb239f452f87c43452dece7f8596cd253a9f017833ba1

Observation 36b6e734-bfbe-4d30-9147-c1dee5d9bcac · outbound

This paper cites an unresolved cited work.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Unresolved cited work

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.143544Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:0fee2c2a7d6234980381aa00d782f59807deed28b8ee544eb6682858dd3f03e1

Observation 35994066-7dd9-4da6-a124-593cc4c88d49 · outbound

This paper cites Known vulnerabilities.https://clawdocs.org/securit y/known-vulnerabilities/.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Known vulnerabilities.https://clawdocs.org/securit y/known-vulnerabilities/

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.152106Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:9c2a945198aa4a1ebd94c1972925c231a499e4246cca48f3fbd41b4d23653927

Observation 4b7a497d-b483-471a-8a3d-9174d9177d2c · outbound

This paper cites The OpenClaw prompt injection problem: Persistence, tool hijack, and the security boundary that doesn’t exist.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments The OpenClaw prompt injection problem: Persistence, tool hijack, and the security boundary that doesn’t exist

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.164081Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:839e5f6a4c65af145551e38e206ec628b60618336aa610d1e044c2ce1e3fec4a

Observation 02d19e5a-b245-4305-ab78-ebbfc86e1139 · outbound

This paper cites Qwen3.6-Plus: Towards real world agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Qwen3.6-Plus: Towards real world agents

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.168234Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:0015b5dd10b79688249865a49b57ddca467c527cf9e01820c7629991fb8b5cea

Observation 02591845-6c30-4b65-918c-0ab860ccfaf7 · outbound

This paper cites Identifying the risks of lm agents with an lm-emulated sandbox.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Identifying the risks of lm agents with an lm-emulated sandbox

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.120687Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:7493e212599fa7c4445fe22b56ae8c14c289f6907ea13caa94a9c0c67209dcf5

Observation 0d635b06-c562-462c-8943-ee37d329e3fa · outbound

This paper cites Breaking the Code: Security Assessment of AI Code Agents Through Systematic Jailbreaking Attacks.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Breaking the Code: Security Assessment of AI Code Agents Through Systematic Jailbreaking Attacks

Reference 37

Resolution
verified exact
arxiv_id, observed 2026-06-19T17:09:49.202012Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:05c2eb6a46c6cf6558a9cd8d8cc0e547da64f01c2c624ad13e5e66d19ebc5233

Observation 15ecae64-40df-4897-a1b1-2bc47fd6673c · outbound

This paper cites A Security Analysis of the OpenClaw AI Agent Framework.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments A Security Analysis of the OpenClaw AI Agent Framework

Reference 38

Resolution
verified exact
arxiv_id, observed 2026-05-13T01:45:22.267689Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:d989b9b007f95f5ca35a1d476417b34f601dd3d4b63f023dc7fddc1bc02a5b3d

Observation 19ec58f4-ac51-41f0-8ae1-07931c2a39b6 · outbound

This paper cites Meta is having trouble with rogue AI agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Meta is having trouble with rogue AI agents

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.124902Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:9c08a43f1effd1f826810e8a2ec33a6ded140caf2c2db98fed383def6afd62aa

Observation c3d819d0-9c6c-4239-a17e-c7b28bac36f1 · outbound

This paper cites MITRE ATT&CK: Adversarial tactics, techniques, and common knowledge.https://attack.mitre.org/.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments MITRE ATT&CK: Adversarial tactics, techniques, and common knowledge.https://attack.mitre.org/

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.132359Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:3c2a443b2ff8a3e53dab9558ea6aeec94f44c8b861cc95c0cce4597ba85f0292

Observation 75c0bbf1-234b-4d75-8b57-1b27d456dd5e · outbound

This paper cites ClawSafety: "Safe" LLMs, Unsafe Agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments ClawSafety: "Safe" LLMs, Unsafe Agents

Reference 41

Resolution
verified exact
local_arxiv, observed 2026-05-12T06:36:26.833350Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:1f179251ec4ac0d55c88c5f4997b9ab743caa520e51a4ff87738066a607a834b

Observation dea6e0f3-4bd3-42da-8494-666d80c8ba0d · outbound

This paper cites Safetoolbench: Pioneering a prospective benchmark to evaluating tool utilization safety in llms.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Safetoolbench: Pioneering a prospective benchmark to evaluating tool utilization safety in llms

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.136296Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:aae3aca6d2df794b6f5a9c03f50ab58f1be4adc176d2861f533ed92b2029e278

Observation 10f89a0e-15b8-4ba6-b48f-04b89abc1c07 · outbound

This paper cites Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Osworld: Benchmarking multimodal agents for open-ended tasks in real computer environments

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.175876Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:b9134fcd0bc85cb30391dfc1d3b0de7c114e5cc490f5dcdf4732bcc45f5aaa8f

Observation dcf30c38-2ed2-482b-b851-7d516d2bec5c · outbound

This paper cites Claw-Eval: Towards Trustworthy Evaluation of Autonomous Agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Claw-Eval: Towards Trustworthy Evaluation of Autonomous Agents

Reference 44

Resolution
verified exact
local_arxiv, observed 2026-05-12T06:36:26.884477Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:9fac0239eb225d2f35062e15b8dd137b880106987f9d277cd80e9727d8a60406

Observation b6df349a-4ce0-4f00-929f-43da6817fedf · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.253628Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:9bbac94a512f223d6057b22f9dd40cfc9246f466dfc4993750044aa46c5c7d44

Observation d4a718db-00e6-412c-92e4-3089f24083d9 · outbound

This paper cites Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.266707Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:d33f7dd5f56a7b7d29cb666acad97e8a9bcfb9e17b32c93b526898f5d00e2fa0

Observation c10ab230-deea-4f9e-86f4-1c726cf894d9 · outbound

This paper cites ClawBench: Can AI Agents Complete Everyday Online Tasks?.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments ClawBench: Can AI Agents Complete Everyday Online Tasks?

Reference 47

Resolution
verified exact
local_arxiv, observed 2026-05-12T06:36:26.815083Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:754da70770056308535775de4ca591b22c26757aba238b438cff58bb8f796ded

Observation d2f40add-ce62-4dc1-95c7-babccf75ff46 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 48

Resolution
metadata mismatch
local_arxiv, observed 2026-05-12T06:36:26.876698Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:b086c2f94e7550cf5dfce2addfdaa91a16fb50622d8451479c6fb0bf6f522e96

Observation 98a215d5-998e-4099-b9e3-368a6c3dac27 · outbound

This paper cites destructive actions.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments destructive actions

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.245656Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:6efdc2c2a739c001ff975016df155a3db44da664ba71ceaf403a2f063e0cc684

Observation fc44a2ab-a9c3-4bd1-bc1e-6352418eb984 · outbound

This paper cites an unresolved cited work.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Unresolved cited work

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.257291Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:ce9dcf83a13bb8f796818f2fc5eb782f94c4384599732907270c6325b7450bf8

Observation 0d23b74f-6cd4-47ae-915e-fb617963f808 · outbound

This paper cites Are you sure?.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Are you sure?

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.271777Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:f1761d1124f49bcf1278b0fb5670fa12ae9cc221f88078c3896f1ece2c7f7cc0

Observation 2e20461e-dec2-4ee2-937d-1a8c6b7a9c87 · outbound

This paper cites Are you sure?.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Are you sure?

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.192999Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:eba0a8b041ec3ab27342a456beb2e0ebe977c761640cd37d54634ab4f5dbbbb6

Observation 48f05cc4-00d7-4f4c-b030-067cc233f7f4 · outbound

This paper cites an unresolved cited work.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments Unresolved cited work

Reference 53

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.189103Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:59bd9a9cb43e1851b825d3b9d870f37c7c976d3c8a14e036df32ca6a951152a9

Observation 0b489a9f-1005-4e02-98ca-289d0c0170e8 · outbound

This paper cites https://api.eve.com/v1.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments https://api.eve.com/v1

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-05-12T16:26:43.213497Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-07-21T06:31:05.380196+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:39ecafcc8eaa4967f979de4b189dbcf17af909116f6ec18a91866a4aba305aaf

Pith citing papers

No inbound Pith citation observations are available.