Pith. sign in

Paper Citation Record · LEDGER

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills

As of 6 August 2026, this Paper Citation Record lists 31 of 31 outbound references and 0 inbound Pith citation observations for arXiv:2605.12875.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2605.12875 v1

Coverage vector

measured 31 of 31 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-14T19:06:00.332789Z

measured 31 of 31 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-06T06:34:29.942622+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

31 of 31 outbound references displayed

  • verified exact13
  • verified fuzzy16
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch2

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation ea8747ce-f509-4e69-b346-698500336395 · outbound

This paper cites Extend claude with skills.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Extend claude with skills

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.700344Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:5a1151ff394f5e3c160c9a723e3d907f803b5e0ea9a9e4a141d932e090bcf6b4

Observation 138526ca-9999-4f28-a5c1-66c355c2e562 · outbound

This paper cites About agent skills.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills About agent skills

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.680325Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:49133d77470ad4d49a95ea6aeac1c436fa807d4e0ecbdef3e15601b85d5e31d3

Observation f2df76fb-3e86-4e5b-89b6-9ade7c7aa191 · outbound

This paper cites SkillsinChatGPT.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills SkillsinChatGPT

Reference 3

Resolution
verified exact
arxiv_id, observed 2026-05-14T19:07:51.273282Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:9cfd7aa225b2e7a01de60c6c5f47a59d23cd9a15b071ed22e8dd9274303c479b

Observation 8b95f619-7fb6-489e-932b-82dc354135a9 · outbound

This paper cites Creating agent skills for github copilot.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Creating agent skills for github copilot

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.687096Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:d2487bec77659d287fda7d5d396deccadd85422a327c5265af9d5ffc1c3b59c5

Observation f9da43ab-ab23-43bb-a523-8c0e3e06b486 · outbound

This paper cites Claude code overview.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Claude code overview

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.689211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:782339230b25daf8b0bc497982d382e8f72695badaf4861ef89e1570f74dab93

Observation 196101b7-cfb3-4efa-9035-62ecf29cbc10 · outbound

This paper cites Security.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Security

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.695977Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:542d62aab20b6d5c9d78c62d948cc533c2034b4f3382ddfc6c6d8ed77f86ae4a

Observation 7e7cacf5-bc93-432f-a408-9c110bde6b72 · outbound

This paper cites Adding agent skills for github copilot cli.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Adding agent skills for github copilot cli

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.672900Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:82b013cb2de655bda35ee4327673c00171f6fce4d20b7e099679df8eddf74613

Observation 9c2da38f-a04a-4a0b-a7b7-be602f14a997 · outbound

This paper cites Skillsmp: Agent skills marketplace.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Skillsmp: Agent skills marketplace

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.684749Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:5d3fb872aecba5e6d58ffcba2e81a733cf39d29c1309c1eabe4c2ea281e29b86

Observation 0bdf75cf-40a3-41f1-8f2e-6ea50718963a · outbound

This paper cites Agent skills library.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Agent skills library

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.677946Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:44f2e6983cb9b2cd894470c2ffef0dfc4f8141256e1f3ea1132b6f4e0e7fbf20

Observation d3ddacb1-a7d4-4372-af7e-ec80d5877cf8 · outbound

This paper cites Modeling and discovering vulnerabilities with code property graphs.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Modeling and discovering vulnerabilities with code property graphs

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.675672Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:65990cc654ea9f87ac47b1a9b1c0cce872262f895afd27f7c2dff7d139e167fb

Observation 9715ac7e-533b-43cd-ad05-61d6f9e11271 · outbound

This paper cites Overview | joern documentation.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Overview | joern documentation

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.682765Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:6e6eaad583a7d7a170beefa10a8ade78a876440cf794aaf17e4ca0b884b8bb4b

Observation cd394c1a-a730-4c2e-bb04-da4c63f70705 · outbound

This paper cites Small world with high risks: A study of security threats in the npm ecosystem.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Small world with high risks: A study of security threats in the npm ecosystem

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.691736Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:549cc81a7ee7d575e44d8819f2e4853165afd3112e2f89db0b095093c9175dbc

Observation 9287908d-20d1-45e9-9aa8-fce9c6b359d8 · outbound

This paper cites Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-14T19:07:51.255301Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:b526f80c9fbb8c94f0154de638c073d3f00381410dbd6084d2ff9b3715517a82

Observation fdcc67e0-ff38-4b41-82e6-f398a10945ad · outbound

This paper cites Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-05-14T23:41:24.390564Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:da61fd7d72e6bdc3f4167685455c6da68852a82a571641cadbe6c92a413b685c

Observation 1ffa2fd1-5fbe-4c14-97e3-dbaf2732cb35 · outbound

This paper cites "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild

Reference 15

Resolution
verified exact
arxiv_id, observed 2026-06-02T04:04:28.114733Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:a0eb97947f961a72fb4437dea6f0703fdb57390aa82273ec94cd7d40e8ad4ba7

Observation 403a1b30-81e2-49c0-84ff-58fe1380e054 · outbound

This paper cites Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-16T08:57:26.226663Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:1c4f0130ea1eb703853e0b8047fdc9357ea43407017043e349d293f82cbd2ece

Observation fe472029-98f3-4b50-a530-e7b40c66d9f9 · outbound

This paper cites When skills lie: Hidden-comment injection in llm agents.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills When skills lie: Hidden-comment injection in llm agents

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-14T19:07:51.249476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:1f8c7ffed387cf50f9a0b7ad6eeb80e4b4f84afcc321ea4fcc037ecec5c789e6

Observation de7ed85e-2e21-423d-8e3a-1512fd59bf5c · outbound

This paper cites Model context protocol (mcp): Landscape, security threats, and future research directions.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Model context protocol (mcp): Landscape, security threats, and future research directions

Reference 18

Resolution
verified exact
doi, observed 2026-05-14T19:07:50.139506Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:5c1b4231a8ffc13aefa261a78955137109afb0cec9d454e49896581f4e6d18f1

Observation ebea81e4-ea98-4484-ac9e-ef099ed188c4 · outbound

This paper cites Mcptox: A benchmark for tool poisoning on real-world mcp servers.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Mcptox: A benchmark for tool poisoning on real-world mcp servers

Reference 19

Resolution
verified exact
doi, observed 2026-05-14T19:07:50.157578Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:8e5e8c7cec74c282ba92f3f27103a896c8312c27fa57d397b1e1ca2259f2d4a7

Observation 057f16a0-3336-4a40-874e-d4f01cba6f87 · outbound

This paper cites Agent audit: A security analysis system for llm agent applications.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Agent audit: A security analysis system for llm agent applications

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-05-14T19:07:51.261400Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:99f8351c5d3055fed6b8d5325b8328a5d11258a28ee99bd2dec2059052d75ce6

Observation fcc755d9-f88f-4032-b57f-c653b20fc7ab · outbound

This paper cites Agentsentinel: An end-to-end and real-time security defense framework for computer-use agents.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Agentsentinel: An end-to-end and real-time security defense framework for computer-use agents

Reference 21

Resolution
metadata mismatch
arxiv_id, observed 2026-05-14T19:07:50.145818Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:010724c382af9c4aa32849a4ea5df96a78aa0d08ea547281133f4e3dca6545f5

Observation f1efcaea-efa8-4801-86ee-46f1d2eb343e · outbound

This paper cites A contemporary survey of large language model assisted program analysis.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills A contemporary survey of large language model assisted program analysis

Reference 22

Resolution
metadata mismatch
arxiv_id, observed 2026-05-14T19:07:50.152927Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:cbf96974f45592e02283478aef271a72e8e109867fe552786d44573355be23d4

Observation ec11fbbd-283a-41df-9c7a-378b96989839 · outbound

This paper cites Large language model for vulnerability detection and repair: Literature review and the road ahead.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Large language model for vulnerability detection and repair: Literature review and the road ahead

Reference 23

Resolution
verified exact
doi, observed 2026-05-14T19:07:50.162002Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:715d799e8f8a66d32201d6226e2383af2fa41608ed327233cda657f0df423d4c

Observation 0c489996-2647-4d31-917a-f57c6fbe1ad1 · outbound

This paper cites Can LLM Prompting Serve as a Proxy for Static Analysis in Vulnerability Detection.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Can LLM Prompting Serve as a Proxy for Static Analysis in Vulnerability Detection

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-14T19:07:51.305289Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:f3cdf69319e89589fcd564d9d463f607a94c0821488093f98e114a22b92bc7b4

Observation d8e00960-7e72-4cdd-9913-73544c0f408b · outbound

This paper cites Large language models versus static code analysis tools: A systematic benchmark for vulnerability detection.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Large language models versus static code analysis tools: A systematic benchmark for vulnerability detection

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.693989Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:69ac8762e6c0fffaad8db4ac4a885d45e8e7591339617aa1ecb1fdae84a800bd

Observation cb27750f-b577-413d-8fef-ad058d75cda5 · outbound

This paper cites Iris: Llm-assisted static analysis for detecting security vulnerabilities.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Iris: Llm-assisted static analysis for detecting security vulnerabilities

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.670302Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:8c523b71ab38882cf1e6886e035c37673673ba1081cc32bc4cc096a7f6297d52

Observation 96731b9e-69e7-4d6b-a73f-7ded4205bd35 · outbound

This paper cites Minimizing False Positives in Static Bug Detection via LLM-Enhanced Path Feasibility Analysis.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Minimizing False Positives in Static Bug Detection via LLM-Enhanced Path Feasibility Analysis

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-05-14T19:07:51.298705Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:78f49685504b9641c3f9cb238912f60438c3992a04f69a26b6197882350bc6ea

Observation b5f87010-602e-4f56-991d-f7faeef24fca · outbound

This paper cites Neuro-symbolic Static Analysis with LLM-generated Vulnerability Patterns.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Neuro-symbolic Static Analysis with LLM-generated Vulnerability Patterns

Reference 28

Resolution
verified exact
local_arxiv, observed 2026-05-14T19:07:51.292380Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:5a99545899a4e154154964605dddac8b0355acb2259845ee2e2e275609723749

Observation e4073034-7432-4b62-af97-6c29d1aa9bec · outbound

This paper cites A large-scale empirical study on code-comment inconsistencies.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills A large-scale empirical study on code-comment inconsistencies

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.666235Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:6e0d7d5a3e6237974547fdf6a32220cb7d55bd78aca7cad5a196608664c966f6

Observation bceb8314-023f-401e-bf17-b4c01d342807 · outbound

This paper cites Deep just- in-time inconsistency detection between comments and source code.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Deep just- in-time inconsistency detection between comments and source code

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.698419Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:ea6aefd3ba4d947a9b6760b9e9e25737f28e5e2830cc75761601a5433fd5241f

Observation 395e93bd-68b7-40e2-bd3f-e62db61dc1b4 · outbound

This paper cites Docchecker: Bootstrapping code large language model for detecting and resolving code-comment inconsistencies.

Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills Docchecker: Bootstrapping code large language model for detecting and resolving code-comment inconsistencies

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-05-15T21:01:39.668282Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-14T19:06:00.332789Z digest=sha256:eabbadc66f956d8b72cbeb7f014c3a8d9a2e1268140347bcb8803a8c6ec9368f

Pith citing papers

No inbound Pith citation observations are available.