{"as_of":"2026-08-07T09:17:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:a77085044af293c105e023c813a0704467659196878a9f1e76daa51f7435a64f","coverage":[{"denominator":71,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":71,"source":"paper_references, paper_reference_links","source_observed_at":"2026-05-21T01:42:55.693115Z","state":"measured"},{"denominator":72,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":72,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-07T06:34:17.273281+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-03T00:45:58.094591Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2605.16282","snapshot_observed_at":"2026-08-03T00:45:58.094591Z","title":"and Fung, Benjamin C","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.28685","last_updated":"2026-07-30T03:45:10Z","snapshot_observed_at":"2026-08-05T23:11:26.173613Z","submitted_at":"2026-07-30T03:45:10Z","title":"Safety, or Just Capability? A Validity Audit of Agent-Safety Benchmarks","version":1},"reference_index":2,"source":"arxiv_source","source_observed_at":"2026-08-03T00:45:58.094591Z"},"links":{"cited_paper":"/paper/2605.16282","citing_paper":"/paper/2607.28685"},"observation_digest":"sha256:fdd2a8378830464393614da721d4409c5e4d93b3b701b8daf37e710b9d4ebed1","observation_id":"257adf34-3152-4825-9e69-0a95f0fbc0d7","resolution":{"observed_at":"2026-08-03T00:45:58.094591Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2605.16282/citation-record","integrity":"/paper/2605.16282/integrity","json":"/paper/2605.16282/citation-record.json","paper":"/paper/2605.16282"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2410.09024","last_updated":"2025-04-18T14:30:31Z","snapshot_observed_at":"2026-08-02T12:38:54.249632Z","submitted_at":"2024-10-11T17:39:22Z","title":"AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents","version":3},"cited_work":{"arxiv_id":"2410.09024","doi":"10.48550/arxiv.2410.09024","metadata_source":"pith","pith_arxiv_id":"2410.09024","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents","venue":"cs.LG","work_id":"788aad10-421f-48d7-886c-792665914606","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":1,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2410.09024","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:7603190257dc2b43eaf505bb093f416b29cdb7a2d5241590bac5462672c7c9b8","observation_id":"d7448029-fd2b-46b8-8f01-bbf7ad43d487","resolution":{"observed_at":"2026-05-21T01:43:56.964497Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2511.10949","doi":"10.48550/arxiv.2511.10949","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Arora, S","venue":"ArXiv.org","work_id":"cf88c259-d1aa-490f-b7cd-639980f3272f","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":2,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:787af7b1797e4dc2692d4747176208bf8093476142b0926e40f6b36daf21e21b","observation_id":"a63e0232-3732-49d0-9208-c68909232097","resolution":{"observed_at":"2026-05-21T01:43:56.968973Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2204.05862","last_updated":"2022-04-12T15:02:38Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2022-04-12T15:02:38Z","title":"Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback","version":1},"cited_work":{"arxiv_id":"2204.05862","doi":"10.1016/j.respol.2005.01.014","metadata_source":"pith","pith_arxiv_id":"2204.05862","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback","venue":"cs.CL","work_id":"a1f2574b-a899-4713-be60-c87ba332656c","year":2022},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":3,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2204.05862","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:4f66ee0c82e9c74c429459689807692cf3869e43948a5927997fd636586ccd33","observation_id":"11199b3f-40b2-4b92-a653-44732c62ff5b","resolution":{"observed_at":"2026-05-21T01:43:56.997040Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.18565","last_updated":"2025-05-05T20:52:36Z","snapshot_observed_at":"2026-08-06T04:13:55.623494Z","submitted_at":"2025-04-21T11:39:22Z","title":"RepliBench: Evaluating the Autonomous Replication Capabilities of Language Model Agents","version":2},"cited_work":{"arxiv_id":"2504.18565","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2504.18565","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Black, A","venue":null,"work_id":"5f454503-3e7c-4bfc-b292-27d613a32066","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":4,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2504.18565","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:07bde2820214be74a6bb28a5de089a561e7b2423483ee7c927ec9e489ca08902","observation_id":"6457398a-7e11-4d66-841d-cf2780bdb754","resolution":{"observed_at":"2026-05-21T01:43:56.973932Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2512.04062","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-03T16:58:43.258612Z","title":"Bordes, C","venue":null,"work_id":"f8c7b140-db16-4481-9f07-38382bb909ba","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":5,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:a6ac0716a6b284cdcc6f1d1861db7446d49559b08bb8b8914371cdd6897c321d","observation_id":"f7055d05-e992-49c0-854f-8125434520f9","resolution":{"observed_at":"2026-05-21T01:43:56.991937Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.12784","last_updated":"2024-07-17T17:59:47Z","snapshot_observed_at":"2026-08-07T08:10:22.834939Z","submitted_at":"2024-07-17T17:59:47Z","title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases","version":1},"cited_work":{"arxiv_id":"2407.12784","doi":"10.48550/arxiv.2407.12784","metadata_source":"pith","pith_arxiv_id":"2407.12784","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases","venue":"cs.LG","work_id":"fd576f32-99d7-40a6-866a-ad86ad47565d","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":6,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2407.12784","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:6e0b9457e7d5db3bb6466c259e6fe23060d9eb52c4210745e17bdeb8fd1e1c01","observation_id":"4b9fdf3f-7778-40d7-9dd2-9f12810ad2a9","resolution":{"observed_at":"2026-05-21T01:43:57.001946Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2510.23883","last_updated":"2026-04-03T16:27:34Z","snapshot_observed_at":"2026-08-02T13:42:34.526072Z","submitted_at":"2025-10-27T21:48:11Z","title":"Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges","version":3},"cited_work":{"arxiv_id":"2510.23883","doi":null,"metadata_source":"pith","pith_arxiv_id":"2510.23883","snapshot_observed_at":"2026-07-03T13:58:21.501410Z","title":"Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges","venue":"cs.AI","work_id":"0f6f4567-4af7-4b82-a1dc-0db0106b4207","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":7,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2510.23883","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:ebd8642b82a7c80edadeb792976f68dbb499c60c46d7a4cdea26d849e468156d","observation_id":"97325393-fe10-40ab-8464-4e60c294076c","resolution":{"observed_at":"2026-05-21T01:43:56.931932Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2405.20947","last_updated":"2025-06-15T21:44:25Z","snapshot_observed_at":"2026-07-06T18:23:23.565502Z","submitted_at":"2024-05-31T15:44:33Z","title":"OR-Bench: An Over-Refusal Benchmark for Large Language Models","version":5},"cited_work":{"arxiv_id":"2405.20947","doi":"10.48550/arxiv.2405.20947","metadata_source":"pith","pith_arxiv_id":"2405.20947","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"OR- Bench: An over-refusal benchmark for large language models","venue":"cs.CL","work_id":"5dc76f29-8555-4005-954c-6e085345fc2f","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":8,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2405.20947","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:b8e2f696f2150f65286cc348e54826183b29b36645f108a03c0815845f882e64","observation_id":"2cbda156-ec48-46de-92e9-fed450dadf5a","resolution":{"observed_at":"2026-05-21T01:43:56.924885Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2406.13352","last_updated":"2024-11-24T22:04:23Z","snapshot_observed_at":"2026-07-06T18:33:32.806635Z","submitted_at":"2024-06-19T08:55:56Z","title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","version":3},"cited_work":{"arxiv_id":"2406.13352","doi":"10.48550/arxiv.2406.13352","metadata_source":"pith","pith_arxiv_id":"2406.13352","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents","venue":"cs.CR","work_id":"7b1b672f-e6b4-4df9-aa8b-3396a2eb8b16","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":9,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2406.13352","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:1fa16014c529ea94b7286ce5eeb677868d4f7e45625db8e6a9a115a7d6a3025c","observation_id":"317b4b9f-2ad6-44b5-87e3-6709fa52abb7","resolution":{"observed_at":"2026-05-21T01:43:56.937545Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2503.03704","doi":"10.48550/arxiv.2503.03704","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Yann Dubois, Balázs Galambosi, Percy Liang, and Tat- sunori B Hashimoto","venue":"arXiv (Cornell University)","work_id":"cc008b41-0943-47c8-81e7-bafb5beac6ce","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":10,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:5e011c71e82e0641f82a6b7f48a4df601eeb989197d65401806b9e22abeef1e3","observation_id":"e25cc844-6f5a-4aa3-a9b8-e4b14881adfc","resolution":{"observed_at":"2026-05-21T01:43:56.942984Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2602.11510","doi":"10.48550/arxiv.2602.11510","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agentleak: A full-stack benchmark for privacy leakage in multi-agent llm systems","venue":"Open MIND","work_id":"4f4d5f73-01e3-40b3-84b0-21a059ae4a2e","year":2026},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":11,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:4c21bf4ee940d605d4cc15afa7808a21c6d4da4a2458d9b4dd6c8748ecc64fdb","observation_id":"f3d770a8-7c0d-42e7-bb3a-150ffd0b512d","resolution":{"observed_at":"2026-05-21T01:43:56.913592Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.18575","last_updated":"2025-05-16T22:42:29Z","snapshot_observed_at":"2026-08-07T07:40:41.686734Z","submitted_at":"2025-04-22T17:51:03Z","title":"WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks","version":3},"cited_work":{"arxiv_id":"2504.18575","doi":"10.48550/arxiv.2504.18575","metadata_source":"pith","pith_arxiv_id":"2504.18575","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks","venue":"cs.CR","work_id":"bf1914b2-fd32-4768-a4d5-84720606d71b","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":12,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2504.18575","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:7700413364401e2fddf2be3ad2c28974ccb071659a47c7e7fba3caa9c244618b","observation_id":"7ffffaaa-f023-4b25-9ec1-55900731891a","resolution":{"observed_at":"2026-05-21T01:43:56.902195Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2601.04566","doi":"10.48550/arxiv.2601.04566","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Backdooragent: A unified framework for backdoor attacks on llm-based agents","venue":"arXiv (Cornell University)","work_id":"0562642e-62f5-4b16-9235-77a89af47c79","year":2026},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":13,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:72fcd2b67b3ad6a20a4f969d5bafd17c16c5f78615cf300ab8bec47372d77dd0","observation_id":"04461fc8-bafd-4be1-9322-7842dff66de3","resolution":{"observed_at":"2026-05-21T01:43:56.880888Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15253","last_updated":"2025-06-18T08:30:36Z","snapshot_observed_at":"2026-08-06T23:58:15.219032Z","submitted_at":"2025-06-18T08:30:36Z","title":"RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments","version":1},"cited_work":{"arxiv_id":"2506.15253","doi":"10.48550/arxiv.2506.15253","metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15253","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2506.15253 , year=","venue":"ArXiv.org","work_id":"1307b8fe-e37b-4327-869c-e2359cdfc1ee","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2506.15253","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:181613ec7ca31a3b774fbe2e4852328d86e7dad81c4f44219cd397c46fa18de2","observation_id":"85b0d4e7-a8a2-42ee-86d0-03b4d12aa8f5","resolution":{"observed_at":"2026-05-21T01:43:56.870990Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14093","last_updated":"2024-12-20T02:22:19Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-12-18T17:41:24Z","title":"Alignment faking in large language models","version":2},"cited_work":{"arxiv_id":"2412.14093","doi":"10.48550/arxiv.2412.14093","metadata_source":"pith","pith_arxiv_id":"2412.14093","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Alignment faking in large language models","venue":"cs.AI","work_id":"cc253a89-cda1-4889-9631-bf3ce8147650","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":15,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2412.14093","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:b44d29af8d58ebe9fee1853cb3190c43383c43eae02d64a8ba8bdbc03f9ee49d","observation_id":"853c3ada-9d65-4089-9c8a-cfeaece0b7a2","resolution":{"observed_at":"2026-05-21T01:43:56.885882Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-01T07:38:13.802289+00:00","source":"crossref_status_cache"},{"observed_at":"2026-08-01T07:38:13.802289+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2302.12173","last_updated":"2023-05-05T14:26:17Z","snapshot_observed_at":"2026-07-06T14:55:08.682906Z","submitted_at":"2023-02-23T17:14:38Z","title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","version":2},"cited_work":{"arxiv_id":"2302.12173","doi":"10.1109/sp61157.2025.00250","metadata_source":"pith","pith_arxiv_id":"2302.12173","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","venue":"cs.CR","work_id":"7a8cfce1-ada7-4a7a-8516-6f16b1bd077b","year":2023},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":16,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2302.12173","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:239d3ed4d115b8d68acd01d597a8425dadf93a0bc13d80803e348daccedb1bb8","observation_id":"b32ee26c-2bd6-4fec-9609-431acca58607","resolution":{"observed_at":"2026-05-21T01:43:56.875654Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2512.02445","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-04T08:59:42.381322Z","title":"Hadeliya, M","venue":null,"work_id":"1ec525b9-7e9d-4a8f-9c62-063af712f478","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":17,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:f0f4b144e268006928e341ade97d2d3c0f38248cd0704d83dec1642112ac8679","observation_id":"4e9279dc-b024-4673-880b-171ed4c94d20","resolution":{"observed_at":"2026-05-21T01:43:56.907448Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2502.14143","last_updated":"2025-02-19T23:03:21Z","snapshot_observed_at":"2026-07-06T20:39:28.583884Z","submitted_at":"2025-02-19T23:03:21Z","title":"Multi-Agent Risks from Advanced AI","version":1},"cited_work":{"arxiv_id":"2502.14143","doi":"10.48550/arxiv.2502.14143","metadata_source":"pith","pith_arxiv_id":"2502.14143","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2502.14143 , year=","venue":"cs.MA","work_id":"5c63297e-2866-40b6-878d-2bdbe3c0fdc7","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":18,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2502.14143","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:ac08dec59685a261f3a447628615abf57b142e3d0c6e6eea55b53ab34591405c","observation_id":"509f0dc6-de5c-46f4-b529-ff370c2b0f9d","resolution":{"observed_at":"2026-05-21T01:43:56.982090Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-07-15T18:20:35.094728+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-15T18:20:35.094728+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.01608","doi":"10.48550/arxiv.2603.01608","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Hopman, J","venue":"arXiv (Cornell University)","work_id":"f5daf6c8-2b52-4a62-8ab1-048209f9e530","year":2026},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":19,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:cfaf1b528e086730721bcf4e02469b36c0e1d9c915f9ea4dac1e4bc86d49a452","observation_id":"56f9752d-e8a3-4b38-84f7-a6f74d7b8cd7","resolution":{"observed_at":"2026-05-21T01:43:56.833946Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.01586","last_updated":"2024-10-03T22:12:05Z","snapshot_observed_at":"2026-08-06T06:52:40.785580Z","submitted_at":"2024-02-02T17:26:23Z","title":"TrustAgent: Towards Safe and Trustworthy LLM-based Agents","version":4},"cited_work":{"arxiv_id":"2402.01586","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.01586","snapshot_observed_at":"2026-07-04T10:59:46.991732Z","title":"TrustAgent: Towards safe and trustworthy LLM-based agents through agent constitution","venue":null,"work_id":"48ac267c-5463-491e-8e7f-1a93448965cb","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":20,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2402.01586","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:7cfd3e288aeec26235c219d5b72d5270955e5bebd88bbd61504abc690e8bd100","observation_id":"a7fbe2f2-f1cf-40bb-ac9d-29c6534da786","resolution":{"observed_at":"2026-05-21T01:43:56.839185Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1906.01820","last_updated":"2021-12-01T11:22:52Z","snapshot_observed_at":"2026-08-01T23:32:03.638122Z","submitted_at":"2019-06-05T04:43:25Z","title":"Risks from Learned Optimization in Advanced Machine Learning Systems","version":3},"cited_work":{"arxiv_id":"1906.01820","doi":"10.48550/arxiv.1906.01820","metadata_source":"pith","pith_arxiv_id":"1906.01820","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Risks from Learned Optimization in Advanced Machine Learning Systems","venue":"cs.AI","work_id":"871c0bb7-e08b-4d8b-be76-610707c748dd","year":2019},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":21,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/1906.01820","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:736877cc5723a1f150325eb5db985cb497256f64c70a4aba9f4465134446a8c0","observation_id":"86227a48-bf0a-49a8-828e-3d27de4fa793","resolution":{"observed_at":"2026-05-21T01:43:56.828334Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2602.16901","doi":"10.48550/arxiv.2602.16901","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Jiang, Y","venue":"Open MIND","work_id":"1e8d816d-5eec-49eb-af9b-3c3796137e22","year":2026},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":22,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:2d422ad999ae657b40d87eb3c36cebccbfe69b01ad7cafd263db2480bb83e5c0","observation_id":"594844c5-4a6c-4666-baa5-72e0b5f1fc29","resolution":{"observed_at":"2026-05-21T01:43:56.844416Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2510.15186","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-10T20:47:34.516251Z","title":"Juneja, J","venue":null,"work_id":"28d5285b-4cb6-41f4-bb64-afcc3486daa1","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":23,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:36a186ec60e8941d9c0d7ded51c5c731b37c0fc665f535c0c73b23097d953b45","observation_id":"f6a8b501-c52d-49cb-a0c3-d818f5b7d17f","resolution":{"observed_at":"2026-05-21T01:43:56.818083Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2511.05269","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-03T15:08:33.264680Z","title":"Kavathekar, H","venue":null,"work_id":"349c0ef9-f21c-4323-a799-38b767be61a2","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":24,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:1c893ef8b1fc3c0a2064138cc6a0e5761b9463e2bc411a8e007555c6f0bfe94b","observation_id":"323dda98-9909-4554-bd9a-ebe310de255c","resolution":{"observed_at":"2026-05-21T01:43:56.801027Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.15740","last_updated":"2025-07-08T21:23:22Z","snapshot_observed_at":"2026-08-07T00:13:55.807216Z","submitted_at":"2025-06-17T15:46:15Z","title":"SHADE-Arena: Evaluating Sabotage and Monitoring in LLM Agents","version":2},"cited_work":{"arxiv_id":"2506.15740","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2506.15740","snapshot_observed_at":"2026-07-04T21:00:10.034415Z","title":"Kutasov, Y","venue":null,"work_id":"7d38f351-dbcb-4ff8-9aee-8ed48580fc14","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":25,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2506.15740","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:14ed29e86d24e34bf222463d9fa2cf81c6578e185d8ff571476c42f44f91aca9","observation_id":"c6157c38-f118-4488-965b-126a0e324d1a","resolution":{"observed_at":"2026-05-21T01:43:56.805773Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2410.17520","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-30T16:24:55.097834Z","title":"Bradley Knox, and Kimin Lee","venue":null,"work_id":"03c5316e-4cd2-45c5-a295-ca06c5a4ec7a","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":26,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:3e2e3cc450e810db43568ea7ce120fe01885e1a8e20883c0cda1e3a067191d59","observation_id":"68b27e3c-0afc-42c0-997f-a0fff24e7e37","resolution":{"observed_at":"2026-05-21T01:43:56.812705Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.06703","last_updated":"2026-06-04T09:59:28Z","snapshot_observed_at":"2026-08-05T07:12:18.604381Z","submitted_at":"2024-10-09T09:13:38Z","title":"ST-WebAgentBench: A Benchmark for Evaluating Safety and Trustworthiness in Web Agents","version":7},"cited_work":{"arxiv_id":"2410.06703","doi":"10.48550/arxiv.2410.06703","metadata_source":"pith","pith_arxiv_id":"2410.06703","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"St- webagentbench: A benchmark for evaluating safety and trustworthiness in web agents","venue":"cs.AI","work_id":"02dc69db-8db6-48b1-ac24-4004642dfa94","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":27,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2410.06703","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:c7d0a14033a83a93586b32c6d91a5d8dd0be9d4d3f6d44a755a0f543cb0c7f51","observation_id":"fccabdc4-e26a-4a40-8ad7-a2d8392829cf","resolution":{"observed_at":"2026-06-05T02:16:16.756993Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2512.20798","last_updated":"2026-05-10T00:05:51Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-12-23T21:52:53Z","title":"A Benchmark for Evaluating Outcome-Driven Constraint Violations in Autonomous AI Agents","version":5},"cited_work":{"arxiv_id":"2512.20798","doi":null,"metadata_source":"pith","pith_arxiv_id":"2512.20798","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"A Benchmark for Evaluating Outcome-Driven Constraint Violations in Autonomous AI Agents","venue":"cs.AI","work_id":"46b16db4-09a1-48a4-b68c-ac3eb9d82197","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":28,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2512.20798","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:f986b6e7be8f880f9d3fbdb7d47a2d95bbfd8405529072b4e2bce5344d4e433a","observation_id":"7b1a9fd3-3093-4323-8df2-f34968cf18c4","resolution":{"observed_at":"2026-05-21T01:43:56.891144Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2501.18636","last_updated":"2025-02-23T10:46:28Z","snapshot_observed_at":"2026-07-06T20:28:38.345613Z","submitted_at":"2025-01-28T17:01:31Z","title":"SafeRAG: Benchmarking Security in Retrieval-Augmented Generation of Large Language Model","version":2},"cited_work":{"arxiv_id":"2501.18636","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2501.18636","snapshot_observed_at":"2026-07-03T05:57:41.435546Z","title":"Liang, S","venue":null,"work_id":"c321aa3d-dc36-4c2f-a859-914690c12193","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":29,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2501.18636","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:33deab67feb928fb01e17eb5b63e4c099bfa91de928daefd6db5f66768f29019","observation_id":"cff8d4f4-6bba-42b0-a4bf-9a0969f32cca","resolution":{"observed_at":"2026-05-21T01:43:56.639271Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2506.14697","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-04T13:49:51.074751Z","title":"Agentsafe: Benchmarking the safety of embodied agents on hazardous instructions","venue":null,"work_id":"80442e4b-93fa-448a-bcb4-e8f3856cadb5","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":30,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:ddb1a101eb8e0e97f286b53865a40fecf5d97293eaa24816802cb6778081ef3a","observation_id":"d963c482-fd03-4cc5-8179-dcf80d320a36","resolution":{"observed_at":"2026-05-21T01:43:56.644461Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2506.16402","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Is- bench: Evaluating interactive safety of vlm-driven embodied agents in daily household tasks","venue":null,"work_id":"4458b016-d6ad-48b6-8155-e0798c9023fd","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":31,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:7510cff61b9dfdff52a2a9e549ea83fbdc0686c44ebd2397c1f8bafbb0eb0852","observation_id":"393ab57d-bca6-42ba-8cc7-9a0f32feb5de","resolution":{"observed_at":"2026-05-21T01:43:57.007268Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2506.00641","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-28T19:42:35.867128Z","title":"Agentauditor: Human-level safety and security evaluation for llm agents.arXiv preprint arXiv:2506.00641","venue":null,"work_id":"0d9a6df9-66b5-48e6-8c29-36f34e275348","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":32,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:1a558ae8dca12e8fa9b3d5afffffc1f2c5f076b4890288f9ed333353dba68ea2","observation_id":"0ae9007d-334b-4abd-b96b-75870300796d","resolution":{"observed_at":"2026-05-21T01:43:57.012454Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2502.05206","last_updated":"2026-04-14T16:10:41Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-02-02T05:14:22Z","title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","version":6},"cited_work":{"arxiv_id":"2502.05206","doi":"10.48550/arxiv.2502.05206","metadata_source":"pith","pith_arxiv_id":"2502.05206","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","venue":"cs.CR","work_id":"fdcd074d-b686-45df-923a-9f11dbbd6a82","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":33,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2502.05206","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:c992e991bc86ac7f9b6eb7e3be1deaeed4663edd2201306eeac72f74077496ef","observation_id":"c1eafb32-4e8a-4616-bc67-c910bcde6c26","resolution":{"observed_at":"2026-05-21T01:43:56.823188Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-05-20T16:52:58.948728+00:00","source":"crossref_status_cache"},{"observed_at":"2026-05-20T16:52:58.948728+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2511.18397","doi":"10.48550/arxiv.2511.18397","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Natural Emergent Misalignment from Reward Hacking in Production RL","venue":"arXiv (Cornell University)","work_id":"7ffab50f-285e-4804-b3fe-167071264d7d","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":34,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:83534317ff625260a67dbec84f7cdc60cceb4a68ae31edbd79c63fcb074b556d","observation_id":"e7318f8f-69f2-489e-a78a-6ef3d401c1fe","resolution":{"observed_at":"2026-05-21T01:43:56.655093Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2510.21460","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"McGregor, V","venue":null,"work_id":"4903431b-c1df-4dfe-b2fa-b7e5e228b430","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":35,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:f2384c50a4dfa120af879fbb5bd8032d754300df014533afd6264418be0e8602","observation_id":"102ae941-79ac-43c2-8907-e5b90e58b0f3","resolution":{"observed_at":"2026-05-21T01:43:56.860696Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2412.04984","last_updated":"2025-01-14T20:16:01Z","snapshot_observed_at":"2026-07-29T23:20:20.918596Z","submitted_at":"2024-12-06T12:09:50Z","title":"Frontier Models are Capable of In-context Scheming","version":2},"cited_work":{"arxiv_id":"2412.04984","doi":"10.48550/arxiv.2412.04984","metadata_source":"pith","pith_arxiv_id":"2412.04984","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Frontier Models are Capable of In-context Scheming","venue":"cs.AI","work_id":"1372f9da-8fac-4446-ba43-4e9e053c8b28","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":36,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2412.04984","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:814f09354df804e5555f47e4269b252a59fde56d0d1b108ec336f51b2d962e3a","observation_id":"bc03938c-acf7-4e92-8a54-1d47d8a45a91","resolution":{"observed_at":"2026-05-21T01:43:56.790333Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-01T07:38:14.128935+00:00","source":"crossref_status_cache"},{"observed_at":"2026-08-01T07:38:14.128935+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":null,"venue":null,"work_id":"38878eb4-d10c-4305-b3fc-7e55fdd6e161","year":1995},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":37,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:93d8d3c9e20fe51944dffaac5476aaea73813ada8fa2ce9fae5891e3f12a41fa","observation_id":"f0295ea1-fa65-467c-be28-0d8d34d5f688","resolution":{"observed_at":"2026-05-21T01:43:57.213984Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2507.21504","last_updated":"2025-07-29T04:57:02Z","snapshot_observed_at":"2026-08-06T15:35:42.279155Z","submitted_at":"2025-07-29T04:57:02Z","title":"Evaluation and Benchmarking of LLM Agents: A Survey","version":1},"cited_work":{"arxiv_id":"2507.21504","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2507.21504","snapshot_observed_at":"2026-07-03T10:27:56.022361Z","title":"Evaluation and benchmarking of LLM agents: A survey","venue":null,"work_id":"af80895a-d45c-407b-a5d7-872b1b97f735","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":38,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2507.21504","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:8c6dddff093ff2bfb2e9c08cfee18aaf7bebb6097ecf460cd492668b3590dfa0","observation_id":"b79c7602-7f7c-4d27-a357-45e108c435fa","resolution":{"observed_at":"2026-05-21T01:43:56.680558Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2506.04018","last_updated":"2026-06-22T12:47:48Z","snapshot_observed_at":"2026-08-06T21:30:42.748259Z","submitted_at":"2025-06-04T14:46:47Z","title":"AgentMisalignment: Measuring the Propensity for Misaligned Behaviour in LLM-Based Agents","version":3},"cited_work":{"arxiv_id":"2506.04018","doi":"10.48550/arxiv.2506.04018","metadata_source":"pith","pith_arxiv_id":"2506.04018","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"AgentMisalignment : Measuring the Propensity for Misaligned Behaviour in LLM - Based Agents , October 2025","venue":"cs.AI","work_id":"82ddccdf-64e6-4b74-b3bc-7329daa9e34e","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":39,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2506.04018","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:94a201f028271381865dd4765a7c6e0d6af06a17cd957dc2599c4f39736d313b","observation_id":"fc1e67d8-bf15-4319-a5e5-da783eb72ca5","resolution":{"observed_at":"2026-06-23T04:13:38.836403Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2602.15198","last_updated":"2026-05-27T00:09:20Z","snapshot_observed_at":"2026-08-03T00:20:12.601117Z","submitted_at":"2026-02-16T21:27:38Z","title":"Colosseum: Auditing Collusion in Cooperative Multi-Agent Systems","version":2},"cited_work":{"arxiv_id":"2602.15198","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2602.15198","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Nakamura, A","venue":null,"work_id":"5b0c05a9-f8a4-4397-b396-a3c70cddbd29","year":2026},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":40,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2602.15198","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:f2097cdb8a3741e3765687d311b819c60df0d314bc1b07ea9f7b8be99a0d619a","observation_id":"e94a4214-ee0a-462d-b4cb-42256b2cd592","resolution":{"observed_at":"2026-05-28T02:04:14.756178Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2508.16481","doi":"10.48550/arxiv.2508.16481","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"N \\\"o ther, A","venue":"ArXiv.org","work_id":"e2e4ac02-be3c-4f04-9e6b-4bb0e86c9a9d","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":41,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:8f778d09c6fb23619f6e579e087c0be60d0943a41adfdbda86e030064420c0c1","observation_id":"869c3a57-64a1-4ff9-ae17-3ec45f6b8da3","resolution":{"observed_at":"2026-05-21T01:43:57.035744Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2304.03279","last_updated":"2023-06-13T01:01:42Z","snapshot_observed_at":"2026-07-06T15:13:06.155585Z","submitted_at":"2023-04-06T17:59:03Z","title":"Do the Rewards Justify the Means? Measuring Trade-Offs Between Rewards and Ethical Behavior in the MACHIAVELLI Benchmark","version":4},"cited_work":{"arxiv_id":"2304.03279","doi":"10.48550/arxiv.2304.03279","metadata_source":"arxiv_reference","pith_arxiv_id":"2304.03279","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"doi:10.48550/arXiv.2304.03279","venue":"arXiv (Cornell University)","work_id":"29c6a535-9b0c-4be7-8e71-44aa243fcc93","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":42,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2304.03279","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:fb1544247aae82198b099d9e5c64b1817c9a888173d93ce613fe221921bdcd9d","observation_id":"e8a3e7e2-a852-48ae-8c54-3e7a98dff719","resolution":{"observed_at":"2026-05-21T01:43:56.709741Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.06448","last_updated":"2026-04-06T06:00:37Z","snapshot_observed_at":"2026-08-02T16:10:55.658718Z","submitted_at":"2025-11-09T16:30:44Z","title":"When AI Agents Collude Online: Financial Fraud Risks by Collaborative LLM Agents on Social Platforms","version":2},"cited_work":{"arxiv_id":"2511.06448","doi":null,"metadata_source":"pith","pith_arxiv_id":"2511.06448","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"When AI Agents Collude Online: Financial Fraud Risks by Collaborative LLM Agents on Social Platforms","venue":"cs.MA","work_id":"ac4bc0be-8b5e-42be-ae65-0c915710a344","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":43,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2511.06448","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:d71bb5680dfe3b1cf2955d14854f4426f1518e9ce5990a9e54c0275e14debdf7","observation_id":"5a9e2519-e0b9-4629-aa8f-4bf3ca85ff2b","resolution":{"observed_at":"2026-05-21T01:43:56.736724Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.21792","last_updated":"2024-12-27T17:36:21Z","snapshot_observed_at":"2026-07-06T18:55:11.576666Z","submitted_at":"2024-07-31T17:59:24Z","title":"Safetywashing: Do AI Safety Benchmarks Actually Measure Safety Progress?","version":3},"cited_work":{"arxiv_id":"2407.21792","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2407.21792","snapshot_observed_at":"2026-07-04T21:10:09.315037Z","title":"Kim, Stephen Fitz, and Dan Hendrycks","venue":null,"work_id":"fd35e7b1-cc17-41e8-b857-f311b6dc7a00","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":44,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2407.21792","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:d466efed29f0b8763968b861acc5d5c8be0f5fbe50ee447f8496860ccab9b03d","observation_id":"905caca1-94da-40e4-9adc-a3a18b023ce9","resolution":{"observed_at":"2026-05-21T01:43:56.649657Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2411.12990","last_updated":"2024-11-20T02:38:24Z","snapshot_observed_at":"2026-07-06T19:52:55.369337Z","submitted_at":"2024-11-20T02:38:24Z","title":"BetterBench: Assessing AI Benchmarks, Uncovering Issues, and Establishing Best Practices","version":1},"cited_work":{"arxiv_id":"2411.12990","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2411.12990","snapshot_observed_at":"2026-07-03T22:08:59.991173Z","title":"Reuel, A","venue":null,"work_id":"93399468-612f-4330-9e9b-7d8d7bdfa8ad","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":45,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2411.12990","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:895e3682ade027afdb4c9523a3e2c67638e0a6633e807e1e2559bf56eda48e89","observation_id":"8fc44ee4-99b8-476f-860e-7e8645fc0122","resolution":{"observed_at":"2026-05-21T01:43:56.704660Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2309.15817","last_updated":"2024-05-17T17:17:45Z","snapshot_observed_at":"2026-07-06T16:24:30.545494Z","submitted_at":"2023-09-25T17:08:02Z","title":"Identifying the Risks of LM Agents with an LM-Emulated Sandbox","version":2},"cited_work":{"arxiv_id":"2309.15817","doi":"10.48550/arxiv.2309.15817","metadata_source":"pith","pith_arxiv_id":"2309.15817","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Identifying the Risks of LM Agents with an LM-Emulated Sandbox","venue":"cs.AI","work_id":"3d4c3b66-d749-4939-b1bc-62b10b2ebbb6","year":2023},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":46,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2309.15817","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:92e923636ceb9840845bd69f3d073868a4f1c94fccec8f07bce6bcb60310d247","observation_id":"aa9ecd7e-3111-4372-8f79-b5d03991a1df","resolution":{"observed_at":"2026-05-21T01:43:56.692475Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2509.14260","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-01T19:16:00.233963Z","title":"Schlatter, B","venue":null,"work_id":"9e7756a3-7305-41a3-aec6-afb462723207","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":47,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:75a1f752d04390cdd826bb684cd06f4c439d16c80e2755c7612809867e2006e2","observation_id":"c36f65e9-2496-45e3-bd1c-e9d03e27654a","resolution":{"observed_at":"2026-05-21T01:43:56.700164Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2511.20703","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"PropensityBench: Evaluating propensity under pressure.arXiv preprint arXiv:2511.20703","venue":null,"work_id":"1b5ebb3c-e1e2-415d-b9c1-f1a16815aa32","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":48,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:5c7cd130140808ae7656b1d310ed40823a04ced98eb84ceca28a94091d1c346f","observation_id":"919ac7ed-ea23-413a-b3c7-9eb712fe5cfb","resolution":{"observed_at":"2026-05-21T01:43:56.855920Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2510.04303","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":null,"venue":null,"work_id":"1368f00c-d22e-4050-b4bb-c45421116276","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":49,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:5ca0670a89fe41b5d78b9b8c2d94ff3dbc2c9f08a14c8e6af21afbd4e6a8494e","observation_id":"6c0c96f1-3b89-4fd2-837e-27a291dffcfe","resolution":{"observed_at":"2026-05-21T01:43:56.762811Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2507.06134","doi":"10.48550/arxiv.2507.06134","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Vijayvargiya, A","venue":"ArXiv.org","work_id":"7315530a-8de5-452c-9c59-6e0cc7436bf1","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":50,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:dcc72c0a4e55dc1647556b92185d694a689d0ffdc6537a608cefbb78226577b0","observation_id":"bef34a4a-98b5-41f4-847a-44179fde9bcb","resolution":{"observed_at":"2026-05-21T01:43:56.953464Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2503.18666","last_updated":"2025-07-31T04:00:48Z","snapshot_observed_at":"2026-07-06T20:57:47.748881Z","submitted_at":"2025-03-24T13:31:48Z","title":"AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents","version":3},"cited_work":{"arxiv_id":"2503.18666","doi":"10.48550/arxiv.2503.18666","metadata_source":"pith","pith_arxiv_id":"2503.18666","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents","venue":"cs.AI","work_id":"2d265b31-7dcb-4ab3-8c83-e13bd5598435","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":51,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2503.18666","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:2f59616a9797a9f7136266061047d2e5ca61e53d4d01fc16f91a242e5274318a","observation_id":"061f3076-96ea-4941-bda7-b4a3b59a52aa","resolution":{"observed_at":"2026-05-21T01:43:57.021306Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-03T00:38:11.552641+00:00","source":"crossref_status_cache"},{"observed_at":"2026-08-03T00:38:11.552641+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.15585","last_updated":"2025-06-09T02:36:20Z","snapshot_observed_at":"2026-07-06T21:12:51.325430Z","submitted_at":"2025-04-22T05:02:49Z","title":"A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment","version":4},"cited_work":{"arxiv_id":"2504.15585","doi":"10.48550/arxiv.2504.15585","metadata_source":"arxiv_reference","pith_arxiv_id":"2504.15585","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment","venue":"ArXiv.org","work_id":"890e4d27-50d3-4726-8e34-bbd56d407411","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":52,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2504.15585","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:62fdd1909a51d18a57ab9acf40d006e1c4d6f5557f442f2f7740d4e96d389f09","observation_id":"9a3344e2-5e67-4e03-bc5a-0669f6456152","resolution":{"observed_at":"2026-05-21T01:43:56.850450Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.11432","last_updated":"2025-03-02T04:04:03Z","snapshot_observed_at":"2026-08-02T07:33:16.089197Z","submitted_at":"2023-08-22T13:30:37Z","title":"A Survey on Large Language Model based Autonomous Agents","version":7},"cited_work":{"arxiv_id":"2308.11432","doi":"10.48550/arxiv.2308.11432","metadata_source":"pith","pith_arxiv_id":"2308.11432","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"A Survey on Large Language Model based Autonomous Agents","venue":"cs.AI","work_id":"47f7e8a3-3732-4530-b412-d9c984ce99ed","year":2023},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":53,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2308.11432","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:3d8c96e45e51a8fbf263f49666b60590a1262dc6599f30db40bd1602bd534487","observation_id":"9465a880-24f8-4a52-90af-93158c92b1b1","resolution":{"observed_at":"2026-05-21T01:43:56.717642Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2309.07864","last_updated":"2023-09-19T08:29:18Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-09-14T17:12:03Z","title":"The Rise and Potential of Large Language Model Based Agents: A Survey","version":3},"cited_work":{"arxiv_id":"2309.07864","doi":"10.1186/s12912-025-04245-9","metadata_source":"pith","pith_arxiv_id":"2309.07864","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"The Rise and Potential of Large Language Model Based Agents: A Survey","venue":"cs.AI","work_id":"985ca219-7e34-4c4f-bdc5-ccd39763ad61","year":2023},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":54,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2309.07864","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:b80cb32d84e6bc35231c2fca0d0c32af496c6b47023a19633fb9774d0df0c9b1","observation_id":"c24b1e4b-2cb1-4fa4-a55c-6cb45de64082","resolution":{"observed_at":"2026-05-21T01:43:56.725147Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2509.07315","last_updated":"2025-09-09T01:31:25Z","snapshot_observed_at":"2026-08-04T22:30:33.163371Z","submitted_at":"2025-09-09T01:31:25Z","title":"SafeToolBench: Pioneering a Prospective Benchmark to Evaluating Tool Utilization Safety in LLMs","version":1},"cited_work":{"arxiv_id":"2509.07315","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2509.07315","snapshot_observed_at":"2026-07-02T22:17:26.189855Z","title":"Safetoolbench: Pioneering a prospective benchmark to evaluating tool utilization safety in llms","venue":null,"work_id":"e50134c0-88f5-43f0-8f31-84ff94676f59","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":55,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2509.07315","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:87fe0c7110fefa93e0b3342a92de1258e542c481f71d9071b59434504440ff4c","observation_id":"e1ef2c08-0e70-4678-b327-3718a55b296e","resolution":{"observed_at":"2026-05-21T01:43:56.686578Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2406.09187","last_updated":"2025-05-29T03:09:05Z","snapshot_observed_at":"2026-07-06T18:30:23.849880Z","submitted_at":"2024-06-13T14:49:26Z","title":"GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning","version":3},"cited_work":{"arxiv_id":"2406.09187","doi":null,"metadata_source":"pith","pith_arxiv_id":"2406.09187","snapshot_observed_at":"2026-07-04T20:40:07.847472Z","title":"GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning","venue":"cs.LG","work_id":"05992330-4d47-450c-89bc-49fd6969ed56","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":56,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2406.09187","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:7b5b81e0d2e107faa3ab375e7dcafd704235512f2136c857cb086980abadb5e0","observation_id":"3dc32d50-682f-4799-860e-6f84d6ceb9db","resolution":{"observed_at":"2026-05-21T01:57:50.455179Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":null,"venue":null,"work_id":"933d6483-a1e5-4445-9aa6-0499ca6546db","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":57,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:fda7cf43e52de035039c24824dd3c874ba0dd5783300516df31ed171a930e90c","observation_id":"6792b4dd-5bfc-41f9-95a2-70c74ecb788f","resolution":{"observed_at":"2026-05-21T01:43:57.210432Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2503.16416","last_updated":"2026-04-23T17:36:18Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-03-20T17:59:23Z","title":"Survey on Evaluation of LLM-based Agents","version":2},"cited_work":{"arxiv_id":"2503.16416","doi":"10.48550/arxiv.2503.16416","metadata_source":"pith","pith_arxiv_id":"2503.16416","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"Survey on Evaluation of LLM-based Agents","venue":"cs.AI","work_id":"d9ac1186-88b1-41bd-9bc7-8a0b87e6f305","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":58,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2503.16416","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:2bb46f992494f8bbfdd0a2868522ac41dd5001f0dce8d573bbcee77980c4ce3b","observation_id":"907bf584-306e-46bd-b3cc-2a95e6a32d88","resolution":{"observed_at":"2026-05-21T01:43:56.713747Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-07-11T06:20:44.248546+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-11T06:20:44.248546+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2412.13178","doi":"10.48550/arxiv.2412.13178","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"SafeAgentBench: A benchmark for safe task planning of embodied LLM agents","venue":"arXiv (Cornell University)","work_id":"8b30e459-3b56-42ae-b523-fb6541f40655","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":59,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:bac46eba29b241bf248ff865034dd8a0ca0b922c33920ea7f979f3724b282a25","observation_id":"87a7a443-e182-4e75-b277-cc4a36b9f1e9","resolution":{"observed_at":"2026-05-21T01:43:56.742827Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2601.23112","last_updated":"2026-08-05T16:46:43Z","snapshot_observed_at":"2026-08-07T08:37:39.222319Z","submitted_at":"2026-01-30T15:58:59Z","title":"How Should AI Safety Benchmarks Benchmark Safety?","version":3},"cited_work":{"arxiv_id":"2601.23112","doi":"10.48550/arxiv.2601.23112","metadata_source":"arxiv_reference","pith_arxiv_id":"2601.23112","snapshot_observed_at":"2026-08-06T02:07:04.187677Z","title":"How should ai safety benchmarks benchmark safety?","venue":"Open MIND","work_id":"ef28352e-e4a1-46cc-94ca-7baae7fa7e81","year":2026},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":60,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2601.23112","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:eaf46267add7fbeacb190533cb8b599ebea3885aea460bdf02a60232df697e2e","observation_id":"8b25fa8c-80dd-4d2a-96df-b8eab9b2499c","resolution":{"observed_at":"2026-08-06T02:07:04.187677Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2503.09648","last_updated":"2025-03-12T08:42:05Z","snapshot_observed_at":"2026-07-06T20:51:32.396503Z","submitted_at":"2025-03-12T08:42:05Z","title":"A Survey on Trustworthy LLM Agents: Threats and Countermeasures","version":1},"cited_work":{"arxiv_id":"2503.09648","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2503.09648","snapshot_observed_at":"2026-07-04T10:59:47.023597Z","title":"A survey on trustworthy llm agents: Threats and countermeasures","venue":null,"work_id":"1736602f-4e2a-44d8-990f-89deaf68fb0b","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":61,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2503.09648","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:e92dcf70e57eb7f3eb3a908d54da2ad528bf6a7cf107af9058c648bb149ec86c","observation_id":"6afe3eec-e3fa-4324-b7c2-178e295152dc","resolution":{"observed_at":"2026-05-21T01:43:56.947706Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.10019","last_updated":"2024-10-05T06:50:15Z","snapshot_observed_at":"2026-08-06T04:21:24.397587Z","submitted_at":"2024-01-18T14:40:46Z","title":"R-Judge: Benchmarking Safety Risk Awareness for LLM Agents","version":3},"cited_work":{"arxiv_id":"2401.10019","doi":null,"metadata_source":"pith","pith_arxiv_id":"2401.10019","snapshot_observed_at":"2026-07-11T02:47:50.885307Z","title":"arXiv preprint arXiv:2401.10019 , year=","venue":"cs.CL","work_id":"80797370-dc29-417d-83c5-ec1313a64166","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":62,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2401.10019","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:b7a53f9227dc5e5872f674bd773201755998c4d01011ff20360d7933c7b141fb","observation_id":"967c5c0a-2f0d-4fd8-b5e8-bcd54bff5ea2","resolution":{"observed_at":"2026-05-21T01:43:56.667888Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"status/2025774","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Nothing humbles you like telling your OpenClaw ``confirm before acting'' and watching it speedrun deleting your inbox","venue":null,"work_id":"24a6846f-17f9-4f90-9bc0-b77edc954319","year":2026},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":63,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:6db5da917b38d2f03218c1b5e49ca92936a9ada6a01800492f6107948db906f8","observation_id":"273019c1-ba34-48ec-a485-1e7b818939f6","resolution":{"observed_at":"2026-05-21T01:43:56.919539Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.02691","last_updated":"2024-08-04T04:52:35Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-03-05T06:21:45Z","title":"InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents","version":3},"cited_work":{"arxiv_id":"2403.02691","doi":"10.1145/3696410.3714756","metadata_source":"pith","pith_arxiv_id":"2403.02691","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents","venue":"cs.CL","work_id":"5cbfcda4-ec26-44e4-be60-e1525956d71d","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":64,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2403.02691","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:02aa790235a3370da3a5af2808c66037323c43035973faa52ba7bb1fa53ebb59","observation_id":"c4f743fa-3509-46c5-afde-7f86ab5ef670","resolution":{"observed_at":"2026-05-21T01:43:56.987491Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.02644","last_updated":"2025-05-30T03:50:33Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-10-03T16:30:47Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","version":4},"cited_work":{"arxiv_id":"2410.02644","doi":"10.48550/arxiv.2410.02644","metadata_source":"pith","pith_arxiv_id":"2410.02644","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","venue":"cs.CR","work_id":"15ab4a69-85ab-4295-839d-080a2cd3e7aa","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":65,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2410.02644","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:0ac8810cf5f1af352b17b2222a9b4046ed54c51b001388c1e887e778db2dd2cc","observation_id":"d6bdd1a1-6a24-4dad-b7be-123f13f5c09c","resolution":{"observed_at":"2026-05-21T01:43:57.025992Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14470","last_updated":"2025-05-20T05:58:23Z","snapshot_observed_at":"2026-08-06T12:35:19.109481Z","submitted_at":"2024-12-19T02:35:15Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","version":2},"cited_work":{"arxiv_id":"2412.14470","doi":"10.48550/arxiv.2412.14470","metadata_source":"pith","pith_arxiv_id":"2412.14470","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","venue":"cs.CL","work_id":"96afb8b9-0e7e-442c-93b1-6638599fc041","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":66,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2412.14470","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:f28383e1905278a4b1c08d982a98c01fb7f610c1be1c9d3022005d2b22845773","observation_id":"4f527707-ce98-47f7-9f26-9d30dff09837","resolution":{"observed_at":"2026-05-21T01:43:56.795455Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-07-14T18:20:24.185748+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-14T18:20:24.185748+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2401.11880","last_updated":"2024-08-20T06:45:50Z","snapshot_observed_at":"2026-07-06T17:18:44.456380Z","submitted_at":"2024-01-22T12:11:55Z","title":"PsySafe: A Comprehensive Framework for Psychological-based Attack, Defense, and Evaluation of Multi-agent System Safety","version":3},"cited_work":{"arxiv_id":"2401.11880","doi":"10.48550/arxiv.2401.11880","metadata_source":"arxiv_reference","pith_arxiv_id":"2401.11880","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Psysafe: A comprehensive framework for psychological-based attack, defense, and evaluation of multi-agent system safety","venue":"arXiv (Cornell University)","work_id":"98f21910-5310-4acc-97ce-abf35e13d48a","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":67,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2401.11880","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:edec87e6012ac0ad8e15ed805f9094b0cb45ce1d7794b4f3b7dbaeb23b9b5d10","observation_id":"57f6ad12-bcd2-428d-a55f-e1bb3dde946e","resolution":{"observed_at":"2026-05-21T01:43:57.030529Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2601.06663","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-29T17:23:44.854432Z","title":"Safepro: Evaluating the safety of professional-level ai agents.arXiv preprint arXiv:2601.06663, 2026","venue":null,"work_id":"78ffb81f-f0dd-4827-9958-b5b5b99ce5ec","year":2026},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":68,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:29999b37f3e157f201457fb3c1fffd9ad6f8923cc5acc83148bbf6c2129c5900","observation_id":"e5c1383d-de45-46e6-9327-ea19121a83e1","resolution":{"observed_at":"2026-05-21T01:43:57.016964Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2512.15163","doi":"10.48550/arxiv.2512.15163","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Mcp-safetybench: A benchmark for safety evaluation of large language models with real-world mcp servers","venue":"Open MIND","work_id":"5c449631-d613-478d-aff3-86e9a0d0e575","year":2025},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":69,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:31b035a8b6d07c54d147c09d8520d464e830d76ae201528fc744d2c1e66df10a","observation_id":"27d9d08c-85b0-49c3-8ef9-23467c42abe9","resolution":{"observed_at":"2026-05-21T01:43:56.958592Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2307.15043","last_updated":"2023-12-20T20:48:57Z","snapshot_observed_at":"2026-07-06T15:59:23.019044Z","submitted_at":"2023-07-27T17:49:12Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","version":2},"cited_work":{"arxiv_id":"2307.15043","doi":"10.48550/arxiv.2307.15043","metadata_source":"pith","pith_arxiv_id":"2307.15043","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","venue":"cs.CL","work_id":"3322fa86-1768-4677-8425-dd326b45e078","year":2023},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":70,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2307.15043","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:40e92784cb304b8ea0a20054c8a2c6b57e1e2f30d285c452d2b986d5c63163a7","observation_id":"dfac3783-4610-42ff-9440-cb100574a342","resolution":{"observed_at":"2026-05-21T01:43:56.662569Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-07-15T23:50:40.271168+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-15T23:50:40.271168+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.07867","last_updated":"2024-08-13T01:55:06Z","snapshot_observed_at":"2026-07-06T17:29:05.185768Z","submitted_at":"2024-02-12T18:28:36Z","title":"PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models","version":3},"cited_work":{"arxiv_id":"2402.07867","doi":"10.48550/arxiv.2402.07867","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.07867","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Poisonedrag: Knowledge poi- soning attacks to retrieval-augmented generation of large language models","venue":"arXiv (Cornell University)","work_id":"66bdf5c5-8305-49a1-b957-9bb5993a358e","year":2024},"citing_paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents","version":1},"reference_index":71,"source":"arxiv_source","source_observed_at":"2026-05-21T01:42:55.693115Z"},"links":{"cited_paper":"/paper/2402.07867","citing_paper":"/paper/2605.16282"},"observation_digest":"sha256:09bc0101171cba7b3099c49f07b4a4a513415d6bed2a7b0c46e59c1739c95b84","observation_id":"287ada0c-ae60-400a-a549-643165fec13f","resolution":{"observed_at":"2026-05-21T01:43:56.674346Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2605.16282","last_updated":"2026-04-11T04:25:19Z","latest_version":1,"primary_category":"cs.CY","snapshot_observed_at":"2026-07-06T23:27:29.931962Z","submitted_at":"2026-04-11T04:25:19Z","title":"Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents"},"reference_resolution":{"displayed":71,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":2,"verified_exact":69,"verified_fuzzy":0},"total_outbound_references":71},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"thesis":"As of 7 August 2026, this Paper Citation Record lists 71 of 71 outbound references and 1 inbound Pith citation observation for arXiv:2605.16282."}