Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-19T23:26:15.658106Z
Paper Citation Record · LEDGER
As of 13 August 2026, this Paper Citation Record lists 50 of 50 outbound references and 0 inbound Pith citation observations for arXiv:2605.17453.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-05-19T23:26:15.658106Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-13T06:32:02.005865+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
50 of 50 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 95d54b84-5037-45e3-8a53-b04561ee007f · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Identifying the Risks of LM Agents with an LM-Emulated Sandbox
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 355baa8a-bbaf-47e9-9df6-175720873aab · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Stabletoolbench: Towards stable large-scale benchmarking on tool learning of large language models
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 8eddef7a-33df-4682-9d48-20aa3177e5a4 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Toolsandbox: A stateful, conversational, inter- active evaluation benchmark for llm tool use capabilities
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 14ab0792-eb6d-4bea-84b0-4c1c487d8688 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback 10 Guoqing Ma, Jia Zhu, Hanghui Guo, Weijie Shi, Yue Cui, Jiawei Shen, Zilong Li, and Yidan Liang
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 7aefcc1d-0de4-4dc1-b02f-74d1aa71de71 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 63a3a162-0aa1-4310-b58d-80a4ad02de2e · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Benchmarking and defending against indirect prompt injection attacks on large language models
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 1f0bcdfe-3175-49be-94c1-a37d22fb733e · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 7d17e26e-6f7f-49b5-9d46-1694c640d5b4 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 80704353-e5d1-47cb-8147-d0976cf8267d · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation ed513a7c-7cfb-4e25-9757-4157bba206be · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation aaafa9fe-ca11-44e7-985e-e74772f91982 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mcp-itp: An automated framework for implicit tool poisoning in mcp
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 3087fba8-ba75-4b63-a545-65577d239804 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Invisible threats from model context protocol: Generating stealthy injection payload via tree-based adaptive search
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 9afcc3eb-cb16-4c68-b5b4-e35793513a7b · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Breaking the protocol: Security anal- ysis of the model context protocol specification and prompt in- jection vulnerabilities in tool-integrated llm agents
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 1d808a55-40c1-449e-abeb-6fc8fe68b410 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Impossiblebench: Measuring llms’ propensity of exploiting test cases
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation e884a4a1-0691-4954-89df-c374c085161c · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Vijayvargiya, A
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation dc2c3041-f898-4663-ab5f-ecbda63971a1 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Redteamcua: Realistic adversarial testing of computer-use agents in hybrid web-os environments
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 8bc899a1-8672-45ab-ac97-643fb7e14acd · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mcp-safetybench: A benchmark for safety evaluation of large language models with real-world mcp servers
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation b34d59e1-633c-4807-8385-346f4f346af6 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mcpmark: A benchmark for stress-testing realistic and comprehensive mcp use
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation c4da4341-e137-46bd-8579-f7bbfd3e9cc5 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Redcodeagent: Automatic red-teaming agent against diverse code agents
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation d0e23d28-498d-4a9e-89f2-8930fe8996a0 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Bluecodeagent: A blue teaming agent enabled by automated red teaming for codegen ai
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation bbf9b19c-2b5a-4519-a5ce-d8e515cfb8e0 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation d12efa7c-1108-42fb-9a5f-7ed9959d32e8 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mistral 7B
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation baddb7e9-fe46-472c-bb43-f1efd6668c3c · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Qwen3 Technical Report
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 4597fe2c-74ce-4086-8ab5-1d9430571721 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Qwen2 Technical Report
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation e120a031-aa69-4e49-823c-63edaabde9fe · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback 2 OLMo 2 Furious
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 113fdabe-15fa-402d-b958-56fe8c8ae020 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback The Llama 3 Herd of Models
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation ab64cf79-a2b9-4294-b1c7-94c2086bfbec · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Cwm: An open-weights llm for research on code generation with world models
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 8ac61058-bdd4-46c4-8c69-0cf78a278a75 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Evaluating Privilege Usage of Agents with Real-World Tools
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation ab467022-1356-45bb-a775-279454e2d493 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mcpshield: A security cognition layer for adaptive trust calibration in model context protocol agents
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 485a45cd-f748-422b-ad6a-993cf9f4f59f · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 47acb930-00d5-4610-b6f8-40b5bd42ced8 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Defeating Prompt Injections by Design
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 2db7019a-4e71-4607-87ba-bd12422f5275 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Toolsafe: Enhancing tool invocation safety of llm-based agents via proactive step-level guardrail and feedback
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 2605665c-f537-4653-8067-666bff20e950 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unsafer in Many Turns: Benchmarking and Defending Multi-Turn Safety Risks in Tool-Using Agents
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation c750350c-d39e-4407-b490-a5cb9c00f92b · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Agentsentry: Mitigating indirect prompt injection in llm agents via temporal causal diagnostics and context purification
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 4f2b9ce9-fa27-4d44-a7ac-6625eb5e5805 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Commandsans: Securing ai agents with surgical precision prompt sanitization
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 49b01948-34e7-4e35-aa04-69b3806416b6 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback AgentWatcher: A Rule-based Prompt Injection Monitor
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation b47adc32-c21f-42ba-974b-b6c0116eaa03 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Agentsys: Secure and dynamic llm agents through explicit hierarchical memory management
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 6a8e7267-cf47-44be-b914-0f8d010ee7d7 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 395601be-1313-4331-a841-dddd7408b4f5 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Learning When to Act or Refuse: Guarding Agentic Reasoning Models for Safe Multi-Step Tool Use
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation e99f00df-581c-48a3-ad27-c9efc5fd36cf · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Edward Suh
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 3ca4c3cd-6b4d-45fd-94ef-b44b234b9aba · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback SoK: The Attack Surface of Agentic AI - Tools and Autonomy
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 9138402e-3948-4430-ae39-5ed1ba241556 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Reason- ing with language model is planning with world model
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 9eaed837-5b33-4ae1-8118-a0190b221603 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 172cedb8-1493-4c07-8a6b-a566e4530e00 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Generating code world models with large language models guided by monte carlo tree search.Advances in Neural Information Processing Systems, 37:60429–60474
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation a9d17490-85cc-405b-90f8-5ee468dc51da · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation cf620e62-8db7-44e6-84bc-7899961a0847 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation cf33150b-eabe-4ae3-9bf6-0b4104266d9d · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 655e397f-3065-4b06-9f66-7f5b34b3c842 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Candidate episodes produced by this process are retained only after a two-person audit
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 520986dc-8774-4187-bd44-2564d5667bda · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
Observation 0e819038-85c6-4445-b77e-500192575604 · outbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback trajectory_digest
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.
No inbound Pith citation observations are available.