Pith. sign in

Paper Citation Record · LEDGER

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback

As of 13 August 2026, this Paper Citation Record lists 50 of 50 outbound references and 0 inbound Pith citation observations for arXiv:2605.17453.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2605.17453 v1

Coverage vector

measured 50 of 50 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-19T23:26:15.658106Z

measured 50 of 50 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-13T06:32:02.005865+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

50 of 50 outbound references displayed

  • verified exact32
  • verified fuzzy10
  • unresolved5
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch2

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 95d54b84-5037-45e3-8a53-b04561ee007f · outbound

This paper cites Identifying the Risks of LM Agents with an LM-Emulated Sandbox.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Identifying the Risks of LM Agents with an LM-Emulated Sandbox

Reference 1

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.388844Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:d0d49df9a7c2acab63c9e708d020090e7212ce65427c9927b82b037c91e33f06

Observation 355baa8a-bbaf-47e9-9df6-175720873aab · outbound

This paper cites Stabletoolbench: Towards stable large-scale benchmarking on tool learning of large language models.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Stabletoolbench: Towards stable large-scale benchmarking on tool learning of large language models

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.259922Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:911df0b02923803841f881eb423f9cd7906f01f99473667c4a8a4ac6ccc7af0d

Observation 8eddef7a-33df-4682-9d48-20aa3177e5a4 · outbound

This paper cites Toolsandbox: A stateful, conversational, inter- active evaluation benchmark for llm tool use capabilities.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Toolsandbox: A stateful, conversational, inter- active evaluation benchmark for llm tool use capabilities

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.203426Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:8f8c70c222c821d6bc7de6b56bc050e05edf20db9c53cef9d4fc4cf5c1dbff16

Observation 14ab0792-eb6d-4bea-84b0-4c1c487d8688 · outbound

This paper cites 10 Guoqing Ma, Jia Zhu, Hanghui Guo, Weijie Shi, Yue Cui, Jiawei Shen, Zilong Li, and Yidan Liang.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback 10 Guoqing Ma, Jia Zhu, Hanghui Guo, Weijie Shi, Yue Cui, Jiawei Shen, Zilong Li, and Yidan Liang

Reference 4

Resolution
metadata mismatch
arxiv_id, observed 2026-05-19T23:27:52.401137Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:20d01e8b560c8e4b9f7130cc3bc5e403a51201b51c5b8f249bcc195446aeb226

Observation 7aefcc1d-0de4-4dc1-b02f-74d1aa71de71 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.235138Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:4f66e5da2cb2f03999d020c69ae6ea7e0e5b300470e2e6f5956484b79877fb4e

Observation 63a3a162-0aa1-4310-b58d-80a4ad02de2e · outbound

This paper cites Benchmarking and defending against indirect prompt injection attacks on large language models.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Benchmarking and defending against indirect prompt injection attacks on large language models

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.249277Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:e9de8977ce4817153a5271c3ace617ae316904d4fd00a6bc156bad8dac679c2b

Observation 1f0bcdfe-3175-49be-94c1-a37d22fb733e · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.198732Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:f2c1d41f5e69dab34687e8267eed8d9b14d1ad3269c166d66d76b859777f823f

Observation 7d17e26e-6f7f-49b5-9d46-1694c640d5b4 · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.194418Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:0fd2a6bf5f1d3358018c8ccaf4c7c9f3061720220c0f1eca0c75d5f4167750c1

Observation 80704353-e5d1-47cb-8147-d0976cf8267d · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 9

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.612366Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:e7b86dd285fe297b118c8c205b653760d4996ea854df3d9e2a16b24b54a7eff8

Observation ed513a7c-7cfb-4e25-9757-4157bba206be · outbound

This paper cites MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.575901Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:8ceda8e2fda779ba76d8342bca440832ed6d53e1e8fb733a7fbed4a0cbfec9cc

Observation aaafa9fe-ca11-44e7-985e-e74772f91982 · outbound

This paper cites Mcp-itp: An automated framework for implicit tool poisoning in mcp.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mcp-itp: An automated framework for implicit tool poisoning in mcp

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.518906Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:82480806b87c349207ae4125c82fcb7c9e520ef9c44f239fdf0a22c451db7e92

Observation 3087fba8-ba75-4b63-a545-65577d239804 · outbound

This paper cites Invisible threats from model context protocol: Generating stealthy injection payload via tree-based adaptive search.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Invisible threats from model context protocol: Generating stealthy injection payload via tree-based adaptive search

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.362575Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:ba4cf2a638ee5a6b19290b501add6034f91bba121e00a378a50751e807033c21

Observation 9afcc3eb-cb16-4c68-b5b4-e35793513a7b · outbound

This paper cites Breaking the protocol: Security anal- ysis of the model context protocol specification and prompt in- jection vulnerabilities in tool-integrated llm agents.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Breaking the protocol: Security anal- ysis of the model context protocol specification and prompt in- jection vulnerabilities in tool-integrated llm agents

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.569716Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:e2ea5b7d7957782d6b39b19492f22ea0e23897394ec6069ec1430480b531bed7

Observation 1d808a55-40c1-449e-abeb-6fc8fe68b410 · outbound

This paper cites Impossiblebench: Measuring llms’ propensity of exploiting test cases.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Impossiblebench: Measuring llms’ propensity of exploiting test cases

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.555873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:a0007a3a6bad8e91a0cad361f1ce7dc4194d10251d666292cf7f0fe3b2bcb66f

Observation e884a4a1-0691-4954-89df-c374c085161c · outbound

This paper cites Vijayvargiya, A.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Vijayvargiya, A

Reference 15

Resolution
metadata mismatch
arxiv_id, observed 2026-05-19T23:27:52.582830Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:9df2300e8e91f7966b7a3e8c2b088b6e4ed73378da9c30d85adbb782ddc8ad2b

Observation dc2c3041-f898-4663-ab5f-ecbda63971a1 · outbound

This paper cites Redteamcua: Realistic adversarial testing of computer-use agents in hybrid web-os environments.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Redteamcua: Realistic adversarial testing of computer-use agents in hybrid web-os environments

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.509330Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:5f663bc65554fed5bb0c3113bf46a5d767d5d7e3475f08b8cf35f7c8b4d5d458

Observation 8bc899a1-8672-45ab-ac97-643fb7e14acd · outbound

This paper cites Mcp-safetybench: A benchmark for safety evaluation of large language models with real-world mcp servers.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mcp-safetybench: A benchmark for safety evaluation of large language models with real-world mcp servers

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.618593Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:e4b75bcbaec0e315fab1b1e270511a4f6ec168f66148ec3a7f9a381a26ec884c

Observation b34d59e1-633c-4807-8385-346f4f346af6 · outbound

This paper cites Mcpmark: A benchmark for stress-testing realistic and comprehensive mcp use.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mcpmark: A benchmark for stress-testing realistic and comprehensive mcp use

Reference 18

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.295788Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:29537bf00963fd7b842a63eba66d12a7c0952837acd396d3251c16299daed0f1

Observation c4da4341-e137-46bd-8579-f7bbfd3e9cc5 · outbound

This paper cites Redcodeagent: Automatic red-teaming agent against diverse code agents.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Redcodeagent: Automatic red-teaming agent against diverse code agents

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.279574Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:8bf97383c8761a42ad2a2abe54f30da98a5cc1f3146a462853f5bcee7ce3bc4b

Observation d0e23d28-498d-4a9e-89f2-8930fe8996a0 · outbound

This paper cites Bluecodeagent: A blue teaming agent enabled by automated red teaming for codegen ai.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Bluecodeagent: A blue teaming agent enabled by automated red teaming for codegen ai

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.589339Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:525c80e4484f58a51916ba403189a1d3a85ace931d9c1f270d468ec8aa65e534

Observation bbf9b19c-2b5a-4519-a5ce-d8e515cfb8e0 · outbound

This paper cites AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.374731Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:7e119d8af7673164b1804778dd7abfa7847d969d7ef180ec044482fe3c95eba5

Observation d12efa7c-1108-42fb-9a5f-7ed9959d32e8 · outbound

This paper cites Mistral 7B.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mistral 7B

Reference 22

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.562355Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:e60fafe09f484cbbdd7d9920ef162fa0101a02465a78904bb22255d1a3c1d72f

Observation baddb7e9-fe46-472c-bb43-f1efd6668c3c · outbound

This paper cites Qwen3 Technical Report.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Qwen3 Technical Report

Reference 23

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.307058Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:ba6789f849c60c7944774d02cc5bc078305dc86c1889438eb1c289ccc62aa4d7

Observation 4597fe2c-74ce-4086-8ab5-1d9430571721 · outbound

This paper cites Qwen2 Technical Report.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Qwen2 Technical Report

Reference 24

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.485115Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:67682636e9cca257d4774e276f2e904f2a1962c9419964ac8e34a07de74e9e82

Observation e120a031-aa69-4e49-823c-63edaabde9fe · outbound

This paper cites 2 OLMo 2 Furious.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback 2 OLMo 2 Furious

Reference 25

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.473349Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:33f32953f1130a1a1cca2b7dfed7705ea4fc5c0e81188a4c559f03763393724c

Observation 113fdabe-15fa-402d-b958-56fe8c8ae020 · outbound

This paper cites The Llama 3 Herd of Models.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback The Llama 3 Herd of Models

Reference 26

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.315839Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:6b41dcb81b037219a090863447210ecf1c1cb57eb115f1279cbffa310d9b7da1

Observation ab64cf79-a2b9-4294-b1c7-94c2086bfbec · outbound

This paper cites Cwm: An open-weights llm for research on code generation with world models.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Cwm: An open-weights llm for research on code generation with world models

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.422287Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:b82bbc2445b626d16e58c37f0b839d4688689a1af9059aee18c30bbd1f14566a

Observation 8ac61058-bdd4-46c4-8c69-0cf78a278a75 · outbound

This paper cites Evaluating Privilege Usage of Agents with Real-World Tools.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Evaluating Privilege Usage of Agents with Real-World Tools

Reference 28

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.450166Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:a39e4df7ebc566fc956e0623316f904e9bf04c9480f3cc8c16420b75b508af9a

Observation ab467022-1356-45bb-a775-279454e2d493 · outbound

This paper cites Mcpshield: A security cognition layer for adaptive trust calibration in model context protocol agents.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Mcpshield: A security cognition layer for adaptive trust calibration in model context protocol agents

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.411639Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:ccedbb3958b0db276baed216c7ea75e21abaa5aef0b0bbb8fe53f783534ca993

Observation 485a45cd-f748-422b-ad6a-993cf9f4f59f · outbound

This paper cites The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.244909Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:343041959bfa32c983e729c37ce6a58f1adfc534342385bc6766ab8bbbd18d27

Observation 47acb930-00d5-4610-b6f8-40b5bd42ced8 · outbound

This paper cites Defeating Prompt Injections by Design.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Defeating Prompt Injections by Design

Reference 31

Resolution
verified exact
local_arxiv, observed 2026-05-19T23:27:52.462500Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:1b1ba66c8e46ded698d8e7c36a67f9c2a9d936d9b0ea34cdd44ff72e2cbbbad7

Observation 2db7019a-4e71-4607-87ba-bd12422f5275 · outbound

This paper cites Toolsafe: Enhancing tool invocation safety of llm-based agents via proactive step-level guardrail and feedback.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Toolsafe: Enhancing tool invocation safety of llm-based agents via proactive step-level guardrail and feedback

Reference 32

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.438570Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:8471b244c1d17970594b54ad19d774c287fcfa2c7c3d388b6315fe5d8dcc3f9c

Observation 2605665c-f537-4653-8067-666bff20e950 · outbound

This paper cites Unsafer in Many Turns: Benchmarking and Defending Multi-Turn Safety Risks in Tool-Using Agents.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unsafer in Many Turns: Benchmarking and Defending Multi-Turn Safety Risks in Tool-Using Agents

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-06-12T02:08:25.633841Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:234f62276dd0df90f6fb831f756b2de0e4313f86225288bf56705f8d51fbd2f3

Observation c750350c-d39e-4407-b490-a5cb9c00f92b · outbound

This paper cites Agentsentry: Mitigating indirect prompt injection in llm agents via temporal causal diagnostics and context purification.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Agentsentry: Mitigating indirect prompt injection in llm agents via temporal causal diagnostics and context purification

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.290598Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:2dc3d2ac221fb584391e03f7a5248e8560f661494cf262ffef0052bdce596903

Observation 4f2b9ce9-fa27-4d44-a7ac-6625eb5e5805 · outbound

This paper cites Commandsans: Securing ai agents with surgical precision prompt sanitization.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Commandsans: Securing ai agents with surgical precision prompt sanitization

Reference 35

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.348681Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:76070f07802d311aa1b550baf6fef3362505e858fcec38f2550903f4a90a6a69

Observation 49b01948-34e7-4e35-aa04-69b3806416b6 · outbound

This paper cites AgentWatcher: A Rule-based Prompt Injection Monitor.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback AgentWatcher: A Rule-based Prompt Injection Monitor

Reference 36

Resolution
verified exact
arxiv_id, observed 2026-07-28T02:22:29.738998Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:f3f68f587853d91a6ea38cba132c43f40e412d3515b91d3b795ac6e26c14e211

Observation b47adc32-c21f-42ba-974b-b6c0116eaa03 · outbound

This paper cites Agentsys: Secure and dynamic llm agents through explicit hierarchical memory management.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Agentsys: Secure and dynamic llm agents through explicit hierarchical memory management

Reference 37

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.300973Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:e01753ad67d2858e87860cc98ce83432aadb0cf3b5ed9d7f215ca4e1cb6a325f

Observation 6a8e7267-cf47-44be-b914-0f8d010ee7d7 · outbound

This paper cites BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents

Reference 38

Resolution
verified exact
arxiv_id, observed 2026-08-13T01:24:45.972029Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:587633a7a4fc05070ef3ee69a57bce8f57ede86db6819cc7d69ebe63da0dfa2e

Observation 395601be-1313-4331-a841-dddd7408b4f5 · outbound

This paper cites Learning When to Act or Refuse: Guarding Agentic Reasoning Models for Safe Multi-Step Tool Use.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Learning When to Act or Refuse: Guarding Agentic Reasoning Models for Safe Multi-Step Tool Use

Reference 39

Resolution
verified exact
arxiv_id, observed 2026-06-04T02:07:11.549850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:ebf6834ea9772bd3835aef370f99c5fce015a2f7e0f5248d15a8680986036e16

Observation e99f00df-581c-48a3-ad27-c9efc5fd36cf · outbound

This paper cites Edward Suh.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Edward Suh

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.284887Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:484403f41725d1f4fe9759c9b62fee23c137d8f8c29e088d70a01bd5219cf58d

Observation 3ca4c3cd-6b4d-45fd-94ef-b44b234b9aba · outbound

This paper cites SoK: The Attack Surface of Agentic AI - Tools and Autonomy.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:b0758bf384d010bcc6d3c6564971df692bae522019680658a47d0e30d6e25a6a

Observation 9138402e-3948-4430-ae39-5ed1ba241556 · outbound

This paper cites Reason- ing with language model is planning with world model.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Reason- ing with language model is planning with world model

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.239852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:4ed30615d7fe2892894ff6aaa32ebf338e3b65702ad318a28cf1eb691f0bd2de

Observation 9eaed837-5b33-4ae1-8118-a0190b221603 · outbound

This paper cites an unresolved cited work.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work

Reference 43

Resolution
unresolved
raw_fallback, observed 2026-05-19T23:27:53.255357Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:8214427e64f08c98908601f75a352470f5231db1d050012358ba25e9197f3101

Observation 172cedb8-1493-4c07-8a6b-a566e4530e00 · outbound

This paper cites Generating code world models with large language models guided by monte carlo tree search.Advances in Neural Information Processing Systems, 37:60429–60474.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Generating code world models with large language models guided by monte carlo tree search.Advances in Neural Information Processing Systems, 37:60429–60474

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.264280Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:f159a310014ca337b4f8797659ffe39e9d6d8461bbb79fdc4764d45378084366

Observation a9d17490-85cc-405b-90f8-5ee468dc51da · outbound

This paper cites an unresolved cited work.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work

Reference 45

Resolution
unresolved
raw_fallback, observed 2026-05-19T23:27:53.230454Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:bb0fdcaf0ec7ca6d7fff1d40d0633a0061f5870662fe9f57cc7feee7998448d7

Observation cf620e62-8db7-44e6-84bc-7899961a0847 · outbound

This paper cites an unresolved cited work.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work

Reference 46

Resolution
unresolved
raw_fallback, observed 2026-05-19T23:27:53.222440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:8001c46713495d980d194bb156668f52fb85a5fdf205798e60f9fca2eb1a8e06

Observation cf33150b-eabe-4ae3-9bf6-0b4104266d9d · outbound

This paper cites an unresolved cited work.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work

Reference 47

Resolution
unresolved
raw_fallback, observed 2026-05-19T23:27:53.213645Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:0557beb25d9cdef9b2e5b733a2b2e8572f2b496cfbe50178853e5305ffb7c031

Observation 655e397f-3065-4b06-9f66-7f5b34b3c842 · outbound

This paper cites Candidate episodes produced by this process are retained only after a two-person audit.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Candidate episodes produced by this process are retained only after a two-person audit

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-05-19T23:27:53.218048Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:578f645d5806fd9e3dd3a212d481884b203e63fda361fe5f0c411ef0ee4bb87e

Observation 520986dc-8774-4187-bd44-2564d5667bda · outbound

This paper cites an unresolved cited work.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback Unresolved cited work

Reference 49

Resolution
unresolved
raw_fallback, observed 2026-05-19T23:27:53.207495Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:b4996efadfa682d9b0066bf717a86a600ac37cc72f2864a1bfb82b78fc35282b

Observation 0e819038-85c6-4445-b77e-500192575604 · outbound

This paper cites trajectory_digest.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback trajectory_digest

Reference 50

Resolution
malformed identifier
raw_fallback, observed 2026-05-19T23:27:53.226462Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:7c14760b80f3ab6bab2adc44be8e80c6e2faab29a708753f389559fe0a5f167e

Pith citing papers

No inbound Pith citation observations are available.