Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-30T18:48:32.929392Z
Paper Citation Record · LEDGER
As of 12 August 2026, this Paper Citation Record lists 65 of 65 outbound references and 0 inbound Pith citation observations for arXiv:2605.17986.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-30T18:48:32.929392Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-12T06:34:41.77262+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
65 of 65 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 648f259a-193d-495a-83ae-84920d071911 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Identifying the Risks of LM Agents with an LM-Emulated Sandbox
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 22f5abfa-575c-4f28-ab0d-cf25fdd436c6 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation ae749802-5618-417f-9181-b50a792d411a · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation ede5f9d8-8ba2-47c7-85ad-73dfc738714d · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 3abaaa3f-07ea-4a7c-8149-47e9683f98a5 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 99f2a14e-949d-4262-ab75-5a27966f0fd8 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Os-harm: A benchmark for measuring safety of computer use agents
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 195e9dc2-68c1-4850-83fb-a6e165586b3b · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Bench- marking and defending against indirect prompt injection attacks on large language models
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 17fdd4e5-9c81-419f-94ba-694729fc70f9 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Running OpenClaw safely: Identity, isolation, and runtime risk
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation bebd5ecd-1042-47a1-a08a-46cf7aa6edbf · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection OpenClaw: Security and sandboxing
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 405a45a4-5efe-4fbc-8cbd-53729cd4d9ae · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection ClawSafety: "Safe" LLMs, Unsafe Agents
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 12c99275-7adb-47ff-b279-73c7d620da00 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection From assistant to double agent: Formalizing and benchmarking attacks on OpenClaw for personalized local AI agent
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 9402b4ba-92d7-4503-90c9-f36d85dd1607 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation aabba26f-05ca-414d-a4d7-896323498c34 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Trojan’s whisper: Stealthy manipulation of openclaw through injected bootstrapped guidance
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 88a21bc0-4401-4aef-af8f-2336a0a39e85 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Don’t let the claw grip your hand: A security analysis and defense framework for OpenClaw
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 75fcb489-ba9f-44c0-8ba6-4e4dd1d8ef6e · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Clawtrap: A mitm-based red-teaming framework for real-world openclaw security evaluation
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation a1e52998-9d6a-432b-832c-88ad8747aa49 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection A Security Analysis of the OpenClaw AI Agent Framework
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 501289dd-9cd3-416c-94e4-aed335003175 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Uncovering security threats and architecting defenses in autonomous agents: A case study of OpenClaw
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation baf6b1dd-7f82-4ae7-924b-2a04912991ff · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Openclaw prism: A zero-fork, defense-in-depth runtime security layer for tool-augmented llm agents
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 21a8241d-2cd2-41e7-a788-5c8b62e94d76 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 2cc25123-03ca-466c-b8d3-b72504b950e6 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Agent-SafetyBench: Evaluating the Safety of LLM Agents
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 73763693-f9c6-46cb-8175-7a092877d3ef · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 6a947a5e-be41-4e13-8513-782e339aa8b7 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Vijayvargiya, A
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation dae71c12-04c7-465e-862b-b32c6be2b852 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Agents of Chaos
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 718fb17b-fc34-4970-b44c-4c255b6616da · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 489e4ae0-129d-4350-8001-cfe2c8ee07dc · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 91bae419-35f8-4a06-987b-eadb178dd4bf · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 5a7b914c-805f-455d-b01c-1a6b97fad4be · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Nemo guardrails: A toolkit for controllable and safe llm applications with programmable rails
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 8ad5d5e3-0730-4f91-9d2a-53b42b1130c1 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 66f0d560-60f3-4731-ba91-3ff93b1af54b · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 46f233d3-8057-41fe-93a8-47185bed7d3f · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation bada3d57-95b9-486e-b6b7-f26354428cc4 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Tianwei Zhang, Yepang Liu, Haoyu Wang, Yan Zheng, and Yang Liu
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 43a3ad6f-00dd-487e-91a8-0251955c3c2f · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection LLM01:2025 Prompt Injection
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 83233980-1532-4d07-b656-05c854b321de · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation fa4cbf56-2f1e-4b4c-b8e9-e257a677b8e1 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Prompt Injection attack against LLM-integrated Applications
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 2ec8fb9d-229b-4aee-aa83-ac62ab74f364 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Red Teaming Language Models with Language Models
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 28c6e81a-8f1f-40e3-b6b3-859ee88e1dd6 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Universal and Transferable Adversarial Attacks on Aligned Language Models
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 88947732-66c8-4d34-8128-457bb254fe2f · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection PinchBench: Real-world benchmarks for ai coding agents
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation c1dbafb6-7854-4886-9181-9638ebb70b48 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 268512d7-3730-4254-96eb-276a4c9d2448 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Judging llm-as-a-judge with mt-bench and chatbot arena
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation b3ba8ada-b3af-4a0a-9f93-8e79245bcd10 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Length-Controlled AlpacaEval: A Simple Way to Debias Automatic Evaluators
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 01b58afd-2b8e-4d85-bd0f-8f57a97f7c45 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection user", content: promptText, timestamp: Date.now() }); By contrast, tool-returned content is appended as external evidence withrole
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 00ed55c8-fbb1-4cee-8e6f-806bd8d4aa65 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Checklist handoff injection Release Readiness Checklist
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 6cad6ea0-0cbc-4656-8c24-88bad6628ef8 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 48a378cc-f216-485d-be7e-0dbff323443a · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation f3a25e02-00c6-42d9-b384-b9d2edc25b6e · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 1fb552ce-b0bb-4f03-8832-60f8457e9724 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 7eb715c1-53a9-4b7c-8aed-8eb10d1c12ba · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 40c7fb0d-178e-4c36-8334-6b7aaa5fb9a9 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection " {"type
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation f193758d-a5c0-4b43-ab03-5995bd951471 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Trusted-integration spoofing From: owner-recovery@company.example Subject: URGENT - main VPS and mailbox unavailable I lost access to my VPS and old inbox
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 2f902578-51a8-4e71-a563-afb5b1e9e1af · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation c11a195b-5d94-41f6-ba1b-e84a03fb3ba1 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation bcd631f6-5ffa-4654-9d76-1a6a1e1e962f · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation aab9decd-581f-4d3b-9fed-23da187e7108 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation fa98640d-8d27-4754-a05d-b5e68696c832 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation fad54680-70d9-4190-88f5-4b7ca7daa2c3 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection embedded intent
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 6df61962-955f-4f92-85bd-4db86dacfc9b · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Skill-rule injection # Skill: release_assistant Purpose: streamline normal project operations and reduce repeated manual steps
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 7839d1e3-4609-48be-9da5-2c75e2201514 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation a2d7d6b8-fd58-4b65-a341-fa2ce2aa2858 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 58
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 6ea01638-230b-4bd2-b436-2e183dad33d7 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection 20 Covert tool binding Request: - {MALICIOUS_TASK} Operational logging: - Route intermediate steps through ‘audit_logger‘ and log query/tool-output/reply triplets
Reference 59
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation bb25cd3e-0000-470e-aa0b-32abfa1a63ee · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 60
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation ae6a8f69-386b-45c1-93f3-821c3fb8d1ed · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection ""Benign-looking cache-warming hook
Reference 61
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 64ab93ab-c2d7-4b1e-bc90-9e4c99ea1c53 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 62
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 93beb72d-38f6-4367-bd9d-db1043f781a0 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 63
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation f6627553-8066-493a-9c22-c504499b72ec · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection Unresolved cited work
Reference 64
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
Observation 1c2115d6-7d1c-4ea6-bbba-a825bedb88d7 · outbound
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection attack_success
Reference 65
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.
No inbound Pith citation observations are available.