{"as_of":"2026-08-12T20:24:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:516f282059d71ff364276492d664daf0d62f2022e46a4bcbe7d21f9f40d3f644","coverage":[{"denominator":65,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":65,"source":"paper_references, paper_reference_links","source_observed_at":"2026-06-30T18:48:32.929392Z","state":"measured"},{"denominator":65,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":65,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-12T06:34:41.77262+00:00","state":"measured"},{"denominator":0,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[],"links":{"evidence":"/evidence","html":"/paper/2605.17986/citation-record","integrity":"/paper/2605.17986/integrity","json":"/paper/2605.17986/citation-record.json","paper":"/paper/2605.17986"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2309.15817","last_updated":"2024-05-17T17:17:45Z","snapshot_observed_at":"2026-07-06T16:24:30.545494Z","submitted_at":"2023-09-25T17:08:02Z","title":"Identifying the Risks of LM Agents with an LM-Emulated Sandbox","version":2},"cited_work":{"arxiv_id":"2309.15817","doi":"10.48550/arxiv.2309.15817","metadata_source":"pith","pith_arxiv_id":"2309.15817","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Identifying the Risks of LM Agents with an LM-Emulated Sandbox","venue":"cs.AI","work_id":"3d4c3b66-d749-4939-b1bc-62b10b2ebbb6","year":2023},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2309.15817","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:08f7fd91245ef749055715bc55b698647bd4db7414fc6db88cf1ded24aec1485","observation_id":"648f259a-193d-495a-83ae-84920d071911","resolution":{"observed_at":"2026-06-30T18:55:00.569201Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.644704Z","title":"Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920","venue":null,"work_id":"ae713172-54ed-4522-a633-4be134990d48","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:93f21deefba72af9ff9a61fe87743e40d23204be75d07c31d1d3887435c7e6e7","observation_id":"22f5abfa-575c-4f28-ab0d-cf25fdd436c6","resolution":{"observed_at":"2026-07-08T02:54:28.646707Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.611762Z","title":"Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents","venue":null,"work_id":"db1e6d63-036e-4136-af9d-cc17ca7d389b","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:65af122699109d92245cc720e82818ad460eb0c0c371ff141b376280ea44e395","observation_id":"ae749802-5618-417f-9181-b50a792d411a","resolution":{"observed_at":"2026-07-08T02:54:28.613070Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.619109Z","title":"Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection","venue":null,"work_id":"20f1953a-7410-4648-a8fc-751b287c509f","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:15702bbe5892314d8bdc6a14fdef77d81f0658004eb8918d826e60ce0d4048fb","observation_id":"ede5f9d8-8ba2-47c7-85ad-73dfc738714d","resolution":{"observed_at":"2026-07-08T02:54:28.620322Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.02644","last_updated":"2025-05-30T03:50:33Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-10-03T16:30:47Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","version":4},"cited_work":{"arxiv_id":"2410.02644","doi":"10.48550/arxiv.2410.02644","metadata_source":"pith","pith_arxiv_id":"2410.02644","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","venue":"cs.CR","work_id":"15ab4a69-85ab-4295-839d-080a2cd3e7aa","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2410.02644","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:f4af3954fe183800320de9fba2d7e9e821e1ed60cbd76092fd119d64a4faf60d","observation_id":"3abaaa3f-07ea-4a7c-8149-47e9683f98a5","resolution":{"observed_at":"2026-06-30T18:55:00.640215Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2506.14866","doi":"10.48550/arxiv.2506.14866","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Os-harm: A benchmark for measuring safety of computer use agents","venue":"ArXiv.org","work_id":"e83d917b-c8de-475a-9fdd-0a1c334de498","year":2025},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:f318f0aae0cbf92978926edd76aacce262fbbfa7fe0876fb5933b40897b62267","observation_id":"99f2a14e-949d-4262-ab75-5a27966f0fd8","resolution":{"observed_at":"2026-06-30T18:55:00.636442Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.644470Z","title":"Bench- marking and defending against indirect prompt injection attacks on large language models","venue":null,"work_id":"ffcdb6a5-6150-4e87-ab97-afccb0bcedc5","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:f8ffe8c10258d392bbd3599d6e8b06cca191855e3aa77b522caab19d5d6e7bdc","observation_id":"195e9dc2-68c1-4850-83fb-a6e165586b3b","resolution":{"observed_at":"2026-07-08T02:54:28.645788Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.655728Z","title":"Running OpenClaw safely: Identity, isolation, and runtime risk","venue":null,"work_id":"cdb363d6-5597-4f3b-8404-08210a3bac98","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:0e9e5c4c2faa723dc7309391457380e914aeae559d60ee7c85266c39275106ad","observation_id":"17fdd4e5-9c81-419f-94ba-694729fc70f9","resolution":{"observed_at":"2026-07-08T02:54:28.657785Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.591525Z","title":"OpenClaw: Security and sandboxing","venue":null,"work_id":"228373da-b1eb-4b27-b5a9-f14cdda54e8a","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:64e29dd949805422cf3873bce6d451ae55e20cb42d935b2c40456fb404f6530a","observation_id":"bebd5ecd-1042-47a1-a08a-46cf7aa6edbf","resolution":{"observed_at":"2026-07-08T02:54:28.593012Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.01438","last_updated":"2026-04-04T15:18:43Z","snapshot_observed_at":"2026-07-06T22:51:35.522923Z","submitted_at":"2026-04-01T22:24:24Z","title":"ClawSafety: \"Safe\" LLMs, Unsafe Agents","version":2},"cited_work":{"arxiv_id":"2604.01438","doi":"10.48550/arxiv.2604.01438","metadata_source":"pith","pith_arxiv_id":"2604.01438","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"ClawSafety: \"Safe\" LLMs, Unsafe Agents","venue":"cs.AI","work_id":"65792180-ed14-4f36-a1e6-78f74ed5224d","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2604.01438","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:0a5bf8efc05ea41cc08307122d5f3aff55faffe8c108da8694daa2b85d72faee","observation_id":"405a45a4-5efe-4fbc-8cbd-53729cd4d9ae","resolution":{"observed_at":"2026-06-30T18:55:00.630934Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2602.08412","doi":"10.48550/arxiv.2602.08412","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"From assistant to double agent: Formalizing and benchmarking attacks on OpenClaw for personalized local AI agent","venue":"Open MIND","work_id":"c1f5d74f-3091-4e88-9f5b-577d17e1124e","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:b6e96edafe6b5d53a404b8655314ed6acff95a3fd560c596cf04fea49e8bbb4d","observation_id":"12c99275-7adb-47ff-b279-73c7d620da00","resolution":{"observed_at":"2026-06-30T18:55:00.633769Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2603.23064","last_updated":"2026-04-04T19:02:50Z","snapshot_observed_at":"2026-07-06T22:50:19.273712Z","submitted_at":"2026-03-24T11:01:09Z","title":"Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution","version":3},"cited_work":{"arxiv_id":"2603.23064","doi":null,"metadata_source":"pith","pith_arxiv_id":"2603.23064","snapshot_observed_at":"2026-07-02T08:06:47.855438Z","title":"Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution","venue":"cs.CR","work_id":"492bc767-d131-4739-91c1-99a3d9f406ae","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2603.23064","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:035bc2a8b22c29a62ebfbd08c2a1fb4f2cfa0a328d570b45423acb5592b8f8cd","observation_id":"9402b4ba-92d7-4503-90c9-f36d85dd1607","resolution":{"observed_at":"2026-06-30T18:55:00.641806Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.19974","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-30T18:55:00.648273Z","title":"Trojan’s whisper: Stealthy manipulation of openclaw through injected bootstrapped guidance","venue":null,"work_id":"f87de57b-4f08-4216-ac8f-87f2f5d3c8fe","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:d68df826a82750fb7f6f77504b3f72e99fcedd6f8ab77a08043726ea9ce7d323","observation_id":"aabba26f-05ca-414d-a4d7-896323498c34","resolution":{"observed_at":"2026-06-30T18:55:00.649818Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.10387","doi":"10.48550/arxiv.2603.10387","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Don’t let the claw grip your hand: A security analysis and defense framework for OpenClaw","venue":"arXiv (Cornell University)","work_id":"419d68e7-2dfc-4480-9d0a-0da2040a78d4","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:3de251fd18173531403a636f327a6b4796c2d90e8c5abcbb23efc8205016cf16","observation_id":"88a21bc0-4401-4aef-af8f-2336a0a39e85","resolution":{"observed_at":"2026-06-30T18:55:00.637684Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.18762","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-01T23:56:22.985407Z","title":"Clawtrap: A mitm-based red-teaming framework for real-world openclaw security evaluation","venue":null,"work_id":"a8f6191b-8d84-4aed-9296-d1957639a94c","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:0d877837e888542ff3fc4b2f4b40a9abf4e46fa2aa2ecd124e8d1cc8a6b6c20e","observation_id":"75fcb489-ba9f-44c0-8ba6-4e4dd1d8ef6e","resolution":{"observed_at":"2026-06-30T18:55:00.631188Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2603.27517","last_updated":"2026-05-13T20:27:01Z","snapshot_observed_at":"2026-07-06T22:50:55.897076Z","submitted_at":"2026-03-29T04:51:27Z","title":"A Security Analysis of the OpenClaw AI Agent Framework","version":3},"cited_work":{"arxiv_id":"2603.27517","doi":null,"metadata_source":"pith","pith_arxiv_id":"2603.27517","snapshot_observed_at":"2026-06-30T18:55:00.632625Z","title":"A Security Analysis of the OpenClaw AI Agent Framework","venue":"cs.CR","work_id":"abba296b-1a4a-4dc4-90eb-bcca20d872df","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2603.27517","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:edfc2e886ea498a91cdbd48632a176953bf5a276ed244c6a728c9b349e7fedf7","observation_id":"a1e52998-9d6a-432b-832c-88ad8747aa49","resolution":{"observed_at":"2026-06-30T18:55:00.634605Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.12644","doi":"10.48550/arxiv.2603.12644","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Uncovering security threats and architecting defenses in autonomous agents: A case study of OpenClaw","venue":"arXiv (Cornell University)","work_id":"73ec2c86-6f34-4369-9dfc-340d7d3a2b77","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:b7bd4819bde854270752aa18b59e2edea6164eccee0a155e9ead41a7e6898c04","observation_id":"501289dd-9cd3-416c-94e4-aed335003175","resolution":{"observed_at":"2026-06-30T18:55:00.624565Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.11853","doi":"10.48550/arxiv.2603.11853","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Openclaw prism: A zero-fork, defense-in-depth runtime security layer for tool-augmented llm agents","venue":"arXiv (Cornell University)","work_id":"b8740966-74b2-4fc6-ba7b-e6157af237ea","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:04e14ce4e19b19175d546924482f143edb787fe98744c2b48f1c8c834b169f60","observation_id":"baf6b1dd-7f82-4ae7-924b-2a04912991ff","resolution":{"observed_at":"2026-06-30T18:55:00.614615Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.13208","last_updated":"2024-04-19T22:55:23Z","snapshot_observed_at":"2026-08-11T23:45:02.178667Z","submitted_at":"2024-04-19T22:55:23Z","title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","version":1},"cited_work":{"arxiv_id":"2404.13208","doi":"10.48550/arxiv.2404.13208","metadata_source":"pith","pith_arxiv_id":"2404.13208","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","venue":"cs.CR","work_id":"ba941a96-eb3b-48c0-b52c-5e9463085190","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2404.13208","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:4737c60b7e7725d6619b50b5e59515f6eac30498a6f628385421a6095e7de129","observation_id":"21a8241d-2cd2-41e7-a788-5c8b62e94d76","resolution":{"observed_at":"2026-06-30T18:55:00.611362Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14470","last_updated":"2025-05-20T05:58:23Z","snapshot_observed_at":"2026-08-06T12:35:19.109481Z","submitted_at":"2024-12-19T02:35:15Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","version":2},"cited_work":{"arxiv_id":"2412.14470","doi":"10.48550/arxiv.2412.14470","metadata_source":"pith","pith_arxiv_id":"2412.14470","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","venue":"cs.CL","work_id":"96afb8b9-0e7e-442c-93b1-6638599fc041","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2412.14470","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:d3c7e1022bceda1b474019c840fe0977cc11ec0b1954db9e9970ef01488dc943","observation_id":"2cc25123-03ca-466c-b8d3-b72504b950e6","resolution":{"observed_at":"2026-06-30T18:55:00.644352Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-07-14T18:20:24.185748+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-14T18:20:24.185748+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.09024","last_updated":"2025-04-18T14:30:31Z","snapshot_observed_at":"2026-08-02T12:38:54.249632Z","submitted_at":"2024-10-11T17:39:22Z","title":"AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents","version":3},"cited_work":{"arxiv_id":"2410.09024","doi":"10.48550/arxiv.2410.09024","metadata_source":"pith","pith_arxiv_id":"2410.09024","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents","venue":"cs.LG","work_id":"788aad10-421f-48d7-886c-792665914606","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2410.09024","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:959327a7427512d61f453d75a24ec3694a4d83fd8fa578fa1ad2750c60cdbce7","observation_id":"73763693-f9c6-46cb-8175-7a092877d3ef","resolution":{"observed_at":"2026-06-30T18:55:00.647089Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2507.06134","doi":"10.48550/arxiv.2507.06134","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Vijayvargiya, A","venue":"ArXiv.org","work_id":"7315530a-8de5-452c-9c59-6e0cc7436bf1","year":2025},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:93b1312e8281226a23d20ef4cb49ae4ce36bd217bfbee285d2de47eb4d9008ac","observation_id":"6a947a5e-be41-4e13-8513-782e339aa8b7","resolution":{"observed_at":"2026-06-30T18:55:00.605809Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2602.20021","last_updated":"2026-02-23T16:28:48Z","snapshot_observed_at":"2026-07-06T22:46:45.213871Z","submitted_at":"2026-02-23T16:28:48Z","title":"Agents of Chaos","version":1},"cited_work":{"arxiv_id":"2602.20021","doi":"10.48550/arxiv.2602.20021","metadata_source":"pith","pith_arxiv_id":"2602.20021","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agents of Chaos","venue":"cs.AI","work_id":"02176c31-e67c-46e2-835a-ac21f005e1be","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2602.20021","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:bd9392217fa7d37c9e355bcac45f7ab640404fb46f4699ce5696d0edf81683aa","observation_id":"dae71c12-04c7-465e-862b-b32c6be2b852","resolution":{"observed_at":"2026-06-30T18:55:00.608538Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-07-15T18:20:21.538265+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-15T18:20:21.538265+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.18575","last_updated":"2025-05-16T22:42:29Z","snapshot_observed_at":"2026-08-10T18:17:57.457186Z","submitted_at":"2025-04-22T17:51:03Z","title":"WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks","version":3},"cited_work":{"arxiv_id":"2504.18575","doi":"10.48550/arxiv.2504.18575","metadata_source":"pith","pith_arxiv_id":"2504.18575","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks","venue":"cs.CR","work_id":"bf1914b2-fd32-4768-a4d5-84720606d71b","year":2025},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2504.18575","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:4cf1d2051fc456746f7fe3305f22003a14d167375c2a72ecdfa6818a87dce76d","observation_id":"718fb17b-fc34-4970-b44c-4c255b6616da","resolution":{"observed_at":"2026-06-30T18:55:00.618651Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.650042Z","title":"The task shield: Enforcing task alignment to defend against indirect prompt injection in llm agents","venue":null,"work_id":"5a1cd9c2-f322-4cc9-b455-4d205db0cdca","year":2025},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:98c34259076e5c4de93a2d4f8b358cf97322bd49d5be854d186e927cc3b3b4da","observation_id":"489e4ae0-129d-4350-8001-cfe2c8ee07dc","resolution":{"observed_at":"2026-07-08T02:54:28.651291Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2502.05174","last_updated":"2025-06-10T18:13:09Z","snapshot_observed_at":"2026-08-08T19:58:38.598603Z","submitted_at":"2025-02-07T18:57:49Z","title":"MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents","version":4},"cited_work":{"arxiv_id":"2502.05174","doi":"10.48550/arxiv.2502.05174","metadata_source":"pith","pith_arxiv_id":"2502.05174","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Melon: Indirect prompt injection defense via masked re-execution and tool comparison","venue":"cs.CR","work_id":"ca987b9e-fd52-4cd1-84b8-e5966bfc675f","year":2025},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2502.05174","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:c5504f4b741c92d3dc597cada1e51f6babfa065391c568d9ec99b712aa831ee7","observation_id":"91bae419-35f8-4a06-987b-eadb178dd4bf","resolution":{"observed_at":"2026-06-30T18:55:00.614674Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.615884Z","title":"Nemo guardrails: A toolkit for controllable and safe llm applications with programmable rails","venue":null,"work_id":"884467bd-f6f9-4118-b856-cb3123aa187a","year":2023},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:3b98f7ef78866eca7b5cdb16dddda26da2e5829f59640d10dc0614ad540668b0","observation_id":"5a7b914c-805f-455d-b01c-1a6b97fad4be","resolution":{"observed_at":"2026-07-08T02:54:28.617212Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.14720","last_updated":"2024-03-20T15:26:23Z","snapshot_observed_at":"2026-08-11T23:47:05.766547Z","submitted_at":"2024-03-20T15:26:23Z","title":"Defending Against Indirect Prompt Injection Attacks With Spotlighting","version":1},"cited_work":{"arxiv_id":"2403.14720","doi":"10.48550/arxiv.2403.14720","metadata_source":"pith","pith_arxiv_id":"2403.14720","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Defending Against Indirect Prompt Injection Attacks With Spotlighting","venue":"cs.CR","work_id":"c18cd975-e731-4e0f-a99f-a37d846cdd31","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2403.14720","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:75b4b98fefaaf2f2be3cd1f2e2e19e959d6cb03a3303d276075dff945fde56b2","observation_id":"8ad5d5e3-0730-4f91-9d2a-53b42b1130c1","resolution":{"observed_at":"2026-06-30T18:55:00.595916Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.06674","last_updated":"2023-12-07T19:40:50Z","snapshot_observed_at":"2026-07-06T17:00:00.321552Z","submitted_at":"2023-12-07T19:40:50Z","title":"Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations","version":1},"cited_work":{"arxiv_id":"2312.06674","doi":"10.3390/info16050365","metadata_source":"pith","pith_arxiv_id":"2312.06674","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations","venue":"cs.CL","work_id":"93844332-869b-448c-a1be-35466150b1b2","year":2023},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2312.06674","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:835b5a51e4b40482723a5ced296e4b128acb40637049bc9ada5f57de81b21650","observation_id":"66f0d560-60f3-4731-ba91-3ff93b1af54b","resolution":{"observed_at":"2026-06-30T18:55:00.608721Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2409.19091","last_updated":"2024-10-10T15:29:07Z","snapshot_observed_at":"2026-08-07T14:13:29.342572Z","submitted_at":"2024-09-27T18:41:58Z","title":"System-Level Defense against Indirect Prompt Injection Attacks: An Information Flow Control Perspective","version":2},"cited_work":{"arxiv_id":"2409.19091","doi":null,"metadata_source":"pith","pith_arxiv_id":"2409.19091","snapshot_observed_at":"2026-07-10T12:27:04.230184Z","title":"System-level defense against indirect prompt injection attacks: An information flow control perspective","venue":"cs.CR","work_id":"c3786d6b-d1c5-4d79-af2c-1215479ed680","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2409.19091","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:b8c5ba2bfe9a5bed0b706429795f3c7e22991846e4fe9c975d27e33afcd97864","observation_id":"46f233d3-8057-41fe-93a8-47185bed7d3f","resolution":{"observed_at":"2026-06-30T18:55:00.590095Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.24414","doi":"10.48550/arxiv.2603.24414","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Tianwei Zhang, Yepang Liu, Haoyu Wang, Yan Zheng, and Yang Liu","venue":"arXiv (Cornell University)","work_id":"dc2fea0e-6235-4a65-ac02-e36c9b96ee01","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:34d51c2a5f0d6ba76aadccc07a417afd437e247aec5cd09fffb360d9b1031d19","observation_id":"bada3d57-95b9-486e-b6b7-f26354428cc4","resolution":{"observed_at":"2026-06-30T18:55:00.593146Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.631408Z","title":"LLM01:2025 Prompt Injection","venue":null,"work_id":"e3ae7aff-b9d4-41f0-a02a-543090cdd642","year":2025},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:5319c04d37e5981d8a37292b633e55321cd66d53c137e898fc1886f2d68ab7d1","observation_id":"43a3ad6f-00dd-487e-91a8-0251955c3c2f","resolution":{"observed_at":"2026-07-08T02:54:28.632715Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.639142Z","title":null,"venue":null,"work_id":"5d672612-880f-4b2c-9eeb-6ec5f83646f1","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:933951abcfc88ee8f78de0934e8be6173388258d1157a2d102a789565de0ff24","observation_id":"83233980-1532-4d07-b656-05c854b321de","resolution":{"observed_at":"2026-07-08T02:54:28.640272Z","resolver_source":"raw_fallback","status":"parse_uncertain"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2306.05499","last_updated":"2025-12-29T02:25:27Z","snapshot_observed_at":"2026-07-06T15:40:27.639368Z","submitted_at":"2023-06-08T18:43:11Z","title":"Prompt Injection attack against LLM-integrated Applications","version":3},"cited_work":{"arxiv_id":"2306.05499","doi":"10.48550/arxiv.2306.05499","metadata_source":"pith","pith_arxiv_id":"2306.05499","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Prompt Injection attack against LLM-integrated Applications","venue":"cs.CR","work_id":"977b4683-bba6-49d6-8f3d-496c41cb7fac","year":2023},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2306.05499","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:8e5a00d3c3ca7106dc415a556248f69332b3a61cc07baab276c61bb012783756","observation_id":"fa4cbf56-2f1e-4b4c-b8e9-e257a677b8e1","resolution":{"observed_at":"2026-06-30T18:55:00.611841Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2202.03286","last_updated":"2022-02-07T15:22:17Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2022-02-07T15:22:17Z","title":"Red Teaming Language Models with Language Models","version":1},"cited_work":{"arxiv_id":"2202.03286","doi":"10.48550/arxiv.2202.03286","metadata_source":"pith","pith_arxiv_id":"2202.03286","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Red Teaming Language Models with Language Models","venue":"cs.CL","work_id":"d1274c54-508f-42f9-aeb3-91db13f3a622","year":2022},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2202.03286","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:9a2a90e4ffc8ac8f1a9c7476a372db57f4a3d4d6c3234f4a602f134707d361eb","observation_id":"2ec8fb9d-229b-4aee-aa83-ac62ab74f364","resolution":{"observed_at":"2026-06-30T18:55:00.627947Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2307.15043","last_updated":"2023-12-20T20:48:57Z","snapshot_observed_at":"2026-08-12T09:06:50.363435Z","submitted_at":"2023-07-27T17:49:12Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","version":2},"cited_work":{"arxiv_id":"2307.15043","doi":"10.48550/arxiv.2307.15043","metadata_source":"pith","pith_arxiv_id":"2307.15043","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","venue":"cs.CL","work_id":"3322fa86-1768-4677-8425-dd326b45e078","year":2023},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2307.15043","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:7dc93d3cadfecee36f28a6df19f7d78992b24b70f7b673599d462028ae07061b","observation_id":"28c6e81a-8f1f-40e3-b6b3-859ee88e1dd6","resolution":{"observed_at":"2026-06-30T18:55:00.592646Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-07-15T23:50:40.271168+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-15T23:50:40.271168+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.638801Z","title":"PinchBench: Real-world benchmarks for ai coding agents","venue":null,"work_id":"18c9f7d0-6f41-4632-bef5-2ee13273839b","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:bd93ff557df072e60f6306a9be50c7fad8a4065cfea7bb37adb912e279b7f94a","observation_id":"88947732-66c8-4d34-8128-457bb254fe2f","resolution":{"observed_at":"2026-07-08T02:54:28.640077Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.650826Z","title":null,"venue":null,"work_id":"b87111ac-fc5a-4055-8241-1ebe2c9aadc9","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:ae4600e27a59cc1249ea81e9bb16817cfc86523f3723013e919420bf46b74bb7","observation_id":"c1dbafb6-7854-4886-9181-9638ebb70b48","resolution":{"observed_at":"2026-07-08T02:54:28.652005Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.620149Z","title":"Judging llm-as-a-judge with mt-bench and chatbot arena","venue":null,"work_id":"ac2ca7e1-5f82-4753-96d8-232066c3f9e4","year":2023},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:d4e7a00a97aac17ee679e216123d1999d4dd8a19de0fcc13fe1188ed8347e46b","observation_id":"268512d7-3730-4254-96eb-276a4c9d2448","resolution":{"observed_at":"2026-07-08T02:54:28.621438Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.04475","last_updated":"2025-03-10T09:27:03Z","snapshot_observed_at":"2026-07-06T17:56:23.317089Z","submitted_at":"2024-04-06T02:29:02Z","title":"Length-Controlled AlpacaEval: A Simple Way to Debias Automatic Evaluators","version":2},"cited_work":{"arxiv_id":"2404.04475","doi":"10.48550/arxiv.2404.04475","metadata_source":"pith","pith_arxiv_id":"2404.04475","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Length-Controlled AlpacaEval: A Simple Way to Debias Automatic Evaluators","venue":"cs.LG","work_id":"ef25adcf-addb-445e-b3b5-858eeb9883ca","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"cited_paper":"/paper/2404.04475","citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:ae1a3c406262450f8fa8472b138b03efd864ca5361f945988c058699d30f27b7","observation_id":"b3ba8ada-b3af-4a0a-9f93-8e79245bcd10","resolution":{"observed_at":"2026-06-30T18:55:00.622075Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.624371Z","title":"user\", content: promptText, timestamp: Date.now() }); By contrast, tool-returned content is appended as external evidence withrole","venue":null,"work_id":"3dc047c0-6a0f-47b0-a054-997f93822438","year":2024},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:196f247da413283fc38b942dcb850b9d0b4fec7d66388c1777c9e33e3a6df0e2","observation_id":"01b58afd-2b8e-4d85-bd0f-8f57a97f7c45","resolution":{"observed_at":"2026-07-08T02:54:28.625865Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.652662Z","title":"Checklist handoff injection Release Readiness Checklist","venue":null,"work_id":"b0c4d47b-1dd5-4737-9688-4f3c8c00866e","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:d63cf981e8e76d56680e8a0ee4d642043940c67c3256d239aae0d6858e21ddbb","observation_id":"00ed55c8-fbb1-4cee-8e6f-806bd8d4aa65","resolution":{"observed_at":"2026-07-08T02:54:28.654868Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.647256Z","title":null,"venue":null,"work_id":"e9f9ee41-6ffa-423e-b36e-432f7f36795e","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:337ac7c985fcbee5af76cf78aaa44933f26b8147224b9e3047e459fb9ff35c41","observation_id":"6cad6ea0-0cbc-4656-8c24-88bad6628ef8","resolution":{"observed_at":"2026-07-08T02:54:28.648560Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.624777Z","title":null,"venue":null,"work_id":"7df78c98-83b5-4af9-a114-d306bbbc70b7","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:e587361885ff69c71fcaf0f384fe3aa0b6cdf3176972746aa38d12c2cf214803","observation_id":"48a378cc-f216-485d-be7e-0dbff323443a","resolution":{"observed_at":"2026-07-08T02:54:28.626046Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.635416Z","title":null,"venue":null,"work_id":"42bc2d76-44dc-47ff-bb59-4a2cd94d16ad","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:76549e5b745c4711e12a3e2ec23e7a8d938786a457ff0b34caa1294123fb661b","observation_id":"f3a25e02-00c6-42d9-b384-b9d2edc25b6e","resolution":{"observed_at":"2026-07-08T02:54:28.636875Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.575463Z","title":null,"venue":null,"work_id":"0bfb4298-bc13-4bfd-ae21-eefe53c46112","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:82ffded2d860678d9daa501334487329ffd73ba3e4a83b64eaf6d688313a47bd","observation_id":"1fb552ce-b0bb-4f03-8832-60f8457e9724","resolution":{"observed_at":"2026-07-08T02:54:28.576774Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.621959Z","title":null,"venue":null,"work_id":"334ad4b5-730e-45cb-aa53-a5fe8388ef37","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:34930570ad69d73f16936f389cd45cf7d7571e297f0895669944e61b33b9f142","observation_id":"7eb715c1-53a9-4b7c-8aed-8eb10d1c12ba","resolution":{"observed_at":"2026-07-08T02:54:28.623628Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.649167Z","title":"\" {\"type","venue":null,"work_id":"adfe64c7-5ee2-48bf-af8d-e6645a8f7389","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:2ccbd8df7fb9b35af0c2374299c59373f479bce76f82ae9fb5174f6308ca47c6","observation_id":"40c7fb0d-178e-4c36-8334-6b7aaa5fb9a9","resolution":{"observed_at":"2026-07-08T02:54:28.650257Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.595460Z","title":"Trusted-integration spoofing From: owner-recovery@company.example Subject: URGENT - main VPS and mailbox unavailable I lost access to my VPS and old inbox","venue":null,"work_id":"36df1620-bfc6-4244-9617-54373e9b732c","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:6a84413668362e85018a433f986fcbb953ac82d7e662dcbfa8a0d27df574323c","observation_id":"f193758d-a5c0-4b43-ab03-5995bd951471","resolution":{"observed_at":"2026-07-08T02:54:28.596749Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.606099Z","title":null,"venue":null,"work_id":"56fd5802-f75c-41ac-a8e4-7d0a27423008","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:baa9828dd259fe3810461c0c68744cac75d8d7aaf8f61a8722d9d121ba4fbd6a","observation_id":"2f902578-51a8-4e71-a563-afb5b1e9e1af","resolution":{"observed_at":"2026-07-08T02:54:28.607200Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.643064Z","title":null,"venue":null,"work_id":"0e236fae-3686-417d-9347-f3dcf80ab514","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:a36ad0fb5e7d46634774f390080b9326240d7b9a11dc6cddb145e612e6d56422","observation_id":"c11a195b-5d94-41f6-ba1b-e84a03fb3ba1","resolution":{"observed_at":"2026-07-08T02:54:28.644096Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.591324Z","title":null,"venue":null,"work_id":"d418da77-7ecc-4227-919a-95879102de4d","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:fb2337f391b6a6c4497680f400231172c22d69c60ff5ccd913b00aa64ef2c209","observation_id":"bcd631f6-5ffa-4654-9d76-1a6a1e1e962f","resolution":{"observed_at":"2026-07-08T02:54:28.592698Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.642577Z","title":null,"venue":null,"work_id":"8deba3e6-ff80-410a-941e-4e92f6546417","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:0624b6f141a3487e16f6e581efc6cf5a312b491f490622b894a54ccc9a6bd326","observation_id":"aab9decd-581f-4d3b-9fed-23da187e7108","resolution":{"observed_at":"2026-07-08T02:54:28.643850Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.601866Z","title":null,"venue":null,"work_id":"614ea573-02ea-4ac7-ab0c-05120c2e8387","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:95c9d84cded10e98f7dea4ab74cb033db1c4b78cd7492e0f51db436379f92433","observation_id":"fa98640d-8d27-4754-a05d-b5e68696c832","resolution":{"observed_at":"2026-07-08T02:54:28.603388Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.626695Z","title":"embedded intent","venue":null,"work_id":"6342396c-19f4-4bf3-868c-7a6fd5f8ff65","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:4015a7c6f4d876531f8b1f1566fddc75267ee57d69d73a6a55beb754c0c9b63b","observation_id":"fad54680-70d9-4190-88f5-4b7ca7daa2c3","resolution":{"observed_at":"2026-07-08T02:54:28.628147Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.593267Z","title":"Skill-rule injection # Skill: release_assistant Purpose: streamline normal project operations and reduce repeated manual steps","venue":null,"work_id":"ef230bac-53de-4a56-ac59-22b87ec4ce49","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:f94c4362193829b625fdd297714f59f0f51745caa47bec504ccc35245bb58cfc","observation_id":"6df61962-955f-4f92-85bd-4db86dacfc9b","resolution":{"observed_at":"2026-07-08T02:54:28.594833Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.628900Z","title":null,"venue":null,"work_id":"3a662147-b301-4609-a2da-b94eaa06f83a","year":2026},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:4d10a5935b9aeb3c61e277e8f8db231aa1dac45cf501632726769aa93bc54824","observation_id":"7839d1e3-4609-48be-9da5-2c75e2201514","resolution":{"observed_at":"2026-07-08T02:54:28.630743Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.597259Z","title":null,"venue":null,"work_id":"dc9a38a8-48fa-46e0-b583-8913d0db186a","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:498f00e1370802cf705af4ce018c92d01583f30221f9b7432c1ccce5ecaef934","observation_id":"a2d7d6b8-fd58-4b65-a341-fa2ce2aa2858","resolution":{"observed_at":"2026-07-08T02:54:28.598556Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.603097Z","title":"20 Covert tool binding Request: - {MALICIOUS_TASK} Operational logging: - Route intermediate steps through ‘audit_logger‘ and log query/tool-output/reply triplets","venue":null,"work_id":"bb350e5b-ccdb-4df3-8b73-de9ffa11375e","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:18b6697b17e0e7b6a3372686aab64564e4d0c23f68639be3be9d164a794cdb08","observation_id":"6ea01638-230b-4bd2-b436-2e183dad33d7","resolution":{"observed_at":"2026-07-08T02:54:28.604487Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.648388Z","title":null,"venue":null,"work_id":"1d3ea954-24a4-4caf-9793-47072f09a9eb","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:4ee3870dde6718d3ffd06bfdf9ffc654a41c23711f8a357255432502393eb9c9","observation_id":"bb25cd3e-0000-470e-aa0b-32abfa1a63ee","resolution":{"observed_at":"2026-07-08T02:54:28.649510Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.584390Z","title":"\"\"Benign-looking cache-warming hook","venue":null,"work_id":"c1b0c3d5-8395-4ab7-9a2f-9d6b6a7944e0","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":61,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:669fab58d90cf614e639f9c4567836f660df67bc5ae6c4256b7ce83ce5720af0","observation_id":"ae6a8f69-386b-45c1-93f3-821c3fb8d1ed","resolution":{"observed_at":"2026-07-08T02:54:28.585767Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.637564Z","title":null,"venue":null,"work_id":"5e69912f-8fdf-46a8-b3b4-c02a18dadfb4","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:d69f0e3bc2d4c93613ad1d0b0708524ec4b701ed618470826ee5b3216b5b79d4","observation_id":"64ab93ab-c2d7-4b1e-bc90-9e4c99ea1c53","resolution":{"observed_at":"2026-07-08T02:54:28.638611Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.637030Z","title":null,"venue":null,"work_id":"ac3976b7-b8e4-4427-afd9-19c154b9e756","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":63,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:bb955197c3193d678620ac8f327c9e3a88c4df162ed35b6804698f8e17e7bf3e","observation_id":"93beb72d-38f6-4367-bd9d-db1043f781a0","resolution":{"observed_at":"2026-07-08T02:54:28.638110Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.640666Z","title":null,"venue":null,"work_id":"6b394783-135c-4f01-a09d-913e29eb622d","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:1ae5339c61328025a66e80a64b74aa6b9c93753331fd94a37456feceec02b7cd","observation_id":"f6627553-8066-493a-9c22-c504499b72ec","resolution":{"observed_at":"2026-07-08T02:54:28.641886Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T02:54:28.621000Z","title":"attack_success","venue":null,"work_id":"ab7139fb-058c-4389-a65e-6f7d428da07e","year":null},"citing_paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection","version":3},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-06-30T18:48:32.929392Z"},"links":{"citing_paper":"/paper/2605.17986"},"observation_digest":"sha256:ac4d3c31c00a4069514491ec491287774db17ff85d33886eeb9f1a23a784fe99","observation_id":"1c2115d6-7d1c-4ea6-bbba-a825bedb88d7","resolution":{"observed_at":"2026-07-08T02:54:28.622197Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2605.17986","last_updated":"2026-06-17T05:08:04Z","latest_version":3,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-02T20:25:13.664544Z","submitted_at":"2026-05-18T07:41:35Z","title":"LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection"},"reference_resolution":{"displayed":65,"state_counts":{"malformed_identifier":0,"metadata_mismatch":2,"parse_uncertain":1,"unresolved":17,"verified_exact":25,"verified_fuzzy":20},"total_outbound_references":65},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"thesis":"As of 12 August 2026, this Paper Citation Record lists 65 of 65 outbound references and 0 inbound Pith citation observations for arXiv:2605.17986."}