Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-28T00:25:05.443939Z
Paper Citation Record · LEDGER
As of 6 August 2026, this Paper Citation Record lists 35 of 35 outbound references and 0 inbound Pith citation observations for arXiv:2606.06387.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-28T00:25:05.443939Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-06T06:34:29.942622+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
35 of 35 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation b2e09993-db76-4223-8827-4ddf2de6ddc9 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents NDSS , year=
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e5fbc4d2-4d0b-4bf6-8f80-e8c17a4b36f4 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Zenodo , year=
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3f2171c8-3f2b-4fe3-be33-56f50c7c999a · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents arXiv preprint arXiv:2509.20386 , year=
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 3f9dfbd1-4026-4287-b744-7d1aa49b4dd6 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents 34th USENIX Security Symposium (USENIX Security 25) , pages=
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3e301ccb-e2f7-4960-8e19-a723d65b1155 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Advances in Neural Information Processing Systems , volume=
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 323c740e-855a-4ac4-b932-e192a60d8daa · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Automatic Red Teaming LLM-based Agents with Model Context Protocol Tools , year=
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f60cedea-3fb7-4e67-b9c5-4c1d5e8322a6 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents NDSS , year=
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7d9623dd-b04d-422a-a518-9875e8ac4513 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing , pages=
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9433589d-780a-4303-b60c-16eb6cf714e3 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents IJCAI , year=
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e70cd65c-8595-4934-bed5-264193e8780b · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents ACM Transactions on Software Engineering and Methodology , year=
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4beb326e-d133-43a8-8d19-e6fd04bf08c1 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Computer , volume=
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f9b641d0-6747-4165-9c0a-8654b7de4b7f · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Information , volume=
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 312c35ed-0ca0-4eed-ac66-7b01d24f3009 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Ieee Access , volume=
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c2a10d17-0627-4f7e-96af-9128f006ba91 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents AJCAI , year=
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9de510cd-2e38-49c3-a830-9d88c498e88b · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing , pages=
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 79a58412-1075-42e2-a125-ff5caa0d0ecd · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Les dissonances: Cross-tool harvesting and polluting in pool-of-tools empowered llm agents
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7a37d445-5a20-4989-8bb3-735b81527a6e · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents TL-Training: A Task-Feature-Based Framework for Training Large Language Models in Tool Use
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation db37fca0-4aa7-4f88-a5eb-dc32b0f2bf0e · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Automatic red teaming llm-based agents with model context protocol tools
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 55ee006a-c810-45be-abba-48172a2a47ed · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ac2f3cb4-634b-49ee-80c2-3d51073bbfce · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents \ StruQ \ : Defending against prompt injection with structured queries
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a1d49e6f-4d07-4e67-84f3-b54be81bb7cb · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents The temporal coherence problem: Synthetic point-in-time environments for evaluating llm agents with dynamic tool dependencies
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5f52ee4b-68c4-4a30-86b3-b9eaf2d97f1a · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation bdb3f4b7-89f3-4a56-be5b-3deba8dd82b2 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Obliinjection: Order-oblivious prompt injection attack to llm agents with multi-source data
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4436dc1a-2fed-4466-bee9-ac444d6ed065 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Model context protocol (mcp): Landscape, security threats, and future research directions
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c8cb2dc7-1c85-409f-9bcb-38b54605e459 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents When mcp servers attack: Taxonomy, feasibility, and mitigation
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 687285f5-ff5e-4b2c-a80e-54141d744a06 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Webinject: Prompt injection attack to web agents
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6042ea31-4017-4c3a-8f80-50b6c2ac819d · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Odyssey: Empowering minecraft agents with open-world skills
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 99e9aa51-f5bd-4034-b0a7-941a5fece382 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Adaptools: Adaptive tool-based indirect prompt injection attacks on agentic llms
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation 0b2ced28-69df-4c07-8ccc-f194de081c8a · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Topicattack: An indirect prompt injection attack via topic transition
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation accfe192-5c5e-4942-b183-3aaca9012dc6 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Prompt injection attacks in large language models and ai agent systems: A comprehensive review of vulnerabilities, attack vectors, and defense mechanisms
Reference 36
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a1bf0e3e-5c49-4232-ac50-5a488a7aa345 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Artificial intelligence crime: An overview of malicious use and abuse of ai
Reference 37
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f762d467-1d66-47b9-96a0-ded1abec6922 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Advancing embodied agent security: From safety benchmarks to input moderation
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 10c8286c-c7f1-4730-bab0-86be720276b6 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents Clawed and dangerous: Can we trust open agentic systems
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation aabab065-9c7e-4b32-ac4a-fa6eb7d98e94 · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents A framework for formalizing LLM agent security
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.
Observation be045717-7e52-4ec9-b882-cc70a703099a · outbound
WebMCP Tool Surface Poisoning: Runtime Manipulation Attacks on LLM Agents @mcp-b/global: W3C Web Model Context API polyfill
Reference 41
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.