{"as_of":"2026-08-16T14:16:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:9944fe1203aab48ec91490d5071c2597bbd1f57be4c9fa1ef6412e26a3269bdf","coverage":[{"denominator":27,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":27,"source":"paper_references, paper_reference_links","source_observed_at":"2026-06-27T12:53:33.800969Z","state":"measured"},{"denominator":31,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":31,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-16T06:30:59.297886+00:00","state":"measured"},{"denominator":4,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":4,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-15T19:23:23.346372Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"pith","source_observed_at":"2026-08-10T18:36:42.753993Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2606.10484","snapshot_observed_at":"2026-07-12T08:29:25.498449Z","title":"Agentcanary: A security evaluation framework for autonomous ai agents in real executable environments,","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2607.02038","last_updated":"2026-07-03T06:32:47Z","snapshot_observed_at":"2026-08-14T19:35:31.748120Z","submitted_at":"2026-07-02T11:05:58Z","title":"Hierarchical Anti-Aesthetics: Protecting Facial Privacy against Customized Diffusion Models","version":2},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-07-12T08:29:25.498449Z"},"links":{"cited_paper":"/paper/2606.10484","citing_paper":"/paper/2607.02038"},"observation_digest":"sha256:6e4d81349487f2202b5a386577f95670d9b8c6a31213cac8ff5b27b199a35631","observation_id":"0decaa8a-667e-46b5-95ec-54a8fcf22785","resolution":{"observed_at":"2026-07-12T08:29:25.498449Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2606.10484","snapshot_observed_at":"2026-07-30T17:25:46.911432Z","title":null,"venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.23624","last_updated":"2026-07-29T14:49:58Z","snapshot_observed_at":"2026-08-15T17:18:56.523857Z","submitted_at":"2026-07-26T12:15:09Z","title":"Where Is the Cost of Third-Party API Routers in Agentic Software Development?","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-07-30T17:25:46.911432Z"},"links":{"cited_paper":"/paper/2606.10484","citing_paper":"/paper/2607.23624"},"observation_digest":"sha256:e37270cda05a50ee29c8bcc6364c3958d6e49199052d201c7f83f9a4bae01d1f","observation_id":"85ab5460-39c1-419d-86fe-9ac4ff47a0bc","resolution":{"observed_at":"2026-07-30T17:25:46.911432Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"cited_work":{"arxiv_id":"2606.10484","doi":null,"metadata_source":"pith","pith_arxiv_id":"2606.10484","snapshot_observed_at":"2026-08-10T18:36:42.753993Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","venue":"cs.CR","work_id":"1bbd7e43-feef-4351-8e70-afe32abb2572","year":2026},"citing_paper":{"arxiv_id":"2608.06909","last_updated":"2026-08-07T07:43:12Z","snapshot_observed_at":"2026-08-15T18:25:02.070277Z","submitted_at":"2026-08-07T07:43:12Z","title":"Long-Horizon Agent Trajectory Attribution: A Unified Benchmark and Fine-Grained Annotation Framework","version":1},"reference_index":19,"source":"arxiv_source","source_observed_at":"2026-08-10T18:36:42.708310Z"},"links":{"cited_paper":"/paper/2606.10484","citing_paper":"/paper/2608.06909"},"observation_digest":"sha256:49b3e8875fea2ed3890071549a317a101fcd93676826be3c790e377aafd702ed","observation_id":"1e9bb2e3-ac67-41a0-bd4f-9459b7ab749b","resolution":{"observed_at":"2026-08-10T18:36:42.761618Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2606.10484","snapshot_observed_at":"2026-08-15T19:23:23.346372Z","title":"AgentCanary: A secu- rity evaluation framework for autonomous ai agents in real executable environments","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2608.12977","last_updated":"2026-08-13T08:57:04Z","snapshot_observed_at":"2026-08-16T14:11:33.035378Z","submitted_at":"2026-08-13T08:57:04Z","title":"Beyond Handcrafted Security: Towards Self-Evolving Defense for LLM Agents","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-15T19:23:23.346372Z"},"links":{"cited_paper":"/paper/2606.10484","citing_paper":"/paper/2608.12977"},"observation_digest":"sha256:ee3fedbc6f21a2a7160e7b438dc4b49ebf0dddaef07bb9d80ec0af5e442e12df","observation_id":"5cf22db1-1859-4bb3-a4a3-2882e2601706","resolution":{"observed_at":"2026-08-15T19:23:23.346372Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2606.10484/citation-record","integrity":"/paper/2606.10484/integrity","json":"/paper/2606.10484/citation-record.json","paper":"/paper/2606.10484"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"Accessed: 2026-05-04","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:176dd5bea199e5501bc433e598cbac5397c5a31eaff00b397cba10422e181b4e","observation_id":"5f086488-5852-4517-ab2c-aeb39d3c610b","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"Accessed: 2026-05-04","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:725dab8a03303e9289035e7d850c10a1a1189208eb8fa62b2685df36a319c8a8","observation_id":"193b13bc-78b0-4066-b58c-9534e688ef79","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2602.16943","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-03T06:07:41.485234Z","title":"Mind the gap: Text safety does not transfer to tool-call safety in llm agents","venue":null,"work_id":"5d0462dc-84ae-4bd0-8120-2264efe3c6c0","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:1bc416b02f13ac4dad56b1b59d32b5fcf74edc7282a0140d8789e3f3ee8cd747","observation_id":"03aea92e-7c5c-46b2-8fdf-b5a2db447cd1","resolution":{"observed_at":"2026-07-03T06:07:41.486758Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.11619","doi":"10.48550/arxiv.2603.11619","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Taming OpenClaw: Security analysis and mitigation of autonomous LLM agent threats","venue":"arXiv (Cornell University)","work_id":"007f6b31-1c90-4787-9431-6d395fb755d9","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:5c42bac30ff9bee9abc94b2cc79eacc95ef827ad1d403dff702a0c8e6a29fca5","observation_id":"81e45a2c-de6d-41ca-9856-f2cad7f535f6","resolution":{"observed_at":"2026-07-03T06:07:41.489277Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.05172","last_updated":"2026-04-08T09:27:21Z","snapshot_observed_at":"2026-08-14T19:24:50.886058Z","submitted_at":"2026-04-06T21:09:06Z","title":"ClawsBench: Evaluating Capability and Safety of LLM Productivity Agents in Simulated Workspaces","version":2},"cited_work":{"arxiv_id":"2604.05172","doi":null,"metadata_source":"pith","pith_arxiv_id":"2604.05172","snapshot_observed_at":"2026-07-03T06:07:41.480446Z","title":"ClawsBench: Evaluating Capability and Safety of LLM Productivity Agents in Simulated Workspaces","venue":"cs.AI","work_id":"1d0d802c-947a-4c92-8995-c392b01261d7","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2604.05172","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:1746e2737ce1f68144166623331a4d2241d566a7f135b723a95e30d1aeb641a2","observation_id":"0e0ddb34-c0e9-4b46-a8b4-acfad86dee59","resolution":{"observed_at":"2026-07-03T06:07:41.481734Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"Accessed: 2026-05-04","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:11d3765cc02f39a3dae4552d593dbb10a9b8eb2a6f8ebee688fa893a75e76dc4","observation_id":"ff4906c2-75f6-4039-a1ab-78401fea3b8b","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2506.13131","last_updated":"2025-06-16T06:37:18Z","snapshot_observed_at":"2026-08-11T23:48:15.512738Z","submitted_at":"2025-06-16T06:37:18Z","title":"AlphaEvolve: A coding agent for scientific and algorithmic discovery","version":1},"cited_work":{"arxiv_id":"2506.13131","doi":"10.1016/j.shpsa.2017.03.005","metadata_source":"pith","pith_arxiv_id":"2506.13131","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"AlphaEvolve: A coding agent for scientific and algorithmic discovery","venue":"cs.AI","work_id":"76a0f850-d490-4e4f-ab98-8d25df82cd23","year":2025},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2506.13131","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:51250220f0f03426b41d48bcdda057d5c189de57ff5d22c9a3ce44522a0b9778","observation_id":"339e7326-7b82-4170-bda0-c6fd59d8a8e3","resolution":{"observed_at":"2026-07-03T06:07:41.484161Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"Accessed: 2026-05-04","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:fccdced76ccb19a84188ef1f3c2eadec91ef9039c2047737aac75523efa1ef17","observation_id":"4bdf0a36-2edd-4e2f-85ab-e37bd62e6122","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.13203","last_updated":"2025-08-23T02:09:57Z","snapshot_observed_at":"2026-08-16T12:40:48.826825Z","submitted_at":"2025-04-15T16:11:28Z","title":"X-Teaming: Multi-Turn Jailbreaks and Defenses with Adaptive Multi-Agents","version":2},"cited_work":{"arxiv_id":"2504.13203","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2504.13203","snapshot_observed_at":"2026-07-03T06:07:41.476618Z","title":"X-teaming: Multi- turn jailbreaks and defenses with adaptive multi-agents","venue":null,"work_id":"14895b6e-e521-434c-b30f-db8fcc0f1232","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2504.13203","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:891919fb09ab3fa5d7b6c56969f6483ecb037147240135659ec83db47e582bc1","observation_id":"cb25c529-9ab0-49a9-b890-8269391df712","resolution":{"observed_at":"2026-07-03T06:07:41.477969Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"Identifying the risks of lm agents with an lm-emulated sandbox","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:9dc81afac3d392ebe5c41bbdab02d2494c3e66e323152bf4c7cf4de27a3bf55e","observation_id":"520ca1f0-3d46-4d9c-a05d-e3e4c4a68a65","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2602.20156","last_updated":"2026-02-25T18:14:01Z","snapshot_observed_at":"2026-08-11T16:43:10.190893Z","submitted_at":"2026-02-23T18:59:27Z","title":"Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks","version":3},"cited_work":{"arxiv_id":"2602.20156","doi":"10.48550/arxiv.2602.20156","metadata_source":"pith","pith_arxiv_id":"2602.20156","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks","venue":"cs.CR","work_id":"457096f5-b6b3-42da-ac50-e29571f908bb","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2602.20156","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:8ded6d0cdc2f3646ca67e62e721c098ac44679f41399758bb65e0bc0091ea0e5","observation_id":"d5fbc939-fbe3-4cc3-83bd-24b05a3b5bab","resolution":{"observed_at":"2026-07-03T06:07:41.501052Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.10387","doi":"10.48550/arxiv.2603.10387","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Don’t let the claw grip your hand: A security analysis and defense framework for OpenClaw","venue":"arXiv (Cornell University)","work_id":"419d68e7-2dfc-4480-9d0a-0da2040a78d4","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:772da9be36e305f4a6865c9154c9db3187ffc5b6d6bc073d297de900dd20242b","observation_id":"fb7bf7de-c693-43c8-9eb7-b795e45e0c9c","resolution":{"observed_at":"2026-07-03T06:07:41.503816Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2602.20021","last_updated":"2026-02-23T16:28:48Z","snapshot_observed_at":"2026-07-06T22:46:45.213871Z","submitted_at":"2026-02-23T16:28:48Z","title":"Agents of Chaos","version":1},"cited_work":{"arxiv_id":"2602.20021","doi":"10.48550/arxiv.2602.20021","metadata_source":"pith","pith_arxiv_id":"2602.20021","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agents of Chaos","venue":"cs.AI","work_id":"02176c31-e67c-46e2-835a-ac21f005e1be","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2602.20021","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:6812948705cc24330f1a9065a9e6b9462c809f0b0245241a49d467e2b2f06abf","observation_id":"313875b0-513e-4417-93f3-b6321397d259","resolution":{"observed_at":"2026-07-03T06:07:41.492542Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-07-15T18:20:21.538265+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-15T18:20:21.538265+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2512.16962","doi":"10.48550/arxiv.2512.16962","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"arXiv preprint arXiv:2512.16962 , year=","venue":"arXiv (Cornell University)","work_id":"90120582-e1b6-45f2-af30-e61c82587d05","year":2025},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:48a0b13f0349d981541bafdd86b7e8a6645f8eeb4fe7206639f377897864d31b","observation_id":"7705d572-61bf-4a7f-9603-706edca13b6d","resolution":{"observed_at":"2026-07-03T06:07:41.480446Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2601.05504","doi":"10.48550/arxiv.2601.05504","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"URLhttps://arxiv.org/abs/2601.05504 First Author et al.:Preprint submitted to ElsevierPage 20 of 21 Security, Privacy, and Ethical Risks in OpenClaw","venue":"arXiv (Cornell University)","work_id":"8bb49f6f-4a1a-415a-981f-164bb63b644c","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:69f3143df92197a85608fcca7fb3a076e161f08ed856d894425c34460ab27c52","observation_id":"02eee7be-d9d9-4da8-90db-2f390fe6e858","resolution":{"observed_at":"2026-07-03T06:07:41.466880Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2306.05301","last_updated":"2023-09-07T12:20:45Z","snapshot_observed_at":"2026-08-11T16:55:59.039497Z","submitted_at":"2023-06-08T15:46:32Z","title":"ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases","version":2},"cited_work":{"arxiv_id":"2306.05301","doi":"10.48550/arxiv.2306.05301","metadata_source":"pith","pith_arxiv_id":"2306.05301","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases","venue":"cs.CL","work_id":"e900f660-9178-4fda-ad54-a788e23aa0d8","year":2023},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2306.05301","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:e557e8a868aea2440ccdf4e818982e29b7e66d73fe2800697454f07e8e6c663a","observation_id":"67a1275e-639f-4f94-9afb-d9a7b5ec9a83","resolution":{"observed_at":"2026-07-03T06:07:41.471435Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"28 Xilong Wang, John Bloch, Zedian Shao, Yuepeng Hu, Shuyan Zhou, and Neil Zhenqiang Gong","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:f3d7cb8b7482209a23e1eeb38655954214d92d44bf39cc7ca849b5feda4df616","observation_id":"a9e50ba7-bdda-47e4-b38f-e728e5b113e3","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2603.10165","last_updated":"2026-05-11T10:03:41Z","snapshot_observed_at":"2026-07-06T22:48:35.345421Z","submitted_at":"2026-03-10T18:59:01Z","title":"OpenClaw-RL: Train Any Agent Simply by Talking","version":2},"cited_work":{"arxiv_id":"2603.10165","doi":"10.48550/arxiv.2603.10165","metadata_source":"pith","pith_arxiv_id":"2603.10165","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"OpenClaw-RL: Train Any Agent Simply by Talking","venue":"cs.CL","work_id":"78607317-8305-4515-8dc3-20b4ff5b8f3a","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2603.10165","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:9c6800044c1b3c5087bad7f5b60925503241f34ec1954bae496dcf6826fd7847","observation_id":"1b236a70-7887-456a-9452-5bffc1711795","resolution":{"observed_at":"2026-07-03T06:07:41.495761Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.01438","last_updated":"2026-04-04T15:18:43Z","snapshot_observed_at":"2026-08-15T15:21:10.198748Z","submitted_at":"2026-04-01T22:24:24Z","title":"ClawSafety: \"Safe\" LLMs, Unsafe Agents","version":2},"cited_work":{"arxiv_id":"2604.01438","doi":"10.48550/arxiv.2604.01438","metadata_source":"pith","pith_arxiv_id":"2604.01438","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"ClawSafety: \"Safe\" LLMs, Unsafe Agents","venue":"cs.AI","work_id":"65792180-ed14-4f36-a1e6-78f74ed5224d","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2604.01438","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:6619a17399d8d5e995db5a4d1f58a51c475e3a790cd94249e8d543bce84a5760","observation_id":"513add2a-8e81-4d1f-bb01-2b57d2a9a61e","resolution":{"observed_at":"2026-07-03T06:07:41.498652Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"Toolsafety: A comprehensive dataset for enhancing safety in llm-based agent tool invocations","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:fe3a70a56e8dec9912b74d2c3a9d48fc626e42c8cc3840148df578a402d958bd","observation_id":"a49362a0-25f7-4029-a039-b0e4aa0123b5","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2401.10019","last_updated":"2024-10-05T06:50:15Z","snapshot_observed_at":"2026-08-15T13:54:08.703885Z","submitted_at":"2024-01-18T14:40:46Z","title":"R-Judge: Benchmarking Safety Risk Awareness for LLM Agents","version":3},"cited_work":{"arxiv_id":"2401.10019","doi":null,"metadata_source":"pith","pith_arxiv_id":"2401.10019","snapshot_observed_at":"2026-07-11T02:47:50.885307Z","title":"arXiv preprint arXiv:2401.10019 , year=","venue":"cs.CL","work_id":"80797370-dc29-417d-83c5-ec1313a64166","year":2024},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2401.10019","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:0ad507278d71fc9deb55ebd5dfcec5843ca5895c3af284f865cce68df35850ea","observation_id":"876c6ca4-f5d5-47f6-af89-492a463d9772","resolution":{"observed_at":"2026-07-03T06:07:41.460941Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"Accessed: 2026-05-04","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:36f21935fd6e2677fdffee09063c79b1d2ac2a4713df2ce4824e807098311d0c","observation_id":"761b640e-6c22-403a-a8b1-90b11f8ecd51","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2602.15763","last_updated":"2026-02-24T10:44:44Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-02-17T17:50:56Z","title":"GLM-5: from Vibe Coding to Agentic Engineering","version":2},"cited_work":{"arxiv_id":"2602.15763","doi":"10.48550/arxiv.2602.15763","metadata_source":"pith","pith_arxiv_id":"2602.15763","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"GLM-5: from Vibe Coding to Agentic Engineering","venue":"cs.LG","work_id":"ad29b1a2-bf77-46b3-9ead-fb62b1d2c6fe","year":2026},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2602.15763","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:742d0ef8c4b8d988f5b4c414b4fcfda46e4364a94b5570670294e26692fdd3d0","observation_id":"ae43f29e-99a5-45f5-af85-55c8487c4094","resolution":{"observed_at":"2026-07-03T06:07:41.476720Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:b376430d9f57043077c1630749f675f409d1514773cefa481249c1223c92d69f","observation_id":"bc58e92b-3234-4a55-9c2d-bf5a44f4d13f","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-06-27T12:53:33.800969Z","title":"Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:e6cf28bc80e30cafe47abc188b19cf161e1524f5a65a0bc59936e8f7b843ba1c","observation_id":"9705c800-7c6c-4ee6-82a1-59a7df39af38","resolution":{"observed_at":"2026-06-27T12:53:33.800969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14470","last_updated":"2025-05-20T05:58:23Z","snapshot_observed_at":"2026-08-06T12:35:19.109481Z","submitted_at":"2024-12-19T02:35:15Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","version":2},"cited_work":{"arxiv_id":"2412.14470","doi":"10.48550/arxiv.2412.14470","metadata_source":"pith","pith_arxiv_id":"2412.14470","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","venue":"cs.CL","work_id":"96afb8b9-0e7e-442c-93b1-6638599fc041","year":2024},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2412.14470","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:285089d98b569f82f52b5fd0184293b73f46918a7b5734cc87ebf0aec26be66f","observation_id":"dead27c0-f681-4e55-aef9-017f725fba2d","resolution":{"observed_at":"2026-07-03T06:07:41.482603Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-07-14T18:20:24.185748+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-14T18:20:24.185748+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2307.15043","last_updated":"2023-12-20T20:48:57Z","snapshot_observed_at":"2026-08-12T09:06:50.363435Z","submitted_at":"2023-07-27T17:49:12Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","version":2},"cited_work":{"arxiv_id":"2307.15043","doi":"10.48550/arxiv.2307.15043","metadata_source":"pith","pith_arxiv_id":"2307.15043","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Universal and Transferable Adversarial Attacks on Aligned Language Models","venue":"cs.CL","work_id":"3322fa86-1768-4677-8425-dd326b45e078","year":2023},"citing_paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-06-27T12:53:33.800969Z"},"links":{"cited_paper":"/paper/2307.15043","citing_paper":"/paper/2606.10484"},"observation_digest":"sha256:2d1e8b0e8540f351b1a37c6b50090862adaac4f55d5c9624c7373481666277b5","observation_id":"fc3c8ab7-283d-45e3-9733-5f8f60aba316","resolution":{"observed_at":"2026-07-03T06:07:41.479229Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-07-15T23:50:40.271168+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-15T23:50:40.271168+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2606.10484","last_updated":"2026-06-09T06:55:37Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-14T07:53:57.222567Z","submitted_at":"2026-06-09T06:55:37Z","title":"AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments"},"reference_resolution":{"displayed":27,"state_counts":{"malformed_identifier":0,"metadata_mismatch":5,"parse_uncertain":0,"unresolved":10,"verified_exact":12,"verified_fuzzy":0},"total_outbound_references":27},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-16T06:30:59.297886+00:00","source":"crossref"},{"observed_at":"2026-08-16T06:30:54.164669+00:00","source":"retraction_watch"}],"thesis":"As of 16 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 4 inbound Pith citation observations for arXiv:2606.10484."}