Pith. sign in

Paper Citation Record · LEDGER

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer

As of 7 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 0 inbound Pith citation observations for arXiv:2606.21071.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2606.21071 v1

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-06-26T14:02:37.404821Z

measured 27 of 27 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

27 of 27 outbound references displayed

  • verified exact6
  • verified fuzzy0
  • unresolved19
  • parse uncertain1
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 019662f6-356d-4c7d-9f4c-df963549c716 · outbound

This paper cites SetupBench: Assessing Software Engineering Agents' Ability to Bootstrap Development Environments.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer SetupBench: Assessing Software Engineering Agents' Ability to Bootstrap Development Environments

Reference 1

Resolution
verified exact
arxiv_id, observed 2026-07-04T06:59:37.264275Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:90cb4db74259cf41ed6533a94054fe2b8d691771bc27cc7c690b5804be62a2cb

Observation e9a098f6-2d4e-4046-81a6-2bf4aa5052ec · outbound

This paper cites ToxicSkills: Snyk Finds Malware and Prompt Injection in 36% of AI Agent Skills.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer ToxicSkills: Snyk Finds Malware and Prompt Injection in 36% of AI Agent Skills

Reference 2

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:8619e8abaac440bd24af2d7a5cfe5b15ccf34b01e38616b01cbce6104ccc0007

Observation 824aaf42-b950-4617-b782-d80a3af81cb0 · outbound

This paper cites 280+ leaky skills: How openclaw & clawhub are exposing api keys and pii.Snyk Blog, February, 2026.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer 280+ leaky skills: How openclaw & clawhub are exposing api keys and pii.Snyk Blog, February, 2026

Reference 3

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:c51a2eaf57b55b3520900c964879097b865dbcf8d0e9b21aad04cc3bd092bb8f

Observation 09f56075-0c82-46aa-b636-b10c44a023ef · outbound

This paper cites Technical Report: Exploring the Emerging Threats of the Agent Skill Ecosystem.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Technical Report: Exploring the Emerging Threats of the Agent Skill Ecosystem

Reference 4

Resolution
verified exact
local_arxiv, observed 2026-07-04T06:59:37.264746Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:d7553b2e1f0859d797f00e51afc3a4ffb8d90bc2d47d50691d26ed0fbc9237ba

Observation 3afedd35-fea4-459a-9a8f-74b07e096176 · outbound

This paper cites Openclaw security: Risks of exposed ai agents explained.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Openclaw security: Risks of exposed ai agents explained

Reference 5

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:c1bef29537406ab0862144a1875edf34215031add806cd1ec4f45ee222debad0

Observation c7277061-3e7f-485a-a2d9-cfa3a903c988 · outbound

This paper cites ChatInject: Abusing Chat Templates for Prompt Injection in LLM Agents.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer ChatInject: Abusing Chat Templates for Prompt Injection in LLM Agents

Reference 6

Resolution
verified exact
local_arxiv, observed 2026-07-04T06:59:37.267265Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:d8ad1f532bf70501f50fe7e96ce786fa122d6f01cef435960432fa6ff6ef270c

Observation 4ed6cf14-c911-4fa1-8538-70f4205b288c · outbound

This paper cites Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Protecting Developers.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Protecting Developers

Reference 7

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:90c2e41305d6fc06c1a8a1becb7fa3ad0b883088b2feca00847a57f97a169ffc

Observation 7cf3d34d-7278-4152-8f4d-a1b7ac659f0a · outbound

This paper cites CodeQL: Semantic code analysis engine.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer CodeQL: Semantic code analysis engine

Reference 8

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:4b54f667a77984410deaedb3853912c4118ece033075965f61e3534669a9f174

Observation 707cbe84-9e01-42c1-b92c-be57e93fdc88 · outbound

This paper cites GitHub advisory database.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer GitHub advisory database

Reference 9

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:352b25080fd1a168f5233ed1393a98cf6373ae66b18c137ed2fba560c69534e5

Observation 2277738f-5fa9-49d2-a86e-5bcf285c68c8 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

Reference 10

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:209ac3098f1d9e55e9561876ae89b16dadad7ab686e51d31326ba0198c400270

Observation 7c934dd6-fdc9-41f0-9797-6aedd96d5596 · outbound

This paper cites Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers

Reference 11

Resolution
verified exact
local_arxiv, observed 2026-07-04T06:59:37.270067Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:f2ad8558c4b90821bc7711f53d0a98fd8d55f4d2b5c25d1621b3ffa19ef81ee8

Observation 3114db95-5a8d-418a-89db-b3f908c4ea43 · outbound

This paper cites Nanobot: Lightweight, open-source AI agent for tools, chats, and workflows.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Nanobot: Lightweight, open-source AI agent for tools, chats, and workflows

Reference 12

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:3009ac0190a61e918347c254f2d9ac0334227471ec97f41af5dc89f0c301fac4

Observation bbeb1ed0-db20-44ee-bca8-bdbb25d790e5 · outbound

This paper cites ClawHavoc: 341 malicious clawed skills found by the bot they were targeting, 2026.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer ClawHavoc: 341 malicious clawed skills found by the bot they were targeting, 2026

Reference 13

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:b19202c5fe898632989562fb55d63135024b51d2da59c77a84f5bb5d70207441

Observation cf6bff4c-ab25-4bea-9f18-98a8466c8233 · outbound

This paper cites LangChain, October 2022.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer LangChain, October 2022

Reference 14

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:f50475bb38786413d537231f14acecd0703dc62afbcb3708a925e1785e08ccce

Observation 0b9ce34b-ddb7-42e8-ab07-625eb0fb5f4b · outbound

This paper cites LlamaIndex, 11 2022.https://github.com/jerryjliu/llama_index.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer LlamaIndex, 11 2022.https://github.com/jerryjliu/llama_index

Reference 15

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:e30da6272a3b737bb09ae2abfda99e4e97f947e95ee53bd28132c479b39cb595

Observation f751aa14-e6cc-401f-a040-2f8c13857835 · outbound

This paper cites Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-07-04T06:59:37.262364Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:174edecc4cd646fb5764537fe5219787ee3862a7376af1a8a74f21cc769cd7c5

Observation 128aba34-8d80-40a0-b3a9-99ad81da5c02 · outbound

This paper cites The STRIDE threat model.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer The STRIDE threat model

Reference 17

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:d621514c5bc4d89982a55a2ae89a7ffeecc1e484ed22183abf9bb585fce9375c

Observation 5f10e442-1ddf-4666-a88a-85e78616c487 · outbound

This paper cites Evaluating and comparing memory error vulnerability detectors.Information and Software Technology, 137:106614, 2021.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Evaluating and comparing memory error vulnerability detectors.Information and Software Technology, 137:106614, 2021

Reference 18

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:86a6aa04063b5856c0f0a9fb5f9f3420c52f383d3f608327e82a6f3fd30411da

Observation 346f6cb9-549f-4728-b959-2e6c713e2694 · outbound

This paper cites Open science in software engineering: A study on deep learning-based vulnerability detection.IEEE Transactions on Software Engineering, 49(4):1983–2005, 2022.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Open science in software engineering: A study on deep learning-based vulnerability detection.IEEE Transactions on Software Engineering, 49(4):1983–2005, 2022

Reference 19

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:323804fbafa0dfa368da4ca5dc4116a98a8c156e7896a41f81930727933d9921

Observation dcff3fbf-be82-4aa8-87d8-a9c875056ec4 · outbound

This paper cites DualGauge: Automated joint security-functionality benchmarking of specification- only code generation by LLMs and coding agents.arXiv preprint arXiv:2511.20709, 2026.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer DualGauge: Automated joint security-functionality benchmarking of specification- only code generation by LLMs and coding agents.arXiv preprint arXiv:2511.20709, 2026

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-07-04T06:59:37.259790Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:69dcd7e8ee562804c7d75596bc7cdfb37b3407aeaa49801a0bdc6f39a17caed8

Observation 0f63466b-2618-485d-9462-c6e573961489 · outbound

This paper cites Semgrep: Lightweight static analysis for many languages.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Semgrep: Lightweight static analysis for many languages

Reference 21

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:a5687dce92f01f1c00e6b44efff35bb3de0b76fc76d26445ebbc8543ebc8330b

Observation 145cbb41-cf0c-4e4d-a848-79dfdf4769af · outbound

This paper cites an unresolved cited work.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Unresolved cited work

Reference 22

Resolution
parse uncertain
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:80d2abab3b1735938d34c1d0bda08183a2153cd680725e14c171e7173cc2e55c

Observation 914f4cfc-a62a-4241-ba31-f5a0cbaf612d · outbound

This paper cites John Wiley & Sons, Indianapolis, IN, 2014.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer John Wiley & Sons, Indianapolis, IN, 2014

Reference 23

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:b84413824a75c4934d0e2f9d7e643b5c5f26e903bc013a6167dbf43a1d6b410e

Observation c947ef8f-be68-4a17-b7f3-43935a0061c0 · outbound

This paper cites PicoClaw: Tiny, fast, and deployable anywhere — an ultra-lightweight personal AI assistant.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer PicoClaw: Tiny, fast, and deployable anywhere — an ultra-lightweight personal AI assistant

Reference 24

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:02a6160874d334594a101e00c579bbe5235d4e98f7d7706ed227ea977031b6d7

Observation 344c81f5-c1a9-4aaa-b419-039c393ab2f0 · outbound

This paper cites agent-scan: Security Scanner for AI Agents, MCP Servers, and Agent Skills.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer agent-scan: Security Scanner for AI Agents, MCP Servers, and Agent Skills

Reference 25

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:cb2a3e71a468f0cc64206a07fbfb6079fb4577ba95be410f57b219a1fc2ab85d

Observation e25f391a-4605-4812-aaa1-77b75b958f8c · outbound

This paper cites OpenClaw: Personal AI assistant.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer OpenClaw: Personal AI assistant

Reference 26

Resolution
unresolved
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:783a18f968f5978b769c32ac13f986b95960013a41e1e62260b998a1d8b8103a

Observation e608bf83-8a07-4490-98ad-67aec3d7dffb · outbound

This paper cites CWE-74"] category:.

Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer CWE-74"] category:

Reference 27

Resolution
malformed identifier
no resolver link, observed 2026-06-26T14:02:37.404821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-06-26T14:02:37.404821Z digest=sha256:860b38bd5f10d5f48e2e8eb2b00e3ebcde28f397ceac01f2b89b461a71501037

Pith citing papers

No inbound Pith citation observations are available.