Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-26T14:02:37.404821Z
Paper Citation Record · LEDGER
As of 7 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 0 inbound Pith citation observations for arXiv:2606.21071.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-06-26T14:02:37.404821Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
27 of 27 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 019662f6-356d-4c7d-9f4c-df963549c716 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer SetupBench: Assessing Software Engineering Agents' Ability to Bootstrap Development Environments
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation e9a098f6-2d4e-4046-81a6-2bf4aa5052ec · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer ToxicSkills: Snyk Finds Malware and Prompt Injection in 36% of AI Agent Skills
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 824aaf42-b950-4617-b782-d80a3af81cb0 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer 280+ leaky skills: How openclaw & clawhub are exposing api keys and pii.Snyk Blog, February, 2026
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 09f56075-0c82-46aa-b636-b10c44a023ef · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Technical Report: Exploring the Emerging Threats of the Agent Skill Ecosystem
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 3afedd35-fea4-459a-9a8f-74b07e096176 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Openclaw security: Risks of exposed ai agents explained
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c7277061-3e7f-485a-a2d9-cfa3a903c988 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer ChatInject: Abusing Chat Templates for Prompt Injection in LLM Agents
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 4ed6cf14-c911-4fa1-8538-70f4205b288c · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Protecting Developers
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7cf3d34d-7278-4152-8f4d-a1b7ac659f0a · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer CodeQL: Semantic code analysis engine
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 707cbe84-9e01-42c1-b92c-be57e93fdc88 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer GitHub advisory database
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2277738f-5fa9-49d2-a86e-5bcf285c68c8 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7c934dd6-fdc9-41f0-9797-6aedd96d5596 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Model Context Protocol (MCP) at First Glance: Studying the Security and Maintainability of MCP Servers
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 3114db95-5a8d-418a-89db-b3f908c4ea43 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Nanobot: Lightweight, open-source AI agent for tools, chats, and workflows
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bbeb1ed0-db20-44ee-bca8-bdbb25d790e5 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer ClawHavoc: 341 malicious clawed skills found by the bot they were targeting, 2026
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cf6bff4c-ab25-4bea-9f18-98a8466c8233 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer LangChain, October 2022
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0b9ce34b-ddb7-42e8-ab07-625eb0fb5f4b · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer LlamaIndex, 11 2022.https://github.com/jerryjliu/llama_index
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f751aa14-e6cc-401f-a040-2f8c13857835 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 128aba34-8d80-40a0-b3a9-99ad81da5c02 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer The STRIDE threat model
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5f10e442-1ddf-4666-a88a-85e78616c487 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Evaluating and comparing memory error vulnerability detectors.Information and Software Technology, 137:106614, 2021
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 346f6cb9-549f-4728-b959-2e6c713e2694 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Open science in software engineering: A study on deep learning-based vulnerability detection.IEEE Transactions on Software Engineering, 49(4):1983–2005, 2022
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dcff3fbf-be82-4aa8-87d8-a9c875056ec4 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer DualGauge: Automated joint security-functionality benchmarking of specification- only code generation by LLMs and coding agents.arXiv preprint arXiv:2511.20709, 2026
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.
Observation 0f63466b-2618-485d-9462-c6e573961489 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Semgrep: Lightweight static analysis for many languages
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 145cbb41-cf0c-4e4d-a848-79dfdf4769af · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer Unresolved cited work
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 914f4cfc-a62a-4241-ba31-f5a0cbaf612d · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer John Wiley & Sons, Indianapolis, IN, 2014
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c947ef8f-be68-4a17-b7f3-43935a0061c0 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer PicoClaw: Tiny, fast, and deployable anywhere — an ultra-lightweight personal AI assistant
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 344c81f5-c1a9-4aaa-b419-039c393ab2f0 · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer agent-scan: Security Scanner for AI Agents, MCP Servers, and Agent Skills
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e25f391a-4605-4812-aaa1-77b75b958f8c · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer OpenClaw: Personal AI assistant
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e608bf83-8a07-4490-98ad-67aec3d7dffb · outbound
Local LLM Agents as Vulnerable Runtimes:A Source-Code Audit of the Agent Runtime Layer CWE-74"] category:
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.