Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-02T10:32:34.305658Z
Paper Citation Record · LEDGER
As of 8 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 2 inbound Pith citation observations for arXiv:2606.22916.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-02T10:32:34.305658Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-07T21:46:23.178867Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-08-07T21:46:23.228007Z
29 of 29 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 35e4b550-9009-4b6e-a0c5-77af0bd29a83 · outbound
Intent-Governed Tool Authorization for AI Agents Mitchell, and Helen Nissenbaum
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4ad0b115-7c52-4a14-bf3e-af0d0a81cb75 · outbound
Intent-Governed Tool Authorization for AI Agents StruQ: Defending Against Prompt Injection with Structured Queries, 2024
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e6925ba9-b5db-4f60-947d-7fd4af1dd12e · outbound
Intent-Governed Tool Authorization for AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents, 2024
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1d6554e7-29dd-475e-b524-7a9b20ba8dd0 · outbound
Intent-Governed Tool Authorization for AI Agents Ferraiolo and D
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d0f6652c-2c24-4d45-a1d0-def0189e696e · outbound
Intent-Governed Tool Authorization for AI Agents Operationalizing Contextual Integrity in Privacy-Conscious Assistants, 2024
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5148af58-0ae0-44f1-8027-39fb613b014a · outbound
Intent-Governed Tool Authorization for AI Agents AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations, 2026
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 95a6121f-b61e-4f21-abb2-81c8b95b9eee · outbound
Intent-Governed Tool Authorization for AI Agents Hu, David Ferraiolo, D
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation aadee338-8424-4dab-bc4b-2a7b4a7e7a9d · outbound
Intent-Governed Tool Authorization for AI Agents Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning, 2026
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 155969ce-f6d2-48af-b01b-39ac1b6ec51a · outbound
Intent-Governed Tool Authorization for AI Agents Need to Know: Contextual-Integrity-Grounded Query Rewriting for Privacy-Conscious LLM Delegation, 2026
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fc683ac0-ffc0-49de-bb82-d0b72c09f240 · outbound
Intent-Governed Tool Authorization for AI Agents Securing the Model Context Protocol: Defending LLMs Against Tool Poisoning and Adversarial Attacks, 2025
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 04527dff-7c3f-442d-a8ec-6f0de9fb2625 · outbound
Intent-Governed Tool Authorization for AI Agents AgentDyn: A Dynamic Open-Ended Benchmark for Evaluating Prompt Injection Attacks of Real-World Agent Security System, 2026
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 07390d51-9322-4ebd-b180-551a78573fc9 · outbound
Intent-Governed Tool Authorization for AI Agents ToolSandbox: A Stateful, Conversational, Interactive Evaluation Benchmark for LLM Tool Use Capabilities, 2024
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f1ba5f8d-8550-411d-af00-4b72ce3fe447 · outbound
Intent-Governed Tool Authorization for AI Agents Authorization
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ce07bee1-4c59-4d39-846f-8db0deceea91 · outbound
Intent-Governed Tool Authorization for AI Agents Unresolved cited work
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4305c0a2-561c-46c6-a159-87cd8ffc45bb · outbound
Intent-Governed Tool Authorization for AI Agents Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 317a95c7-4542-42b8-965f-5bcff794f96d · outbound
Intent-Governed Tool Authorization for AI Agents Stanford University Press, 2009
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 248fada8-082e-454e-bf66-5b1528e87fe2 · outbound
Intent-Governed Tool Authorization for AI Agents LLM01:2025 Prompt Injection
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ea0dbd09-bbb0-40bd-b484-24a0b327d865 · outbound
Intent-Governed Tool Authorization for AI Agents OW ASP Top 10 for LLM Applications 2025
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 12854581-b907-4f19-8917-076c26188621 · outbound
Intent-Governed Tool Authorization for AI Agents Maddison, and Tatsunori Hashimoto
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 24193b09-c495-4e28-a941-85aa18df27b7 · outbound
Intent-Governed Tool Authorization for AI Agents Saltzer and Michael D
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 18747825-aa31-4fc9-846d-f4d8f8e1e8e5 · outbound
Intent-Governed Tool Authorization for AI Agents MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems, 2026
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eebae825-626a-4ea0-84ab-2ac6ce20bfb7 · outbound
Intent-Governed Tool Authorization for AI Agents Prompt Injection Attack to Tool Selection in LLM Agents, 2025
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 00621fd8-9e55-4b4d-bda7-b74ec9383132 · outbound
Intent-Governed Tool Authorization for AI Agents ToolTweak: An Attack on Tool Selection in LLM-based Agents, 2025
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 98643bf9-498f-43c6-9087-381d3c6661fd · outbound
Intent-Governed Tool Authorization for AI Agents Data Guard: A Fine-grained Purpose-based Access Control System for Large Data Warehouses, 2025
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e214b054-0206-4d5e-b16d-f35e9c1af57b · outbound
Intent-Governed Tool Authorization for AI Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers, 2025
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 16334e18-31fb-4d43-803b-2114a0d375c8 · outbound
Intent-Governed Tool Authorization for AI Agents Messaging with Purpose Limitation – Privacy-Compliant Publish-Subscribe Systems, 2021
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cf519791-baee-479a-aa36-7bbec0918fb1 · outbound
Intent-Governed Tool Authorization for AI Agents τ-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains, 2024
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 425f23c7-a4f1-4650-9752-c017d720c82f · outbound
Intent-Governed Tool Authorization for AI Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents, 2024
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b8d8d1d6-3e6d-47e0-b085-4800c10f72d7 · outbound
Intent-Governed Tool Authorization for AI Agents AgentSentry: Mitigating Indirect Prompt Injection in LLM Agents via Temporal Causal Diagnostics and Context Purification, 2026
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 889e1901-795c-4aed-8869-f65b2837f1dd · inbound
Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Intent-Governed Tool Authorization for AI Agents
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fdc261ba-1e82-46d5-a9b2-c2aa5dc85c59 · inbound
The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Intent-Governed Tool Authorization for AI Agents
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.