{"as_of":"2026-08-07T08:18:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:4d4246dc881a799681ae084ae3b4067b58bb36774aec20c854817c803a05d839","coverage":[{"denominator":41,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":41,"source":"paper_references, paper_reference_links","source_observed_at":"2026-07-01T01:55:40.954429Z","state":"measured"},{"denominator":41,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":41,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-07T06:34:17.273281+00:00","state":"measured"},{"denominator":0,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[],"links":{"evidence":"/evidence","html":"/paper/2606.30755/citation-record","integrity":"/paper/2606.30755/integrity","json":"/paper/2606.30755/citation-record.json","paper":"/paper/2606.30755"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.530575Z","title":"Anderson","venue":null,"work_id":"b16d2327-1a45-4b62-a32f-5129b8e527fe","year":1972},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:f94102b5cf058b69eb7eae650ffcff9de6a0b66f407356678650ac6ba0b10969","observation_id":"56f8772b-707b-4eed-8d44-cb598fc4d8c4","resolution":{"observed_at":"2026-07-07T05:23:21.531952Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.574106Z","title":"AgentHarm: A benchmark for measuring harmfulness of LLM agents","venue":null,"work_id":"7dcaa334-0ac0-4a22-95a6-e33bb7a03502","year":2025},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:5d1c6df339837c55ca2dae4784713ee4956440f35d9a7b3c3687127ab7f50a2f","observation_id":"b886d389-6932-4ec6-8fa8-330641a89986","resolution":{"observed_at":"2026-07-07T05:23:21.575809Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.577032Z","title":"Elliott Bell and Leonard J","venue":null,"work_id":"383e79d1-d23f-410d-940b-5f57cea4ce74","year":1973},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:e00a39becd912d174d577afbcb03d1fe3e38c5cde421940d0c9891f2ba08ee3b","observation_id":"d1233e5c-85ae-4812-a336-5a1cc61522e6","resolution":{"observed_at":"2026-07-07T05:23:21.579392Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.571623Z","title":null,"venue":null,"work_id":"0e82af5a-466b-47ed-87b5-9743a0ee80b1","year":1977},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:31e695cfc9ad057048a2eec5f6276fb36c0ae6c8b8f7a88a6cca7802bdf15512","observation_id":"7f626961-77a4-476a-8d55-d44916006756","resolution":{"observed_at":"2026-07-07T05:23:21.573234Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2602.14364","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-08T00:24:22.442445Z","title":"arXiv preprint arXiv:2602.14364 , year =","venue":null,"work_id":"e9b445b2-bc82-4843-aed7-9d752166c09a","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:5a08b43b760de541d55d5771b71a3c887a638e61c50f1f70bf73a953c8e3cf92","observation_id":"007fe01d-9370-45aa-8385-babca95f8a33","resolution":{"observed_at":"2026-07-01T12:35:44.135898Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.566510Z","title":"Ai agent security risks in 2026: The incident landscape and hardening frame- work.https://blog.cyberdesserts.com/ai-agent-security-risks/, 2026","venue":null,"work_id":"86a43c16-7ada-4c4e-9119-c879c935e9b8","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:8c6f37af14e04ed82bf7e8b188885678d8a2be621663ea79ac04c81bc0766733","observation_id":"61809342-c090-44fc-b436-49c801e7c72e","resolution":{"observed_at":"2026-07-07T05:23:21.568390Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.569184Z","title":"AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents","venue":null,"work_id":"3680a230-19d8-4c5f-ad2b-5ad066356eb0","year":2024},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:e02f4488ff087b308cc8bdff6dee1b4ed79c312367179ae5633282d659288d74","observation_id":"92690f93-2922-41dd-8b37-d1bcea9bf473","resolution":{"observed_at":"2026-07-07T05:23:21.570756Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.581060Z","title":"OpenClawCVEs: Tracking OpenClaw CVEs","venue":null,"work_id":"e53128e1-b9f0-4d02-9089-c0163671af06","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:e80d6c76490607f39c1b1c32923b077efbd9b8ba38d9dec945ca37a31c711a0f","observation_id":"9e3742ea-69f6-4f18-acc3-d6efc11e25b7","resolution":{"observed_at":"2026-07-07T05:23:21.582955Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2605.26112","last_updated":"2026-05-25T17:59:36Z","snapshot_observed_at":"2026-07-06T23:36:01.564747Z","submitted_at":"2026-05-25T17:59:36Z","title":"From Model Scaling to System Scaling: Scaling the Harness in Agentic AI","version":1},"cited_work":{"arxiv_id":"2605.26112","doi":null,"metadata_source":"pith","pith_arxiv_id":"2605.26112","snapshot_observed_at":"2026-07-09T23:26:36.843763Z","title":"From Model Scaling to System Scaling: Scaling the Harness in Agentic AI","venue":"cs.AI","work_id":"ce1e17f0-1cd9-4e8c-bbbf-ba6288d6957a","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2605.26112","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:5c8bf58996c0c6bb83094877b0234408baf6b39013fcfad287c0dd83352175ab","observation_id":"4d40fbeb-2690-45f1-aacd-56445c903333","resolution":{"observed_at":"2026-07-01T12:35:44.138803Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.560851Z","title":"Model context protocol (mcp): Landscape, security threats, and future research directions.ACM Transactions on Software Engineering and Methodology","venue":null,"work_id":"8e463daf-5ac8-4d38-b1b6-96b28faa5019","year":2025},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:3837368e63816493bfe375dbac3d9130341ba2c0ec8bab66937756303e0685da","observation_id":"6bc7b6df-6a65-475a-a9a1-ae92555460c6","resolution":{"observed_at":"2026-07-07T05:23:21.563153Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.558220Z","title":"Malicious openclaw ‘skill’ targets crypto users on clawhub — 14 malicious skills were uploaded to clawhub last month.Tom’s Hardware, 2026","venue":null,"work_id":"18fae63a-95e8-4fed-8ef8-c17841819fd0","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:31a30b05e87d4948dcd729c36d20474b0866c20a60cac299cd762d0ad1586ed1","observation_id":"923539c2-5742-46d0-af7e-78ef16a73d6f","resolution":{"observed_at":"2026-07-07T05:23:21.560017Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.11088","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-04T13:59:52.293356Z","title":"arXiv preprint arXiv:2603.11088 , year =","venue":null,"work_id":"2273c150-4641-4838-9824-816bc8bddd22","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:653921d0be1fd9f972d3ef3516fd2e0524aa53e6e6fc33554258464aa2e0ede7","observation_id":"e549a117-edb4-48d6-9020-bfdfacde4cc9","resolution":{"observed_at":"2026-07-01T12:35:44.142429Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2601.17549","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-04T09:19:43.635386Z","title":"Breaking the protocol: Security anal- ysis of the model context protocol specification and prompt in- jection vulnerabilities in tool-integrated llm agents","venue":null,"work_id":"1db9ca2d-eba6-4e2e-830a-47115aa4a474","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:4918b78b002af10cda7399efd4d21923790582345be51180b60e6b28c85f74c4","observation_id":"d63eed7b-99d5-4ffe-a184-807998d7b851","resolution":{"observed_at":"2026-07-01T12:35:44.145114Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.550291Z","title":null,"venue":null,"work_id":"4eef3bc1-f1d8-4a65-9d2b-5aacfa52674e","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:162ae2091d3aa94e9ad5f77196b332953710668380b413ee885677f6b0b5e646","observation_id":"a4f686f0-3c5f-4308-b650-c74fedf05447","resolution":{"observed_at":"2026-07-07T05:23:21.551627Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.518790Z","title":"Running openclaw safely: identity, isolation, and runtime risk","venue":null,"work_id":"30bba44c-3b96-45c3-a043-c403128e3471","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:da19d53cb05c8360a5d955ce53e2a83feca40460388a8c35efe1a0133b9e5561","observation_id":"4c8f4c13-13ea-4fab-bb35-b363d60ff614","resolution":{"observed_at":"2026-07-07T05:23:21.520391Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.545185Z","title":"Nvidia nemoclaw: Reference stack for running openclaw in openshell","venue":null,"work_id":"71afcc81-b4af-47ba-9d52-0c45c314f86d","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:1793b8c7a83fab86da6bc36d462ed23bc9bcd10687ce209016523a7f5e7396fa","observation_id":"2c531b0c-71ed-45f7-a0a4-2f37cb8e87a8","resolution":{"observed_at":"2026-07-07T05:23:21.546801Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.547795Z","title":"Claudy day: Chaining prompt injection and data exfiltration in claude.ai","venue":null,"work_id":"28c89b95-f1f8-48f6-9994-b968bce5e298","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:40302738d9ea03fe4e9c168868605b8ac66916f0eb744d3af7c9fd0974fd6540","observation_id":"0c54f5cc-6fb2-421d-9015-70a62ad008f7","resolution":{"observed_at":"2026-07-07T05:23:21.549353Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.552381Z","title":"SLSA: Supply-chain levels for software artifacts","venue":null,"work_id":"a037d2d7-9610-40db-82a6-787e548912ac","year":2021},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:5c348f4732cb7c21b5a45b0ce9a6dcf99de57be30b193e83cbab9f2965eadecf","observation_id":"a6aae13d-96ea-42ef-8783-02b44392636e","resolution":{"observed_at":"2026-07-07T05:23:21.554147Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.554962Z","title":"Security (gateway).https://docs.openclaw.ai/, 2026","venue":null,"work_id":"e7254eb4-032b-4b83-98ca-66852084be70","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:3a12db334d82b329396162e2d39adce03679eadbd5548efbdcdcca2e506cfa2c","observation_id":"9bfa8c4c-75c6-4778-82d6-95390a5e7356","resolution":{"observed_at":"2026-07-07T05:23:21.556621Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.524208Z","title":null,"venue":null,"work_id":"16a2ba4c-65a6-4c22-87f4-8036303944de","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:5d408fa1e10c1f02ebc8a4d09a15122ba100687b3109b002bc766936258077fe","observation_id":"a021e2c9-8bb1-4bda-af71-933f3815aa85","resolution":{"observed_at":"2026-07-07T05:23:21.525503Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.540477Z","title":"OW ASP top 10 for large language model applications.https://owasp","venue":null,"work_id":"2cbff28e-a2ba-4fa1-9709-cd88e48aa502","year":2025},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:8ac94f6882618f948778d0a0e27f3c948361117cab9312ce598a2aa4f9404781","observation_id":"c8f4f7a5-8634-4051-a7b3-e90297d4395a","resolution":{"observed_at":"2026-07-07T05:23:21.542199Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.526113Z","title":"OW ASP top 10 for agentic applications.https://genai.owasp.org/ resource/owasp-top-10-for-agentic-applications-for-2026/, 2026","venue":null,"work_id":"e581dd77-8f35-441b-8a84-7e62dbe22ace","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:becadb957bc77ec82aab6785305a143f125ae469684f968ccba5c42e837a86f7","observation_id":"e45d1b88-3aaa-4058-885a-18c244ff9f99","resolution":{"observed_at":"2026-07-07T05:23:21.527644Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.532682Z","title":"Coding agents: A comprehensive survey of automated bug fixing systems and benchmarks","venue":null,"work_id":"5e2ae5ca-05c9-4858-b80a-5418821cffdb","year":2025},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:07cb96acb56b9bb11771e2f1ffa2e361b6852fa6105309c6b5950f53515bfed5","observation_id":"8f095242-0e49-4e3e-9505-a7999fdb5c34","resolution":{"observed_at":"2026-07-07T05:23:21.534612Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2605.16976","last_updated":"2026-05-16T12:53:31Z","snapshot_observed_at":"2026-08-02T19:09:38.060554Z","submitted_at":"2026-05-16T12:53:31Z","title":"Securing LLM Agents Need Intent-to-Execution Integrity","version":1},"cited_work":{"arxiv_id":"2605.16976","doi":null,"metadata_source":"pith","pith_arxiv_id":"2605.16976","snapshot_observed_at":"2026-07-04T15:19:56.827185Z","title":"Securing LLM Agents Need Intent-to-Execution Integrity","venue":"cs.CR","work_id":"27900f2a-078d-425a-9781-07abd85516a6","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2605.16976","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:ea0ff873292207bae9c395195815367b197af4e72213b85f6a3b6e61c177293c","observation_id":"3c0ad7d4-7be4-4a2c-8edc-07ed474961b5","resolution":{"observed_at":"2026-07-01T12:35:44.144513Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.03767","last_updated":"2025-04-11T16:59:05Z","snapshot_observed_at":"2026-08-04T11:49:52.391715Z","submitted_at":"2025-04-02T21:46:02Z","title":"MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits","version":2},"cited_work":{"arxiv_id":"2504.03767","doi":"10.48550/arxiv.2504.03767","metadata_source":"pith","pith_arxiv_id":"2504.03767","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Mcp safety audit: Llms with the model context protocol allow major security exploits","venue":"cs.CR","work_id":"d5c42cc2-8444-459f-bcc5-f36d34de7a47","year":2025},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2504.03767","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:caaa7b2d26cda4a3569954f0eb39435fb380cf7c4fd53fc95189e31c7d73bf45","observation_id":"0d5bd4df-7ea2-4ed4-b803-8c97fcf48342","resolution":{"observed_at":"2026-07-01T12:35:44.121509Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.535378Z","title":"Maddison, and Tatsunori Hashimoto","venue":null,"work_id":"781bfdd7-6389-41c3-be75-b0c4e581b1eb","year":2024},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:940bab29633f00c0f725a15cb4dc2e8230a504d2cdaddf6f7787e17471e84b4c","observation_id":"a618e25f-ce8a-440e-8b4c-bc7caf12edbc","resolution":{"observed_at":"2026-07-07T05:23:21.536753Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.542917Z","title":"SeClaw: Secured personal ai assistant","venue":null,"work_id":"f69a57b5-acf1-40e7-8c1c-4bf889de895e","year":null},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:bfb7446b4e676a291394a9f870d2964f77ffdbb9623340b8781d30aa8aae8f5c","observation_id":"4d417c3c-8727-4def-bdef-738a55776df0","resolution":{"observed_at":"2026-07-07T05:23:21.544537Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.528605Z","title":null,"venue":null,"work_id":"d6cd0d9d-111e-4d8e-a74f-f09c1d1b128a","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:39df4d9a5d5fcae195aa76626b26a27683183d2069f610622408c96cad3f92d3","observation_id":"022a633c-0e79-4eff-976d-3dbd4bc4a8bf","resolution":{"observed_at":"2026-07-07T05:23:21.529927Z","resolver_source":"raw_fallback","status":"parse_uncertain"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.537733Z","title":"Saltzer and Michael D","venue":null,"work_id":"4559c80f-b327-4e4d-a410-6b7ec81e902f","year":1975},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:7160141ed4c78782004635d4ad8bd78e218035220455beca0f7265ae0675e563","observation_id":"128c7f5c-8402-4895-92d3-a4105ec52873","resolution":{"observed_at":"2026-07-07T05:23:21.539122Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.564322Z","title":"Openclaw — personal ai assistant.github, 2026","venue":null,"work_id":"207b7459-3363-4cf0-b6b2-66712b44e17f","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:36984a42b38b6084fc7a3923b7ff2327ac0568fdf2c97fb9c2aa167721b1e0cf","observation_id":"75fbd36b-c2a4-43cb-9569-5d5e430825ff","resolution":{"observed_at":"2026-07-07T05:23:21.565750Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2503.04957","last_updated":"2025-03-06T20:43:14Z","snapshot_observed_at":"2026-07-06T20:48:13.849680Z","submitted_at":"2025-03-06T20:43:14Z","title":"SafeArena: Evaluating the Safety of Autonomous Web Agents","version":1},"cited_work":{"arxiv_id":"2503.04957","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2503.04957","snapshot_observed_at":"2026-07-04T10:59:46.546058Z","title":"Safearena: Evaluating the safety of autonomous web agents","venue":null,"work_id":"4112362f-3fda-4a14-a761-3d5567824aa9","year":2025},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2503.04957","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:b1b4983b753aef3ec5f451d77b5acadcc51c9cc6f4a10dd2704981b9db521be4","observation_id":"75049aa2-db5b-41ba-ae8c-0c534c3b874f","resolution":{"observed_at":"2026-07-01T12:35:44.148105Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.13208","last_updated":"2024-04-19T22:55:23Z","snapshot_observed_at":"2026-08-02T11:48:17.206729Z","submitted_at":"2024-04-19T22:55:23Z","title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","version":1},"cited_work":{"arxiv_id":"2404.13208","doi":"10.48550/arxiv.2404.13208","metadata_source":"pith","pith_arxiv_id":"2404.13208","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","venue":"cs.CR","work_id":"ba941a96-eb3b-48c0-b52c-5e9463085190","year":2024},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2404.13208","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:99bc70b9cce73251fdc95337722eed1019458db65136ef3f98970bc94273d9d9","observation_id":"f5cfd133-5294-43c7-a576-eefe60423d0f","resolution":{"observed_at":"2026-07-01T12:35:44.139809Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2602.10453","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-04T13:39:51.337137Z","title":"arXiv preprint arXiv:2602.10453 , year=","venue":null,"work_id":"16c524eb-7f93-4bcc-bcb4-d30238f9c00a","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:b329fd666b09cf4b431f73014573018ea51490ea28fba7d02ad7482b9268c690","observation_id":"b568f65d-78e7-427b-937b-51875cd5d806","resolution":{"observed_at":"2026-07-01T12:35:44.120350Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.03131","last_updated":"2026-04-03T15:52:36Z","snapshot_observed_at":"2026-07-06T22:52:20.577677Z","submitted_at":"2026-04-03T15:52:36Z","title":"A Systematic Security Evaluation of OpenClaw and Its Variants","version":1},"cited_work":{"arxiv_id":"2604.03131","doi":null,"metadata_source":"pith","pith_arxiv_id":"2604.03131","snapshot_observed_at":"2026-07-03T06:27:42.550738Z","title":"A Systematic Security Evaluation of OpenClaw and Its Variants","venue":"cs.CR","work_id":"22bc6f3d-dd89-4d9d-8993-2ee04896d9ce","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2604.03131","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:1541a9edd9ca85aa5a73dc1294705785c13e9a3f3e9fcaf34144dc231d4609b6","observation_id":"e004d1e8-1c78-4e15-b925-48ccc13fea18","resolution":{"observed_at":"2026-07-01T12:35:44.125751Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.01438","last_updated":"2026-04-04T15:18:43Z","snapshot_observed_at":"2026-07-06T22:51:35.522923Z","submitted_at":"2026-04-01T22:24:24Z","title":"ClawSafety: \"Safe\" LLMs, Unsafe Agents","version":2},"cited_work":{"arxiv_id":"2604.01438","doi":"10.48550/arxiv.2604.01438","metadata_source":"pith","pith_arxiv_id":"2604.01438","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"ClawSafety: \"Safe\" LLMs, Unsafe Agents","venue":"cs.AI","work_id":"65792180-ed14-4f36-a1e6-78f74ed5224d","year":2026},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2604.01438","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:05e865cde27e18f78bc39c177d55269600ccf341ab513eb03d3d61214335452b","observation_id":"29644b9c-1388-481e-8824-bcedde026de9","resolution":{"observed_at":"2026-07-01T12:35:44.133228Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2510.10073","last_updated":"2026-04-14T02:53:37Z","snapshot_observed_at":"2026-07-06T22:32:22.953630Z","submitted_at":"2025-10-11T07:18:12Z","title":"SecureWebArena: A Holistic Security Evaluation Benchmark for LVLM-based Web Agents","version":2},"cited_work":{"arxiv_id":"2510.10073","doi":"10.48550/arxiv.2510.10073","metadata_source":"pith","pith_arxiv_id":"2510.10073","snapshot_observed_at":"2026-08-05T02:49:54.815029Z","title":"SecureWebArena: A Holistic Security Evaluation Benchmark for LVLM-based Web Agents","venue":"cs.CR","work_id":"986db19d-142b-480d-af41-4630c3508025","year":2025},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2510.10073","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:277f3910b25ec316329155e9ebf7b0899928c517bb29fad18209df90c88be424","observation_id":"6d8fb2c5-780e-4420-8260-0c41ba7fd405","resolution":{"observed_at":"2026-07-01T12:35:44.111703Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.584036Z","title":"R-Judge: Benchmarking safety risk awareness for LLM agents","venue":null,"work_id":"836cbb05-51db-4c2e-8ab5-45bf7aab80e5","year":2024},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:b1b3203a792bc2b3146ef481435ffbada7c6e1da866f44705e0eaf0b5abc3734","observation_id":"81371c37-faa0-4534-8242-97af9ac154da","resolution":{"observed_at":"2026-07-07T05:23:21.586086Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-07T05:23:21.521360Z","title":"InjecAgent: Benchmarking indirect prompt injections in tool-integrated large language model agents","venue":null,"work_id":"b41c0893-956e-4037-83cd-a769d6c36533","year":2024},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:2118fb26e383e3389e3250dbe87ed5ef5c78ae221228cd5e330c99300c8937ca","observation_id":"72f6a7bd-1506-4b72-b096-2e03dcc4ccac","resolution":{"observed_at":"2026-07-07T05:23:21.523289Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2410.02644","last_updated":"2025-05-30T03:50:33Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2024-10-03T16:30:47Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","version":4},"cited_work":{"arxiv_id":"2410.02644","doi":"10.48550/arxiv.2410.02644","metadata_source":"pith","pith_arxiv_id":"2410.02644","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","venue":"cs.CR","work_id":"15ab4a69-85ab-4295-839d-080a2cd3e7aa","year":2024},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2410.02644","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:5deed198583571fc762fde5a0e01d51ab3985c063e8ab847838a7fb9fe73c882","observation_id":"52618e1e-d08c-4721-9348-cff9c83832eb","resolution":{"observed_at":"2026-07-01T12:35:44.115038Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2508.12752","last_updated":"2025-08-18T09:26:14Z","snapshot_observed_at":"2026-08-05T19:21:34.223685Z","submitted_at":"2025-08-18T09:26:14Z","title":"Deep Research: A Survey of Autonomous Research Agents","version":1},"cited_work":{"arxiv_id":"2508.12752","doi":"10.48550/arxiv.2508.12752","metadata_source":"pith","pith_arxiv_id":"2508.12752","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Deep research: A survey of autonomous research agents.arXiv preprint arXiv:2508.12752, 2025a","venue":"cs.IR","work_id":"94fabb43-10d5-4689-a4ff-8b7caab0406c","year":2025},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2508.12752","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:e52e9a6d6b94c93b813381f052837f04a6dd8e33fb30fc6462139da037d994be","observation_id":"84cd81f1-3234-471e-a3b9-7b5e116226cf","resolution":{"observed_at":"2026-07-01T12:35:44.109156Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2412.14470","last_updated":"2025-05-20T05:58:23Z","snapshot_observed_at":"2026-08-06T12:35:19.109481Z","submitted_at":"2024-12-19T02:35:15Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","version":2},"cited_work":{"arxiv_id":"2412.14470","doi":"10.48550/arxiv.2412.14470","metadata_source":"pith","pith_arxiv_id":"2412.14470","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Agent-SafetyBench: Evaluating the Safety of LLM Agents","venue":"cs.CL","work_id":"96afb8b9-0e7e-442c-93b1-6638599fc041","year":2024},"citing_paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-07-01T01:55:40.954429Z"},"links":{"cited_paper":"/paper/2412.14470","citing_paper":"/paper/2606.30755"},"observation_digest":"sha256:13710b4f6242337a5d8762f345d07114b5dd99a6289a27a916ab879c1388764f","observation_id":"a9c00921-aa68-4452-96e6-705831a906c8","resolution":{"observed_at":"2026-07-01T12:35:44.141583Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-07-14T18:20:24.185748+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-14T18:20:24.185748+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2606.30755","last_updated":"2026-06-29T18:00:45Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-07-07T00:04:34.491408Z","submitted_at":"2026-06-29T18:00:45Z","title":"Understanding and Evaluating Claw-like Agent Security Through a Computer-Systems Lens"},"reference_resolution":{"displayed":41,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":1,"unresolved":3,"verified_exact":15,"verified_fuzzy":22},"total_outbound_references":41},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"thesis":"As of 7 August 2026, this Paper Citation Record lists 41 of 41 outbound references and 0 inbound Pith citation observations for arXiv:2606.30755."}