Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-07-12T02:36:01.385664Z
Paper Citation Record · LEDGER
As of 10 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 0 inbound Pith citation observations for arXiv:2607.03423.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-07-12T02:36:01.385664Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-10T06:31:04.303077+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
29 of 29 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 6d9cb9c1-b79c-40c4-838d-4cf32f3feb7c · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Toolformer: Language Models Can Teach Themselves to Use Tools
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation a68f4694-6298-4351-821a-80afb2485982 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Re- act: Synergizing reasoning and acting in language models
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 36e0c54d-935b-42bc-bee8-5d557df68c6e · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Gorilla: Large Language Model Connected with Massive APIs
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5c402414-357a-4d53-9476-43d4d8b6bf1b · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIs
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b5a3a0f2-946c-4067-9ddb-e41f902da1a3 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Github Copilot coding agent, 2025
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f421f7ac-05cd-49b3-88eb-ccf978dbcd95 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Claude code, 2025
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation de600818-f8b1-408b-a802-45bc1eba284a · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Codex CLI, 2025
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 558a1d8f-b0fc-4e2a-ba14-2dfe0b0345d1 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies STAC:Wheninnocenttools form dangerous chains to jailbreak LLM agents
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5a04ae7a-07b4-4192-995b-fa3fb5f7a616 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies ChainFuzzer: Greybox fuzzing for workflow- levelmulti-toolvulnerabilitiesinLLMagents.arXiv preprint arXiv:2603.12614, 2026
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation efc53ed8-f136-4e2d-918b-91fa75e54067 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies MSA: A cross-MCP privacy attack via memory exfiltration of large language models
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bcc55e16-145f-454f-b06a-4bf6ca00533a · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Silent egress: When implicit prompt injection makes LLM agents leak without a trace.arXiv preprint arXiv:2602.22450, 2026
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 68b40d21-9dac-4a58-98c3-49686626e3c4 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies MCP-ITP: An automated framework for implicit tool poisoning in MCP.arXiv preprint arXiv:2601.07395, 2026
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fe7c50c2-3ea6-4b54-98a0-7f8cdeae2fc4 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Model context protocol threat modeling and analyzing vulnerabilities to prompt injection with tool poisoning.arXiv preprint arXiv:2603.22489, 2026
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 214fc414-9d7e-436d-90b6-30b44ed5360c · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies MCP security bench (MSB): Benchmarking attacks against model context protocol in LLM agents.arXiv preprint arXiv:2510.15994, 2025
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 20a33cf9-c714-4349-a5a9-0d2250ac505b · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Function calling and other API updates,
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d271584e-7708-4a11-a7b8-deae2cb74ee8 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Blog post, 13 June 2023
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 858a85f1-9fff-424c-b8cb-1c98d61a10a3 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies LangChain, 2022
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 93ceb349-420e-434e-95df-ec37ac343fb0 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation e2188785-cb14-4baa-9a43-48811239879c · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies LaPadula
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d49cba52-79e1-4ddc-867b-b776ba068f74 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Microsoft frontier governance framework,
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8892f3d7-4cbd-4fbd-8ab9-c4b3d1548f1e · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Accessed 2026-06-26
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d63d6aee-775b-4bb6-b946-fd5aef0097a0 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Frontier safety framework, ver- sion 3.0, 2025
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fba40229-381d-41e6-abeb-6fefa49b3ae1 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Responsible scaling policy, 2025
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bd88f5f7-4419-4ee7-8b06-f88514c8bf5b · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Preparedness framework, version 2, 2025
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c681967a-0bd6-4856-8c69-a29e87571757 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Regulation (EU) 2024/1689 of the euro- pean parliament and of the council laying down harmonised rules on artificial intelligence (Arti- ficial Intelligence Act)
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 41831636-8752-48e9-971f-3c3a47e6177f · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Managing misuse risk for dual-use foundation mod- els
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cc807357-c607-4ff9-a067-137e174a4431 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies International AI safety report 2026
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8c1c4471-e678-41dd-81b0-679306396f64 · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Model evaluation for extreme risks
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8a3b59b2-3665-463d-ba68-61b9d01f5ded · outbound
Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Evaluating Language-Model Agents on Realistic Autonomous Tasks
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.