Pith. sign in

Paper Citation Record · LEDGER

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies

As of 10 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 0 inbound Pith citation observations for arXiv:2607.03423.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.03423 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-07-12T02:36:01.385664Z

measured 29 of 29 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-10T06:31:04.303077+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

29 of 29 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved29
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 6d9cb9c1-b79c-40c4-838d-4cf32f3feb7c · outbound

This paper cites Toolformer: Language Models Can Teach Themselves to Use Tools.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Toolformer: Language Models Can Teach Themselves to Use Tools

Reference 1

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:c5572543c3719ee2c1b6448127595420a63821aa80d3227895d3c01fb1089a5f

Observation a68f4694-6298-4351-821a-80afb2485982 · outbound

This paper cites Re- act: Synergizing reasoning and acting in language models.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Re- act: Synergizing reasoning and acting in language models

Reference 2

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:a6f6a0c20bc6a3fa4e4e543d729293dfe010c8e5837d1b2e45486d065bec87b1

Observation 36e0c54d-935b-42bc-bee8-5d557df68c6e · outbound

This paper cites Gorilla: Large Language Model Connected with Massive APIs.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Gorilla: Large Language Model Connected with Massive APIs

Reference 3

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:3fef4c1d567f69c65de6e347ad3ead842d40d33dd444c14d695437513b090acd

Observation 5c402414-357a-4d53-9476-43d4d8b6bf1b · outbound

This paper cites ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIs.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIs

Reference 4

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:716385adb0fa624c9d5b8f9a9600cc326f27085e7ef68a1822be9ee31143beea

Observation b5a3a0f2-946c-4067-9ddb-e41f902da1a3 · outbound

This paper cites Github Copilot coding agent, 2025.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Github Copilot coding agent, 2025

Reference 5

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:cedf5300bb0072b6878b0e6d59500c7390402a1b0a6638e0f20b6ad4c35c22de

Observation f421f7ac-05cd-49b3-88eb-ccf978dbcd95 · outbound

This paper cites Claude code, 2025.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Claude code, 2025

Reference 6

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:d0d40ee4fe4a2a100951243178e0d84c892ae4279fb87d9dd6041afd8d9a16f3

Observation de600818-f8b1-408b-a802-45bc1eba284a · outbound

This paper cites Codex CLI, 2025.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Codex CLI, 2025

Reference 7

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:2bd3842fe3c4a0736506026084629616cf300099d30de6f208af4ac6bf1daa89

Observation 558a1d8f-b0fc-4e2a-ba14-2dfe0b0345d1 · outbound

This paper cites STAC:Wheninnocenttools form dangerous chains to jailbreak LLM agents.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies STAC:Wheninnocenttools form dangerous chains to jailbreak LLM agents

Reference 8

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:8058caabc4fa56a1f7d15a51cec08721612ec4c10a6b607b828a1f1734313024

Observation 5a04ae7a-07b4-4192-995b-fa3fb5f7a616 · outbound

This paper cites ChainFuzzer: Greybox fuzzing for workflow- levelmulti-toolvulnerabilitiesinLLMagents.arXiv preprint arXiv:2603.12614, 2026.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies ChainFuzzer: Greybox fuzzing for workflow- levelmulti-toolvulnerabilitiesinLLMagents.arXiv preprint arXiv:2603.12614, 2026

Reference 9

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:8e30ec74e7a59f73e9495bdaa32caceeaaa26913ba73f25d014114564996accc

Observation efc53ed8-f136-4e2d-918b-91fa75e54067 · outbound

This paper cites MSA: A cross-MCP privacy attack via memory exfiltration of large language models.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies MSA: A cross-MCP privacy attack via memory exfiltration of large language models

Reference 10

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:0e659f309c7c05b213f04ae442eaf09b7e6c64a57652d4da28175741ab2e10e4

Observation bcc55e16-145f-454f-b06a-4bf6ca00533a · outbound

This paper cites Silent egress: When implicit prompt injection makes LLM agents leak without a trace.arXiv preprint arXiv:2602.22450, 2026.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Silent egress: When implicit prompt injection makes LLM agents leak without a trace.arXiv preprint arXiv:2602.22450, 2026

Reference 11

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:c3584bd6f4243cda06fd4576de96d7c97da73b19f92d0e2cd74c82b89df2efa0

Observation 68b40d21-9dac-4a58-98c3-49686626e3c4 · outbound

This paper cites MCP-ITP: An automated framework for implicit tool poisoning in MCP.arXiv preprint arXiv:2601.07395, 2026.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies MCP-ITP: An automated framework for implicit tool poisoning in MCP.arXiv preprint arXiv:2601.07395, 2026

Reference 12

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:0b2962effd9072e140486fdfe4e9388e635d52316e6d491841e0b889e11e84f8

Observation fe7c50c2-3ea6-4b54-98a0-7f8cdeae2fc4 · outbound

This paper cites Model context protocol threat modeling and analyzing vulnerabilities to prompt injection with tool poisoning.arXiv preprint arXiv:2603.22489, 2026.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Model context protocol threat modeling and analyzing vulnerabilities to prompt injection with tool poisoning.arXiv preprint arXiv:2603.22489, 2026

Reference 13

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:4a12fc4043604c1f7be7a7be80a16c8116893cbe79016526e15fad09a0febacc

Observation 214fc414-9d7e-436d-90b6-30b44ed5360c · outbound

This paper cites MCP security bench (MSB): Benchmarking attacks against model context protocol in LLM agents.arXiv preprint arXiv:2510.15994, 2025.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies MCP security bench (MSB): Benchmarking attacks against model context protocol in LLM agents.arXiv preprint arXiv:2510.15994, 2025

Reference 14

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:c41b59b5cc55cc40b29433ee5c04be6cd184fa30569772163f9b3200d7474399

Observation 20a33cf9-c714-4349-a5a9-0d2250ac505b · outbound

This paper cites Function calling and other API updates,.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Function calling and other API updates,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:3497cc6c4b756415168b20abf028f94f96cb8e64e97525b0a45c044d0771c56e

Observation d271584e-7708-4a11-a7b8-deae2cb74ee8 · outbound

This paper cites Blog post, 13 June 2023.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Blog post, 13 June 2023

Reference 16

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:e99b38b551fd72ee3197ce4f905649d14a72afb51b8af12859461efb4830febb

Observation 858a85f1-9fff-424c-b8cb-1c98d61a10a3 · outbound

This paper cites LangChain, 2022.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies LangChain, 2022

Reference 17

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:e6929e52e4024633a592e59e8b6ba39775f06279c0247dd6977ab16b85bfd372

Observation 93ceb349-420e-434e-95df-ec37ac343fb0 · outbound

This paper cites AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation

Reference 18

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:f524ef470f0d5c4b74faac984167f6d0e6625a4cf74baeb972f44fddf413608b

Observation e2188785-cb14-4baa-9a43-48811239879c · outbound

This paper cites LaPadula.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies LaPadula

Reference 19

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:606e2493bd645180ad39ba59b6e440e41c1d95a8ce172fbbfaa75f93b4d24855

Observation d49cba52-79e1-4ddc-867b-b776ba068f74 · outbound

This paper cites Microsoft frontier governance framework,.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Microsoft frontier governance framework,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:2ee4a448e134f156dcacf26587ea6c1f45023bebd9413196e0d0829459528aea

Observation 8892f3d7-4cbd-4fbd-8ab9-c4b3d1548f1e · outbound

This paper cites Accessed 2026-06-26.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Accessed 2026-06-26

Reference 21

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:ecea0d7d1d72fb7e8fd1326b4f6aa3e84a4448bef0cc2df14a8e4c7e71e0eff3

Observation d63d6aee-775b-4bb6-b946-fd5aef0097a0 · outbound

This paper cites Frontier safety framework, ver- sion 3.0, 2025.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Frontier safety framework, ver- sion 3.0, 2025

Reference 22

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:62e902b49c3975860934e09e1dd5e22ca9de62c88e4bfb09ef3d687c68ef85c4

Observation fba40229-381d-41e6-abeb-6fefa49b3ae1 · outbound

This paper cites Responsible scaling policy, 2025.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Responsible scaling policy, 2025

Reference 23

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:7e281707062afd77973eca16e02935e28a98f33453e0df7cfecbaef5d12b3d8b

Observation bd88f5f7-4419-4ee7-8b06-f88514c8bf5b · outbound

This paper cites Preparedness framework, version 2, 2025.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Preparedness framework, version 2, 2025

Reference 24

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:5a4d51dfddadd4fee22d730916f49d5795ecce8f370207c4d0e68e8cc0a11bd5

Observation c681967a-0bd6-4856-8c69-a29e87571757 · outbound

This paper cites Regulation (EU) 2024/1689 of the euro- pean parliament and of the council laying down harmonised rules on artificial intelligence (Arti- ficial Intelligence Act).

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Regulation (EU) 2024/1689 of the euro- pean parliament and of the council laying down harmonised rules on artificial intelligence (Arti- ficial Intelligence Act)

Reference 25

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:2496af45d65ff7841474999bb3de42a73d0c18c3258517ceb138fa7b4affcc3b

Observation 41831636-8752-48e9-971f-3c3a47e6177f · outbound

This paper cites Managing misuse risk for dual-use foundation mod- els.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Managing misuse risk for dual-use foundation mod- els

Reference 26

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:0908bf5c23fcbd5335f2308659117a4a7376b1af24ea3ee3854f1b0af232e1ab

Observation cc807357-c607-4ff9-a067-137e174a4431 · outbound

This paper cites International AI safety report 2026.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies International AI safety report 2026

Reference 27

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:d0e5ced84f563b2ffc6c67607bc7d7cf04b5a8f47da885a3d4e89b86131e2c66

Observation 8c1c4471-e678-41dd-81b0-679306396f64 · outbound

This paper cites Model evaluation for extreme risks.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Model evaluation for extreme risks

Reference 29

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:1c9b553c109254be384dd794bbf9e62b792ca6498eaee97f0ed8344a745aefdd

Observation 8a3b59b2-3665-463d-ba68-61b9d01f5ded · outbound

This paper cites Evaluating Language-Model Agents on Realistic Autonomous Tasks.

Securing Multi-Tool AI Agent Chains With Dynamic, Real-Time Compositional Policies Evaluating Language-Model Agents on Realistic Autonomous Tasks

Reference 30

Resolution
unresolved
no resolver link, observed 2026-07-12T02:36:01.385664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-12T02:36:01.385664Z digest=sha256:34ad5dfa55c2b83959b5dd28d00ef6de0fcc344ebd76455d7fb169167f611df5

Pith citing papers

No inbound Pith citation observations are available.