Pith. sign in

Paper Citation Record · LEDGER

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure

As of 13 August 2026, this Paper Citation Record lists 25 of 25 outbound references and 0 inbound Pith citation observations for arXiv:2607.08288.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.08288 v1

Coverage vector

measured 25 of 25 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-07-10T10:00:19.465944Z

measured 25 of 25 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-13T06:32:02.005865+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

25 of 25 outbound references displayed

  • verified exact10
  • verified fuzzy11
  • unresolved0
  • parse uncertain0
  • malformed identifier3
  • metadata mismatch1

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation df37b3eb-ce39-4be2-9471-8fc288a5d032 · outbound

This paper cites Disrupting the First Reported AI- Orchestrated Cyber Espionage Campaign.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Disrupting the First Reported AI- Orchestrated Cyber Espionage Campaign

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.334550Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:9b1dfc47f7654ca35e35db5c8e3c12fab7f3cf43d839c7446307680c5b98a1c5

Observation 26f0d3c0-3b9a-4009-84ea-e8c35fa92322 · outbound

This paper cites GPT-4.1 Model.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure GPT-4.1 Model

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.329492Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:485059a13e239da30db89f70c47607a169284fa1837436aefe93dc192dd579b5

Observation 5c741c11-12c6-45fa-8a31-b6510f4eefe6 · outbound

This paper cites A Survey of Cyber- Physical Attacks and Detection Methods in Smart Water Distribution Systems.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure A Survey of Cyber- Physical Attacks and Detection Methods in Smart Water Distribution Systems

Reference 3

Resolution
metadata mismatch
arxiv_id, observed 2026-07-10T10:07:01.009963Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:8f35063c2c602bf81e0f77468089d4df6b857e51e4c781a6afda061685e1cc7d

Observation fa7228e2-6d23-4f38-83f0-68f034ac62f9 · outbound

This paper cites L333, pp.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure L333, pp

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.315735Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:fcaa723c4ddc1f5644040959aef0305c6693f4deee6230a35c96df99b239d930

Observation febf772b-be26-49e0-8ded-dba75a62b10f · outbound

This paper cites Stand-der- Technik-Bibliothek.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Stand-der- Technik-Bibliothek

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.332849Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:4320ffc63be5d6baa48fab0d4da7485bae932d5e7e1bf92989fae9dc55ca8709

Observation b08a8005-4a62-41db-882d-066b98cb3b51 · outbound

This paper cites Model Context Protocol.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Model Context Protocol

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.331175Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:79b539863363e04c543e6b42006e7e3a1485ff1d6cb34ec9c3419b101c551ca2

Observation 7b126e55-21a9-4bd1-bd22-509c52b7b299 · outbound

This paper cites Towards the Automation of Attack Graph- Based Risk Assessment with OSCAL.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Towards the Automation of Attack Graph- Based Risk Assessment with OSCAL

Reference 7

Resolution
malformed identifier
raw_fallback, observed 2026-07-10T10:07:01.327943Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:466e12734efe76a453366411d9dc2f1cb225b5b2e9f2fe740647b32e08f55309

Observation 8adcf2a2-d0b5-4e03-8462-013ca9224f09 · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 8

Resolution
malformed identifier
local_arxiv, observed 2026-07-10T10:07:01.026230Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:5675388f1df6f16fdfa02da1ab5d00e6a9854deaea8b31fa51c2bdf77f82fa76

Observation 90a3c1ad-2af0-441e-b20b-d81fffadf249 · outbound

This paper cites Integrated Risk Scoring and Exploit Prediction for Cyber-Physical Power System Vul- nerabilities.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Integrated Risk Scoring and Exploit Prediction for Cyber-Physical Power System Vul- nerabilities

Reference 9

Resolution
verified exact
doi, observed 2026-07-10T10:07:00.828901Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:87e2d86aa8e58d38b6fe87e24ec3867971cfb24dfa013b4df836d2dfcdd6cddd

Observation 8da4f9a9-5d24-4d60-8fb0-3347bdf67003 · outbound

This paper cites CISA Stakeholder-Specific Vulnerability Categorization Guide.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure CISA Stakeholder-Specific Vulnerability Categorization Guide

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.324414Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:895aa92bd5ba6ea4f99de8ccf597333230ccbe9b1b5694d53c39e2de16e27983

Observation c339eb63-7de1-4fe0-b56e-47cfd307deb8 · outbound

This paper cites Common Vulnerability Scoring System Version 4.0: User Guide.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Common Vulnerability Scoring System Version 4.0: User Guide

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.322676Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:a76871466054982113b776aba958e724bb1ff89c24617336a3973bfba59c3a0e

Observation be5f3483-8945-4a24-929a-ad2c900d4c9b · outbound

This paper cites Towards an open standard for assessing the severity of robot security vulnerabilities, the Robot Vulnerability Scoring System (RVSS).

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Towards an open standard for assessing the severity of robot security vulnerabilities, the Robot Vulnerability Scoring System (RVSS)

Reference 12

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:00.818378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:fbf16bfd5588f8d9e7e3796026d2d220656fbe286f6a3f73131d49d360aef1b5

Observation 29fe8337-bf3f-40f9-bdeb-a1c05e73ca34 · outbound

This paper cites Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritiza- tion.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritiza- tion

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-07-10T10:07:00.826747Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:b05a9440f5ad07d49d955b16b0dab6bd6b971a387ba7a232b27a2ca4ce0748a4

Observation 1156a84b-c9dc-4c82-837e-d50a2e668b1c · outbound

This paper cites Dynamic Vulnerability Severity Cal- culator for Industrial Control Systems.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Dynamic Vulnerability Severity Cal- culator for Industrial Control Systems

Reference 14

Resolution
verified exact
doi, observed 2026-07-10T10:07:00.823892Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:329e08e02099f7ec8daeafd1d210827d82177c6ad26acbccd4e8fea8f87054dd

Observation bf364a0d-31b6-4248-be1c-0edb854a3b54 · outbound

This paper cites A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges

Reference 15

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.023608Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:71f0c18ca5d27ae80e18d97754543465073a261e88252ee429406932dbdb4465

Observation 647ce3c4-4ed0-4a20-aa43-aa0fa1f23446 · outbound

This paper cites Exploit Prediction Scoring System (EPSS).

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Exploit Prediction Scoring System (EPSS)

Reference 17

Resolution
verified exact
doi, observed 2026-07-10T10:07:00.817677Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:a85647f4b6b7ba6d8839cbe6dee8fbfe475018c97a6aeef3041d193b3145d280

Observation bb56844d-c1bf-4f55-8b45-0a7b549d0254 · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 18

Resolution
malformed identifier
local_arxiv, observed 2026-07-10T10:07:00.827231Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:d34b11535614a373042c568f54e77bb6da5ad37ffec9e275c51e4269ef885f5d

Observation ee385496-f361-4292-8678-624262320a64 · outbound

This paper cites AgCyRAG: an Agentic Knowledge Graph based RAG Framework for Automated Secu- rity Analysis.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure AgCyRAG: an Agentic Knowledge Graph based RAG Framework for Automated Secu- rity Analysis

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.319095Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:fb902660f7befdc36ea2337707f65f421452cd428ddd1a2179c6ee6f27edf57e

Observation 2362171a-444d-4a8e-bfdc-951d4346d8ee · outbound

This paper cites Agentic AI for Autonomous Defense in Software Supply Chain Secu- rity: Beyond Provenance to Vulnerability Mitigation.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Agentic AI for Autonomous Defense in Software Supply Chain Secu- rity: Beyond Provenance to Vulnerability Mitigation

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-07-10T10:07:01.020853Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:bf716bd1777e8fbaa4e4cb03cdef88265772c9ffad04414ed23f967322452ae8

Observation 37c7a9aa-96dd-4d1f-950b-8df909cebb0e · outbound

This paper cites Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.012931Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:9ba50a73e6b370619f3de0effa080c589cd56cf3441eaeeeef69a0f313156626

Observation f95f48ac-37b7-4c98-9eac-80bdac932ef6 · outbound

This paper cites ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control

Reference 22

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.028882Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:a33f5e14000c05dd40b54d44ed98589da046ca998e3486202d9572a48a93db3b

Observation e362f7aa-c3ab-4325-bdd6-448acfe45ccd · outbound

This paper cites Industrial Cybersecurity.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Industrial Cybersecurity

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.317373Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:e09c4a9d7bdf2eb57a4ac8e02703538f04c90fb2ad4056a86464f82f4db2cdd9

Observation 9ca6bb2c-5381-4667-8b8c-836317303042 · outbound

This paper cites Using LLMs for Security Advisory Investigations: How Far Are We?.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Using LLMs for Security Advisory Investigations: How Far Are We?

Reference 24

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.015449Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:05272c158593e42c9b9cb913be5f5265668b8a3f156844d05049e487f772a8e2

Observation 65d3bbbb-724f-4d8a-9810-e8586f127e2a · outbound

This paper cites Binding Operational Directive 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Binding Operational Directive 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.320861Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:4cc5950135b6e433021569a01071e604f3037b1eff496be575569513ee2ed9de

Observation 4692d70e-0fea-4e64-9e1c-91f062d45c8a · outbound

This paper cites Guide to Industrial Control Systems (ICS) Security.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Guide to Industrial Control Systems (ICS) Security

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.326063Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:52a1673a667736fdffa4300032606444b937ea4479fcfc961e7a7ff2d276529e

Pith citing papers

No inbound Pith citation observations are available.