Pith. sign in

Paper Citation Record · LEDGER

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation

As of 20 August 2026, this Paper Citation Record lists 33 of 33 outbound references and 1 inbound Pith citation observation for arXiv:2607.13987.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.13987 v1

Coverage vector

measured 33 of 33 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-02T03:09:54.394990Z

measured 34 of 34 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-20T06:33:59.587034+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-11T14:49:41.241416Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-11T14:49:41.608258Z

Reference resolution

33 of 33 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved33
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 30ddc63f-f447-43b0-8bc8-db7527c4810d · outbound

This paper cites Guyon and A.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Guyon and A

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:53.917558Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:53.917558Z digest=sha256:b37ce0f87ccbd2f13e99b2f2e8128bf864bf73faa41145dfc6ff89222aa6d590

Observation b9aad8ef-51c0-4ad8-91ab-5bb70f749568 · outbound

This paper cites , title =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation , title =

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.007177Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.007177Z digest=sha256:53ca6979437c2b660640bc3dc81f5622408a2db84f5b9bb37164fb00f7bc9b54

Observation 52095056-7f70-4e63-8178-5e5fa55a1d5d · outbound

This paper cites an unresolved cited work.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Unresolved cited work

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.061130Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.061130Z digest=sha256:f5ba0a38380fc0ac5cb70b473495094ac198287a0684d281dde96444c5c11c06

Observation 0e3f9fb4-66ce-4b78-bd29-726a14125654 · outbound

This paper cites Proceedings of the 33rd USENIX Security Symposium (USENIX Security) , year =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Proceedings of the 33rd USENIX Security Symposium (USENIX Security) , year =

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.150913Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.150913Z digest=sha256:00996074c6fb1665c26fa746da36b61ea27374deb2688e38fe46739a19595adf

Observation 388101da-b2d8-4c3c-8e68-9124abb3a0bb · outbound

This paper cites Proceedings of the 34th USENIX Security Symposium (USENIX Security) , year =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Proceedings of the 34th USENIX Security Symposium (USENIX Security) , year =

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.189011Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.189011Z digest=sha256:9b4d65d90925777106d42dac5760041dad9dae7b064ea5304491c4366e1fbc9b

Observation 9259de3b-2776-4f3a-a675-6817dc4777d3 · outbound

This paper cites Proceedings of the Network and Distributed System Security Symposium (NDSS) , year =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Proceedings of the Network and Distributed System Security Symposium (NDSS) , year =

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.270130Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.270130Z digest=sha256:bfa068fd95d64dd5707b8f3ae29b04b51cc7b0831a7dffcf7ef7efd23ac29622

Observation abb8d95e-c764-49fe-b5a2-e2d1c2109961 · outbound

This paper cites Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.333431Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.333431Z digest=sha256:3319c9f401860657e6144d6761a7aab14eda05626770fa0c818c072d37690742

Observation 9ce722e2-5e25-48b1-9c5e-670ac68c29dd · outbound

This paper cites Exploiting LLM Agent Supply Chains via Payload-less Skills.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Exploiting LLM Agent Supply Chains via Payload-less Skills

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.337040Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.337040Z digest=sha256:bff9b338324abfa7670ac5ebb9a645a95b8f025636b38156bc54d827e40abd52

Observation 67690c3c-b8db-4c52-b2f0-3443d6458299 · outbound

This paper cites Proceedings of the 17th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA) , year =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Proceedings of the 17th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA) , year =

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.339679Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.339679Z digest=sha256:de7a382bcfccb8f406e73445a54ed4dd98d36e962e6aaba22f53834573d47ede

Observation 9268a0fd-d6dd-4bee-aa51-250df6bf28fb · outbound

This paper cites Proceedings of the 2025 Conference on Applied Machine Learning for Information Security , pages =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Proceedings of the 2025 Conference on Applied Machine Learning for Information Security , pages =

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.341854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.341854Z digest=sha256:f87e8ed010e68c0052c2f9c5ddf9e71f36b5b702507988ea6d9d3acb32b82533

Observation a5301f39-d432-4ca5-a328-985f9cbe5f89 · outbound

This paper cites SoK: Taxonomy of Attacks on Open-Source Software Supply Chains , year=.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation SoK: Taxonomy of Attacks on Open-Source Software Supply Chains , year=

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.344377Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.344377Z digest=sha256:7bf51bf810e1535e31e02d60ec00fb8f3352d0168dea497765d510a4047607a3

Observation 4f6d58fa-e1b4-4a3f-8350-2097ac690d16 · outbound

This paper cites and Wan, Sheng and Zhang, Sheng and Lee, Wang-Chien and Sima, Xiaoyuan and Zhao, Siyuan and Wang, Chi , title =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation and Wan, Sheng and Zhang, Sheng and Lee, Wang-Chien and Sima, Xiaoyuan and Zhao, Siyuan and Wang, Chi , title =

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.346647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.346647Z digest=sha256:bb7f32651ecdbcc0ef34420a208962e3c76cff2d8fbb135a1af3d35a41f071fc

Observation 172a5431-174e-4adb-9b4a-ddf5cd61d6c5 · outbound

This paper cites and Cao, Yuan , title =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation and Cao, Yuan , title =

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.348820Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.348820Z digest=sha256:618762601e9a369da06f7110fc5220cb9d2c6dab8178be0ca542b84cf020e791

Observation fdabc139-32d9-41a8-89c4-3c5a5b6d6cab · outbound

This paper cites Toolformer: Language Models Can Teach Themselves to Use Tools , booktitle =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Toolformer: Language Models Can Teach Themselves to Use Tools , booktitle =

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.350999Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.350999Z digest=sha256:23e040b3b687ba13b3cc730804ec2f6409566af4751b3881cbb2411d6735d583

Observation 51a23ef0-6532-4acf-bf2a-255e4f8e591f · outbound

This paper cites an unresolved cited work.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Unresolved cited work

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.353743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.353743Z digest=sha256:9216e12e04c816698ffd7838f997bcbf2a5174c1deefa8a409ab0490f55b30dd

Observation fa410b31-30ab-4d70-a298-53c5888041e8 · outbound

This paper cites an unresolved cited work.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Unresolved cited work

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.355900Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.355900Z digest=sha256:3af3cf4a274efceacb4d43bfc18e7e2379dde77be27f059b17f141c40c3e18a8

Observation 9d9708b3-2ca0-4556-8f33-aabd2631319e · outbound

This paper cites an unresolved cited work.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Unresolved cited work

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.358022Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.358022Z digest=sha256:725f678f085cd64797afb39ffe27b4cb9ba425230ee778d884edb819267c2194

Observation fd5ba0f2-b10e-4120-908e-d542760ddc2c · outbound

This paper cites 34th USENIX Security Symposium (USENIX Security 25) , year =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation 34th USENIX Security Symposium (USENIX Security 25) , year =

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.360478Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.360478Z digest=sha256:459e73869262c9d6650a1316380b9633f94765b423bcbec5c40b63b543b173ee

Observation 4809838a-1656-4e00-8094-98a7d0bc50e6 · outbound

This paper cites an unresolved cited work.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Unresolved cited work

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.362731Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.362731Z digest=sha256:05619e0c18e5f2a8e1f34ed232aa0f73b5755ef20d743538ace4f3322fd759ea

Observation e5a13136-67f7-4ca9-8012-9867b7ce4a18 · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.365075Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.365075Z digest=sha256:178e7ffd8f6e3afb9cb36151fca5fd1850c21232a4add90ade10230667eb42aa

Observation 2fc6fcd8-e73d-462c-b431-4516ccef9b12 · outbound

This paper cites AgentBound: Securing Execution Boundaries of AI Agents , journal =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation AgentBound: Securing Execution Boundaries of AI Agents , journal =

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.367228Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.367228Z digest=sha256:a36bbe72593f4cdb704ab46db0d45ff1eaba6df3109fd4d2c916e3ad0eaa467d

Observation b0ce20aa-81d0-4eac-aff8-50b791f27d1f · outbound

This paper cites A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.369710Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.369710Z digest=sha256:2a7e55bf2eff75e8b96aaf4ad61af4a7813ad484530cb3666ed7474d7bb7452d

Observation edae0d6f-8007-43b2-abd5-9673688d6321 · outbound

This paper cites Proceedings of the ACM CAIS Workshop on Agent Skills (AgentSkills) , year =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Proceedings of the ACM CAIS Workshop on Agent Skills (AgentSkills) , year =

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.372196Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.372196Z digest=sha256:626a64fbced23e1541bee87b29a4df919cf9f92de257eaaf7edd5c6538768984

Observation 6dc4492f-926a-4a0e-b069-6d77ce5c969a · outbound

This paper cites an unresolved cited work.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Unresolved cited work

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.374360Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.374360Z digest=sha256:866dc3cddf1f1110d9672513f9f236ee70264709bbc5096851516bac23fec708

Observation 0291c510-1360-42f9-8083-ef3ed6123e8f · outbound

This paper cites and Wan, Sheng and Zhang, Sheng and Lee, Wang-Chien and Sima, Xiaoyuan and Zhao, Siyuan and Wang, Chi , title =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation and Wan, Sheng and Zhang, Sheng and Lee, Wang-Chien and Sima, Xiaoyuan and Zhao, Siyuan and Wang, Chi , title =

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.376508Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.376508Z digest=sha256:d054ff2174ee266eae5296846a1bfe1601d80bc9509d8b99cf869bac56f5c3dc

Observation 47b03463-4333-4231-8239-36b4056d2825 · outbound

This paper cites Preprints.org , year =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Preprints.org , year =

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.378644Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.378644Z digest=sha256:9e30f0f3d872b86a8c38887f96f30f26951882562729212f598fd416c3badde1

Observation a547c4f5-08ae-495c-850b-d583f85f4441 · outbound

This paper cites SkillsBench: Benchmarking How Well Agent Skills Work Across Diverse Tasks.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation SkillsBench: Benchmarking How Well Agent Skills Work Across Diverse Tasks

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.380836Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.380836Z digest=sha256:acf3d1db7a45e9055394fbd6e04d1437cdbd863248b076cd5e5e40b2e5e4d466

Observation 81cfdfa0-6348-44c6-84b0-a3cf613ac928 · outbound

This paper cites Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.383286Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.383286Z digest=sha256:3fff9279435c088199aa4fe7e6391260c25faf8a2f949f214eb59d6479942069

Observation cf821782-25fa-4d9f-9836-4fe903465c3e · outbound

This paper cites Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.385719Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.385719Z digest=sha256:b0256e217386568aca3bab4da56635c22d75fb710afc1958b57ea2457d0c4499

Observation 99d22276-df8b-4e01-87b5-c84aa00f8381 · outbound

This paper cites "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.388070Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.388070Z digest=sha256:7d2c514d5c9b3e08cacee3cf9d1a3f24228bb043e53fecd9e353a4ea397f7ef3

Observation 4c0b8187-cdcb-4538-8358-c484c8e2b10d · outbound

This paper cites and others , title =.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation and others , title =

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.390569Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.390569Z digest=sha256:6728067ab88b10f172dbbffdb2e3a5ef43c613b08fa1bdc6c82b5d1626c6c154

Observation d46f439c-2dfa-4873-86fb-8076c4084063 · outbound

This paper cites an unresolved cited work.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation Unresolved cited work

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.392806Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.392806Z digest=sha256:77b71073c9f8ee227454f4775df66d4ab2b125751cb29e4fd789bf2872828b2a

Observation 9c6d80cf-0d7f-4e58-aadb-46dc59a7d0d8 · outbound

This paper cites and Chen, Z.

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation and Chen, Z

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-02T03:09:54.394990Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-02T03:09:54.394990Z digest=sha256:40fc425d799ff7dbf1d4a6a87043dfadd24561cea6eca6dc075e4b1e2936801f

Pith citing papers

Observation b8a1e26b-bf33-4b59-8aba-1b2a5ba0da0e · inbound

ElasticBack: Stealthy Conditional Backdoor in LLM-Agent Skills via Coupled Trigger-Rule Optimization cites this paper.

ElasticBack: Stealthy Conditional Backdoor in LLM-Agent Skills via Coupled Trigger-Rule Optimization Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation

Reference 11

Resolution
metadata mismatch
local_arxiv, observed 2026-08-11T14:49:41.613414Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=arxiv_source observed=2026-08-11T14:49:41.241416Z digest=sha256:23e7c3066f34766692099a9b7ca834a04e55b3e07cab2874886efe19f541017e