Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-01T11:38:21.167591Z
Paper Citation Record · LEDGER
As of 22 August 2026, this Paper Citation Record lists 36 of 36 outbound references and 0 inbound Pith citation observations for arXiv:2607.19837.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-01T11:38:21.167591Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-22T06:32:14.747728+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
36 of 36 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation 439a50fc-99b9-4e87-8b3e-ef0aa8567205 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Toolformer: Language models can teach themselves to use tools,
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 406f13a8-d145-472d-abd3-0c4fea9fd29a · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents ReAct: Synergizing Reasoning and Acting in Language Models
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3835fcb9-75e7-43d8-9357-b1e3b5998c37 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Webarena: A realistic web environ- ment for building autonomous agents,
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dc5d88c4-e067-4ab8-a17b-266a9a27e4f4 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Hug- ginggpt: Solving ai tasks with chatgpt and its friends in hugging face,
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4324c514-e183-449d-85ee-2f56c0bfff77 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Openhands: An open platform for ai software developers as generalist agents,
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ef692a33-3a5a-4d1e-8e4f-32f774fed009 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Not what you’ve signed up for: Compromising real- world llm-integrated applications with indirect prompt injection,
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b8224f54-7a93-4d77-907b-630c8fd2f9e3 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents OW ASP Top 10 for Large Language Model Applications,
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 69c3665a-794d-4bbf-a3a7-5398b763c3f3 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Prompt injection attacks against gpt-3,
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0f285f95-910b-465d-acc6-52ad24d85793 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Ignore Previous Prompt: Attack Techniques For Language Models
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1d34a9f1-220a-4668-9a11-9b2259266236 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Agentvigil: Automatic black-box red-teaming for indirect prompt injection against llm agents,
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 24eae479-604f-4232-bf5d-39ced6fdad31 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Topicattack: An indirect prompt injection attack via topic transition,
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c1f18558-62f8-4566-9ddf-8fca0cd700df · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Agentx- ploit: End-to-end red-teaming for ai agents powdered by multi-agent systems
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d091e421-e7d3-4936-ab85-ce9eda9ccf9b · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Adaptools: Adaptive tool-based in- direct prompt injection attacks on agentic llms,
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 74d790ad-8cb5-4176-bda6-496a1c82b9f4 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Security challenges in ai agent deployment: Insights from a large scale public competi- tion,
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 16c1cd37-6130-40e8-95af-1498e1c15a93 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents "real attackers don’t compute gradients
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 509b499f-e1b6-4b29-a5c4-111513f6c1fd · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Prompt Injection attack against LLM-integrated Applications
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3d7e5468-3fd0-4549-9d6d-d937b507e4f5 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c3b1ab49-46b0-4d2e-b6ef-2942b7526974 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 05a35f45-341e-4709-92d2-1921aee36735 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents ChatInject: Abusing Chat Templates for Prompt Injection in LLM Agents
Reference 19
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 884ac497-cf9b-4395-bf92-330b86f12931 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Prompt Injection Attack to Tool Selection in LLM Agents
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 10044431-dfe8-496f-a514-cc53671bdb1a · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Obliinjection: Order-oblivious prompt injection attack to llm agents with multi-source data,
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1b17e9f1-3daf-4a2b-ae26-da210751b368 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6d20f8c5-8837-485e-9eb0-d048eb27d4b3 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Autohijacker: Automatic indirect prompt injection against black-box LLM agents,
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6f47252f-d67d-4d46-8782-9986e52a8ca1 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Agentxploit: End-to-end red-teaming for AI agents powdered by multi-agent systems,
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 974b7850-a8c9-4c18-9a0c-1e312a6b0300 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Tooltweak: An attack on tool selection in llm-based agents,
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 2f16feac-0b42-4e09-95a7-4bc030cc665c · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Verigrey: Greybox agent validation,
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 00f2b1d0-3081-4e5a-bca5-0a832b70c9c2 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents SkillJect: Effectively Automating Skill-Based Prompt Injection for Skill-Enabled Agents
Reference 27
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1f54a5ea-3e5e-4731-9dbf-5e8c0f3b8ecd · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Udora: A unified red teaming framework against llm agents by dynamically hijacking their own reasoning,
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 506ddbd4-b000-4ee3-b561-3aacd36afb6c · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Bench- marking and defending against indirect prompt injection attacks on large language models,
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f29c388e-4120-4db7-8372-d5d81442e719 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Agent security bench (asb): Formalizing and benchmark- ing attacks and defenses in llm-based agents,
Reference 30
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 617e5efd-51f7-4608-ba58-8137230741e6 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Universal and Context-Independent Triggers for Precise Control of LLM Outputs
Reference 31
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9df13c94-2b54-4595-8378-68e2012e0a89 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Trojan’s whisper: Stealthy manipulation of openclaw through injected bootstrapped guidance,
Reference 32
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 4c3c54a5-a722-4862-8002-5e1b296c0bc4 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Openclaw docs,
Reference 33
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eb9eb1ff-679c-4e82-b893-34f5e6c0727a · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Fine-tuned deberta-v3-base for prompt injection detection,
Reference 34
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1a8d5faf-b4fd-4723-adea-a3a4f4635572 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents Defending Against Indirect Prompt Injection Attacks With Spotlighting
Reference 35
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0bf5d298-f643-4924-88c2-b4ec411cc881 · outbound
Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents "Real Attackers Don't Compute Gradients": Bridging the Gap Between Adversarial ML Research and Practice
Reference 2022
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
No inbound Pith citation observations are available.