Pith. sign in

Paper Citation Record · LEDGER

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales

As of 8 August 2026, this Paper Citation Record lists 42 of 42 outbound references and 0 inbound Pith citation observations for arXiv:2607.25364.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.25364 v2

Coverage vector

measured 42 of 42 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-01T02:43:24.479481Z

measured 42 of 42 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

42 of 42 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved42
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 1ba4f6a6-30fb-481a-8f5a-90e59fa7c11e · outbound

This paper cites Language models don’t always say what they think: Unfaithful explanations in chain-of-thought prompting,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Language models don’t always say what they think: Unfaithful explanations in chain-of-thought prompting,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.352814Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.352814Z digest=sha256:7816f7ccbc8e02097c847eda62316c27137451ca46d703c4ebb6ea262d3499ff

Observation 30f3eaf1-2751-44ea-8341-6fb671924c9c · outbound

This paper cites Measuring Faithfulness in Chain-of-Thought Reasoning.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Measuring Faithfulness in Chain-of-Thought Reasoning

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.356785Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.356785Z digest=sha256:a9c14c8c330a02aee41c40eb568326c75ccb7365f68030dd9fdf064abfba87e6

Observation 1cceac1a-1566-4796-bcd4-e584f0a64e61 · outbound

This paper cites Dissociation of Faithful and Unfaithful Reasoning in LLMs.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Dissociation of Faithful and Unfaithful Reasoning in LLMs

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.360349Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.360349Z digest=sha256:ac11fa173eea8e5b09f61f74d813e40a0e2942fed3fef6fb03a35669b2895090

Observation 66d7d7b2-43c9-45ed-9df5-cfde15ee7be0 · outbound

This paper cites ReAct: Synergizing reasoning and acting in language models,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales ReAct: Synergizing reasoning and acting in language models,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.364143Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.364143Z digest=sha256:5cfabd0c6a748d6d2679916dabf96ac6998a0e07dfc72fbdf4e0e3c09defebcc

Observation b4fd514e-2589-4ef1-9f3a-63bc552d2159 · outbound

This paper cites Why should i trust you?: Explaining the predictions of any classifier,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Why should i trust you?: Explaining the predictions of any classifier,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.367334Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.367334Z digest=sha256:95dc97b59c8e212edbbdbd7b5d6762deed8e3e19294c7e7b02694963a9383852

Observation 47aabdc4-0bb3-4bb7-84ad-5ae7e145b974 · outbound

This paper cites Explanation in artificial intelligence: Insights from the social sciences,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Explanation in artificial intelligence: Insights from the social sciences,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.370635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.370635Z digest=sha256:aa039c54fe742b6b4d25d49ef34fe25b34d64484fd6a9d84883183fa21351873

Observation 476171b9-768c-4051-8dc1-7c8216f482d3 · outbound

This paper cites The mythos of model interpretability,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales The mythos of model interpretability,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.374468Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.374468Z digest=sha256:15088c1c069a6daa83d944a7cb29cbacf4507b2d66aea7ad7d36a4463f36495e

Observation 79da502c-62ce-433c-8703-257314de1352 · outbound

This paper cites Interpreting interpretability: Understanding data scientists’ use of interpretability tools for machine learning,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Interpreting interpretability: Understanding data scientists’ use of interpretability tools for machine learning,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.377349Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.377349Z digest=sha256:aa38036668f4e5d3d60c7171bd63d5c780e2080553b995e5e84e87fa439314ef

Observation 2facfbaf-3ad0-45f4-809d-438e014232c2 · outbound

This paper cites Manipulating and measuring model interpretability,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Manipulating and measuring model interpretability,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.380532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.380532Z digest=sha256:debd53e6cdba0665a24e0c1d2f317ed76e5f8c7cd94a762876874d4b75887dda

Observation 8474d2c9-58f9-4df3-9a52-9d220f5cc51e · outbound

This paper cites The protection of information in computer systems,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales The protection of information in computer systems,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.383451Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.383451Z digest=sha256:70331966ee7323cd35fa251121d30554b3bee6639f4ad6160e3d59eebf69f7bb

Observation 3c88cc5e-9ce7-4304-892a-5d7de42eb12b · outbound

This paper cites Guide to attribute based access control (ABAC) definition and considerations,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Guide to attribute based access control (ABAC) definition and considerations,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.386727Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.386727Z digest=sha256:6a638ef3625ce588add807fcfa1de04731a6c4bdd675b5f494505827f5668c5d

Observation aabd5ec7-50c3-437a-9504-4ce3315f49d3 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world LLM-Integrated applications with indirect prompt injection,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Not what you’ve signed up for: Compromising real-world LLM-Integrated applications with indirect prompt injection,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.389933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.389933Z digest=sha256:7090145e4f37245fa857e4cc3b086135f7286bde0e515d441efa3c2cf5497f3e

Observation 5b4eabb0-c7b8-4c40-9b63-5df472774372 · outbound

This paper cites Identifying the risks of LM agents with an LM-Emulated sandbox,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Identifying the risks of LM agents with an LM-Emulated sandbox,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.392897Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.392897Z digest=sha256:6936d522d29f798c85063d674ca5de043a9c718a2a6b075e7a72bab627b6e0c7

Observation 6a6fcd77-073b-4781-9175-6342a5c34068 · outbound

This paper cites AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.398938Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.398938Z digest=sha256:c3232bd84a63aeef96298bada3752dcbe71b1351941e8bfc99aaa78b91c2213a

Observation a839a774-fff0-4a4e-9df9-a93eb081b0ec · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.401927Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.401927Z digest=sha256:a4be0c3aba1c5811a067031237b55cba840f7b965d98270221bcf2505ccc1b04

Observation e7adc28e-5ca5-46ae-80a4-90807afe7682 · outbound

This paper cites Prompt injection attack to tool selection in LLM agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Prompt injection attack to tool selection in LLM agents,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.404813Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.404813Z digest=sha256:906dbe3e25dce5f28a2f8417e4beb7c9510a862286ac141b3fea723bb2fcf7b1

Observation 95438d9f-decf-490a-9b18-1353d82b4016 · outbound

This paper cites MCPTox: A benchmark for tool poisoning on real-world MCP servers,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales MCPTox: A benchmark for tool poisoning on real-world MCP servers,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.407651Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.407651Z digest=sha256:a565fa4e9290cf4d82e9c6dc3af9e623b525a0a7db6b65d2e0dc0e6894774424

Observation e8bcb4a3-5204-483a-862b-dbba69d49b4e · outbound

This paper cites StruQ: Defending against prompt injection with structured queries,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales StruQ: Defending against prompt injection with structured queries,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.410667Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.410667Z digest=sha256:99085c80cfc11d169220304a373052c33b8a1a8b1508c69364a72ffda0751b40

Observation 94859335-b483-49c4-af0b-ec5f630aaefe · outbound

This paper cites AttriGuard: Defeating indirect prompt injection in LLM agents via causal attribution of tool invocations,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AttriGuard: Defeating indirect prompt injection in LLM agents via causal attribution of tool invocations,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.413469Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.413469Z digest=sha256:2d082b12633545ae99b2289b4513c419bb9d3d749800af443ee96e9dbb0688a9

Observation f817ebf8-deca-4e8f-b4b7-7bfedb4edc14 · outbound

This paper cites Tools – model context protocol specification, 2025-11-25,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Tools – model context protocol specification, 2025-11-25,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.416234Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.416234Z digest=sha256:5f7830f054b3485b0ced1cf9442900738b329b3644dcc2bcca6c0e0618c3b33f

Observation 59685e37-29d5-4330-a633-1756888f2d4b · outbound

This paper cites Authorization – model context protocol specification, 2025-11-25,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Authorization – model context protocol specification, 2025-11-25,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.418987Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.418987Z digest=sha256:595e9d6f49e0f6ce88fdfe5321253aa708df45ba8ee3c9a0cd6956c1fb811fe6

Observation 7d7a5f4b-1740-4ebf-bef3-9af82886f3bc · outbound

This paper cites Artificial intelligence risk management framework: Generative artificial intelligence profile,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Artificial intelligence risk management framework: Generative artificial intelligence profile,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.421868Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.421868Z digest=sha256:95961902ce46543021225533f57ccab3ea2d4743799644457cbb5299145cb020

Observation b48a26a1-8fed-4913-b31a-819a0130acb0 · outbound

This paper cites LLM01:2025 prompt injection,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales LLM01:2025 prompt injection,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.424764Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.424764Z digest=sha256:37f0478078e4c8cab3517059fed4a3c00677ee12950365290b53cf05ecbdc24b

Observation b92a1314-4622-4363-9304-76ecd1f0775e · outbound

This paper cites Auditable Agents.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Auditable Agents

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.427810Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.427810Z digest=sha256:967691abf6f062eb0d4da1e3ae84449a474b81c13e661eef10cb78a8d97b4038

Observation 48b4a103-e437-4b03-bb7b-d4b1637d0ecd · outbound

This paper cites Agent audit: A security analysis system for LLM agent applications,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Agent audit: A security analysis system for LLM agent applications,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.430985Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.430985Z digest=sha256:a85e5b1002ac7f4c6dac310e73e75d78c880458134c718aa3e976efaa39217f4

Observation 0b823ec3-0b7a-4043-8ba5-7206228ce627 · outbound

This paper cites JSON canonicalization scheme (JCS),.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales JSON canonicalization scheme (JCS),

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.433909Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.433909Z digest=sha256:88886bdd7ac178a66a8e65dd0d494a63029621135c932424dcd071e33e1f1d5a

Observation 889e1901-795c-4aed-8869-f65b2837f1dd · outbound

This paper cites Intent-Governed Tool Authorization for AI Agents.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Intent-Governed Tool Authorization for AI Agents

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.437055Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.437055Z digest=sha256:bc3fa4a0c3c078f3bc2ec937f7a03c641816a4b79de7a3db50e8522fb267b63a

Observation 44635574-ed87-41ee-99d2-dc669a5f25ec · outbound

This paper cites To trust or to think: Cognitive forcing functions can reduce overreliance on AI in AI-Assisted decision-making,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales To trust or to think: Cognitive forcing functions can reduce overreliance on AI in AI-Assisted decision-making,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.440196Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.440196Z digest=sha256:3b6403685bb00989b4cadc600b2a3025bb41f0a6ac4a75705d7a4ec5c821bf67

Observation 36b9d225-6749-4868-bc36-00a4604e4379 · outbound

This paper cites Crying wolf: An empirical study of SSL warning effectiveness,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Crying wolf: An empirical study of SSL warning effectiveness,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.443194Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.443194Z digest=sha256:4c7fcba06ce533a7ebb23a736871432c8d697f539018fac2b32e0746225706ad

Observation 2f9267a9-b8da-498d-9839-c33c470e550f · outbound

This paper cites Guidelines for Human-AI interaction,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Guidelines for Human-AI interaction,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.446007Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.446007Z digest=sha256:ede10114ec0ab5ddf491b83c6589cd9ff7d5026bb190602b5197e93338132129

Observation 79a844e1-04aa-409d-af1c-55737551824e · outbound

This paper cites Explainable security,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Explainable security,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.448942Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.448942Z digest=sha256:034190156eaf446c09adf2dc015394df7037dea908a2ad7a2be4606963861069

Observation 93087a73-a41e-4ee4-a334-ab858490967c · outbound

This paper cites Towards explainable access control [BlueSky Paper],.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Towards explainable access control [BlueSky Paper],

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.451918Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.451918Z digest=sha256:24ed11250a2bb51f56e3c161068c9eda5d689d313885600f6afaba279d4af89b

Observation d8283456-f77a-43d9-8edb-0be319dba038 · outbound

This paper cites SmartAuth: User-centered authorization for the internet of things,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales SmartAuth: User-centered authorization for the internet of things,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.454854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.454854Z digest=sha256:9c9152baec21cd3eb3e26ca9ca511d6ff737d025507d6b5931563aeedf0d89f7

Observation 5892d669-93d4-4927-8266-e12852075377 · outbound

This paper cites AWare: Preventing abuse of privacy-sensitive sensors via operation bindings,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AWare: Preventing abuse of privacy-sensitive sensors via operation bindings,

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.457964Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.457964Z digest=sha256:f677a4b1c2b3a6da2af0bf0c14564e733fe26cfa07e9bce3cabb4ac7215b55cc

Observation 92cc9bb8-f2e2-4f13-ae0b-d9102364fe40 · outbound

This paper cites Decision provenance: Harnessing data flow for accountable systems,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Decision provenance: Harnessing data flow for accountable systems,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.461082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.461082Z digest=sha256:904ef0dd113b1224c8b214e2ed11bea5741286afa4b6442b674b65fe346b21d3

Observation 58b99851-2307-4081-99b6-9c54c7d3e4fd · outbound

This paper cites ACCESSPROV: Tracking the provenance of access control decisions,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales ACCESSPROV: Tracking the provenance of access control decisions,

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.464227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.464227Z digest=sha256:b9937492440c76b6eb025e7f642ccdb9f00416fc1223b2a8e991b26c1175e423

Observation 8dd6cb4f-e480-4019-89b8-bfcc21f5ff7c · outbound

This paper cites Defeating Prompt Injections by Design.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Defeating Prompt Injections by Design

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.467196Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.467196Z digest=sha256:3b39a593ef1c633a30518c41dc04e3b3a832cd268d8a68241918e75ba127cd5f

Observation 1fe5df0a-f9df-4553-89ca-46a108e0a5e3 · outbound

This paper cites Securing AI Agents with Information-Flow Control.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Securing AI Agents with Information-Flow Control

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.470393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.470393Z digest=sha256:1c85b8a2ea2a51c9ef22520bead57c3d1d2127950877c419548423d4bc0c2d15

Observation 972b83f8-82d8-4ab2-bf0e-d848e20dfd4a · outbound

This paper cites Securing agents with tracked capabilities,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Securing agents with tracked capabilities,

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.473769Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.473769Z digest=sha256:1de7678f35ec14d8bce80d2be417f776d6c628715008521125b07332ce0d6c35

Observation 0f7f09be-02bd-42bf-9e67-f1b0cc3bbc2f · outbound

This paper cites AgentSpec: Customizable runtime enforcement for safe and reliable LLM agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AgentSpec: Customizable runtime enforcement for safe and reliable LLM agents,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.476635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.476635Z digest=sha256:523244ddd5339626f2cd90a20fa5281edac8a7f7c9a17b078078497bdc4ab017

Observation 1077a7db-9985-4860-b4de-c635c5cddfec · outbound

This paper cites Towards verifiably safe tool use for LLM agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Towards verifiably safe tool use for LLM agents,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.479481Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.479481Z digest=sha256:7d33cbd3435b56c0a9b3c3640f11e8e033b00fa15f120ad8452e0c58db8b3a11

Observation 918492e6-a78d-40df-b636-7d4301aef83b · outbound

This paper cites Available: https://openreview.net/forum?id=GEcwtMk1uA.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Available: https://openreview.net/forum?id=GEcwtMk1uA

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.395876Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.395876Z digest=sha256:e8b0f1c93b829444a0a2ae1c3af843ecb2b071076ff3c47e863000ae12027de6

Pith citing papers

No inbound Pith citation observations are available.