Pith. sign in

Paper Citation Record · LEDGER

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance

As of 7 August 2026, this Paper Citation Record lists 55 of 55 outbound references and 0 inbound Pith citation observations for arXiv:2608.01558.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.01558 v1

Coverage vector

measured 55 of 55 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T00:12:27.078558Z

measured 55 of 55 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

55 of 55 outbound references displayed

  • verified exact6
  • verified fuzzy10
  • unresolved39
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation d90b0aef-fc35-4176-9847-d71e7c2998a8 · outbound

This paper cites 2024.System architecture for the 5G System (TS 23.501).

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2024.System architecture for the 5G System (TS 23.501)

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.575025Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:22.866701Z digest=sha256:48f7f04bdd0951726bd6420a1dbb4d9c19702d20bbf10ed7dc4afd41a9868954

Observation 508f4b3a-d805-4f3d-8234-47afce6c2e12 · outbound

This paper cites Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:22.935267Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:22.935267Z digest=sha256:364f798b76dd35b33bdc591b67dc537b3839be37bf70407f2902c5e78c6da338

Observation b7dfa417-2d66-441a-9b2b-2fb93ac7d73e · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.018725Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.018725Z digest=sha256:5d98dda6499737ae6b79c033a5f1fa20f801f05963b2a7d909b8f7f82871b30e

Observation 7655f297-4550-4aee-b806-2a18b97ac2eb · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.119614Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.119614Z digest=sha256:c4d627a26c77f72adc48e32547df3079f1bf62629c91a5c2c92d7dc80809a8ea

Observation c3facac2-0e00-4c0c-aed9-bbd8c38eb557 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 5

Resolution
verified exact
raw_fallback, observed 2026-08-07T00:12:58.790971Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:23.194415Z digest=sha256:90606c519e5c09860504a6e14807601260413bb8efab9bdcf68bfce5e554013e

Observation f332cb43-44ed-47b3-bb15-2d598316e784 · outbound

This paper cites AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.283898Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.283898Z digest=sha256:52a6c2341bfbdb791b88cc0bb4c8c0928d407f68730bdcf5df59b2e55bdf86de

Observation 345b9450-26d8-49f5-97a3-22b13a5d5372 · outbound

This paper cites 2012.Computer Security Incident Handling Guide (NIST SP 800-61 Rev.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2012.Computer Security Incident Handling Guide (NIST SP 800-61 Rev

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.545974Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:23.368163Z digest=sha256:6121bad8c8625164e3b0049d45e476dc1d27e837c04aa17981078685db7f2374

Observation 4982389e-3cb7-4eef-841b-8e46e62152cf · outbound

This paper cites 2025.Securing AI Agents with Cisco’s Open-Source A2A Scanner.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Securing AI Agents with Cisco’s Open-Source A2A Scanner

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.531905Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:23.430931Z digest=sha256:86c2a6b2a7c535dd32248688e004c66b875219b119ca74104a19b9acfe1caa68

Observation 12a6028b-46e2-497f-9099-3e687c51ea92 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 9

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.518070Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:23.482516Z digest=sha256:9c02de1474da84b67100e9e81733dea52f426070cd60077636224a48f9ca3e0d

Observation a7a7e11a-186f-4033-a1fb-0de4a6ce2a25 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.578617Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.578617Z digest=sha256:968e06d8b6badc2de8282808bbd296263b1d35b514bcc69b734913abbb3c1460

Observation b560053b-4adf-47e6-85ef-147adec35fd9 · outbound

This paper cites Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.625640Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.625640Z digest=sha256:b7d94c23dcc39f96ba27be917bd2849d11b0c41a5069d387e59ad1c1843b011b

Observation 752afc91-068b-4e94-8e2c-55e86530c623 · outbound

This paper cites Defeating Prompt Injections by Design.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Defeating Prompt Injections by Design

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.711741Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.711741Z digest=sha256:e09516cf34e22f3df6f1a58393bce9498af50ec190e493e152691c7578d9fe63

Observation 0d707773-6112-4200-91d1-82a20796ddbe · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.784463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.784463Z digest=sha256:0ded93f17a81bba7c4075262002cf791357866ecf04d896798666520ef443383

Observation 0f5ac053-9f9d-4e43-b4f2-62f43889da4c · outbound

This paper cites A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP).

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.867036Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.867036Z digest=sha256:42f2471270036ce36ef81438d997fa96749da1187b4696750c0b3a843f4e6a4d

Observation ed5b273b-06c8-40a4-81ea-7e1a09c5f7d9 · outbound

This paper cites 2018.MiFID II Articles 17 and 21; RTS 6 Algorithmic Trading.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2018.MiFID II Articles 17 and 21; RTS 6 Algorithmic Trading

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.503952Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:23.980376Z digest=sha256:ed5b71731672264ebb06fcb8d1b7778c6b8c0df589b8a949351945cddd045142

Observation 76b2a1c9-1e9e-4e20-9bc0-1a529b3408ad · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:24.077540Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:24.077540Z digest=sha256:dbf823ba4e989fdfb234dd3e623d8b64c693df9eb37f3262e21538763583df25

Observation a97c45a7-0929-471c-ab3a-90dd132c3903 · outbound

This paper cites 2025.Safeguarding AI Agents: An In-Depth Look at A2A Protocol Risks.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Safeguarding AI Agents: An In-Depth Look at A2A Protocol Risks

Reference 17

Resolution
verified exact
raw_fallback, observed 2026-08-07T00:12:58.569959Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.177719Z digest=sha256:5c6ce8a9525f2253f16a4ba88ecfb0a802a7cdc3353c2bd540f41e22f3950a2e

Observation b4d4b2f8-ca56-4a56-b4a8-c9e594d47e4d · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 18

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.489856Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.249778Z digest=sha256:f6d2ce6dc351ef2ccba8017ac07faca1b2f7fc32ee3a8aabba18918720882b02

Observation 3fb1543d-b560-4271-9859-6410d51c2893 · outbound

This paper cites 2023.HL7 FHIR Release 5: Workflow Module.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2023.HL7 FHIR Release 5: Workflow Module

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.474737Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.312520Z digest=sha256:d19745d66689683aeef8e895092dd3104987ea238242f514f842983c25f39fda

Observation 096cf875-d7a9-4935-94c6-3b4e673fa876 · outbound

This paper cites Don't Make Models Guess Security and Safety: Symbolic Guardrails for Domain-Specific AI Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Don't Make Models Guess Security and Safety: Symbolic Guardrails for Domain-Specific AI Agents

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:24.400080Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:24.400080Z digest=sha256:41ce879b18bd84fa104fa6ad7b46e14fd55c084c0e42994e92b89ca121ad81d8

Observation 52e314d6-b13d-4526-b304-b05bfdc6b52e · outbound

This paper cites RepetitionCurse: Measuring and Understanding Router Imbalance in Mixture-of-Experts LLMs under DoS Stress.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance RepetitionCurse: Measuring and Understanding Router Imbalance in Mixture-of-Experts LLMs under DoS Stress

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-08-07T00:12:58.362037Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.458193Z digest=sha256:abd32e44c39aaea08db86d1218fc4e827193423f489cbd58ee28d83ef96a535d

Observation 456f57e7-6c97-4e49-ae3e-09d5ecce964c · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 22

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.459263Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.525702Z digest=sha256:54fa00a01f7548a159ae83c8646c5cc6e1a3b9779e31280c1714c4677a530064

Observation e610b514-8243-471d-b14b-65abcb25fd59 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 23

Resolution
verified exact
doi, observed 2026-08-07T00:12:42.649877Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.577229Z digest=sha256:7c9a203157c4628fda1674494c1c303978a4bb7f6751b5028b2f7f6a336cb90a

Observation 663c4715-075b-4a8b-933e-70c67598f1ee · outbound

This paper cites 2025.Potential Attack Surfaces in Agent2Agent (A2A) Protocol.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Potential Attack Surfaces in Agent2Agent (A2A) Protocol

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.442944Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.663366Z digest=sha256:cbff8ba4a1eaf0e31d04e8ece750dcae9bdea70c3be3a73d4a14eb0b4a9380f4

Observation 71f63925-21cb-4534-a09f-99c0f9fa8664 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:24.716939Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:24.716939Z digest=sha256:8fc436167ffb2b2a2c4bd77b483ff2ec9bc0238d3fbfd0a228696f0fe7d16914

Observation 78243060-5fa4-4890-ae64-9c6f4248e067 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 26

Resolution
verified exact
doi, observed 2026-08-07T00:12:42.470683Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.780186Z digest=sha256:b9af1bf50e1905438dd267f8bff28405e38d1059e2d4cc722ae0b893e89b052e

Observation eb452181-ee18-4f62-b1ca-0d1bae3a2c5b · outbound

This paper cites 2025.ACP Joins Forces with A2A Under the Linux Foundation’s LF AI & Data.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.ACP Joins Forces with A2A Under the Linux Foundation’s LF AI & Data

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.427440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.838712Z digest=sha256:7f4de2502ce5052346ee4c7572e662f1ec55bb706fda89ada0b6502cb0281123

Observation 6fde1e6d-e018-42c1-87af-c49f61f02043 · outbound

This paper cites Life-Cycle Routing Vulnerabilities of LLM Router.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Life-Cycle Routing Vulnerabilities of LLM Router

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:24.911258Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:24.911258Z digest=sha256:3ac3ef64b2c95321cb27b01dced7b6fec39955cbb90639cb434df72abb5eef16

Observation 77a0b4f7-0765-4890-b4a2-52ac4e864081 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 29

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.411614Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:24.980670Z digest=sha256:e8da32606b0ef0e745d6ec22e266024d9a4b2468f0d0b061eb0bf7727bc0c4dc

Observation 87e5d589-ed43-460a-8cb5-72f0bc6e0714 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 30

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.392032Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:25.015079Z digest=sha256:81dc151e43216fd02dcec9820699f9ace683e5c07bc5bca42b1b0f6f5fd0fc89

Observation cf032acd-a091-4d9c-909e-04c7a881af85 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.092502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.092502Z digest=sha256:dcb375fe7d1f7832170bb1eaacc586130f265909f2a09e7d602f5b96ae0af2af

Observation 60075151-2517-4ac8-ac33-6151af36fca9 · outbound

This paper cites Security Considerations for Multi-agent Systems.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Security Considerations for Multi-agent Systems

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.164426Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.164426Z digest=sha256:b33de3721e13dac8217ede966085feaf4e40a561fdf7ba911d114ac999929ea3

Observation 7ed7363c-916d-4dcb-9bbd-887ab9a97125 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 33

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.371119Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:25.236137Z digest=sha256:acd9005763b5239c49d87bd87cd01ecce880e8d73860d71eec7596d8fd2142a1

Observation 544baad3-4d8c-42f8-a7f7-8094c98cfb95 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 34

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.347754Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:25.300553Z digest=sha256:01c4e21f07c4a004e27c4bbcc9d897d5d8087e375aaf6016928fc1556244fb2b

Observation 6c6d1120-29b5-4128-9578-f9c013ce9061 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 35

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.331578Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:25.386968Z digest=sha256:1ec8082898cd83bed6e7226c671f0ebfd635b996b4ba86e0f2345ce201efcdd2

Observation 3b43a8ba-78a0-4810-96b4-396a523c4364 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 36

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.307043Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:25.453517Z digest=sha256:cd6b30186e1419794b985d062b06f20610a0f46f1c7632546b4d1208b848ca89

Observation 5c4db43f-afef-4d0f-bc0e-1af3fed63b7b · outbound

This paper cites Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.516024Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.516024Z digest=sha256:6749b336477dcdbbdb86ed99bd1216634e4f5ef4ea54cba603fde16b448a1ceb

Observation 75121b02-8aed-4888-91cd-87613c0d45a6 · outbound

This paper cites 2026.A2A Protocol Security: Authenticating Agent-to-Agent Communi- cation.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2026.A2A Protocol Security: Authenticating Agent-to-Agent Communi- cation

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.272211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:25.610975Z digest=sha256:b75348abf431c435234047fac902dd8292ca87d23186308aeac19da699d8c8f4

Observation 446a917b-4392-4785-8152-6b8b809c6b60 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 39

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.036365Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:25.686470Z digest=sha256:bf4f09da5d4c5475a5a1ba01b5c33347eb86f62d0c792b656483dd0c50d3c5f2

Observation 6d5755eb-7184-4249-bc1f-95add8c6fd6c · outbound

This paper cites Prompt Injection Attack to Tool Selection in LLM Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Prompt Injection Attack to Tool Selection in LLM Agents

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.831378Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.831378Z digest=sha256:1d2a76f01fa561f74d1b62e14f1d2a1f85d84e276ae90b265e0e87ac94c16c09

Observation 32663088-c234-4639-84e0-42d246b24447 · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Progent: Securing AI Agents with Privilege Control

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.895446Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.895446Z digest=sha256:78739f4295361bb8b5dac0633b02310e3d551cd9e47d1cc09a9b77c27ad334b9

Observation ed50bcb4-1f05-445a-b2ce-2b59540e69d4 · outbound

This paper cites Route to Rome Attack: Directing LLM Routers to Expensive Models via Adversarial Suffix Optimization.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Route to Rome Attack: Directing LLM Routers to Expensive Models via Adversarial Suffix Optimization

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.015766Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.015766Z digest=sha256:0feb218b1f681354cab7fdcd7a4d27e620836229150edfb020646882f7d9a8fa

Observation 57a63382-f3dc-43ee-8317-8b52ef0cdab6 · outbound

This paper cites 2025.Linux Foundation Announces the Forma- tion of the Agentic AI Foundation (AAIF).

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Linux Foundation Announces the Forma- tion of the Agentic AI Foundation (AAIF)

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:12:59.835938Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:26.121588Z digest=sha256:46a9c67b620d4e1212a8910d162276911b0609569ee20da4db7d31d4e68f2b73

Observation 8679f679-8ad9-410a-8543-f962ff3dd360 · outbound

This paper cites 2025.Linux Foundation Launches the Agent2Agent Protocol Project to Enable Secure, Intelligent Communication Between AI Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Linux Foundation Launches the Agent2Agent Protocol Project to Enable Secure, Intelligent Communication Between AI Agents

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:12:59.269986Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:26.296684Z digest=sha256:7961588b2bd4d79f813956645ff157da90018d33165dc19abc4ddaa28a2033c7

Observation 21ad1643-490a-4954-a7ff-b87eb2d7bfad · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 45

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:12:59.543610Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:26.211036Z digest=sha256:9f81f642e70c8ae67055f6bd0cd501ab97c638a5cad54012bf938938b5e431a6

Observation 84c6b314-84ef-488c-8ddd-afc663ba51d0 · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.491944Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.491944Z digest=sha256:6202042ede31a41532808639a0d1ec9449303d58b3a6bab7e412af4020bf8d8a

Observation 30284983-2ca0-436a-9563-ea2437dc1589 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 47

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:12:59.017385Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:26.391388Z digest=sha256:e64c64e437f2953c27056a5baf5e62e5d9c114611ee177970f9999b5ab97af06

Observation 36cfab86-09f9-4d41-beae-26d34d1865e7 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.677481Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.677481Z digest=sha256:e4262ab6d2a03e6ef525c98864485212487ee72e38b0bb8c28c758bf10f04eb0

Observation 1867f1c6-7164-4a3b-ad41-b75d7b65c53e · outbound

This paper cites ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.587196Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.587196Z digest=sha256:262e58ca6c8d0bb0afc5bd70f9228261ba0cad321288e285a0ebc9fbdc62543d

Observation b46de631-1721-4aa0-8f88-30252ed74380 · outbound

This paper cites Stealing User Prompts from Mixture of Experts.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Stealing User Prompts from Mixture of Experts

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.839942Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.839942Z digest=sha256:8900451305e9924fe8443ec3e93dfa1ee3430ea232ff21c75e5e7b63dde3d8da

Observation 6b32b77d-b644-4426-be8a-c43df23e9368 · outbound

This paper cites RouteHijack: Routing-Aware Attack on Mixture-of-Experts LLMs.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance RouteHijack: Routing-Aware Attack on Mixture-of-Experts LLMs

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.741411Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.741411Z digest=sha256:851e291aae8b316f237aeaf6d5e1101681c7665e6031b56a0febb2e33b9039bb

Observation 6baedb92-ac0c-4dd5-a071-338cecee1a3b · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:27.004844Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:27.004844Z digest=sha256:316dd42cbbffe6ffa6798781f9ecd5d5efeb0037035442903828f9403ce91041

Observation 364c5f77-8357-4899-aab5-bf48bd693a52 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 53

Resolution
verified exact
raw_fallback, observed 2026-08-07T00:12:42.992528Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.

source=pdf_text observed=2026-08-07T00:12:26.925470Z digest=sha256:ea809a8ddc0c18e89c7d53757661febb9b04eac658bf9e21069cf60a75230c16

Observation b762fbc8-2f22-4c04-afaf-36ca9dbed0c2 · outbound

This paper cites PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:27.078558Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:27.078558Z digest=sha256:4e8ac9c7fea4f07aec0cc1ec0ca16b63b593dae3db431e06d996647592f64803

Observation 08950bca-1daa-4dde-8a86-4f1e282ff083 · outbound

This paper cites Rerouting LLM Routers.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Rerouting LLM Routers

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.735180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.735180Z digest=sha256:cc021c04e1bc74910bfcf342dc8419169315927eb7019b83091a20f9d218aa05

Pith citing papers

No inbound Pith citation observations are available.