Pith. sign in

Paper Citation Record · LEDGER

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents

As of 20 August 2026, this Paper Citation Record lists 55 of 55 outbound references and 0 inbound Pith citation observations for arXiv:2608.04741.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.04741 v1

Coverage vector

measured 55 of 55 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T17:42:06.624702Z

measured 55 of 55 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-20T06:33:59.587034+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

55 of 55 outbound references displayed

  • verified exact2
  • verified fuzzy36
  • unresolved16
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch1

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 0c06a9e7-cc4a-41a3-a311-3acce751fa83 · outbound

This paper cites A {Large-Scale} measurement of website login policies.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents A {Large-Scale} measurement of website login policies

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.557607Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.441269Z digest=sha256:ed8937d27d0a449160a008c8a96d57cf2cea886b2ee15cccd85b8e3bbd8c9b68

Observation bbb70c9c-5074-4cb9-bcee-d43731f71a45 · outbound

This paper cites Agentharm: A benchmark for measuring harmfulness of llm agents.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Agentharm: A benchmark for measuring harmfulness of llm agents

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.549913Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.444995Z digest=sha256:257a2f62fcf6d159b79c9bbc2fcdfc2bd43743403e751ba0eb1e2a69d47feb53

Observation 5acbad47-b0d5-4a06-b076-814729825694 · outbound

This paper cites Phishing activity trends report, 1st quarter 2025.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Phishing activity trends report, 1st quarter 2025

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.542958Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.448942Z digest=sha256:16d03ebcf46b5f295bea6670bced020419e62f9745fae56bf3190ff6a076efb7

Observation 9d1c3dc1-7c75-4bf6-978e-34199d0c4a96 · outbound

This paper cites Car- bon: domain-independent automatic web form filling.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Car- bon: domain-independent automatic web form filling

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.536030Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.452388Z digest=sha256:3f52fe93bef21b9908fdd48b4a242dc3727373fffd265a725d8ea1a5273a06d7

Observation 0e5f3b4a-478e-4910-af57-2627c85cf3ea · outbound

This paper cites Vpi-bench: Visual prompt injection attacks for computer-use agents.arXiv preprint arXiv:2506.02456(2025).

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Vpi-bench: Visual prompt injection attacks for computer-use agents.arXiv preprint arXiv:2506.02456(2025)

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.456309Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.456309Z digest=sha256:7ab89881df44741789732dfc19b2e7a679916119b1ea51689daedd55127bc171

Observation ad6420f2-2139-4eaf-8765-ce1ef1f72e86 · outbound

This paper cites Real: Benchmarking autonomous agents on deterministic simu- lations of real websites.Advances in Neural Information Processing Systems 38(2026).

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Real: Benchmarking autonomous agents on deterministic simu- lations of real websites.Advances in Neural Information Processing Systems 38(2026)

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.528299Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.460070Z digest=sha256:e06960435b1e80253930e871a6eacc2ab650d63b8477f9bfe06a369f9a50acf9

Observation f158a4ea-de03-4ef6-8d65-19e03acd5f2c · outbound

This paper cites Efficient selectivity and backup operators in monte-carlo tree search.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Efficient selectivity and backup operators in monte-carlo tree search

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.520094Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.463706Z digest=sha256:f310d2a86e8ffe0f414bba421209c98090b505cd8b6dceeef6812a0154f55060

Observation 1cd58b4e-a788-4296-a713-be06b18d6f92 · outbound

This paper cites Decepticon: How dark patterns manipulate web agents.arXiv preprint arXiv:2512.22894(2025).

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Decepticon: How dark patterns manipulate web agents.arXiv preprint arXiv:2512.22894(2025)

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.467683Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.467683Z digest=sha256:86e6babcd62c516d5487e8dbc860de6c42a6464075133d52687d4d66e9c73aa0

Observation cbfe2e78-bc94-496f-9be8-286b4bc748dc · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems 37 (2024), 82895–82920.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems 37 (2024), 82895–82920

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.510037Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.471130Z digest=sha256:fa6fbb66ffa5cbf2f449bec4742e3700c02714bec2e9229b21684d60c56519aa

Observation 98041349-4e5f-4039-b7e2-cabbc9b00a79 · outbound

This paper cites Mind2web: Towards a generalist agent for the web.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Mind2web: Towards a generalist agent for the web

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.502378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.474244Z digest=sha256:1d34402366fd86c8843678c7435669b2173faf374b9d35ecc32a1e23e3d4f153

Observation 64fb2902-695f-4237-8479-033aa5276a20 · outbound

This paper cites User-driven automation of web form filling.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents User-driven automation of web form filling

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.495608Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.477936Z digest=sha256:8663d1d02414736d16b722b385cd1b54d5bdca1bf985d28188174f50ae55c886

Observation bd13c105-9972-4f45-b0a2-4cdc8ba26691 · outbound

This paper cites an unresolved cited work.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Unresolved cited work

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.481121Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.481121Z digest=sha256:072383ef9ff4499766c50dbb8ab48a3bb5c6528bb03847c039e91e813ca9403d

Observation 88690090-5ea0-4a8d-b968-6d9ab6149e87 · outbound

This paper cites Wasp: Benchmarking web agent security against prompt injection attacks.Advances in Neural Information Processing Systems 38(2026).

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Wasp: Benchmarking web agent security against prompt injection attacks.Advances in Neural Information Processing Systems 38(2026)

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.489006Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.483589Z digest=sha256:d63416d9e6886a06355d8861a0e51bae09b926186ed30a20528fa78cabfa3b7e

Observation 9169ba28-1482-4e7d-bd6c-f70d72dd0ce4 · outbound

This paper cites Passwords Are Meant to Be Secret: A Practical Secure Password Entry Channel for Web Browsers.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Passwords Are Meant to Be Secret: A Practical Secure Password Entry Channel for Web Browsers

Reference 14

Resolution
metadata mismatch
local_arxiv, observed 2026-08-06T17:42:07.077682Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.486460Z digest=sha256:a960973311187331b05c932eef020d537e8cda24792ea919f0be2863dddfee8d

Observation b1b54759-65dc-4a4c-9bf3-ca097555ecea · outbound

This paper cites {Topic-FlipRAG}:{Topic-Orientated} adversarial opinion manipulation attacks to {Retrieval-Augmented} generation models.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents {Topic-FlipRAG}:{Topic-Orientated} adversarial opinion manipulation attacks to {Retrieval-Augmented} generation models

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.481653Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.490342Z digest=sha256:bfc265248c53644a431c5943b98949631fb4e2009d29df9b3c9dfa6dbee4af2b

Observation d0d057d8-569d-4618-9b7b-f4b5d13eabc5 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.472923Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.493016Z digest=sha256:a55150d5c42ae0001327f0f4c8f34079b8ced18ad995bdec606e6d068fc3347e

Observation 4e81c17a-611d-46bc-b011-853535dba31d · outbound

This paper cites Learning to Navigate the Web.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Learning to Navigate the Web

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.496941Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.496941Z digest=sha256:3d9baf865e59cf52325d5a8494ab0395645cab450c89c04e7e39b19d2abc3305

Observation f556136c-c0d8-4694-a7e7-9f8e43e436bf · outbound

This paper cites Webvoyager: Building an end-to-end web agent with large multimodal models.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Webvoyager: Building an end-to-end web agent with large multimodal models

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.463047Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.501249Z digest=sha256:fed4fb76eccaadb393a2500582f64f3a5e1e5ec57883c83ff07d0e73004f1b12

Observation 3eb38f5c-10a0-4197-b87e-aa1006979022 · outbound

This paper cites Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.503639Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.503639Z digest=sha256:f06d4759b691bfd9a185c114869e4d662820a12b9078b3aded0d8dea5da018b2

Observation dd0301f5-87cb-46c7-a1cb-4ceebaac7e8c · outbound

This paper cites Y., LO, R., JANG, L., DUVVUR, V., LIM, M.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Y., LO, R., JANG, L., DUVVUR, V., LIM, M

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.453400Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.507232Z digest=sha256:63c7e349c84a49a8f89e145c186883c2793fc37cbf0081993b39509e98ae998c

Observation f0f1bff5-1ea6-4d55-9d69-8a5293ff150e · outbound

This paper cites Les dissonances: Cross-tool harvesting and polluting in pool-of-tools empowered llm agents.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Les dissonances: Cross-tool harvesting and polluting in pool-of-tools empowered llm agents

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.445671Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.510133Z digest=sha256:3bdea115bd8303a03474a50d223acd7a80d776f1dd683271966eae19a776075a

Observation 74fdf42b-fffa-4042-b859-5b2a870ec5c0 · outbound

This paper cites Eia: Environmental injection attack on generalist web agents for privacy leakage.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Eia: Environmental injection attack on generalist web agents for privacy leakage

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.438106Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.513401Z digest=sha256:d8a604fcf96a38ccf935d3c2cb53c35909c9147d7d40c357531994951f8ddc9f

Observation db134c8c-9f2a-4ad0-8a8f-da11c4adf9af · outbound

This paper cites Fill in the blanks: Empirical anal- ysis of the privacy threats of browser form autofill.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Fill in the blanks: Empirical anal- ysis of the privacy threats of browser form autofill

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.431435Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.516251Z digest=sha256:d4fc716d4d974bcc3000e3530dabcc991ef7c399a35ac8c6c684d2f6dac0fc01

Observation fd2f45a7-0f85-4c9b-92ff-8bf5727f6610 · outbound

This paper cites Reinforcement Learning on Web Interfaces Using Workflow-Guided Exploration.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Reinforcement Learning on Web Interfaces Using Workflow-Guided Exploration

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.519204Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.519204Z digest=sha256:1337fbce3df11e487b64347f20936693a5c62ceeddff78183abefe4f4fda2204

Observation 5ce63290-07de-4085-bc42-dd938674c723 · outbound

This paper cites H., DIVAKARAN, D.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents H., DIVAKARAN, D

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.423512Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.522980Z digest=sha256:75619eff963030b83896c02d8a7d2b35040021c0a73565f2ed6a1896f87d64e0

Observation 8f183b19-d169-487c-b4ff-4c3b85ae76ee · outbound

This paper cites an unresolved cited work.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Unresolved cited work

Reference 26

Resolution
unresolved
raw_fallback, observed 2026-08-06T17:42:07.415437Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.525610Z digest=sha256:d4becf8e47ab78aad0079bb5ff63d0b4faa3508d2cc69a35a85a5af791c61af7

Observation 80c3476e-d826-414c-b6c1-e9fb32e540c1 · outbound

This paper cites an unresolved cited work.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Unresolved cited work

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.528977Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.528977Z digest=sha256:4a39f7380ed8ba08e159406e4a5bf150d6ceca950f38feaeaba0c6aa287b5ac3

Observation 4cb0301f-ca33-4426-90d1-f27180b5cee9 · outbound

This paper cites Microsoft digital defense report 2025.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Microsoft digital defense report 2025

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.407692Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.532986Z digest=sha256:83a2ce3a2eefbec8a9fec8ae8ce9a1ecc7b3ef81a28f597a6f56b0371afb2fa9

Observation 99be01bd-bb5f-4fe6-8c90-94cc13c7d254 · outbound

This paper cites SpatialJB: How Text Distribution Art Becomes the "Jailbreak Key" for LLM Guardrails.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents SpatialJB: How Text Distribution Art Becomes the "Jailbreak Key" for LLM Guardrails

Reference 29

Resolution
verified exact
raw_fallback, observed 2026-08-13T02:21:51.267303Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.535475Z digest=sha256:d0d8fd6d51411d148cea0dd47258b112cb660ffda874ef4099891ed9587659c6

Observation 252ceac1-2319-47d1-90c0-8e32e40bd09d · outbound

This paper cites Browser use: Enable ai to control your browser.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Browser use: Enable ai to control your browser

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.401393Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.538520Z digest=sha256:e7a2cc935a39197f06713070a2537d3ecda94faff3f48cf6a373d62efabb7ffd

Observation 88004904-6b3a-4ba3-a68b-df5e5e96f444 · outbound

This paper cites Gui agents: A survey.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Gui agents: A survey

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.395115Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.541001Z digest=sha256:36b6f7126af5246481ed0e9dc51eee9e843fb4b63cf7479d4593d3eaf11f34b1

Observation 1779d405-86c0-4cf4-b900-29843d6c9c87 · outbound

This paper cites End-to-end goal-driven web navigation.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents End-to-end goal-driven web navigation

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.387856Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.544346Z digest=sha256:0d1f3cf7f4b8a61a692d1efaacbd2b645a94691555917b70f8816ef0148f0632

Observation dbc0865c-1e7f-4cc5-9122-d2e1bfb0ddde · outbound

This paper cites What happens after you leak your password: Understanding cre- dential sharing on phishing sites.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents What happens after you leak your password: Understanding cre- dential sharing on phishing sites

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.379481Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.547617Z digest=sha256:a6de40cb8bb55200450a0bacc9f0285fc518f92840a2a04bfbeae80fadc184ad

Observation 12a1ef06-0e46-4973-a765-3626768f5672 · outbound

This paper cites How americans protect their online data.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents How americans protect their online data

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.369918Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.550505Z digest=sha256:48ef27bf20d206acb25f2bf8ca07dd98fe3bf712ed407456ca808f39f31aa072

Observation c06644a6-cc01-4d17-a71d-64035d285fb8 · outbound

This paper cites "I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents "I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents

Reference 35

Resolution
verified exact
local_arxiv, observed 2026-08-06T17:42:06.930325Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.553219Z digest=sha256:a1b8133d8ecbc38efc6335e33f75e54e6816af4e28c3c314f33a80a5b7bc3144

Observation 980ac03b-fc92-405a-b24a-5bb18d7e2641 · outbound

This paper cites Z.,ANDSUN, L.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Z.,ANDSUN, L

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.361662Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.558419Z digest=sha256:bf005e2d50e84e74b8034fb760213d52e5cb07bd164a04582075736cc569a50a

Observation 3e00ce7f-bae1-498d-be9c-9ce6750c1174 · outbound

This paper cites World of bits: An open-domain platform for web-based agents.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents World of bits: An open-domain platform for web-based agents

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.353417Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.561858Z digest=sha256:a02a08d3c2fc66dbd250d9c344874ab8f044837819e0cbce5d47fbc48271a421

Observation 07fd7f01-41c4-4f9a-b5f7-00583a0d33eb · outbound

This paper cites Password managers: Attacks and defenses.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Password managers: Attacks and defenses

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.346163Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.565314Z digest=sha256:b649d43ae0dacbcfb17ad0bbdded6b0193c23edb7cee10f11aa3cee338f74d46

Observation 04f8fd7c-377f-4e73-99be-7a66ead02a61 · outbound

This paper cites Skyvern: Automate browser-based workflows with ai.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Skyvern: Automate browser-based workflows with ai

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.339219Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.568168Z digest=sha256:57f29d01cd730ff42e41d8be14c31b4152db3a70f4584524d3bb6d38af1a7af0

Observation 0fcea2bc-3e8e-4d16-8cd4-fa9888a91f5e · outbound

This paper cites Muzzle: Adap- tive agentic red-teaming of web agents against indirect prompt injection attacks.arXiv preprint arXiv:2602.09222(2026).

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Muzzle: Adap- tive agentic red-teaming of web agents against indirect prompt injection attacks.arXiv preprint arXiv:2602.09222(2026)

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.570867Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.570867Z digest=sha256:4c0c995431c8df1203b9ecfdf82924662f8f33f9b39413d2ed7fc6144bf6d168

Observation 9af78636-577a-4b5a-8f48-6062d9f584e7 · outbound

This paper cites G., SZALACHOWSKI, P.,ANDZHOU, J.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents G., SZALACHOWSKI, P.,ANDZHOU, J

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.329024Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.573544Z digest=sha256:664ae97a0a3d2afe516b77ee32f26880c7bd8b06257e48bc68bb64bf51743af7

Observation c8c6b994-563d-4f5b-bc15-b86eb36bd7e6 · outbound

This paper cites Digital iden- tity guidelines: Authentication and authenticator management.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Digital iden- tity guidelines: Authentication and authenticator management

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.320741Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.576792Z digest=sha256:96d1709d97923acb5b6d5a492859f1a08353614505257ce81c99106359ccb5c8

Observation 1142396f-0fe4-428f-bee7-3bece7f94629 · outbound

This paper cites AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.580319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.580319Z digest=sha256:7a7c0fdbb7a70d1408ecc1a479bb375668823e87f3c2fe98aa03301dcf32a846

Observation 83b5c4e0-e0bd-4249-9a3d-fe8153ca95b0 · outbound

This paper cites Manipulating multimodal agents via cross- modal prompt injection.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Manipulating multimodal agents via cross- modal prompt injection

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.312746Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.584591Z digest=sha256:c7ead48b23451f9eaec8057ad86e49a9316e72f250d330a9680a9be7cd9e1b39

Observation 338f8c91-f9aa-4c65-a91f-fe7a5c9d29c9 · outbound

This paper cites an unresolved cited work.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Unresolved cited work

Reference 45

Resolution
unresolved
raw_fallback, observed 2026-08-06T17:42:07.305170Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.588212Z digest=sha256:a153fffc59f887a739de44431d8b729167293e2ae35a56907e34e2cc1e25af5a

Observation 179b35f2-f90c-41d4-a017-2343d6a87226 · outbound

This paper cites When bots take the bait: Exposing and mitigating the emerging social engineering attack in web automation agent.arXiv preprint arXiv:2601.07263(2026).

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents When bots take the bait: Exposing and mitigating the emerging social engineering attack in web automation agent.arXiv preprint arXiv:2601.07263(2026)

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.591770Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.591770Z digest=sha256:a20850900041999e3cd0280acd7b27c79b45e0664c5d7c4706e41e889d60f387

Observation d3e666f8-28a9-48fe-9248-200d80e88cf5 · outbound

This paper cites H., GOU, B., SONG, D., SUN, H.,ANDSU, Y.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents H., GOU, B., SONG, D., SUN, H.,ANDSU, Y

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.298374Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.595198Z digest=sha256:980c21eaaa9c9bee1e7a43ceff50b19ff85a8c694673be1f0667664144b73f07

Observation 19ac1970-eca5-43c4-88ee-1e11290094cc · outbound

This paper cites Set-of-Mark Prompting Unleashes Extraordinary Visual Grounding in GPT-4V.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Set-of-Mark Prompting Unleashes Extraordinary Visual Grounding in GPT-4V

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.598082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.598082Z digest=sha256:1ce259ca90243402c51794fd255d66960536e771dfd48f123a1343fa94ac5314

Observation 567715ce-6635-461d-a14c-4e476672590f · outbound

This paper cites Litewebagent: The open-source suite for vlm-based web-agent applications.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Litewebagent: The open-source suite for vlm-based web-agent applications

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.291537Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.601738Z digest=sha256:de3eba44d5b3a2dc2be4fff27d6016df0f88c8c8e32ac9407ec5b726b35b0efc

Observation 01ceb5ba-e222-49c5-ab72-31ab857d465a · outbound

This paper cites Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Agent security bench (asb): Formalizing and benchmarking attacks and defenses in llm-based agents

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.282052Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.604592Z digest=sha256:601fc326b8ed09670944e900ba8786581f28a3b5f77f5d252b3299125deb259d

Observation 28fdadac-9531-407c-aafd-87a204207c0f · outbound

This paper cites Browsesafe: Understanding and preventing prompt in- jection within ai browser agents.arXiv preprint arXiv:2511.20597 (2025).

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Browsesafe: Understanding and preventing prompt in- jection within ai browser agents.arXiv preprint arXiv:2511.20597 (2025)

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.609002Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.609002Z digest=sha256:25f9910b1d7d3af7da5ce2f0fc7e9b2f15834b858f6df1951d62c6f70a815b35

Observation aad90a79-e894-460f-aeac-fe09729d0771 · outbound

This paper cites Attacking vision-language com- puter agents via pop-ups.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Attacking vision-language com- puter agents via pop-ups

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.273747Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.613121Z digest=sha256:7fa66f6a4d71df856f338cd24f72fec63a3f92d9207539e9aac99adad2de2f47

Observation f076ef29-57d8-48f7-8b1a-316dd3d74edc · outbound

This paper cites Genesis: Evolving attack strategies for llm web agent red-teaming.arXiv preprint arXiv:2510.18314(2025).

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Genesis: Evolving attack strategies for llm web agent red-teaming.arXiv preprint arXiv:2510.18314(2025)

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.616784Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.616784Z digest=sha256:ab64c116717b18c8b23a1ad9e0f171edc42a8e52c7db942dfb4a50a24981f1e0

Observation 234e6629-8eba-4481-9c64-4bcaa4b15888 · outbound

This paper cites Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-06T17:42:06.620914Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T17:42:06.620914Z digest=sha256:2448cc97e70244455818f330dde6f9ecf215202d81c187dbe899a431e98827d6

Observation 39ceafb1-fa49-4336-94f0-dd0c54496b15 · outbound

This paper cites {PoisonedRAG}: Knowl- edge corruption attacks to {Retrieval-Augmented} generation of large language models.

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents {PoisonedRAG}: Knowl- edge corruption attacks to {Retrieval-Augmented} generation of large language models

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T17:42:07.264825Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-08-06T17:42:06.624702Z digest=sha256:026ca627886936824141f8b28db50241efce0866f882dd1a6075ec341ae6d9de

Pith citing papers

No inbound Pith citation observations are available.