Pith. sign in

Paper Citation Record · LEDGER

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming

As of 9 August 2026, this Paper Citation Record lists 55 of 55 outbound references and 0 inbound Pith citation observations for arXiv:2608.05108.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.05108 v1

Coverage vector

measured 55 of 55 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T05:11:49.315668Z

measured 55 of 55 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

55 of 55 outbound references displayed

  • verified exact0
  • verified fuzzy26
  • unresolved28
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation ce8157a8-3198-4805-9f11-09358257bf05 · outbound

This paper cites Ignore previous prompt: Attack techniques for language models,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Ignore previous prompt: Attack techniques for language models,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.154237Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.154237Z digest=sha256:ba637b225e029d0137ab6686f0b70a0c9d7b8cc2e217f908e6dca266bfe276cc

Observation f2f22714-4efa-45ed-94b5-9bd9f4957670 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection,

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.781256Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:45.267686Z digest=sha256:240745f79097656db2ef9b0926d6623114f2caae079f60a79c03a4c1cc0002af

Observation bd61774f-d9cd-4278-95d3-dcd980725294 · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Formalizing and benchmarking prompt injection attacks and defenses,

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.674740Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:45.327186Z digest=sha256:43717e79ea8346064568461ce509a69c542081c592a6996a7c4d827fec5c7859

Observation 76d5a701-c412-4fe4-a7c4-3195dff7f224 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool- integrated large language model agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Injecagent: Benchmarking indirect prompt injections in tool- integrated large language model agents,

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.473490Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:45.414814Z digest=sha256:b4cf2353428861bf4013f089dff96cda1385e2d060f9e583e294050d272b38a1

Observation bde26fa6-ac1b-4460-aa32-edc540ebccec · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents,

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.289540Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:45.463507Z digest=sha256:de0da0176a1519183ce327ddb969ffe0b7121fdfa02f01d52d0c81d47b3c6682

Observation 14016feb-d5b0-4dd6-b8ab-4c41d96bc745 · outbound

This paper cites The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.495675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.495675Z digest=sha256:3d792d4a287ad846042695d770d0d96a9369892bab898739cd5ff30b32feda5c

Observation 7c719ede-b99a-4713-8f57-90f3d7c72b39 · outbound

This paper cites Muse spark safety & preparedness report,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Muse spark safety & preparedness report,

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.149686Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:45.604178Z digest=sha256:ca60a5be60be88bc7acf9156b89ec199fffbb4130cda4f3dab4b024342e0f759

Observation 16083f83-3eea-4cce-ac70-1f620f990eab · outbound

This paper cites Claude opus 4.7 system card,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claude opus 4.7 system card,

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:56.015812Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:45.676598Z digest=sha256:42767c566525372efe2fb09e93448ba92d0f6d177f3ec7652222d1766dca3fba

Observation 23e69e23-13f4-44f8-a68b-54603f45fa10 · outbound

This paper cites Datasentinel: A game-theoretic detection of prompt injection attacks,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Datasentinel: A game-theoretic detection of prompt injection attacks,

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.853663Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:45.725244Z digest=sha256:60c466a3ac344a46bf61be65500be28c3a40088b7d9a9882843de8f721142ed1

Observation a610dc2b-5572-47b4-ba4c-9b8222a28ea6 · outbound

This paper cites PromptGuard Prompt Injection Guardrail,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming PromptGuard Prompt Injection Guardrail,

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.674204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:45.794378Z digest=sha256:791a1a1c93d35b05c641c230e64459019ab4890022105856f5f84567ce11c634

Observation f1bf1c37-421f-42e8-a85b-5263240f4e08 · outbound

This paper cites AgentWatcher: A Rule-based Prompt Injection Monitor.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming AgentWatcher: A Rule-based Prompt Injection Monitor

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.854500Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.854500Z digest=sha256:b729c06042b0b788085170086fe8986d2763788ab7de6aa654279465744e15ac

Observation cb5317d7-a23e-4772-8e0c-cd71d6462d0b · outbound

This paper cites Meta secalign: A secure foundation llm against prompt injection attacks,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Meta secalign: A secure foundation llm against prompt injection attacks,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.943166Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.943166Z digest=sha256:d2e59330229bacebfa691ab46f0ef102b6911cc4b6179f2a4ced7423debf431d

Observation fccb7cd8-214d-4419-9e71-61df4f9a1633 · outbound

This paper cites Purple-teaming LLMs with Adversarial Defender Training.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Purple-teaming LLMs with Adversarial Defender Training

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:45.995659Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:45.995659Z digest=sha256:8547d418c9d26fc281280f648acb176310486c302443d59efd9de26cab7ad011

Observation 128eff0f-a175-4f43-85ee-a0e8d2807bf2 · outbound

This paper cites Black-box red-teaming of multi-agent systems via reinforcement learning,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Black-box red-teaming of multi-agent systems via reinforcement learning,

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.546133Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:46.063263Z digest=sha256:3dc07b9bf2f7f22d585f3370628f091cc0c507da16f7eb8fe03dedb683329f24

Observation 1506dadd-4cfc-4288-87d3-46cd75cdeb52 · outbound

This paper cites Learning to Inject: Automated Prompt Injection via Reinforcement Learning.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Learning to Inject: Automated Prompt Injection via Reinforcement Learning

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.111393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.111393Z digest=sha256:f853ee3fa2a020b912b8e516e736c2277499bed3dc7ac0efcf234b05505132f6

Observation 6058760e-f676-4eeb-be9d-2d872b0e74d7 · outbound

This paper cites Rl is a hammer and llms are nails: A simple reinforcement learning recipe for strong prompt injection,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Rl is a hammer and llms are nails: A simple reinforcement learning recipe for strong prompt injection,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.203274Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.203274Z digest=sha256:ea0fea42fb580d6b89efb0d6becc869df25f9233313d233278da2bee0649208d

Observation f8e5973a-ec6c-48b5-8515-b3a7e9413797 · outbound

This paper cites PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.310041Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.310041Z digest=sha256:9b9fa85b6e2afe6a6d4a4b2ccdcd9d7f6e26bdac25bca4cce15c0d91b487d10f

Observation 40477b0a-9b12-4a28-bfe1-36da9440ec23 · outbound

This paper cites Tree of attacks: Jailbreaking black-box llms automatically,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Tree of attacks: Jailbreaking black-box llms automatically,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.382227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.382227Z digest=sha256:80eac7b292bc902b25652e3ea3032ea8a41be611ed6e52bbc8a9fda39136aacf

Observation 7986393b-053b-411a-9513-0af5e38c9095 · outbound

This paper cites Jailbreaking black box large language models in twenty queries,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Jailbreaking black box large language models in twenty queries,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.449184Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.449184Z digest=sha256:cde13d4507d44069ddb93d40232fc37dbccc2a3d75d2e5d317b2805a4857c0c2

Observation 8b07b5e7-5bfc-4f94-a98d-05a9ccd7b76a · outbound

This paper cites Agentvigil: Automatic black-box red-teaming for indirect prompt injection against llm agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Agentvigil: Automatic black-box red-teaming for indirect prompt injection against llm agents,

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.370992Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:46.532386Z digest=sha256:8bb8ff1fcec9fb61e0866397539a509d6686e12eb242e54d0f772b7a9e30e817

Observation 975147fa-4954-4812-8b14-8f12eb3df08d · outbound

This paper cites Piarena: A platform for prompt injection evaluation,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Piarena: A platform for prompt injection evaluation,

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.198269Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:46.588128Z digest=sha256:fff42ff2970eeec9a020c03efa80f162f764d148b2acd5965a4bffa57e613364

Observation d4dae2ee-2ff0-427c-83aa-68f923b3ab64 · outbound

This paper cites Gpt-red: Automated red teaming via self-play at scale.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Gpt-red: Automated red teaming via self-play at scale

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:55.032827Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:46.654896Z digest=sha256:edee68319b488d36b4a2b752f60ebf7722718dbd61a96a3a12218f3686a815b0

Observation 6b1bbc84-dceb-4cd5-8669-4c88c9828352 · outbound

This paper cites How vulnerable are ai agents to indirect prompt injections? insights from a large-scale public competition,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming How vulnerable are ai agents to indirect prompt injections? insights from a large-scale public competition,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.711658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.711658Z digest=sha256:a9ad6bc50a9dd8d3e5e9e8a2ec863d1ba7049da3f7e3d93995dfc50c56715cac

Observation f286f7ff-181a-40e7-8e00-de6f0b86b501 · outbound

This paper cites Muzzle: Adaptive agentic red-teaming of web agents against indirect prompt injection attacks,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Muzzle: Adaptive agentic red-teaming of web agents against indirect prompt injection attacks,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.767256Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.767256Z digest=sha256:500af6fde96f8a735f217ce75275dbd5b08e475ce70eb17592fb1168283a3ace

Observation 66b2b30e-52df-4521-8173-9b09574fa6b6 · outbound

This paper cites Autodan- turbo: A lifelong agent for strategy self-exploration to jailbreak llms,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Autodan- turbo: A lifelong agent for strategy self-exploration to jailbreak llms,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.785109Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:46.906206Z digest=sha256:d0fcba3f6ec7db2c5a96a2a96f028987793cf5658ce1d6bfd0bcbb09b3931236

Observation 773492fa-d159-4a91-b778-4d6aac32070e · outbound

This paper cites DecodingTrust-Agent Platform (DTap): A Controllable and Interactive Red-Teaming Platform for AI Agents.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming DecodingTrust-Agent Platform (DTap): A Controllable and Interactive Red-Teaming Platform for AI Agents

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:46.996106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:46.996106Z digest=sha256:3e8c50613147eb1f11f8e7d9db343977ffc66a12f497a5dc51a03c819f9ce0ae

Observation ef34a227-74f2-469e-9719-296058853a8b · outbound

This paper cites ReAct: Synergizing Reasoning and Acting in Language Models.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming ReAct: Synergizing Reasoning and Acting in Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.055268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.055268Z digest=sha256:b815b7d0f2af9a255f4ed0b6a175ea26c94f5b5b3af545e602577856e0d53176

Observation 83da0063-c6d1-44d6-ad44-f293bc8c0929 · outbound

This paper cites Toolllm: Facilitating large language models to master 16000+ real-world apis,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Toolllm: Facilitating large language models to master 16000+ real-world apis,

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.496789Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:47.096713Z digest=sha256:e8c0e4a74c4401fc6f611b0cf43b889da87a7c1836c11172a1ee0ae54862be88

Observation e32db511-3395-4a05-b2f4-daa3e63dbbf3 · outbound

This paper cites Autoharness: improving llm agents by automatically synthesizing a code harness,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Autoharness: improving llm agents by automatically synthesizing a code harness,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.164645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.164645Z digest=sha256:e63460ef4f30d76c1a2dadbbcb808a407897019b3f7e347f542e1d555b61b0fe

Observation 3e3a3567-d74d-46e1-965d-21c61d8ce21a · outbound

This paper cites Multi-agent Architecture Search via Agentic Supernet.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Multi-agent Architecture Search via Agentic Supernet

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.247014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.247014Z digest=sha256:d5a678806de993f4b608f86d517bd6f000434129a1f5f03ab2b8705061abcee1

Observation 554b4a78-c0c9-49bb-8e1c-30dc5a1c2eaa · outbound

This paper cites TextGrad: Automatic "Differentiation" via Text.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming TextGrad: Automatic "Differentiation" via Text

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.342591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.342591Z digest=sha256:7bebac54b2f70a9739cb284b66d1f50d2bb8da34f2b734193bc53bdf1d0d463f

Observation 3c0af994-60f6-4303-96f5-c5a3d88969e6 · outbound

This paper cites Test-time training with self-supervision for generalization under distribution shifts,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Test-time training with self-supervision for generalization under distribution shifts,

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.272634Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:47.402594Z digest=sha256:3b2063426bdfe2858bffe95bfe4fee37546c13ed6a0d12c936824828d8bc397f

Observation 4761427b-17af-4cfc-94f1-f0fe0af33f58 · outbound

This paper cites Gemini CLI: An open-source AI agent for the terminal,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Gemini CLI: An open-source AI agent for the terminal,

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:54.073223Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:47.493187Z digest=sha256:4dabd8763c20f7ebe0a5764e422c794e0741467e147c18e9bd4a0979fffe466e

Observation 5a1b9b39-aa08-4a74-b822-af031cc6d786 · outbound

This paper cites Codex CLI: A lightweight coding agent that runs in your terminal,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Codex CLI: A lightweight coding agent that runs in your terminal,

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.825124Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:47.564559Z digest=sha256:e63918392082dfdf4315100194aa358c961a0de1403c7bfc33c02ad4eca209a8

Observation b8b85a14-c728-4f94-8f93-c37e7e3f8b8d · outbound

This paper cites Claw code: A clean-room open-source coding-agent CLI,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claw code: A clean-room open-source coding-agent CLI,

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.561952Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:47.614225Z digest=sha256:a3bab44d9615119bd26e9593f5e8187fa52b890d2b8aeb3bc18ea1328ca93294

Observation c49965f8-9100-48da-8537-c1ebcda2ae54 · outbound

This paper cites Hermes agent: An open-source self-hosted autonomous AI agent,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Hermes agent: An open-source self-hosted autonomous AI agent,

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.262640Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:47.654480Z digest=sha256:0822cd440414ae6b0c71cf62755a464e34c58abc8c167c5d6a6e033bcf15440d

Observation 72716773-1290-4acc-85d2-783456d67671 · outbound

This paper cites Claude code: An agentic coding tool for the terminal,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claude code: An agentic coding tool for the terminal,

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:53.011248Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:47.694271Z digest=sha256:3997f56546aac8e5d9c4bfb0831a46200f40e30af7fc2d386f7d69ac5f3b88c6

Observation 03c25b03-505b-4056-9caa-f7d8060cf3a2 · outbound

This paper cites Attention tracker: Detecting prompt injection attacks in llms,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Attention tracker: Detecting prompt injection attacks in llms,

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:52.823611Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:47.764775Z digest=sha256:9349c52aa094d4aa43c0804b322f262c1f76281a069bcab00cfae4c4c6b6f65d

Observation 6bf302bb-3a4c-4b99-9e42-3f29ecb6f5dd · outbound

This paper cites Piguard: Prompt injection guardrail via mitigating overdefense for free,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Piguard: Prompt injection guardrail via mitigating overdefense for free,

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:52.534030Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:47.844255Z digest=sha256:5db7d65a852c5a04dc496ad44f38c9bae73acb0e9020524d379a3fc753da1ab1

Observation 4c31e5f5-4e0d-4b42-9b48-68ca1a65e058 · outbound

This paper cites Pishield: Detecting prompt injection attacks via intrinsic llm features,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Pishield: Detecting prompt injection attacks via intrinsic llm features,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.884895Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.884895Z digest=sha256:7e76037de0f0051fe83479134b2e1b200739e6490d72f2a0a8757adc30d0c655

Observation b87c2d68-6b1a-4788-97cb-a45d674b1b06 · outbound

This paper cites Pisanitizer: Preventing prompt injection to long-context llms via prompt sanitization,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Pisanitizer: Preventing prompt injection to long-context llms via prompt sanitization,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.889944Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.889944Z digest=sha256:2109d6e53b0b71d0d5276d5faf3726557d8bb32dfbd77b4d455e2d06b61b1b9a

Observation 407bed97-eabb-4702-8561-0b84d15625bf · outbound

This paper cites PromptArmor: Simple yet Effective Prompt Injection Defenses.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming PromptArmor: Simple yet Effective Prompt Injection Defenses

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:47.970675Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:47.970675Z digest=sha256:35bfc184da52de24da79a13214d49c5be913db2b0d86bc02edeb8b117cd81676

Observation 333ca45e-6c47-4e83-9f80-76610928175c · outbound

This paper cites Defending against prompt injection with datafilter,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Defending against prompt injection with datafilter,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.140727Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.140727Z digest=sha256:848a4b48c2cee53d9912c575d9041e524e35e48735c9af7a5e5c9673dd608b50

Observation 059b8f4f-e9f5-4311-a80e-d78b91967332 · outbound

This paper cites Defeating Prompt Injections by Design.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Defeating Prompt Injections by Design

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.276646Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.276646Z digest=sha256:61b461749463c70a25fd000214cdb118ffa767b3bd1583318d338dedb87b4ccb

Observation 82359524-7b03-44e3-a8b2-982d4129ad90 · outbound

This paper cites Drift: Dynamic rule-based defense with injection isolation for securing llm agents,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Drift: Dynamic rule-based defense with injection isolation for securing llm agents,

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:52.260009Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:48.451426Z digest=sha256:c2c52542f23ca0876355834577315edcef0f4b8f0682ef0960c8a0ee27848dc4

Observation d8392da2-dc0a-404f-91c0-488d8251085d · outbound

This paper cites AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.601504Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.601504Z digest=sha256:ac14112095e6800811d4f03484be55b56f553a2778dc8d4d5dd179a8ab511208

Observation c23152a6-c5e5-4cd2-a546-fbde8379b1b4 · outbound

This paper cites Claude opus 4.8 system card,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Claude opus 4.8 system card,

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:51.990541Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:48.792435Z digest=sha256:b910d3c5c2f0b58ffe008d68efd273d23cb3b8a2f362ce0197e65cac1304dd9f

Observation d09fb8ad-d715-4abd-8272-6f2a4d75c615 · outbound

This paper cites Secalign: Defend- ing against prompt injection with preference optimization,.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Secalign: Defend- ing against prompt injection with preference optimization,

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:51.702584Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:48.892272Z digest=sha256:9c85de008b96cf0f451631e863c703deb6c30eb1c1dd7ff580d82d4042b2bf52

Observation 9f07afa9-9677-4cdc-8795-3b858e9f8935 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-06T05:11:48.996878Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T05:11:48.996878Z digest=sha256:6aa20ffd2e7a0b6d04f563f65770e299193347b1a7e6bd082b27f314855345d4

Observation c7126831-551e-4344-84b8-ffab5e6054f3 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 50

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:51.514757Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:49.034052Z digest=sha256:ecec201289cc6d22be7c22772ba69f49cae32efe9b8405c2be65fef06abbee8a

Observation f5074bf4-fd08-4704-b766-4b57a2c2cdc8 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 51

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:51.296756Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:49.083594Z digest=sha256:0f1dcd48ce556b03dbf068357a05bd97961b68a8b24481829f114bd813bdd3ad

Observation c1fea9e2-c54c-47e1-b6a8-1f3ee21011a3 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 52

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:51.021691Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:49.126679Z digest=sha256:3b2fe70404564f602e6b84da4b4067f69754e9179c94029620d8bf9b2879a948

Observation b27962e6-48cf-4f7a-b695-dcc41b949dc2 · outbound

This paper cites an unresolved cited work.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming Unresolved cited work

Reference 53

Resolution
unresolved
raw_fallback, observed 2026-08-06T05:11:50.833130Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:49.191010Z digest=sha256:733b36bd36de80529ae0a3e5cff4802ec7301730e79b91b36b3a638017ce078d

Observation dc2a7192-903f-4f9e-bae5-1e721339cad3 · outbound

This paper cites ## In-context examples.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming ## In-context examples

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T05:11:50.559662Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:49.260862Z digest=sha256:b7d4506131819c9caf82e0e46e446842e3e2b148c7d823e0dd8ea742bf8cc7a2

Observation a1f25a28-a12e-4227-91e7-d3686e6a9dcf · outbound

This paper cites ## When this strategy is expected to fail.

Agent Against Agent: An Agentic System for Automatic Prompt Injection Red Teaming ## When this strategy is expected to fail

Reference 55

Resolution
malformed identifier
raw_fallback, observed 2026-08-06T05:11:50.294110Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-06T05:11:49.315668Z digest=sha256:dd2c2dc259a55128a504f0c4f501b3d71111b028fb7c201ca11b63ab688cc88f

Pith citing papers

No inbound Pith citation observations are available.