{"as_of":"2026-08-08T19:35:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:dea885e20252fd9e23d123dbe065d6c720b8c1ce07c6864682a86e2ccfa340e7","coverage":[{"denominator":29,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":29,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-08T10:29:59.077007Z","state":"measured"},{"denominator":29,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":29,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-08T06:32:00.761636+00:00","state":"measured"},{"denominator":0,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[],"links":{"evidence":"/evidence","html":"/paper/2608.05563/citation-record","integrity":"/paper/2608.05563/integrity","json":"/paper/2608.05563/citation-record.json","paper":"/paper/2608.05563"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2604.08377","last_updated":"2026-04-09T15:38:27Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-04-09T15:38:27Z","title":"SkillClaw: Let Skills Evolve Collectively with Agentic Evolver","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.08377","snapshot_observed_at":"2026-08-08T10:29:58.999382Z","title":"arXiv preprint arXiv:2604.08377 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":1,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:58.999382Z"},"links":{"cited_paper":"/paper/2604.08377","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:0e0cce72a5e87056f1e06c80a5d8fdbd12240ddb5bdd2568006bef0bdad5c0b8","observation_id":"c3e34d0d-d402-44d5-b159-5dc557550844","resolution":{"observed_at":"2026-08-08T10:29:58.999382Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.003389Z","title":"arXiv preprint arXiv:2603.01145 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":2,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.003389Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:f7592bc9fc92bb6028cc9339d313086063e8626c8f8feb407e477747ff2fcb4f","observation_id":"7f49f8aa-0029-4b6e-8622-bb2d56c38e04","resolution":{"observed_at":"2026-08-08T10:29:59.003389Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2603.25158","last_updated":"2026-06-04T12:51:52Z","snapshot_observed_at":"2026-08-06T10:33:38.415457Z","submitted_at":"2026-03-26T08:26:38Z","title":"Trace2Skill: Distill Trajectory-Local Lessons into Transferable Agent Skills","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2603.25158","snapshot_observed_at":"2026-08-08T10:29:59.006107Z","title":"arXiv preprint arXiv:2603.25158 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":3,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.006107Z"},"links":{"cited_paper":"/paper/2603.25158","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:766becca33195183659a4d7dfa333583a96d4c19de9b4ebabf0af88cc5d7a846","observation_id":"12472d6b-fe59-49fe-b510-8ebf23f6ad11","resolution":{"observed_at":"2026-08-08T10:29:59.006107Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2602.02474","last_updated":"2026-05-24T19:01:09Z","snapshot_observed_at":"2026-08-03T05:25:38.558727Z","submitted_at":"2026-02-02T18:53:28Z","title":"MemSkill: Learning and Evolving Memory Skills for Self-Evolving Agents","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2602.02474","snapshot_observed_at":"2026-08-08T10:29:59.009049Z","title":"arXiv preprint arXiv:2602.02474 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":4,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.009049Z"},"links":{"cited_paper":"/paper/2602.02474","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:5d401d537f1fcb5c4564bd6aa31ac9b0185a143a8791d3ff2bfd3968c5b40e90","observation_id":"08b4280b-e5f9-442d-b016-6856c87e5c5d","resolution":{"observed_at":"2026-08-08T10:29:59.009049Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2602.08234","last_updated":"2026-02-09T03:17:17Z","snapshot_observed_at":"2026-07-06T22:45:05.823859Z","submitted_at":"2026-02-09T03:17:17Z","title":"SkillRL: Evolving Agents via Recursive Skill-Augmented Reinforcement Learning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2602.08234","snapshot_observed_at":"2026-08-08T10:29:59.011833Z","title":"arXiv preprint arXiv:2602.08234 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":5,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.011833Z"},"links":{"cited_paper":"/paper/2602.08234","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:373de9d0742095f30105252ae10cb28bb04e0b1e50f59e7cc8314cae0fad62d9","observation_id":"702c83e1-5ab8-4e44-a00b-c57fa6d90181","resolution":{"observed_at":"2026-08-08T10:29:59.011833Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2604.01687","last_updated":"2026-04-12T23:04:42Z","snapshot_observed_at":"2026-07-06T22:51:35.522923Z","submitted_at":"2026-04-02T06:43:20Z","title":"CoEvoSkills: Self-Evolving Agent Skills via Co-Evolutionary Verification","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.01687","snapshot_observed_at":"2026-08-08T10:29:59.014730Z","title":"Yu , title =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":6,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.014730Z"},"links":{"cited_paper":"/paper/2604.01687","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:f5751f33716ee677dfb88e2ffa64d9bf0a44ad1c14214bcc4cd94a4eecf6039c","observation_id":"203148ba-e32d-4464-8440-ef783a35a619","resolution":{"observed_at":"2026-08-08T10:29:59.014730Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2604.10674","last_updated":"2026-04-12T14:57:52Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-04-12T14:57:52Z","title":"Skill-SD: Skill-Conditioned Self-Distillation for Multi-turn LLM Agents","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.10674","snapshot_observed_at":"2026-08-08T10:29:59.018200Z","title":"arXiv preprint arXiv:2604.10674 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":7,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.018200Z"},"links":{"cited_paper":"/paper/2604.10674","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:48f548b1b6719a2a3dbe792a89210b821fe951e2b2dd2e78016973ee8c458e92","observation_id":"77f00043-46a6-4eaf-a298-80f1d3bc98b5","resolution":{"observed_at":"2026-08-08T10:29:59.018200Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2605.27366","last_updated":"2026-07-03T08:22:38Z","snapshot_observed_at":"2026-07-31T02:06:56.514566Z","submitted_at":"2026-05-26T17:59:19Z","title":"MUSE-Autoskill: Self-Evolving Agents via Skill Creation, Memory, Management, and Evaluation","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2605.27366","snapshot_observed_at":"2026-08-08T10:29:59.021186Z","title":"arXiv preprint arXiv:2605.27366 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":8,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.021186Z"},"links":{"cited_paper":"/paper/2605.27366","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:989bf224a6375dcdd106ca53b32f330533b03ca562367192a6070c1c158324b1","observation_id":"b13b5c2c-327a-48b4-91ae-7252cf15ba7d","resolution":{"observed_at":"2026-08-08T10:29:59.021186Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2602.12430","last_updated":"2026-06-02T16:14:54Z","snapshot_observed_at":"2026-08-06T11:11:16.632352Z","submitted_at":"2026-02-12T21:33:25Z","title":"Agent Skills for Large Language Models: Architecture, Acquisition, Security, and the Path Forward","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2602.12430","snapshot_observed_at":"2026-08-08T10:29:59.024120Z","title":"arXiv preprint arXiv:2602.12430 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":9,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.024120Z"},"links":{"cited_paper":"/paper/2602.12430","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:4887f8f40f3cc5fa1cadd6349451aa3720f83a4b50356e5115d3d1ba0a83b497","observation_id":"ef29bdbe-b321-4c9b-9221-8b3b943f35ff","resolution":{"observed_at":"2026-08-08T10:29:59.024120Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2604.09378","last_updated":"2026-04-10T14:48:29Z","snapshot_observed_at":"2026-07-06T22:58:17.167367Z","submitted_at":"2026-04-10T14:48:29Z","title":"BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.09378","snapshot_observed_at":"2026-08-08T10:29:59.027325Z","title":"arXiv preprint arXiv:2604.09378 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":10,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.027325Z"},"links":{"cited_paper":"/paper/2604.09378","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:11df8c63f1811951aade367adc3c3e8818fcb5cc3e6d6aa498750449d8463e33","observation_id":"aea099d6-7366-45a2-9533-8ba1c4da6484","resolution":{"observed_at":"2026-08-08T10:29:59.027325Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.432596Z","title":"Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security (AISec) , year =","venue":null,"work_id":"9778be8b-98d5-4be0-95da-5f486d34a910","year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":11,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.030309Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:37822dbf6113932a26432959d4ca2d48f0d9a628bd46ed3ec5743ba1bb9110a1","observation_id":"79b90aa3-c3f8-4752-ab0c-edb276d4481f","resolution":{"observed_at":"2026-08-08T10:29:59.435849Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2602.20156","last_updated":"2026-02-25T18:14:01Z","snapshot_observed_at":"2026-08-03T01:14:27.800784Z","submitted_at":"2026-02-23T18:59:27Z","title":"Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2602.20156","snapshot_observed_at":"2026-08-08T10:29:59.032958Z","title":"arXiv preprint arXiv:2602.20156 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":12,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.032958Z"},"links":{"cited_paper":"/paper/2602.20156","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:51b4c8bcfd9136cf4bf47f7cd2a9532880ea81d3a771944cb77be65a7a8ed80d","observation_id":"64822be4-74d0-45e4-a5ad-43e5fdc3d17c","resolution":{"observed_at":"2026-08-08T10:29:59.032958Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.035846Z","title":"arXiv preprint arXiv:2603.22489 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":13,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.035846Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:0f04ca6bcdd31a287cd2e9543e80d5f29a7481ab006e04100ea7c21701fe8e6a","observation_id":"9774584c-6667-4952-b88c-92c6ff73ee8e","resolution":{"observed_at":"2026-08-08T10:29:59.035846Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.423802Z","title":"34th USENIX Security Symposium (USENIX Security 25) , pages =","venue":null,"work_id":"d8e648af-a54e-459c-bd4a-c92defa790a5","year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.038339Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:51be7974b895e811818b2480c33536500cba16f013d0ae0f81cd064c9e430b21","observation_id":"18e28088-3458-4a90-9cf3-53e5daff1f5d","resolution":{"observed_at":"2026-08-08T10:29:59.426890Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.415157Z","title":"Advances in Neural Information Processing Systems , volume =","venue":null,"work_id":"ccb27863-eed9-4189-89dd-16461726351a","year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":15,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.040893Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:57082bce422a9d7bb67db9c781ab5a5c7b780676305245d0a4b4afbe498e7321","observation_id":"54f5b452-dacb-4824-8723-718e6dee17e2","resolution":{"observed_at":"2026-08-08T10:29:59.418165Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.406338Z","title":"Advances in Neural Information Processing Systems , year =","venue":null,"work_id":"5f5ba7a6-a098-4dfc-97d7-f8423eb08b35","year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":16,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.043509Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:ac8d3d6fc8b4214ca76a53d1b6287d2c7a5d8396384324a37e8b25c4e7f247a1","observation_id":"df2cb47d-369c-4a42-ac79-13752c65615d","resolution":{"observed_at":"2026-08-08T10:29:59.409483Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.02623","last_updated":"2026-04-07T14:45:15Z","snapshot_observed_at":"2026-08-05T14:57:29.112440Z","submitted_at":"2026-04-03T01:25:12Z","title":"Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.02623","snapshot_observed_at":"2026-08-08T10:29:59.046095Z","title":"arXiv preprint arXiv:2604.02623 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":17,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.046095Z"},"links":{"cited_paper":"/paper/2604.02623","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:0a0528a02819a6cf61bf33d7995030bef9fd62faac8b98999c7e5f073291eb90","observation_id":"fdb82491-ade9-4e8c-b5b5-d6fc0aa387b8","resolution":{"observed_at":"2026-08-08T10:29:59.046095Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2604.03081","last_updated":"2026-04-03T14:58:58Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-04-03T14:58:58Z","title":"Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.03081","snapshot_observed_at":"2026-08-08T10:29:59.048951Z","title":"arXiv preprint arXiv:2604.03081 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":18,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.048951Z"},"links":{"cited_paper":"/paper/2604.03081","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:b3ad6af1f89f1e1d9571aab77588b1b6b837f6e09e02d782fb9b61af40b8f34c","observation_id":"1f9a3a05-9f45-4182-8452-59359b1b2344","resolution":{"observed_at":"2026-08-08T10:29:59.048951Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2606.07943","last_updated":"2026-06-06T02:10:03Z","snapshot_observed_at":"2026-08-07T22:38:29.909628Z","submitted_at":"2026-06-06T02:10:03Z","title":"POISE: Position-Aware Undetectable Skill Injection on LLM Agents","version":1},"cited_work":{"arxiv_id":"2606.07943","doi":null,"metadata_source":"pith","pith_arxiv_id":"2606.07943","snapshot_observed_at":"2026-08-08T10:29:59.136604Z","title":"POISE: Position-Aware Undetectable Skill Injection on LLM Agents","venue":"cs.CR","work_id":"f80d1e18-22f3-4263-b8b9-cfd9af2b5555","year":2026},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":19,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.051774Z"},"links":{"cited_paper":"/paper/2606.07943","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:50b17f20a4ef34ff980ca1005fe1bbb7e9ebeb43ee291a2c5067cf5a35dcdf44","observation_id":"52dfd8f2-2446-42f6-8087-a91c8c3ab514","resolution":{"observed_at":"2026-08-08T10:29:59.141151Z","resolver_source":"local_arxiv","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2604.22888","last_updated":"2026-04-24T09:07:05Z","snapshot_observed_at":"2026-07-06T23:09:10.050398Z","submitted_at":"2026-04-24T09:07:05Z","title":"RouteGuard: Internal-Signal Detection of Skill Poisoning in LLM Agents","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2604.22888","snapshot_observed_at":"2026-08-08T10:29:59.054626Z","title":"arXiv preprint arXiv:2604.22888 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":20,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.054626Z"},"links":{"cited_paper":"/paper/2604.22888","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:ae401f0404be60f6321bdcc8b03e4567f8a91ea9066946e6d635d9238f76289f","observation_id":"63520643-47f4-47bb-bd4a-51ecc9cb3da8","resolution":{"observed_at":"2026-08-08T10:29:59.054626Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2406.14991","last_updated":"2024-10-17T07:23:23Z","snapshot_observed_at":"2026-07-06T18:34:47.155846Z","submitted_at":"2024-06-21T09:06:45Z","title":"SpreadsheetBench: Towards Challenging Real World Spreadsheet Manipulation","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2406.14991","snapshot_observed_at":"2026-08-08T10:29:59.057018Z","title":"Advances in Neural Information Processing Systems , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":21,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.057018Z"},"links":{"cited_paper":"/paper/2406.14991","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:88df88f83682d537fc588af20a2c6d5347521183dbde3084dfff9a20e518b6da","observation_id":"7d485769-de5e-43d2-a4fa-0c9f348f2b10","resolution":{"observed_at":"2026-08-08T10:29:59.057018Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2404.13208","last_updated":"2024-04-19T22:55:23Z","snapshot_observed_at":"2026-08-02T11:48:17.206729Z","submitted_at":"2024-04-19T22:55:23Z","title":"The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.13208","snapshot_observed_at":"2026-08-08T10:29:59.059458Z","title":"arXiv preprint arXiv:2404.13208 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":22,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.059458Z"},"links":{"cited_paper":"/paper/2404.13208","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:6a3c7a2e54600392dca6e1cfb192f066ff1d510714c5aca68150d025a5d903c4","observation_id":"47a8f1cb-f459-4c87-b77a-ede1ee958333","resolution":{"observed_at":"2026-08-08T10:29:59.059458Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2410.05451","last_updated":"2025-07-03T05:45:41Z","snapshot_observed_at":"2026-07-06T19:29:18.770662Z","submitted_at":"2024-10-07T19:34:35Z","title":"SecAlign: Defending Against Prompt Injection with Preference Optimization","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2410.05451","snapshot_observed_at":"2026-08-08T10:29:59.061970Z","title":"arXiv preprint arXiv:2410.05451 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":23,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.061970Z"},"links":{"cited_paper":"/paper/2410.05451","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:5934ef2d1b8e2407646047fb4bd0dce71375f8e921aca9c0aac3267a4251ca69","observation_id":"f3623add-4284-47d0-8bfa-52234f36fd50","resolution":{"observed_at":"2026-08-08T10:29:59.061970Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2503.18813","last_updated":"2025-06-24T08:05:33Z","snapshot_observed_at":"2026-08-07T19:59:01.081751Z","submitted_at":"2025-03-24T15:54:10Z","title":"Defeating Prompt Injections by Design","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2503.18813","snapshot_observed_at":"2026-08-08T10:29:59.064504Z","title":"arXiv preprint arXiv:2503.18813 , year =","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":24,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.064504Z"},"links":{"cited_paper":"/paper/2503.18813","citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:bf9b3c1cd0ccac674022f8fb87c836d912479d58a8a3c774ccad91ac3367a847","observation_id":"06127f57-e930-4246-a512-a8b1cdb6e24d","resolution":{"observed_at":"2026-08-08T10:29:59.064504Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.397035Z","title":"28th USENIX Security Symposium (USENIX Security 19) , pages =","venue":null,"work_id":"52f041c2-9156-446c-9667-728f181ffb98","year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":25,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.067049Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:7cfcd639ed5e855732433e783be83c43b9bfd12ea7cd820f8b5c41831ed325fe","observation_id":"336e4314-02d9-4ddf-a668-e55e0f97dd8a","resolution":{"observed_at":"2026-08-08T10:29:59.400361Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.069386Z","title":"2025 , note =","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":26,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.069386Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:b658607d5667cb01b1227b30b20ab4856dd3b8945a66ebaf2909e8aa252e71c0","observation_id":"de25e940-1677-4624-9375-6bdc24afb8c9","resolution":{"observed_at":"2026-08-08T10:29:59.069386Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.382942Z","title":"2025 , note =","venue":null,"work_id":"15971ef3-beba-4961-875f-2b1e5e22b088","year":2025},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":27,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.072029Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:eb021d73718f75a509492fc35f21ca01a0e59bf72c317d97fc05905382a1033f","observation_id":"5d1398a4-01b8-4d7f-8e7a-a9b543fa0c1e","resolution":{"observed_at":"2026-08-08T10:29:59.386209Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.374102Z","title":"2025 , note =","venue":null,"work_id":"52c321ab-f80f-4498-8d61-21e39f04f966","year":2025},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":28,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.074545Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:61aab98c601c8483fc973913abb8be555ba43d28b77f01f392def5de658470d9","observation_id":"4d322958-8d36-431e-8b62-b1a0db7d55ae","resolution":{"observed_at":"2026-08-08T10:29:59.377279Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-08T10:29:59.365053Z","title":null,"venue":null,"work_id":"9d613181-0260-4bf0-b425-7dbfb36b7536","year":null},"citing_paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems","version":1},"reference_index":29,"source":"arxiv_source","source_observed_at":"2026-08-08T10:29:59.077007Z"},"links":{"citing_paper":"/paper/2608.05563"},"observation_digest":"sha256:3c68af2c14285db1b340ad469b80238b21fd6eba20a3c4a210f83fd282375f46","observation_id":"8b82ca98-fcbc-4da9-9b2c-14ef16bd0991","resolution":{"observed_at":"2026-08-08T10:29:59.368087Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2608.05563","last_updated":"2026-08-06T03:32:43Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-08T19:16:30.380617Z","submitted_at":"2026-08-06T03:32:43Z","title":"When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems"},"reference_resolution":{"displayed":29,"state_counts":{"malformed_identifier":0,"metadata_mismatch":1,"parse_uncertain":0,"unresolved":21,"verified_exact":0,"verified_fuzzy":7},"total_outbound_references":29},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"thesis":"As of 8 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 0 inbound Pith citation observations for arXiv:2608.05563."}