Pith. sign in

Paper Citation Record · LEDGER

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents

As of 8 August 2026, this Paper Citation Record lists 32 of 32 outbound references and 0 inbound Pith citation observations for arXiv:2608.05884.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.05884 v1

Coverage vector

measured 32 of 32 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T21:46:23.185376Z

measured 32 of 32 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

32 of 32 outbound references displayed

  • verified exact0
  • verified fuzzy15
  • unresolved11
  • parse uncertain2
  • malformed identifier0
  • metadata mismatch4

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 5415756e-7ed2-4c3c-9b3b-729ecdec0aea · outbound

This paper cites Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.737672Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.031735Z digest=sha256:f953fcb7f4b7ee0c09a71c5cbd4a7a736b50886934017649d0699ecbac792917

Observation 1c2e7a2d-8b3d-499c-aed1-a17b73d9d6bd · outbound

This paper cites Accelerating the adoption of software and artificial intelligence agent identity and authorization.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Accelerating the adoption of software and artificial intelligence agent identity and authorization

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.726853Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.037423Z digest=sha256:6e03c3c87d3a5d92d6db64379e114083977ac32b4e939bf414588fe08f287597

Observation 64eb9206-c389-450c-bcd7-87fe3c47336f · outbound

This paper cites CVE program glossary.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents CVE program glossary

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.716191Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.046348Z digest=sha256:981a45bad8dce17a705dd9a0be1c912423a60b8ecb131f785aec7410bb433615

Observation 930953cb-2ee5-4d72-bb2e-5c977f8edd12 · outbound

This paper cites Agent baseline: Six security outcomes for safely building, deploying and operating AI agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Agent baseline: Six security outcomes for safely building, deploying and operating AI agents

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.705198Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.050508Z digest=sha256:0bdab9021ce1f6082f17afe1a1ba5dbed73bf0f3d34f0c1550b79c6f44dc704e

Observation 1f5feeca-7050-4879-8650-638a5c4ffaa4 · outbound

This paper cites Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.693093Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.054324Z digest=sha256:f4ed5a9dd24a3f62bd1fa7b5a74aaa9d903fbb8218b63f979c61c62993568ee7

Observation abecf350-9b96-4983-9a10-a0ac1664572d · outbound

This paper cites LLM06:2025 Excessive Agency.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents LLM06:2025 Excessive Agency

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.681955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.066092Z digest=sha256:3bb191e76c76bfbc12fad5e2a4d9a7c82ef0cb12ed65f080f68b797e1ea8463c

Observation 42e2e241-18c1-4abd-a900-e0060a5efa35 · outbound

This paper cites Complete Dictionary Learning via $\ell_p$-norm Maximization.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Complete Dictionary Learning via $\ell_p$-norm Maximization

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.078142Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.078142Z digest=sha256:d2891e5bdeab17afc137b7a973cffe1d0ab5928aeafecf48003ecfc0d8fa5d72

Observation 932b6529-685a-418a-9d9c-4184cb5f23aa · outbound

This paper cites Guide to enterprise patch management planning: Preventive maintenance for technology.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Guide to enterprise patch management planning: Preventive maintenance for technology

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.671347Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.082061Z digest=sha256:ce5b7f461df7f0c90ca4a0880ce1c1fd73cd585d469aea67c228487138fe731f

Observation 75c001a0-a75b-47d6-a6e3-251beac83376 · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.092713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.092713Z digest=sha256:82b6ca76b39fdbcbe04bb664941c5a6306ebd609a851f0b1049e82b26b0eb906

Observation 96f6e19c-3e4f-4f76-b2e7-3adf4810215a · outbound

This paper cites Cyber defense matrix.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Cyber defense matrix

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.660898Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.104328Z digest=sha256:6cbf1e2fe9f20b77dd7a3e89156d67ded0d8884271f7b2042f941e9929ba2588

Observation cb7c2515-45dd-4fd0-ac2c-e99a6953accf · outbound

This paper cites AI agent remote code execution.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents AI agent remote code execution

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.650229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.107898Z digest=sha256:fc972de34ee3d898a0a140f4f927cc0747d804ccf8bf6c2ef67375ca3003d005

Observation 3276b1c2-7c82-4d44-9fcf-66944c7e54c9 · outbound

This paper cites , howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents , howpublished =

Reference 22

Resolution
parse uncertain
no resolver link, observed 2026-08-07T21:46:23.115180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.115180Z digest=sha256:1d61b138565324065e33780c2d0def5b904424efecd719b710ad9da1d2a90cc2

Observation b5cd30f9-2f84-4298-b025-caca076eeb17 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 23

Resolution
parse uncertain
no resolver link, observed 2026-08-07T21:46:23.118904Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.118904Z digest=sha256:20c149527f25c17860bbc70d3b3e9d5161daf7392d035a51d7665ba43517a202

Observation ebee3091-c85d-4e25-95d4-22842858a8b5 · outbound

This paper cites 2026 , month = jul, howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2026 , month = jul, howpublished =

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.624209Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.122223Z digest=sha256:495a1009872c1adf889a3cde2cc57782c2103285d62aef78dc5740b03c48515d

Observation 739dbcfe-6dbf-4919-ab1a-3ffa606b8483 · outbound

This paper cites 2025 , month = aug, howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2025 , month = aug, howpublished =

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.613044Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.125718Z digest=sha256:09fc15d41979f09b4e1fd0e30044ec716a3d76fdb2b6056e2df247cb63022da5

Observation 7fb36911-593c-41d2-a412-80ee9afb4ae5 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.129671Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.129671Z digest=sha256:644513c060b71d692828c4fd39862b8c7c4ec60bbda3c1cf908ca55710b14cd0

Observation 18313a73-227c-434a-906c-35357144d502 · outbound

This paper cites 2022 , month = apr, doi =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2022 , month = apr, doi =

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.594302Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.133320Z digest=sha256:bb461c48604cd4eeffe80953a565f8fbc6d670928f2aa25bb2ff37c2d6d95dd3

Observation bdc2018d-2675-4b72-bef5-1e09df9862da · outbound

This paper cites Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.136931Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.136931Z digest=sha256:a4c67673e8cc193a21f392dc0c75447274e97da59a57bb733116be1e07bb660e

Observation 1f2dd371-a2fd-47a6-afc7-f937b711a170 · outbound

This paper cites Haines and Somesh Jha and Richard P.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Haines and Somesh Jha and Richard P

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.583226Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.140659Z digest=sha256:0f4fc44d36baffcb7b15df93abf18353b799cd6926be288b9a499d50e55659b4

Observation 217393ac-46d8-491c-b418-cec6ad2f4f7c · outbound

This paper cites 2026 , month = feb, type =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2026 , month = feb, type =

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.571886Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.144245Z digest=sha256:de0ef6fb749866e19a0255d6d766b2f8a899078f2348f144991addbb38535f44

Observation 74dc51d4-9edb-4f76-955e-d8249283dfd3 · outbound

This paper cites Authenticated Delegation and Authorized AI Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Authenticated Delegation and Authorized AI Agents

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.147775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.147775Z digest=sha256:33d37bb738610decad99606f4c06a7261c02f9f74aca64548a80476c1219ccf5

Observation 512a8847-7ec1-4824-8100-9a21d45e4ff9 · outbound

This paper cites Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.151426Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.151426Z digest=sha256:2f18f0396c22125de103b58c778e44715040aeb1b6b267c9dcf8cd6626716c8c

Observation 1ff63302-8548-4a26-bae3-05156959092a · outbound

This paper cites The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents

Reference 33

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.263208Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.154924Z digest=sha256:0fc971fcad876b3e345428935f41e65afdd286a5df5b01789d6bb77d718d7742

Observation d11472dd-044d-4900-b953-607a114f83cf · outbound

This paper cites Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.158456Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.158456Z digest=sha256:0feb8e4e24ec599a273088de4260498d386b75d225fa131190d136535b2df02e

Observation b8763d81-1b0f-432a-8070-936b747ebbee · outbound

This paper cites Do Coding Agents Understand Least-Privilege Authorization?.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Do Coding Agents Understand Least-Privilege Authorization?

Reference 35

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.249319Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.161803Z digest=sha256:420fa1f877c0f5590637ac221755fd6d51e7ed282e2067be947330f387115a7a

Observation afc2c480-0158-4566-a2af-738301c2cfc6 · outbound

This paper cites Poskitt and Jun Sun , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Poskitt and Jun Sun , title =

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.560382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.165381Z digest=sha256:63a7ea155cb39640ef3fad4457b425338e90013cdc20497a55b99523fe4933af

Observation 9507c2c8-4bcb-4209-9305-bc8766478b75 · outbound

This paper cites arXiv preprint arXiv:2603.20953 , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents arXiv preprint arXiv:2603.20953 , year =

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.168974Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.168974Z digest=sha256:b59fbfc2a25f0ba60a9e3de0e43217e6d384fe05abcf326c700c58eb4e4abb00

Observation 488b57ee-d62f-4920-9e3f-555d9d1be740 · outbound

This paper cites Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.172245Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.172245Z digest=sha256:fef9a55c2dfca17c4fa825ee074c52346e6825bf36e9d691d6fc8bf1202e0958

Observation 64c2d950-463b-454b-99b2-7d8d55e974cd · outbound

This paper cites arXiv preprint arXiv:2603.16586 , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents arXiv preprint arXiv:2603.16586 , year =

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.175452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.175452Z digest=sha256:d5b4407b2d787ec22b474feb279a59991e3440abff31d0331cc4e5a35adf7a99

Observation fdc261ba-1e82-46d5-a9b2-c2aa5dc85c59 · outbound

This paper cites Intent-Governed Tool Authorization for AI Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Intent-Governed Tool Authorization for AI Agents

Reference 40

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.233895Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.178867Z digest=sha256:9eba7c9d4ea1ff46ae81a867ad4a7dc5c6506666e3c946cf74b31d9c93168e53

Observation b3f1c257-8c23-4208-ad9e-4c2310f8b43e · outbound

This paper cites When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents

Reference 41

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.447632Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.182040Z digest=sha256:cff162459e29c2d2d18395910b9e0ffc9b4a9c4e52db7cdd61d809e63ce72f8f

Observation 1217cedd-1aae-45d6-8cb5-7b32995a9e36 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 42

Resolution
unresolved
raw_fallback, observed 2026-08-07T21:46:23.549537Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.185376Z digest=sha256:1f5732aaa4fcd7469148736b04fa73db60b0a81539f06fbdfe4dc0d4b1e9d275

Pith citing papers

No inbound Pith citation observations are available.