{"as_of":"2026-08-08T15:45:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:4bd3a88cfab26328e2a118f232865e912dd1ebf3f32d505770915fd06b88d2fc","coverage":[{"denominator":14,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":14,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T14:27:34.042960Z","state":"measured"},{"denominator":14,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":14,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-08T06:32:00.761636+00:00","state":"measured"},{"denominator":0,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[],"links":{"evidence":"/evidence","html":"/paper/2608.06130/citation-record","integrity":"/paper/2608.06130/integrity","json":"/paper/2608.06130/citation-record.json","paper":"/paper/2608.06130"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2503.23278","last_updated":"2025-10-07T07:13:32Z","snapshot_observed_at":"2026-07-06T21:00:55.979837Z","submitted_at":"2025-03-30T01:58:22Z","title":"Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2503.23278","snapshot_observed_at":"2026-08-07T14:27:33.135800Z","title":"Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Direc- tions,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.135800Z"},"links":{"cited_paper":"/paper/2503.23278","citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:5bd89c8e534a098c674672077ec6d3b6f0c295d44945bcaa6981dbf0c6e7b504","observation_id":"17a7852e-c1b4-4476-a390-2db3f4145d40","resolution":{"observed_at":"2026-08-07T14:27:33.135800Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:35.533341Z","title":"OpenClaw Security Policy,","venue":null,"work_id":"0d0dceeb-111c-4c1d-884f-f63ccca18ea0","year":null},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.170766Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:f58b3c359c1fd9cb7aa6bdcca37f143056d906f61220e210ec7c8607c29c50dd","observation_id":"fe31d99e-b749-4a5c-a88b-1cff9b1c28d8","resolution":{"observed_at":"2026-08-07T14:27:35.587887Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:35.219997Z","title":"Infostealer Steals OpenClaw AI Agent Sessions,","venue":null,"work_id":"f1adeb1e-3c47-4f7b-a9ca-87dd5cac1f49","year":2026},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.324733Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:e92f96f669309caa5c54a5def09f53b492392b994f8ecac08176f46b55e7015f","observation_id":"781c1802-1add-4254-bcf8-20d9d238cc4d","resolution":{"observed_at":"2026-08-07T14:27:35.308761Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:33.395556Z","title":"Blind Gods and Broken Screens: Architect- ing a Secure, Intent-Centric Mobile Agent Operating System,","venue":null,"work_id":null,"year":2026},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.395556Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:a20ca8608a67fcc58b8f183a3e4f29f055260da38339b5155c72dc9b03d917c9","observation_id":"4fef9ecd-3aea-420b-96f7-30be572e6b89","resolution":{"observed_at":"2026-08-07T14:27:33.395556Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:35.121364Z","title":"NemoClaw: Enterprise Security and Privacy for OpenClaw AI Agents,","venue":null,"work_id":"294a81e1-6797-4ae2-8204-76e7c923197d","year":2026},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.482854Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:6f237c7ff875cf3336ec685e3f015a34cb3b7ae0fed81f985b7865e32289a962","observation_id":"6e4e2448-d45a-41ce-8199-bd445b918086","resolution":{"observed_at":"2026-08-07T14:27:35.154261Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:34.965304Z","title":"MCP-Secure: A Runtime Access Control Layer for Privilege-Aware LLM Agent Tooling,","venue":null,"work_id":"fc4c8e6d-b6b0-429e-9340-b01df1690325","year":2026},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.558101Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:f9442dfe45dd7212968b95c1b7c69f20d491a05b9bc3fb94894e5f0cba1d4cb0","observation_id":"6e57f795-94c5-4d9b-b8c9-ab7b958b1f23","resolution":{"observed_at":"2026-08-07T14:27:35.052952Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.21034","last_updated":"2025-08-29T17:59:50Z","snapshot_observed_at":"2026-08-07T15:58:46.201544Z","submitted_at":"2025-04-27T23:10:00Z","title":"SAGA: A Security Architecture for Governing AI Agentic Systems","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.21034","snapshot_observed_at":"2026-08-07T14:27:33.593269Z","title":"SAGA: A Security Architecture for Governing AI Agentic Systems,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.593269Z"},"links":{"cited_paper":"/paper/2504.21034","citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:0cb44a79f45b73cdad3590562e03eadd0fcd28d993898ca0ef76307de0e59333","observation_id":"27acd262-2487-4caa-9597-9ecfb5e8fa8c","resolution":{"observed_at":"2026-08-07T14:27:33.593269Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:34.862751Z","title":"Agent- Bound: Securing Execution Boundaries of AI Agents,","venue":null,"work_id":"211e18b2-43b7-4c80-bdd7-4de6689f680e","year":null},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.675516Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:9728ecbbabf34bfb1bac7e10a7c5bb2dfdf63e49356100e1d1a13ec8713ec50b","observation_id":"5881482b-84ef-4d1f-8a1c-4fc52b977055","resolution":{"observed_at":"2026-08-07T14:27:34.903250Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2504.08623","last_updated":"2025-05-02T18:26:39Z","snapshot_observed_at":"2026-08-07T16:06:28.979271Z","submitted_at":"2025-04-11T15:25:58Z","title":"Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.08623","snapshot_observed_at":"2026-08-07T14:27:33.775533Z","title":"Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.775533Z"},"links":{"cited_paper":"/paper/2504.08623","citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:a24b1873c9e92fdf768db97f34bed12f3976dc7ef75140f1f39c03d1681fd2db","observation_id":"7e6b9710-23b0-470b-920c-62a78fdffe36","resolution":{"observed_at":"2026-08-07T14:27:33.775533Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2504.03767","last_updated":"2025-04-11T16:59:05Z","snapshot_observed_at":"2026-08-07T16:13:26.130839Z","submitted_at":"2025-04-02T21:46:02Z","title":"MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2504.03767","snapshot_observed_at":"2026-08-07T14:27:33.809373Z","title":"MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits,","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.809373Z"},"links":{"cited_paper":"/paper/2504.03767","citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:c4e5519006d219488e3e3dbd03ef3e26203c5e6fd68cad449389f960d65feaeb","observation_id":"932c6c89-b55f-4316-bd74-f27663fbc676","resolution":{"observed_at":"2026-08-07T14:27:33.809373Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:34.678945Z","title":"AgentDojo: A Dynamic Environment to Eval- uate Prompt Injection Attacks and Defenses for LLM Agents,","venue":null,"work_id":"c9c02548-a038-4547-88b8-41e07a04f8b1","year":2024},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.908450Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:3b29f778258d17bfac669c6e8fec91830d236c6f10db3716891f1da300ede645","observation_id":"a12ff46d-8645-4885-a600-d3e3e92d3d2a","resolution":{"observed_at":"2026-08-07T14:27:34.768361Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:34.535927Z","title":"InjecAgent: Benchmark- ing Indirect Prompt Injections in Tool-Integrated LLM Agents,","venue":null,"work_id":"7afab948-7f2e-4c58-addc-602331c66d85","year":2024},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.993638Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:eeefcbfdd453715fb0b19e672e5791c5ac80c51e2d8e1963f0fa1bccca8a59b8","observation_id":"1025c973-6284-472f-9f94-026673b0a0df","resolution":{"observed_at":"2026-08-07T14:27:34.609680Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:34.370106Z","title":"AI Agent Traps,","venue":null,"work_id":"338d0857-eb77-4efe-b4d4-837e27d7efa3","year":2026},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:34.042960Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:6ca27895c0239e757526183ce2cb5461082be1b626dd1c85a7f88cc96b6dcbd7","observation_id":"9a1a3a07-f3fb-4865-a3d9-bacfffeff1b7","resolution":{"observed_at":"2026-08-07T14:27:34.416997Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T14:27:35.379081Z","title":"Available: https://github.com/openclaw/openclaw/ blob/main/SECURITY .md","venue":null,"work_id":"0ea86990-1e11-47a3-acb2-bf00217e0f56","year":null},"citing_paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture","version":1},"reference_index":2026,"source":"pdf_text","source_observed_at":"2026-08-07T14:27:33.282486Z"},"links":{"citing_paper":"/paper/2608.06130"},"observation_digest":"sha256:5bfeced454a1ade7f39147a54e4e8d9d459b462264a128039538dfa8741ab23f","observation_id":"30f2f200-8973-4532-be4b-8ea5dd2f96c5","resolution":{"observed_at":"2026-08-07T14:27:35.448525Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2608.06130","last_updated":"2026-08-06T15:04:26Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-08T15:19:47.725305Z","submitted_at":"2026-08-06T15:04:26Z","title":"Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture"},"reference_resolution":{"displayed":14,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":5,"verified_exact":0,"verified_fuzzy":9},"total_outbound_references":14},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-08T06:32:00.761636+00:00","source":"crossref"},{"observed_at":"2026-08-08T06:31:55.24221+00:00","source":"retraction_watch"}],"thesis":"As of 8 August 2026, this Paper Citation Record lists 14 of 14 outbound references and 0 inbound Pith citation observations for arXiv:2608.06130."}