Pith. sign in

Paper Citation Record · LEDGER

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems

As of 14 August 2026, this Paper Citation Record lists 23 of 23 outbound references and 0 inbound Pith citation observations for arXiv:2607.19432.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.19432 v1

Coverage vector

measured 23 of 23 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-01T15:07:27.137476Z

measured 23 of 23 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-13T06:32:02.005865+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

23 of 23 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved23
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 297ecb51-a18b-4f54-92bf-ea852bf64b3f · outbound

This paper cites Introducing the Model Context Protocol,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Introducing the Model Context Protocol,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:25.078957Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:25.078957Z digest=sha256:b5b8a7c4ff167b248f4f288de9c9b34392e4a876e9e232e7b1be27c84c3ecdcb

Observation 7fcd43c2-53aa-4586-b12f-09ea20480fdb · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:25.375608Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:25.375608Z digest=sha256:be40d16c39935c1f44a013b7c22921e0475994bba47d1e39b6d215034165de5d

Observation 04849e86-e6cb-4d28-b1be-e6afc5c30c46 · outbound

This paper cites MCP Security Notification: Tool Poison- ing Attacks and GitHub MCP Prompt Injection,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCP Security Notification: Tool Poison- ing Attacks and GitHub MCP Prompt Injection,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:25.544016Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:25.544016Z digest=sha256:714e08db012f2043f5bf19d3daf8b4a5d9d0c5bdc875b779177f13f34686bd97

Observation cf71caf9-db01-46bd-968c-f1304c3ddaaa · outbound

This paper cites WhatsApp MCP Exploited via Rug-Pull At- tack,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems WhatsApp MCP Exploited via Rug-Pull At- tack,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:25.602557Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:25.602557Z digest=sha256:0ec6696a7e975b2276c5f4826ba7cb4c416ff4b3a487d51607b378b90d79156f

Observation 0881bdf9-edf7-46d9-bf0c-d7d0962ec40f · outbound

This paper cites STAC: When Innocent Tools Form Dangerous Chains for LLM Agents.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems STAC: When Innocent Tools Form Dangerous Chains for LLM Agents

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:25.693636Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:25.693636Z digest=sha256:9e303e8b06680b98c44c46a84455fbf9cb9dbaafd90242b1932dc7439c3c15d7

Observation 65f1943e-24c4-473c-9887-ab358dc24999 · outbound

This paper cites The Promptware Kill Chain,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems The Promptware Kill Chain,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:25.774651Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:25.774651Z digest=sha256:accff8773afaf065ad2f324cd75b34956d87676cf9fdd0069a2609f721aa94ee

Observation 6b5ead94-6e06-456a-a533-e26dd79ef1c2 · outbound

This paper cites MCPShield: A Security Cognition Layer for Adaptive Trust Calibration in Model Context Protocol Agents,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCPShield: A Security Cognition Layer for Adaptive Trust Calibration in Model Context Protocol Agents,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:25.951008Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:25.951008Z digest=sha256:c87c850245f15d61d940673d67fb99e3e4dd2c85dc0f2f798d0381ac23be3006

Observation f1ba299a-d8ca-40a0-93da-835264868d79 · outbound

This paper cites MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCP-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.076931Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.076931Z digest=sha256:fb13d731d73b1c767e8ddc88332dad7b7c2d8ff4a0a9e1e78c9a4970f289e38b

Observation 00143c95-048a-4af2-a9b5-3d83aadadea0 · outbound

This paper cites MindGuard: Tracking, Detecting, and Attributing MCP Tool Poisoning Attack via Decision Dependence Graph,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MindGuard: Tracking, Detecting, and Attributing MCP Tool Poisoning Attack via Decision Dependence Graph,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.138141Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.138141Z digest=sha256:a65563fdba2160f9fe66ebd55255de1acd05edf23ed7cfae61ded86e327ce4f4

Observation 5d1b7a0b-8918-4914-97de-e8df3ed51067 · outbound

This paper cites MCPTox: A Benchmark for Tool Poisoning on Real-World MCP Servers,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCPTox: A Benchmark for Tool Poisoning on Real-World MCP Servers,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.188371Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.188371Z digest=sha256:813628593647e4d12725310c82e6d4a4011eaa5254a205996b0e94818ace0712

Observation ac9760dd-fcee-4ada-9c1f-9d509e6b9ad9 · outbound

This paper cites Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.264517Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.264517Z digest=sha256:000b23d029093dad8533f80a693223b3341dc0c374fc75d3f54a4996cc86a64e

Observation 5160222a-3cc9-4d01-9c55-94a5df232b4b · outbound

This paper cites A systematic survey on multi- step attack detection,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems A systematic survey on multi- step attack detection,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.325748Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.325748Z digest=sha256:99ae4d384afc59e11b9c4da059f8fd2585f92304ceeaf71478f4023ca077e140

Observation 773bc88e-6868-40d6-8314-ee3e5b2081b4 · outbound

This paper cites Real-time multistep attack prediction based on hidden Markov models,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Real-time multistep attack prediction based on hidden Markov models,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.441209Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.441209Z digest=sha256:6fd7e857d28cddd893baaaa251ac938e231238405f0371a446c623eb859bd678

Observation a689a81e-7bc8-4f53-a1c5-e2e4fb0545ef · outbound

This paper cites KAIROS: Practical Intrusion Detection and Investigation using Whole- system Provenance,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems KAIROS: Practical Intrusion Detection and Investigation using Whole- system Provenance,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.534645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.534645Z digest=sha256:f5d333ab83c8e947f89773a0a2f4e92f51e1e4fd142369dd6b0f87e0180da110

Observation 3205e2af-fccb-4420-b4f0-10af8a31d27b · outbound

This paper cites MAAC: Multi-step Attack Alert Correlation using Semantic Vectorization,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MAAC: Multi-step Attack Alert Correlation using Semantic Vectorization,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.594388Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.594388Z digest=sha256:0e8e83a4272a37f1a73406d0a481e3ec04c1a690354f4c180121d3c91b214a22

Observation 419dc962-5f29-4880-9bb4-9ac28e2d0310 · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.667184Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.667184Z digest=sha256:ca3b584e639766eec8e74b5a62e68bc3f321f7bb3268af0254b35d797443aef9

Observation f8e68bd0-9940-4d46-a07c-075d574fcc25 · outbound

This paper cites MCP-SafetyBench: A Benchmark for Safety Evaluation of Large Language Models with Real- World MCP Servers,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems MCP-SafetyBench: A Benchmark for Safety Evaluation of Large Language Models with Real- World MCP Servers,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.724243Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.724243Z digest=sha256:b68fda9ce5aec214531950189c5f4befe8cdb1e103ba8dda1197d5b54cf88313

Observation bba5fd3a-39c3-46de-b413-da05b33b197e · outbound

This paper cites Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.820487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.820487Z digest=sha256:cdf066523f605588ddb32c60641139dc22d0a4860bcd40dbf5e30c38bf25ada2

Observation 81f4d9d6-bcbd-4dce-a97d-b887707ba0fe · outbound

This paper cites Temporal Attack Pattern Detection in Multi-Agent AI Workflows: An Open Framework for Training Trace-Based Security Models,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Temporal Attack Pattern Detection in Multi-Agent AI Workflows: An Open Framework for Training Trace-Based Security Models,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:26.947983Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:26.947983Z digest=sha256:d5416bb09f43a0268fce4b77faca3bd6115c4b9cbd532515227424955d8644af

Observation 480047d8-bc68-41a9-a14e-5ea1cdd6f4c3 · outbound

This paper cites From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:27.040743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:27.040743Z digest=sha256:f084808f31ed3ac2b67237c15966c8dab5b094de984d426870b39726206f895a

Observation 11ef57fd-0de9-4141-a9b8-845aaf3494d7 · outbound

This paper cites Cross-Agent Privilege Escalation: When Agents Free Each Other,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Cross-Agent Privilege Escalation: When Agents Free Each Other,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:27.073413Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:27.073413Z digest=sha256:d34fdd6c5280424fa0f257746411ec70c19fe4f86d9b347fdf62ea8605be1195

Observation 8c0ed8bd-ff51-4e02-b3e7-88c98fe23732 · outbound

This paper cites Poison Everywhere: No Output from Your MCP Server is Safe,.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Poison Everywhere: No Output from Your MCP Server is Safe,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:27.137476Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:27.137476Z digest=sha256:406d9ab509a2bd001b761795ca45bd9c772fc15109c623c5564deedaaea14d62

Observation a8fa1f76-858c-4d0a-8631-7fbab9b279bb · outbound

This paper cites Available: https://www.anthropic.com/news/ model-context-protocol.

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems Available: https://www.anthropic.com/news/ model-context-protocol

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-01T15:07:25.234002Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T15:07:25.234002Z digest=sha256:4540d77e4b5ec27ba57769e2f5ee3e15be503aa18a16f069d643f235d71e86bd

Pith citing papers

No inbound Pith citation observations are available.