Pith. sign in

Paper Citation Record · LEDGER

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure

As of 22 August 2026, this Paper Citation Record lists 25 of 25 outbound references and 0 inbound Pith citation observations for arXiv:2607.08288.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.08288 v1

Coverage vector

measured 25 of 25 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-07-10T10:00:19.465944Z

measured 25 of 25 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-22T06:32:14.747728+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

25 of 25 outbound references displayed

  • verified exact10
  • verified fuzzy11
  • unresolved0
  • parse uncertain0
  • malformed identifier3
  • metadata mismatch1

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation df37b3eb-ce39-4be2-9471-8fc288a5d032 · outbound

This paper cites Disrupting the First Reported AI- Orchestrated Cyber Espionage Campaign.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Disrupting the First Reported AI- Orchestrated Cyber Espionage Campaign

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.334550Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:ce92cc88feded13bd82a704e4b03dcf22ba7f0e067898b3e0d56b764fc78d7e2

Observation 26f0d3c0-3b9a-4009-84ea-e8c35fa92322 · outbound

This paper cites GPT-4.1 Model.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure GPT-4.1 Model

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.329492Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:67f1f10bdf2b110295939cc6c205db34e9804c27567f2fbaf836c5bf15513826

Observation 5c741c11-12c6-45fa-8a31-b6510f4eefe6 · outbound

This paper cites A Survey of Cyber- Physical Attacks and Detection Methods in Smart Water Distribution Systems.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure A Survey of Cyber- Physical Attacks and Detection Methods in Smart Water Distribution Systems

Reference 3

Resolution
metadata mismatch
arxiv_id, observed 2026-07-10T10:07:01.009963Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:459ac92369a8bfb1635f4b6456973035d0af6496c8211383e7969fd3bb60c94d

Observation fa7228e2-6d23-4f38-83f0-68f034ac62f9 · outbound

This paper cites L333, pp.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure L333, pp

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.315735Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:44d2fca0e7e14920625827f12d6778fed3771d649c390d36f27050b1b15373eb

Observation febf772b-be26-49e0-8ded-dba75a62b10f · outbound

This paper cites Stand-der- Technik-Bibliothek.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Stand-der- Technik-Bibliothek

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.332849Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:cd44ae50be90c2ba068e0ac1c3262e383f6a767158f2f9a86b83bfadaf3bb42d

Observation b08a8005-4a62-41db-882d-066b98cb3b51 · outbound

This paper cites Model Context Protocol.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Model Context Protocol

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.331175Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:4b05883bfe1f7bee8ee58e8121ca99d9a7df72bc03f4550903a3ffd5e46db6d2

Observation 7b126e55-21a9-4bd1-bd22-509c52b7b299 · outbound

This paper cites Towards the Automation of Attack Graph- Based Risk Assessment with OSCAL.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Towards the Automation of Attack Graph- Based Risk Assessment with OSCAL

Reference 7

Resolution
malformed identifier
raw_fallback, observed 2026-07-10T10:07:01.327943Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:7c05d8728cfcfc3b905817fb16ea9ffc5de43b8a3933287476462d9245f28b62

Observation 8adcf2a2-d0b5-4e03-8462-013ca9224f09 · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 8

Resolution
malformed identifier
local_arxiv, observed 2026-07-10T10:07:01.026230Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:ec96a97695590566048f0545a2bdb59436287be6106efba3681e80c38809b15d

Observation 90a3c1ad-2af0-441e-b20b-d81fffadf249 · outbound

This paper cites Integrated Risk Scoring and Exploit Prediction for Cyber-Physical Power System Vul- nerabilities.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Integrated Risk Scoring and Exploit Prediction for Cyber-Physical Power System Vul- nerabilities

Reference 9

Resolution
verified exact
doi, observed 2026-07-10T10:07:00.828901Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:5a4ac31bec9d9cf06cfd1357eeb956ff8c976624e6468157ad9e24de2c4080ba

Observation 8da4f9a9-5d24-4d60-8fb0-3347bdf67003 · outbound

This paper cites CISA Stakeholder-Specific Vulnerability Categorization Guide.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure CISA Stakeholder-Specific Vulnerability Categorization Guide

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.324414Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:4562170baa3bc40bc50d12026a75febfa49703d8b31b99379baad2e2ceade298

Observation c339eb63-7de1-4fe0-b56e-47cfd307deb8 · outbound

This paper cites Common Vulnerability Scoring System Version 4.0: User Guide.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Common Vulnerability Scoring System Version 4.0: User Guide

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.322676Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:9f9f3fc6551ca424008f611a5e783044c5fdb4c2d03648dd99510f178f310a81

Observation be5f3483-8945-4a24-929a-ad2c900d4c9b · outbound

This paper cites Towards an open standard for assessing the severity of robot security vulnerabilities, the Robot Vulnerability Scoring System (RVSS).

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Towards an open standard for assessing the severity of robot security vulnerabilities, the Robot Vulnerability Scoring System (RVSS)

Reference 12

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:00.818378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:1f7bd2b50f65ce71cb5b01bdaefc7b90b773cc32a2681bcebc624bbad86065fc

Observation 29fe8337-bf3f-40f9-bdeb-a1c05e73ca34 · outbound

This paper cites Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritiza- tion.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritiza- tion

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-07-10T10:07:00.826747Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:b291bcb3fd137b35cd65d3eb56d1f20c60494fd80813073163dc259c981ee1e1

Observation 1156a84b-c9dc-4c82-837e-d50a2e668b1c · outbound

This paper cites Dynamic Vulnerability Severity Cal- culator for Industrial Control Systems.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Dynamic Vulnerability Severity Cal- culator for Industrial Control Systems

Reference 14

Resolution
verified exact
doi, observed 2026-07-10T10:07:00.823892Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:d92cbfaf9d16b016c4d9b5f8b17a39195ba55dbd81ba6a40c5c048dcf5b7beca

Observation bf364a0d-31b6-4248-be1c-0edb854a3b54 · outbound

This paper cites A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges

Reference 15

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.023608Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:3c98aaf4ea96d4ddb52a1c094d0578a7f92f0f9b79322648bdfc67e475a755ee

Observation 647ce3c4-4ed0-4a20-aa43-aa0fa1f23446 · outbound

This paper cites Exploit Prediction Scoring System (EPSS).

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Exploit Prediction Scoring System (EPSS)

Reference 17

Resolution
verified exact
doi, observed 2026-07-10T10:07:00.817677Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:3860325e4ee8809d8d10534c9977bf76f5c6df3a3025ecc6f84adf0ffc2185e1

Observation bb56844d-c1bf-4f55-8b45-0a7b549d0254 · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 18

Resolution
malformed identifier
local_arxiv, observed 2026-07-10T10:07:00.827231Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:5f545f486cc1766ac108bb54aa1df60b34eadd7b9d4fee9a2f8097bf1f22462f

Observation ee385496-f361-4292-8678-624262320a64 · outbound

This paper cites AgCyRAG: an Agentic Knowledge Graph based RAG Framework for Automated Secu- rity Analysis.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure AgCyRAG: an Agentic Knowledge Graph based RAG Framework for Automated Secu- rity Analysis

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.319095Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:53ddc323fc6ff342282a295a21208d9a784fc4439d5c4470603c0bbc0b183247

Observation 2362171a-444d-4a8e-bfdc-951d4346d8ee · outbound

This paper cites Agentic AI for Autonomous Defense in Software Supply Chain Secu- rity: Beyond Provenance to Vulnerability Mitigation.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Agentic AI for Autonomous Defense in Software Supply Chain Secu- rity: Beyond Provenance to Vulnerability Mitigation

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-07-10T10:07:01.020853Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:07d19c9dc45f56e2565e46ab95aca2fa9c13c54f196fd1678f946b99b30cf216

Observation 37c7a9aa-96dd-4d1f-950b-8df909cebb0e · outbound

This paper cites Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.012931Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:7d1620b6ef5531ef0754184c8881f1410af7f2957a972ea380828157fa6dba75

Observation f95f48ac-37b7-4c98-9eac-80bdac932ef6 · outbound

This paper cites ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control

Reference 22

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.028882Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:f07621e36b7ef0f42ed916018be77897dfc066696a8f73dd1684919fc7f8122b

Observation e362f7aa-c3ab-4325-bdd6-448acfe45ccd · outbound

This paper cites Industrial Cybersecurity.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Industrial Cybersecurity

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.317373Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:f772c1e0e6af152b8a79c17464e4e19c3e19357c11d9c5a1000a5b206a901e1c

Observation 9ca6bb2c-5381-4667-8b8c-836317303042 · outbound

This paper cites Using LLMs for Security Advisory Investigations: How Far Are We?.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Using LLMs for Security Advisory Investigations: How Far Are We?

Reference 24

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.015449Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:566ba2cc25d3118bedbe1ab89e502710e694fae2872656fb791c1669104f1075

Observation 65d3bbbb-724f-4d8a-9810-e8586f127e2a · outbound

This paper cites Binding Operational Directive 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Binding Operational Directive 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.320861Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:6566ecdef287fc44ef4e78f67125c017ac362a37f87c7ababc6232e743214795

Observation 4692d70e-0fea-4e64-9e1c-91f062d45c8a · outbound

This paper cites Guide to Industrial Control Systems (ICS) Security.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Guide to Industrial Control Systems (ICS) Security

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.326063Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:57e26971b9d5581c4cc444222b4a333438842f14f5164a451382388df0bc8baa

Pith citing papers

No inbound Pith citation observations are available.