Pith. sign in

Paper Citation Record · LEDGER

Intent-Governed Tool Authorization for AI Agents

As of 8 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 2 inbound Pith citation observations for arXiv:2606.22916.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2606.22916 v3

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-02T10:32:34.305658Z

measured 31 of 31 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 2 of 2 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T21:46:23.178867Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-07T21:46:23.228007Z

Reference resolution

29 of 29 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved29
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 35e4b550-9009-4b6e-a0c5-77af0bd29a83 · outbound

This paper cites Mitchell, and Helen Nissenbaum.

Intent-Governed Tool Authorization for AI Agents Mitchell, and Helen Nissenbaum

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.190015Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.190015Z digest=sha256:6ac4596e40d1570dd775f0648b6eb44816d9c750a78f101f73a3b87234daebf1

Observation 4ad0b115-7c52-4a14-bf3e-af0d0a81cb75 · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries, 2024.

Intent-Governed Tool Authorization for AI Agents StruQ: Defending Against Prompt Injection with Structured Queries, 2024

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.195425Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.195425Z digest=sha256:1d9892c0873883ee81322b3e54fc7fb06c92925490ce3dd43e18cfb4413699f7

Observation e6925ba9-b5db-4f60-947d-7fd4af1dd12e · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents, 2024.

Intent-Governed Tool Authorization for AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents, 2024

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.200454Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.200454Z digest=sha256:30ff5e6fd349b755d359403529d2945e5e0d9948d46a4036f668135bd07a4dc2

Observation 1d6554e7-29dd-475e-b524-7a9b20ba8dd0 · outbound

This paper cites Ferraiolo and D.

Intent-Governed Tool Authorization for AI Agents Ferraiolo and D

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.204718Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.204718Z digest=sha256:a53476b26c349b119b874e4ea0ee723b05cdb90679678f1e63d24243a61c6479

Observation d0f6652c-2c24-4d45-a1d0-def0189e696e · outbound

This paper cites Operationalizing Contextual Integrity in Privacy-Conscious Assistants, 2024.

Intent-Governed Tool Authorization for AI Agents Operationalizing Contextual Integrity in Privacy-Conscious Assistants, 2024

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.209047Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.209047Z digest=sha256:ccf1d012882240f1a099708d97d320925c09d1ad94a596553e39b7e29775912f

Observation 5148af58-0ae0-44f1-8027-39fb613b014a · outbound

This paper cites AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations, 2026.

Intent-Governed Tool Authorization for AI Agents AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations, 2026

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.213183Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.213183Z digest=sha256:4b8d464267c2e5241d58b0ea5004142704116fad56ea057d1f7f141c3a71bb8e

Observation 95a6121f-b61e-4f21-abb2-81c8b95b9eee · outbound

This paper cites Hu, David Ferraiolo, D.

Intent-Governed Tool Authorization for AI Agents Hu, David Ferraiolo, D

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.217976Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.217976Z digest=sha256:f7bf080c012fa0ef1fe473fbf44da0980554d0fa8f41d4f5f52ea1335c354f24

Observation aadee338-8424-4dab-bc4b-2a7b4a7e7a9d · outbound

This paper cites Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning, 2026.

Intent-Governed Tool Authorization for AI Agents Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning, 2026

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.221964Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.221964Z digest=sha256:65c19cd88eb2b10c38d028450240ffbd2044ef41e636bec30325164db5b4cdea

Observation 155969ce-f6d2-48af-b01b-39ac1b6ec51a · outbound

This paper cites Need to Know: Contextual-Integrity-Grounded Query Rewriting for Privacy-Conscious LLM Delegation, 2026.

Intent-Governed Tool Authorization for AI Agents Need to Know: Contextual-Integrity-Grounded Query Rewriting for Privacy-Conscious LLM Delegation, 2026

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.226055Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.226055Z digest=sha256:8502b54541203b2e5f49da53e89271e36a753157e75b8cdb3b12eb52f999ded6

Observation fc683ac0-ffc0-49de-bb82-d0b72c09f240 · outbound

This paper cites Securing the Model Context Protocol: Defending LLMs Against Tool Poisoning and Adversarial Attacks, 2025.

Intent-Governed Tool Authorization for AI Agents Securing the Model Context Protocol: Defending LLMs Against Tool Poisoning and Adversarial Attacks, 2025

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.230584Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.230584Z digest=sha256:fbe83b0cd430af28022084e0e26e09650ed504cb1c5c94565eb5a1e81c0b9625

Observation 04527dff-7c3f-442d-a8ec-6f0de9fb2625 · outbound

This paper cites AgentDyn: A Dynamic Open-Ended Benchmark for Evaluating Prompt Injection Attacks of Real-World Agent Security System, 2026.

Intent-Governed Tool Authorization for AI Agents AgentDyn: A Dynamic Open-Ended Benchmark for Evaluating Prompt Injection Attacks of Real-World Agent Security System, 2026

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.234585Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.234585Z digest=sha256:fdee5c23cd897aec331190e940915bdcd4ab52962b3068f6b2d54ea867c61ceb

Observation 07390d51-9322-4ebd-b180-551a78573fc9 · outbound

This paper cites ToolSandbox: A Stateful, Conversational, Interactive Evaluation Benchmark for LLM Tool Use Capabilities, 2024.

Intent-Governed Tool Authorization for AI Agents ToolSandbox: A Stateful, Conversational, Interactive Evaluation Benchmark for LLM Tool Use Capabilities, 2024

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.238425Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.238425Z digest=sha256:8c95c94861b096ff30eeb1ac7c9dfde7edc023e80f859e0021c1bb96d9bd7684

Observation f1ba5f8d-8550-411d-af00-4b72ce3fe447 · outbound

This paper cites Authorization.

Intent-Governed Tool Authorization for AI Agents Authorization

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.242656Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.242656Z digest=sha256:b9fd1ef30ed1d044319f9c44cae78c4b103a4e025a5ff8efd19842082458f320

Observation ce07bee1-4c59-4d39-846f-8db0deceea91 · outbound

This paper cites an unresolved cited work.

Intent-Governed Tool Authorization for AI Agents Unresolved cited work

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.246480Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.246480Z digest=sha256:95d1b2d2b4e440545059f77535401c40ffa9ee8bd50eb12e0f9912edebe1128d

Observation 4305c0a2-561c-46c6-a159-87cd8ffc45bb · outbound

This paper cites Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile.

Intent-Governed Tool Authorization for AI Agents Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.250987Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.250987Z digest=sha256:5892dec54c718739950fdc4bf17df84793ece33b24f3a196b729a372d198ddae

Observation 317a95c7-4542-42b8-965f-5bcff794f96d · outbound

This paper cites Stanford University Press, 2009.

Intent-Governed Tool Authorization for AI Agents Stanford University Press, 2009

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.254698Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.254698Z digest=sha256:78b9ca6c89ac88a861528974325be48d5bb063ef794fa2b64c32008ba815f100

Observation 248fada8-082e-454e-bf66-5b1528e87fe2 · outbound

This paper cites LLM01:2025 Prompt Injection.

Intent-Governed Tool Authorization for AI Agents LLM01:2025 Prompt Injection

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.258538Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.258538Z digest=sha256:07cb0b5e8cf8c29719176a0be6ebf4aaa59c65d6b102bc64b0be4143adc4724d

Observation ea0dbd09-bbb0-40bd-b484-24a0b327d865 · outbound

This paper cites OW ASP Top 10 for LLM Applications 2025.

Intent-Governed Tool Authorization for AI Agents OW ASP Top 10 for LLM Applications 2025

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.262506Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.262506Z digest=sha256:d78c5fef6e4d87567f46afa046a179bb90e3032dd9ebeed206a093409cccb511

Observation 12854581-b907-4f19-8917-076c26188621 · outbound

This paper cites Maddison, and Tatsunori Hashimoto.

Intent-Governed Tool Authorization for AI Agents Maddison, and Tatsunori Hashimoto

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.266439Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.266439Z digest=sha256:0093e597d21d813faa66f101d5157ea31d123d661751a722329a03fa3e9b4b58

Observation 24193b09-c495-4e28-a941-85aa18df27b7 · outbound

This paper cites Saltzer and Michael D.

Intent-Governed Tool Authorization for AI Agents Saltzer and Michael D

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.270482Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.270482Z digest=sha256:66404b8986fd7c1b367c364284a931915ac37ac6dc4e37b4f1a872802de83313

Observation 18747825-aa31-4fc9-846d-f4d8f8e1e8e5 · outbound

This paper cites MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems, 2026.

Intent-Governed Tool Authorization for AI Agents MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems, 2026

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.274818Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.274818Z digest=sha256:a3a477539bd38b6b30dcff47a59d1f70416b2cc5e04a175b10444f266c555f2d

Observation eebae825-626a-4ea0-84ab-2ac6ce20bfb7 · outbound

This paper cites Prompt Injection Attack to Tool Selection in LLM Agents, 2025.

Intent-Governed Tool Authorization for AI Agents Prompt Injection Attack to Tool Selection in LLM Agents, 2025

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.278453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.278453Z digest=sha256:43ce74a4312bf9b0cbd56a4ea53bdfb03a0737c3a826380ab9dfc9f4937b2cb0

Observation 00621fd8-9e55-4b4d-bda7-b74ec9383132 · outbound

This paper cites ToolTweak: An Attack on Tool Selection in LLM-based Agents, 2025.

Intent-Governed Tool Authorization for AI Agents ToolTweak: An Attack on Tool Selection in LLM-based Agents, 2025

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.282521Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.282521Z digest=sha256:364fc550261c11d87c2f2b4b9e2939188aa6b86f8150c92ae908af1ffd75c060

Observation 98643bf9-498f-43c6-9087-381d3c6661fd · outbound

This paper cites Data Guard: A Fine-grained Purpose-based Access Control System for Large Data Warehouses, 2025.

Intent-Governed Tool Authorization for AI Agents Data Guard: A Fine-grained Purpose-based Access Control System for Large Data Warehouses, 2025

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.286490Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.286490Z digest=sha256:33dbd36539747d2159f7febb11488d524156dd70751058b067df64dbe0027ae3

Observation e214b054-0206-4d5e-b16d-f35e9c1af57b · outbound

This paper cites MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers, 2025.

Intent-Governed Tool Authorization for AI Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers, 2025

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.290321Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.290321Z digest=sha256:ddbdd2a14ed55aa353a16df8a060f89de578567a0a7950bbf45ccad3f48f612f

Observation 16334e18-31fb-4d43-803b-2114a0d375c8 · outbound

This paper cites Messaging with Purpose Limitation – Privacy-Compliant Publish-Subscribe Systems, 2021.

Intent-Governed Tool Authorization for AI Agents Messaging with Purpose Limitation – Privacy-Compliant Publish-Subscribe Systems, 2021

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.294081Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.294081Z digest=sha256:d8a4f3072615fc073b4d6de0f94941a71c277ffd46a1a985dac254edf43e33ad

Observation cf519791-baee-479a-aa36-7bbec0918fb1 · outbound

This paper cites τ-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains, 2024.

Intent-Governed Tool Authorization for AI Agents τ-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains, 2024

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.297969Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.297969Z digest=sha256:7e5cc8ae05d599a89a4a54c27757227ea9834781dbcdca70d5b573d7f54c1238

Observation 425f23c7-a4f1-4650-9752-c017d720c82f · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents, 2024.

Intent-Governed Tool Authorization for AI Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents, 2024

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.301794Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.301794Z digest=sha256:a75f365634ff9881c5cc3485ac3da77b1839138dc322a1be5cf2eb85f9d141ac

Observation b8d8d1d6-3e6d-47e0-b085-4800c10f72d7 · outbound

This paper cites AgentSentry: Mitigating Indirect Prompt Injection in LLM Agents via Temporal Causal Diagnostics and Context Purification, 2026.

Intent-Governed Tool Authorization for AI Agents AgentSentry: Mitigating Indirect Prompt Injection in LLM Agents via Temporal Causal Diagnostics and Context Purification, 2026

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.305658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.305658Z digest=sha256:1ae3955d01ef994d860fdb31e9bfd368f2eb0ca50f3a569b43d578b4c0d32d4c

Pith citing papers

Observation 889e1901-795c-4aed-8869-f65b2837f1dd · inbound

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales cites this paper.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Intent-Governed Tool Authorization for AI Agents

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.437055Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.437055Z digest=sha256:bc3fa4a0c3c078f3bc2ec937f7a03c641816a4b79de7a3db50e8522fb267b63a

Observation fdc261ba-1e82-46d5-a9b2-c2aa5dc85c59 · inbound

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents cites this paper.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Intent-Governed Tool Authorization for AI Agents

Reference 40

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.233895Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.178867Z digest=sha256:f3bf105ace6b71e2458e8048c8120c777eb969be440f3a10590026ac738531f7