Pith. sign in

Paper Citation Record · LEDGER

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

As of 15 August 2026, this Paper Citation Record lists 100 of 107 outbound references and 10 inbound Pith citation observations for arXiv:2506.13666.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.13666 v1

Coverage vector

measured 100 of 107 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T00:32:36.760608Z

measured 110 of 110 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-15T06:32:42.880941+00:00

measured 10 of 10 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-06T21:44:54.864170Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

100 of 107 outbound references displayed

  • verified exact0
  • verified fuzzy13
  • unresolved87
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation cab8fd2c-7197-4197-b0fc-fef0587b23a5 · outbound

This paper cites Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.443050Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.443050Z digest=sha256:111f79d709e34001f6c55c66c0ae568abe4b7d6beda9ce22c73a371e85d9afa2

Observation da9cb528-7157-4b44-8b73-00c0227eb123 · outbound

This paper cites Introducing the model context protocol.https://www.anthropic.com/news/ model-context-protocol, November 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Introducing the model context protocol.https://www.anthropic.com/news/ model-context-protocol, November 2024

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.447486Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.447486Z digest=sha256:b9ecdd511b8eb199ccd51d96328432c997fe163d241f8d0ffaaf195b61894c2d

Observation e62633f9-e83d-4a72-b74f-41265a3c4fd3 · outbound

This paper cites Foundational Challenges in Assuring Alignment and Safety of Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Foundational Challenges in Assuring Alignment and Safety of Large Language Models

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.451035Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.451035Z digest=sha256:5968525fef9a164b3ff6ef02b5cc368162e831b6b3359cf95cb4a460aa81065f

Observation db8f1793-bf40-42a1-9c1f-9efc77144c16 · outbound

This paper cites Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.454938Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.454938Z digest=sha256:9bf5352bcc2df9572ab906057f73b1fd8f55c0d0819970f67398fc52e6c2b84c

Observation e8dd5d7a-7962-493e-b320-9fbace30b48a · outbound

This paper cites Safety-tuned LLaMAs: Lessons from improving the safety of large language models that follow instructions.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety-tuned LLaMAs: Lessons from improving the safety of large language models that follow instructions

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.458413Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.458413Z digest=sha256:27824395e242bf7136575afd777c0c9bb166703dc650f71003af797d1a82a4e9

Observation 1a387885-bd0a-4de2-9931-609e4c15616b · outbound

This paper cites an unresolved cited work.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Unresolved cited work

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.461485Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.461485Z digest=sha256:70a3912ad39677ac5d9c2d6a20d57338d4cb08ee2534db80661b929f4aebccbc

Observation 89437d5c-6824-41ee-9761-7ae1f94654d8 · outbound

This paper cites Highlights from lex fridman’s interview of yann lecun, March.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Highlights from lex fridman’s interview of yann lecun, March

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.464997Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.464997Z digest=sha256:58129b07af4f689c4aca1f68b91660813a847d61dae926729a54b717e0a421ec

Observation c256f18c-5b5b-4146-88f5-2b3a8045b973 · outbound

This paper cites A survey on evaluation of large language models.ACM transactions on intelligent systems and technology, 15(3):1–45, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey on evaluation of large language models.ACM transactions on intelligent systems and technology, 15(3):1–45, 2024

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.471713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.471713Z digest=sha256:4f50f8cfd3a0770fb62f5ab3c68191d8493a1f37ba0cace91b609b1d688a90ca

Observation 11cc4119-caec-474e-968a-138ed5374a77 · outbound

This paper cites Pappas, Florian Tramèr, Hamed Hassani, and Eric Wong.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Pappas, Florian Tramèr, Hamed Hassani, and Eric Wong

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.474958Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.474958Z digest=sha256:b10a7828c842d38a4944ea7b0c9615fb2dc7dc1cad7237c4a265c9580f765f37

Observation 4c2d0d40-1d6a-4979-80f0-8940a1819874 · outbound

This paper cites Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2025

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.477590Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.477590Z digest=sha256:f6650767f465f0d60c5d3ada5c8dbd8da95598c7bfd43d53c5109c1c7735df78

Observation 599af7df-89b2-426a-9af3-6f744f976cd4 · outbound

This paper cites Safety-aware fine-tuning of large language models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety-aware fine-tuning of large language models

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.480493Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.480493Z digest=sha256:9920b8a4b69025fd13476e00023f59e595eb50e4b8bf5c6ffb6ec2e43e66a112

Observation 349a1758-8d22-4163-8e06-8da4d2fdd95d · outbound

This paper cites Scaling instruction-finetuned language models.Journal of Machine Learning Research, 25(70):1–53, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Scaling instruction-finetuned language models.Journal of Machine Learning Research, 25(70):1–53, 2024

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.483792Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.483792Z digest=sha256:339c7c7bec7794809fea74809365db1f01a6b7f5cf642512fca9f6721ba0def6

Observation 4cb8a155-06a1-4f7e-ac1c-f3da080f6365 · outbound

This paper cites Textworld: A learning environment for text-based games.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Textworld: A learning environment for text-based games

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.486870Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.486870Z digest=sha256:770ded21da99589929c7a8a803bf602d5f7fc677efb82962f66f9d2db24226fc

Observation 47c933f4-d52b-4cd3-a619-3aae05a6b0ad · outbound

This paper cites DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.489432Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.489432Z digest=sha256:c9da7ad50dc1c7f01418db2fe9524c582f2e5b8dabaae99c558b8f88770125bb

Observation b12f1fb7-e970-4920-862b-1ac01661ce5c · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Ai agents under threat: A survey of key security challenges and future pathways

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.492579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.492579Z digest=sha256:4fbb037afd024e9b3c0c8e1798b559ac9a899b15afd314ba84d0a572dc60ea63

Observation 5d55cfb2-91e3-4329-b16a-8462d561c64c · outbound

This paper cites Bert: Pre-training of deep bidirectional transformers for language understanding.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Bert: Pre-training of deep bidirectional transformers for language understanding

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.495577Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.495577Z digest=sha256:b81b22bba378d9a7bdd9ebb738d26cdb046cd1398d37ed0ff3333ad65b424e72

Observation e7069162-a4b2-4c9d-8d8a-ab81d166a0c9 · outbound

This paper cites A Wolf in Sheep's Clothing: Generalized Nested Jailbreak Prompts can Fool Large Language Models Easily.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Wolf in Sheep's Clothing: Generalized Nested Jailbreak Prompts can Fool Large Language Models Easily

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.498449Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.498449Z digest=sha256:dd5f501d468d53c33a18ce38ec857656d120c8bfa4484bb496d2995977f7f5e4

Observation 8888b506-9c6e-4569-bb1b-e1f604fda046 · outbound

This paper cites A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP).

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.501355Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.501355Z digest=sha256:6673e7776987b3276bc1e3100eb5d0bcb3982cde80eb15a451d5c62d32238ac9

Observation 82bac543-6e04-41e9-8fa1-0d01ddab0f31 · outbound

This paper cites Pawan Kumar, and Adel Bibi.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Pawan Kumar, and Adel Bibi

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.504729Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.504729Z digest=sha256:62718e2ca6963250d2d61131da46ae0f3475fe5c83e20b342e3d4a80c7b5ab99

Observation 87ea844c-4b84-4efe-b22f-b0f8cc12c09b · outbound

This paper cites Imprompter: Tricking LLM Agents into Improper Tool Use.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.507283Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.507283Z digest=sha256:b45562f8bde7c6f7aab92c672ba236031218a045fa27c0ab55e84d67860309db

Observation b2baea63-0248-4742-94a6-3ba85ab31972 · outbound

This paper cites Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.510129Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.510129Z digest=sha256:3c763a23096103e0b9d5a710361c58a0b2778a0b70c6c87a306013c000432a9a

Observation 71d669d1-12cd-4a41-869c-ffc4f118f42d · outbound

This paper cites Textbooks Are All You Need.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Textbooks Are All You Need

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.512749Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.512749Z digest=sha256:c65561ba20055c9b4e6abab6adfbc39df9a3e61b832c338de2c196d9f9f54a83

Observation 6338beed-56ee-4479-b1ce-ca417488e76c · outbound

This paper cites Large Language Model based Multi-Agents: A Survey of Progress and Challenges.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Large Language Model based Multi-Agents: A Survey of Progress and Challenges

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.515911Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.515911Z digest=sha256:b68bff5dfd3d402b93c6406cf8d780a0aa93419b7495a37e5ecdb3ea9f6fb14a

Observation 15daf63a-56cd-4b96-afdb-15cb2ff8a771 · outbound

This paper cites Regulating chatgpt and other large generative ai models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Regulating chatgpt and other large generative ai models

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.519516Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.519516Z digest=sha256:9ab3002ad9548b3e0129e09134d50a2a45a30c36ca79986abe5ef205bed3536b

Observation 74fbc7fb-4214-4ff9-92f1-0361627e54d6 · outbound

This paper cites A survey on large language models: Applications, challenges, limitations, and practical usage.Authorea Preprints, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey on large language models: Applications, challenges, limitations, and practical usage.Authorea Preprints, 2023

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.522302Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.522302Z digest=sha256:b32782bd7901f62d3992e28bda70c3851bf89035b4f12c0489201f406fcbc4ff

Observation c9306aa5-16ba-4a9d-985a-e15869da3867 · outbound

This paper cites What is in Your Safe Data? Identifying Benign Data that Breaks Safety.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems What is in Your Safe Data? Identifying Benign Data that Breaks Safety

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.525213Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.525213Z digest=sha256:0d36e3fad7565e6f034994ca5acdcf0bd21b84a7f24fe27d2160a6ac0a6136fb

Observation 73b9fd81-05b3-489c-b34b-cac9663ac932 · outbound

This paper cites Red-Teaming LLM Multi-Agent Systems via Communication Attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Red-Teaming LLM Multi-Agent Systems via Communication Attacks

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.528134Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.528134Z digest=sha256:889d105aefbf488e51535aee95af3ff4f4a94fe1dcf2021d56233aaac2c562b9

Observation ed2a81ee-4b17-4cac-8223-bbed55d65379 · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.535179Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.535179Z digest=sha256:8b86dfc56575d1de077aba0b1480397c68df58643af70e50d5a6d967c458e0d0

Observation ecd65069-43f6-4e93-b30d-fac8feff78d3 · outbound

This paper cites T1: Advancing Language Model Reasoning through Reinforcement Learning and Inference Scaling.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems T1: Advancing Language Model Reasoning through Reinforcement Learning and Inference Scaling

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.538291Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.538291Z digest=sha256:2e0044c325c97d8ee6b837698e640d1599f9ab39c941ef54a4b2752dae536436

Observation 3ed7c96d-4758-44d2-816c-28d632e2b569 · outbound

This paper cites Scaling Trends in Language Model Robustness.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Scaling Trends in Language Model Robustness

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.541321Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.541321Z digest=sha256:555dc2c1761fcb3e2a77c3c117488a79606f30b7442de578ed87dbd74a8999c7

Observation 740059a3-efc9-4b55-8bda-5f99777f08ed · outbound

This paper cites A survey of safety and trustworthiness of large language models through the lens of verification and validation.Artificial Intelligence Review, 57(7):175, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey of safety and trustworthiness of large language models through the lens of verification and validation.Artificial Intelligence Review, 57(7):175, 2024

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.544502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.544502Z digest=sha256:2f98e43dc6a3fef4fff4278cccd0663f8d1162c0e8760f75b7c1827d10e0d6f4

Observation abacfcb5-873b-48ac-93bf-9f014ab7eb00 · outbound

This paper cites Babyai 1.1, 2020.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Babyai 1.1, 2020

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.547224Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.547224Z digest=sha256:098f09b530b35c2147bba32e5e771d1906f8244b068c78acf685810128d79142

Observation 427cf786-071f-45a2-b516-8bde402013dc · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.550081Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.550081Z digest=sha256:79b8bea8dc57c23ea45f0bd53eabfd3fba2598ad53dbaf14345239a1eb5cb997

Observation ec439bd0-f2ff-4c1a-a184-71b64c84c100 · outbound

This paper cites Mcp security notification: Tool poisoning attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Mcp security notification: Tool poisoning attacks

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.553330Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.553330Z digest=sha256:0fb6a0a34180ea33f327c9b6b254846a6d97c63720faa5dba15486ab420b05e9

Observation 1244253f-4154-4114-bd33-9b4ed1d2517d · outbound

This paper cites SafeChain: Safety of Language Models with Long Chain-of-Thought Reasoning Capabilities.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems SafeChain: Safety of Language Models with Long Chain-of-Thought Reasoning Capabilities

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.556165Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.556165Z digest=sha256:c05237527f0595374a8aeaff0cf8e5d86a70d0766fcfd17bd732680c9b2adfff

Observation bdb8422b-033e-43a6-89cf-c0bda4e306b9 · outbound

This paper cites Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.559678Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.559678Z digest=sha256:fbf26cfd9eea43fcdb8478dcdf0df010010323dbfbea16fe1df649d970587f2f

Observation 19c5409f-c863-4e40-9a1b-ee970cc44425 · outbound

This paper cites Llm-mod: Can large language models assist content moderation? InExtended Abstracts of the CHI Conference on Human Factors in Computing Systems.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Llm-mod: Can large language models assist content moderation? InExtended Abstracts of the CHI Conference on Human Factors in Computing Systems

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.563012Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.563012Z digest=sha256:0231a3e81c8c24c20e4c42c359f8a1277f316937f2f3bfd64633527d20f6c7db

Observation 7f1e61ea-52c3-40fa-a6f5-62f2bf479779 · outbound

This paper cites Watch your language: Investigating content moderation with large language models.Proceedings of the International AAAI Conference on Web and Social Media, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Watch your language: Investigating content moderation with large language models.Proceedings of the International AAAI Conference on Web and Social Media, 2024

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.565644Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.565644Z digest=sha256:0c15720e0feacd4715c3d90d2f60cc23a76e50308d65475953eb35bdaaa8bcc9

Observation 511c0034-a37f-4235-b47d-765d0119c364 · outbound

This paper cites MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.568714Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.568714Z digest=sha256:fd8c2e73142b1cca758e89074f510a88eed453710e30d19c957b27b1951be4d1

Observation 1d46beab-1ba3-4821-9853-c92ee7fc1333 · outbound

This paper cites How not to be stupid about ai, with yann lecun.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems How not to be stupid about ai, with yann lecun

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.571929Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.571929Z digest=sha256:c1a1be993d8f5e6f3548d48f5ce2ebaa5412ff8553304db021023cd57939fd44

Observation 4a01d0f6-66ab-4bb4-bdc9-77680eb4f755 · outbound

This paper cites Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.575227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.575227Z digest=sha256:73c34799c36b98533bd6d51d2887b7126a09332f90781c1ab74efb1c4ec998d9

Observation 59802d7a-0a03-4b0c-9a71-8ec832f81fca · outbound

This paper cites Common 7B Language Models Already Possess Strong Math Capabilities.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Common 7B Language Models Already Possess Strong Math Capabilities

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.578494Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.578494Z digest=sha256:d11eb9716db7e9a8a40e12ec295836febd9cb152f3d34f2db8b5836ed12b40a7

Observation c8132a73-f252-428c-96ae-e33004d5b5c2 · outbound

This paper cites Camel: Communicative agents for" mind" exploration of large language model society.Advances in Neural Information Processing Systems, 36:51991–52008, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Camel: Communicative agents for" mind" exploration of large language model society.Advances in Neural Information Processing Systems, 36:51991–52008, 2023

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.581487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.581487Z digest=sha256:9786cb349db6e6c77e6ba00bb7e2f9b153f7b8c7cbbd7796e554a90989d33ded

Observation 9a00be52-d04d-4e03-ab77-9f90bda7a673 · outbound

This paper cites DeepInception: Hypnotize Large Language Model to Be Jailbreaker.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems DeepInception: Hypnotize Large Language Model to Be Jailbreaker

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.584165Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.584165Z digest=sha256:79ff5fcd21354bb0184b35285220af860b2c6c0d1b34e053648027be0eb89be6

Observation a299b3ba-ca64-428c-a5f5-87a036e037af · outbound

This paper cites The Unlocking Spell on Base LLMs: Rethinking Alignment via In-Context Learning.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The Unlocking Spell on Base LLMs: Rethinking Alignment via In-Context Learning

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.587266Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.587266Z digest=sha256:0929587a2eefdc4d765fd9c968c1bc8a443cc726e60f0cafd480203d0415ebbc

Observation feffbfcf-e616-4ee4-a8e2-f837a306ebf3 · outbound

This paper cites Understanding and enhancing the transferability of jailbreaking attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Understanding and enhancing the transferability of jailbreaking attacks

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.590175Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.590175Z digest=sha256:10bf1f4f6a726e7123e4b20ba48cb1fc9b45eb50475993572b6940529241a7cb

Observation 5f27bde5-03c1-4068-bc86-5710b3f6facc · outbound

This paper cites ToolACE: Winning the Points of LLM Function Calling.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ToolACE: Winning the Points of LLM Function Calling

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.593020Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.593020Z digest=sha256:231c2a0322cc06f8e08e79d2ad1388b97bc4c973f2f7a386c34a9209df6c85e4

Observation 64067349-a619-4bd7-b98d-afd287c03953 · outbound

This paper cites Autodan: Generating stealthy jailbreak prompts on aligned large language models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Autodan: Generating stealthy jailbreak prompts on aligned large language models

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.595996Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.595996Z digest=sha256:365420c3e35b6f747e366d03a49a04460c0c948d0b6d8b48e082971ea4315b97

Observation f578c017-50af-4261-9762-8f77c9152e97 · outbound

This paper cites Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.598721Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.598721Z digest=sha256:6d5d680322692e021ce6a8d2c6ab70131ced30c175f234e8cbfd81d94e14c348

Observation bbfc070e-c4aa-4838-bdd6-01e020769a5f · outbound

This paper cites RobustFT: Robust Supervised Fine-tuning for Large Language Models under Noisy Response.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems RobustFT: Robust Supervised Fine-tuning for Large Language Models under Noisy Response

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.601660Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.601660Z digest=sha256:23a6b999726c8085c370bcf74eb40e81ffb2181206bebcf8e419d534018215c4

Observation f700f20c-b668-4c99-a7fc-334e65e65551 · outbound

This paper cites CodeChameleon: Personalized Encryption Framework for Jailbreaking Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems CodeChameleon: Personalized Encryption Framework for Jailbreaking Large Language Models

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.604717Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.604717Z digest=sha256:95a4e90197bf26998735ede947e6912abd82b8779c37638d02d6e5cec251d902

Observation 7954f0b0-91d6-43a7-8bd6-2edf9f2652f8 · outbound

This paper cites Agentboard: An analytical evaluation board of multi-turn llm agents, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Agentboard: An analytical evaluation board of multi-turn llm agents, 2024

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.607632Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.607632Z digest=sha256:c1f6f05678d318bbe5171da2c381cc04e162dd1cc94d5c65b64c09659303b5f7

Observation f5dc2dfc-0fac-4b1a-b621-b202218ea1a0 · outbound

This paper cites Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.610249Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.610249Z digest=sha256:6fc94d24239e510477c333303628975f5c1d07ee57a39433891d42b46f2edd4a

Observation 7b9f233f-ddce-4c8d-9b52-39901c78a083 · outbound

This paper cites AgentSafe: Safeguarding Large Language Model-based Multi-agent Systems via Hierarchical Data Management.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems AgentSafe: Safeguarding Large Language Model-based Multi-agent Systems via Hierarchical Data Management

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.613450Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.613450Z digest=sha256:75c6bc0e77bb51bd1de41a487b26768238d9727600d0cb0244ea2ab42bea3b19

Observation c7de98e6-ed07-46f7-a216-adaf5a45e658 · outbound

This paper cites an unresolved cited work.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Unresolved cited work

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.617161Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.617161Z digest=sha256:24f97484815344d641d98c928012e50fcdd3c85e8a50d62881c98bccfbeab2ed

Observation 4540d3ec-8f76-41be-b476-e4d565fa9ffe · outbound

This paper cites A Comprehensive Overview of Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Comprehensive Overview of Large Language Models

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.619901Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.619901Z digest=sha256:445724a6a92856294ecefd3d3ad613096a07be6d8e4f6090e8a5afca076c4a96

Observation 26ca70b2-80f0-4e90-9655-1d19342371e8 · outbound

This paper cites GPT-4 technical report.CoRR, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems GPT-4 technical report.CoRR, 2023

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.623242Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.623242Z digest=sha256:cad71d25ca030238f83900253f0a467e07417a15d23e69e5b543db8f3fd5850e

Observation 93a25dfa-c201-4bb1-aaef-b423ed7d83e6 · outbound

This paper cites Training language models to follow instructions with human feedback.Advances in neural information processing systems, 35:27730–27744, 2022.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Training language models to follow instructions with human feedback.Advances in neural information processing systems, 35:27730–27744, 2022

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.626365Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.626365Z digest=sha256:ef23b3b1fbbb6b893c50ad5563683fb9b03e2cf8bbc881906c7fb68a4c3b1c26

Observation 5153d8fc-048f-4b5a-a9a7-4b814de674f6 · outbound

This paper cites Self-alignment of large language models via monopolylogue-based social scene sim- ulation.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Self-alignment of large language models via monopolylogue-based social scene sim- ulation

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.618797Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.629215Z digest=sha256:cc19f74fe8a766e2caceb63dbb97d17fed99f59f848eb71014e2777f18060998

Observation 9e7ec986-2242-46b0-b1ce-329bf2db8fb7 · outbound

This paper cites A survey on agent-based modelling assisted by machine learning.Expert Systems, 42(1):e13325, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey on agent-based modelling assisted by machine learning.Expert Systems, 42(1):e13325, 2025

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.608506Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.632627Z digest=sha256:1d91399d424a7b8dd1d4fbdad9de43fd0c7f382eeaf9d8826ec0a544a15e50f8

Observation b9f45d87-fa24-49cb-852f-836ec4551680 · outbound

This paper cites ADaPT: As-Needed Decomposition and Planning with Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ADaPT: As-Needed Decomposition and Planning with Language Models

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.635903Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.635903Z digest=sha256:c274a53655bfb6b7bec2431e6cc378992c954fca4c4c06e57a61c43322d52253

Observation bfe99cd4-0424-4e95-bcd6-a7d4a6e6dd80 · outbound

This paper cites Fine-tuning Aligned Language Models Compromises Safety, Even When Users Do Not Intend To!.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Fine-tuning Aligned Language Models Compromises Safety, Even When Users Do Not Intend To!

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.639515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.639515Z digest=sha256:360506594bf2c1433eb16391650e0d20378cee67284e5719f0ff9ddca32aeb23

Observation fc79b600-34e2-42f3-bf03-69748daac3d7 · outbound

This paper cites Safety alignment should be made more than just a few tokens deep.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety alignment should be made more than just a few tokens deep

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.598823Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.642841Z digest=sha256:380b159ba8948fec1ed23ad14124f46670c05fc37f7c16b6208dbbc710439e16

Observation 54ba21df-c8af-47e0-a521-de0985373cb3 · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.645879Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.645879Z digest=sha256:c3c770f93a3598db52b72637a2df8c597849851f050eb50a33d1a3cb791c7c4b

Observation a26c16fc-22fc-46ef-83f1-d36f03a32ea9 · outbound

This paper cites Tptu: Task planning and tool usage of large language model-based ai agents.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Tptu: Task planning and tool usage of large language model-based ai agents

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.588649Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.648975Z digest=sha256:6af49c719b2096c43dcee1bf67eac396891584adbe05e9c2b4143824de43a0de

Observation eee225d5-1ecd-48db-83f4-59c3f3eb83e2 · outbound

This paper cites Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36: 68539–68551, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36: 68539–68551, 2023

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.651630Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.651630Z digest=sha256:c81bb476045ebdfdff60eae867a76ae66dfafaafcd626650ee356d61d39b4015

Observation 95941cb5-c39b-4245-9ab4-f38416c441f1 · outbound

This paper cites Large Language Model Safety: A Holistic Survey.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Large Language Model Safety: A Holistic Survey

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.657747Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.657747Z digest=sha256:3cb55a513b7de65e4873872a594000c0b32f3aae928eff748fc6007566772709

Observation e38e1f26-8af7-43dc-846e-f22688ba3362 · outbound

This paper cites Welcome to the era of experience.Google AI, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Welcome to the era of experience.Google AI, 2025

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.572748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.660554Z digest=sha256:d8d1044a860b0ffccdaa31f475c205f6c47dd097579add5cba9ff25d9c7d5d3b

Observation bc18e7db-d374-4fb0-bf7f-cce0c18a9f5c · outbound

This paper cites Large language model (chatgpt) as a support tool for breast tumor board.NPJ Breast Cancer, 9(1):44, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Large language model (chatgpt) as a support tool for breast tumor board.NPJ Breast Cancer, 9(1):44, 2023

Reference 71

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.563133Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.663467Z digest=sha256:cc15e413fdfc41e68b5ec52fe3d662fb9701d5d9c223886d952a118836e713f2

Observation 068ee5fd-9a41-438b-bcaa-82dc516b2131 · outbound

This paper cites ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.666302Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.666302Z digest=sha256:2864995ec62f9b7cfd0680567dba23de1119670e7829111a8ef97de523062c78

Observation f034a09e-e2fa-4274-ab49-808463f0e4b1 · outbound

This paper cites A Survey on Post-training of Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Survey on Post-training of Large Language Models

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.669532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.669532Z digest=sha256:6b289de39529485285b670148787ef87c6552636ff4b45604009e0ccfbb44eb8

Observation e49dc2bf-5595-4833-a4fd-4f0d3ee92e48 · outbound

This paper cites Multi-Agent Collaboration Mechanisms: A Survey of LLMs.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Multi-Agent Collaboration Mechanisms: A Survey of LLMs

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.672515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.672515Z digest=sha256:fee2da6fa683d80710a16e7dde7a3c7337da0ba472e6c8d07ee98227723a9300

Observation 036f6ddd-16e2-4554-a054-a056ef1b0c3c · outbound

This paper cites House Committee on Oversight and Accountability.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems House Committee on Oversight and Accountability

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.553788Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.675669Z digest=sha256:dc5259f8c824afcc286be623db5769d026a1e390d6c4c8100e9c011d040846f8

Observation 6ba5b7ab-5472-4f04-ba3b-bd5d1c00b471 · outbound

This paper cites From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.678358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.678358Z digest=sha256:81b5aa8fbc993d289acc1dc307b14ba68cd1c0682a467b9eee7e448666e045eb

Observation 6fe0c16b-c9c5-4686-b103-ddb0ced94a13 · outbound

This paper cites Backdooralign: Mitigating fine-tuning based jailbreak attack with backdoor enhanced safety alignment.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Backdooralign: Mitigating fine-tuning based jailbreak attack with backdoor enhanced safety alignment

Reference 77

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.544261Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.682146Z digest=sha256:ca35e54fc31a1956dedaacf84b352499b6fd8ded23d355dc27bc72409f47613d

Observation 1cd39cb2-ad4d-4097-9cd9-44ea269ef0ba · outbound

This paper cites A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.685699Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.685699Z digest=sha256:537035ab502471dc302187d9e992bfc155545289751f435db1ccb43e584d5eb1

Observation be9ee4a7-10a0-4f4b-a793-d24b6bec5b18 · outbound

This paper cites ScienceWorld: Is your Agent Smarter than a 5th Grader?.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ScienceWorld: Is your Agent Smarter than a 5th Grader?

Reference 79

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.689405Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.689405Z digest=sha256:da87d795d0aaa53c9d7485a2940ddfb3b3f4d2bdc36df24c72f92005db4455b0

Observation 785cfa32-51aa-4d6f-ad78-502d0157a6af · outbound

This paper cites G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent Systems.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent Systems

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.692682Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.692682Z digest=sha256:d2170ceaee6c836f90552ccb098f19b38047db528b87f868d9cb7243d0eeddcd

Observation b61d1d5a-cf4b-4993-a884-8647f3aef8da · outbound

This paper cites Augmenting language models with long-term memory.Advances in Neural Information Processing Systems, 36:74530–74543, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Augmenting language models with long-term memory.Advances in Neural Information Processing Systems, 36:74530–74543, 2023

Reference 81

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.695853Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.695853Z digest=sha256:a0051adc256dba3ec0013bc002930d1f2aa84ffe9a9575710c7b6763ada7a330

Observation c81ab498-e158-400f-84ac-8be0fcd0581e · outbound

This paper cites AgentGym: Evolving Large Language Model-based Agents across Diverse Environments.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems AgentGym: Evolving Large Language Model-based Agents across Diverse Environments

Reference 82

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.698999Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.698999Z digest=sha256:e60255518b6559e12e04a29ad7f72a1cd22815065da82024609d6765ae1d8b5d

Observation e48af40e-acf2-42d8-b9d9-dd4fc079521b · outbound

This paper cites The rise and potential of large language model based agents: A survey.Science China Information Sciences, 68(2):121101, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The rise and potential of large language model based agents: A survey.Science China Information Sciences, 68(2):121101, 2025

Reference 83

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.702156Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.702156Z digest=sha256:2a40904f39c14dd045215358bf41bc8cdffdc0e73b1acd87e6e81e4f764c12fe

Observation f96d077d-7cfb-4ecc-949e-513f4ebb4f35 · outbound

This paper cites Certifiably robust rag against retrieval corruption.arXiv preprint arXiv:2405.15556, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Certifiably robust rag against retrieval corruption.arXiv preprint arXiv:2405.15556, 2024

Reference 84

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.704889Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.704889Z digest=sha256:231e26a4d342d65a60f02fe2fd0d632aacdc86ea39730b9637d7dd938aa895ee

Observation 380e6eee-66c5-484b-86ee-9f201f1e5933 · outbound

This paper cites Bag of tricks: Benchmarking of jailbreak attacks on llms.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Bag of tricks: Benchmarking of jailbreak attacks on llms

Reference 85

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.521751Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.707657Z digest=sha256:512a94ff0a7325c6a5942c8c8871b9e42fcf0801d61beafc55cbb6c40c7ecab8

Observation 74828f52-df54-443a-8638-be1165b46fcd · outbound

This paper cites Qwen3 Technical Report.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Qwen3 Technical Report

Reference 86

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.710457Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.710457Z digest=sha256:b02763a8fb27910686dcfcd6d1fefe4145c2916ee39b4cff5f15f2f2d25b4677

Observation 95703251-2882-404c-9a50-c7e497ae4a07 · outbound

This paper cites Gpt4tools: Teaching large language model to use tools via self-instruction.Advances in Neural Information Processing Systems, 36:71995–72007, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Gpt4tools: Teaching large language model to use tools via self-instruction.Advances in Neural Information Processing Systems, 36:71995–72007, 2023

Reference 87

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.713245Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.713245Z digest=sha256:11d1bb325cd0e9d4cd0b8e5731712d832a4c73dc685e9cebf7cdf6be466a958e

Observation a19666c5-0f5d-45e7-a5fb-c9349549add3 · outbound

This paper cites The second half.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The second half

Reference 88

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.506455Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.716985Z digest=sha256:1d1bafdd11528fc435b5d42a9bd6aecc5bb4e560080e93fafaba374ad4da523b

Observation 7f61f150-b491-4527-9a47-b62e72b3d17d · outbound

This paper cites Webshop: Towards scalable real-world web interaction with grounded language agents.Advances in Neural Information Processing Systems, 35:20744–20757, 2022.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Webshop: Towards scalable real-world web interaction with grounded language agents.Advances in Neural Information Processing Systems, 35:20744–20757, 2022

Reference 89

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.719731Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.719731Z digest=sha256:be2d58e14c46cdadb8405ea77c46fb087903d01170adab276b6490b250249fac

Observation fea6eceb-7aa5-4c7c-b05d-1c583cb0e5d6 · outbound

This paper cites On the vulnerability of safety alignment in open-access llms.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems On the vulnerability of safety alignment in open-access llms

Reference 90

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.490297Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.722464Z digest=sha256:b61e09e17b71d301b4023fa3a65f7300f329102fe28cc3c6ecb1092148c1dfff

Observation adf6ba7d-7317-400d-a0e8-27f41b4d2700 · outbound

This paper cites NetSafe: Exploring the Topological Safety of Multi-agent Networks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems NetSafe: Exploring the Topological Safety of Multi-agent Networks

Reference 91

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.725488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.725488Z digest=sha256:0b54db23ab3c0b7583380e7711fe5a6de3d7b96e8ce92636bed9c409673faf28

Observation 658a354a-f690-49f2-985f-f7672cd019dc · outbound

This paper cites A Survey on Trustworthy LLM Agents: Threats and Countermeasures.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Survey on Trustworthy LLM Agents: Threats and Countermeasures

Reference 92

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.728262Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.728262Z digest=sha256:c27c37f44ef8bd0a8c5165f681e3d5caedb8080c9305382dacb8dd7f9461f8cb

Observation 1524d6e6-286a-43ba-93ef-3b2fef453951 · outbound

This paper cites GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher

Reference 93

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.731379Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.731379Z digest=sha256:da7265f76ba7a9a01548f8078c580bbad64bca170ed9241640e18b6ee2e56fad

Observation 00c62709-3317-40a3-b346-442a63fdae42 · outbound

This paper cites The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG).

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG)

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.734755Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.734755Z digest=sha256:2c64f750f903f65c9a2cd391a6edbf9a0a01878acf08002ae2bb2152d397ecd6

Observation f589ac32-fc8d-4d1b-96e3-5b2e30bd4aa3 · outbound

This paper cites Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 95

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.737890Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.737890Z digest=sha256:24772263c1faeaf76ed0c5601eaaf7f2588ad55ee84a5d7c470542c3e30c5c6a

Observation ab6de568-c470-4aab-88e5-dea0578791ba · outbound

This paper cites Cut the Crap: An Economical Communication Pipeline for LLM-based Multi-Agent Systems.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Cut the Crap: An Economical Communication Pipeline for LLM-based Multi-Agent Systems

Reference 96

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.740954Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.740954Z digest=sha256:e8f4547b389be7060a76429ab6f015aec5a327c47e5ec5e9338b8ec9739a0c69

Observation e4edd56d-f9ec-49a4-953c-f24c4b7be12c · outbound

This paper cites G-Designer: Architecting Multi-agent Communication Topologies via Graph Neural Networks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems G-Designer: Architecting Multi-agent Communication Topologies via Graph Neural Networks

Reference 97

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.744658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.744658Z digest=sha256:d31606f442f278e2e2a7b76740943197827ac1e330cfcb65492f0653274eaaa1

Observation 957146b2-5704-4b00-aba6-c0e9972dae84 · outbound

This paper cites Multi-agent Architecture Search via Agentic Supernet.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Multi-agent Architecture Search via Agentic Supernet

Reference 98

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.747826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.747826Z digest=sha256:1eb2c5ff6b9b821702eb1189b80d40f524c7c36d7a4c7e06f447ddaaa0704558

Observation 135758a2-101f-46b2-b1b3-b9f34e775ef4 · outbound

This paper cites On large language models safety, security, and privacy: A survey.Journal of Electronic Science and Technology, page 100301, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems On large language models safety, security, and privacy: A survey.Journal of Electronic Science and Technology, page 100301, 2025

Reference 99

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.480624Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.751306Z digest=sha256:af6ab0eb3a1208b30c42571f8cd9557475eaccb1c3610be4e6fa7299040ff875

Observation 345cee46-9e13-41d1-b269-df216f2781e7 · outbound

This paper cites A Survey on the Memory Mechanism of Large Language Model based Agents.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Survey on the Memory Mechanism of Large Language Model based Agents

Reference 100

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.754225Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.754225Z digest=sha256:2881f80458734d68f9932a3d3e21d4bb8f45673fef21833d9d647ed137c7c9cb

Observation 076583d6-15c9-4396-a3d0-44469bf491fb · outbound

This paper cites Agent-SafetyBench: Evaluating the Safety of LLM Agents.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Agent-SafetyBench: Evaluating the Safety of LLM Agents

Reference 101

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.757251Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.757251Z digest=sha256:4c893c3c065394b151c49402ab9550b034f38c7c6f69f1e993acdb75adbbc48a

Observation 3a8ecb07-4fc3-4a68-ab6a-ff2bac3b1b42 · outbound

This paper cites Weak-to-strong jailbreaking on large language models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Weak-to-strong jailbreaking on large language models

Reference 102

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.470778Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-07T00:32:36.760608Z digest=sha256:6837d70a8d376c5d5344bcf432e29db73ec2fa7df4393cf69360c533ea1d415a

Pith citing papers

Observation 90e1e1ed-8764-4e66-a8d9-6960ea2c0b21 · inbound

A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis cites this paper.

A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T21:44:54.864170Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:44:54.864170Z digest=sha256:66f13adf90246a9c908ab3b3f1ff977507e410c25d619760de4b475668fb3d68

Observation cfe0e7e8-93f6-4771-ad9f-5e537f17e30b · inbound

A Survey of Context Engineering for Large Language Models cites this paper.

A Survey of Context Engineering for Large Language Models We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 268

Resolution
verified exact
arxiv_id, observed 2026-05-13T20:58:45.454680Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-13T20:58:45.060041Z digest=sha256:abe66626c0d0cdbec545db765b275eaa0bbed9748e059194f730b4212e4b1fb0

Observation e0d13b95-ba3d-45c4-a254-a4f2d61dcdb2 · inbound

Quantifying Conversation Drift in MCP via Latent Polytope cites this paper.

Quantifying Conversation Drift in MCP via Latent Polytope We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-05T22:51:28.082763Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T22:51:28.082763Z digest=sha256:9f7e3b1ed764e9b2a26bb4e8cee07c5af4287d1bc71c8f9424ce0f4098dfb1e7

Observation 20c9401e-5b28-422d-ba1a-9243586357e2 · inbound

SafeSearch: Automated Red-Teaming of LLM-Based Search Agents cites this paper.

SafeSearch: Automated Red-Teaming of LLM-Based Search Agents We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-04T14:43:49.514734Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T14:43:49.514734Z digest=sha256:07810882443deff28a6fe5956db38b82862e54b31c2f262be33b30b6dc03ba5d

Observation fefa0c54-1a93-4642-b570-953c2be5843e · inbound

AgentBound: Securing Execution Boundaries of AI Agents cites this paper.

AgentBound: Securing Execution Boundaries of AI Agents We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-18T05:15:54.194195Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-18T05:12:23.542793Z digest=sha256:64f69847ee9c9986d8aeb39c06c004c08ed725cd6e002c0c3f4094204c5fcd87

Observation 3124087a-1487-43c7-acf0-c3166b8bb612 · inbound

BalDRO: A Distributionally Robust Optimization based Framework for Large Language Model Unlearning cites this paper.

BalDRO: A Distributionally Robust Optimization based Framework for Large Language Model Unlearning We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-03T10:45:41.323277Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T10:45:41.323277Z digest=sha256:74f601f961d2080d7587c9d5c8fe95c609c76481b72f8320072673ed51d7d846

Observation 99d5a936-f809-49ba-9bd3-93cff40c539c · inbound

Combating Data Laundering in LLM Training cites this paper.

Combating Data Laundering in LLM Training We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 16

Resolution
unresolved
no resolver link, observed 2026-07-13T14:08:35.474488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-13T14:08:35.474488Z digest=sha256:5e54f5238901dfa6d6956f16e8ceecf62168b9f273edb2fde06eb65f0c1c6a8a

Observation 480a69b4-2b84-4ec8-a628-112915abefca · inbound

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers cites this paper.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.943736Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:2ce841e2a4e41942779a87236f3766cebab9ddc06eb00d5f3f60f06c28e88c16

Observation 90f557b0-dd05-47fa-bd65-952d9dc1467e · inbound

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security cites this paper.

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-10T21:10:46.722140Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-10T17:10:50.283791Z digest=sha256:ead0432c1130c3d78780bf3e35e54947e0a97c9cadd18546b97448bc006fddd2

Observation 6bfb7f42-7003-402d-9b36-9ebc80aaad4c · inbound

"What Happens Locally, Leaks Globally": Detecting Privacy Leakage Risks in MCP Servers cites this paper.

"What Happens Locally, Leaks Globally": Detecting Privacy Leakage Risks in MCP Servers We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 9

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T06:49:38.283917Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-06-26T14:07:59.170493Z digest=sha256:13210b74eacac7119ded4e8cfad4ba241943fc8ab8ef9a2425b8b66539169065