Pith. sign in

Paper Citation Record · LEDGER

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents

As of 21 August 2026, this Paper Citation Record lists 76 of 76 outbound references and 1 inbound Pith citation observation for arXiv:2507.02699.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2507.02699 v1

Coverage vector

measured 76 of 76 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-06T20:29:46.464523Z

measured 77 of 77 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-21T06:32:19.484+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-05-20T10:51:19.555985Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-05-20T10:53:13.363465Z

Reference resolution

76 of 76 outbound references displayed

  • verified exact0
  • verified fuzzy71
  • unresolved5
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 6325995f-bcba-4904-9719-c869eddb0d9f · outbound

This paper cites infosecurity-magazine.com/news/ 91-of-apt-attacks-start-with-a-spear-phishing/ , 2012.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents infosecurity-magazine.com/news/ 91-of-apt-attacks-start-with-a-spear-phishing/ , 2012

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.200866Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:39.959006Z digest=sha256:5ebc552cd9a20b2a6158dac410e22c8986a922a2e3425ef278979081bed72e48

Observation 2fb8f170-7167-45c9-a293-09886f92b949 · outbound

This paper cites https://www.paubox.com/blog/ the-email-connection-with-atp-attacks , 2023.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://www.paubox.com/blog/ the-email-connection-with-atp-attacks , 2023

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.184103Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.061302Z digest=sha256:1e824bac51497b07c6bac1322a03b2a11bfc8275b855a14207cfbc80a63d1052

Observation 0bb9c941-fb87-4299-8cef-6fc719a3d2d5 · outbound

This paper cites https://github.com/ transitive-bullshit/agentic, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/ transitive-bullshit/agentic, 2025

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.166448Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.135382Z digest=sha256:a4a530baab1450efe22384635920298f38110642ff47ca0060868a0dd63744da

Observation a3e333ff-e6b7-477f-82cd-5937bcabf11f · outbound

This paper cites https://github.com/ aiwaves-cn/agents, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/ aiwaves-cn/agents, 2025

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.149457Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.214054Z digest=sha256:75509f3e2ba4a48aa43d2a740de45c080ed25bae163ddafed3372de4b876c620

Observation b37628b6-6efd-4ba5-836d-7edf0ac29f85 · outbound

This paper cites https://docs.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://docs

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.133888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.285134Z digest=sha256:8da66ea1d46bd16ea40f6a4cf2cc7f682fd0897845db664a74274daf22b6ca45

Observation 337266e5-4e21-4224-ac68-eadb16b0bb87 · outbound

This paper cites https://github.com/HKUDS/ AutoAgent, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/HKUDS/ AutoAgent, 2025

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.119874Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.369271Z digest=sha256:add4ebd6bebb8bcd438557eac30816cc71f909e5020f5f85cff61218027c6534

Observation c31d47cb-e53f-4048-8ae0-da64d5f57be2 · outbound

This paper cites https://github.com/ deepseek-ai/DeepSeek-R1, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/ deepseek-ai/DeepSeek-R1, 2025

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.103738Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.471796Z digest=sha256:42a9dab7e6019cd0b29eef4a87183425056e199af686f3ee475877e085d9bee4

Observation 00df22cf-646e-4139-9857-8b9cd7b6dde4 · outbound

This paper cites https://github.com/ deepseek-ai/DeepSeek-V3, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/ deepseek-ai/DeepSeek-V3, 2025

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.087541Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.557561Z digest=sha256:cf9c5471376cc7bc27cc20aeff605b4fa2b4981b80d960f7913ffc5257109c4b

Observation c4759c04-b8b6-494b-9e21-5f13db739875 · outbound

This paper cites https://ai.google.dev/ gemini-api/docs/models?authuser=1# gemini-1.5-pro, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://ai.google.dev/ gemini-api/docs/models?authuser=1# gemini-1.5-pro, 2025

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.071198Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.633975Z digest=sha256:25b980c2e5e7441bdd4c09c96fae3b78e593443d4cd9be6e0c2cd13ae4d10533

Observation ba818543-c5ad-4c39-b1e4-55883bef6a99 · outbound

This paper cites https://ai.google.dev/ gemini-api/docs/models?authuser=1# gemini-2.0-flash, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://ai.google.dev/ gemini-api/docs/models?authuser=1# gemini-2.0-flash, 2025

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.055478Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.711855Z digest=sha256:c428b1073a5d09a1b1f17ef51c6077f3441558febe3b43ca2d81d41880b324a6

Observation 43acee7e-2371-4ffe-ad92-ef800d56c240 · outbound

This paper cites https://github.com/, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/, 2025

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.037870Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.790902Z digest=sha256:d30099a8d67adcb128517af6f13e37bb1322ef8fdf87d67c6ade2ec1a399cee1

Observation e59f635a-055b-4158-8b83-97bc395cfeca · outbound

This paper cites https://github.com/griptape-ai/ griptape, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/griptape-ai/ griptape, 2025

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.022706Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.867170Z digest=sha256:8f25e5be788f6578d5e13461a38752f5869add3f2c222b2b76d0f7a329e0a003

Observation d6377911-5b69-4071-a8f6-ada44c15ba9d · outbound

This paper cites https://github.com/deepset-ai/ haystack, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/deepset-ai/ haystack, 2025

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:57.006723Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.942749Z digest=sha256:b853075452c1fbc122dfe6e3fe26be7fb738fef6087ba6aea91237836f469157

Observation 65c9a792-6ac1-498b-93ee-f3342b48a841 · outbound

This paper cites https://huggingface.co/, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://huggingface.co/, 2025

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:56.991661Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:40.987812Z digest=sha256:6cfaa3c7061d68e762150fd72116418c5f319d21b6ad4f81d1769c8739bdeced

Observation 38379a74-07ae-4628-9e8f-bac969167e68 · outbound

This paper cites https://github.com/InternLM/ lagent, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/InternLM/ lagent, 2025

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:56.975802Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.122183Z digest=sha256:38d69b1c789bbf85ff4853d72f670b488f9d14843522d5d5a47ea8f89ef7556e

Observation ac9ab31a-59aa-4c05-b1d2-ef1e8eac7fe8 · outbound

This paper cites https://github.com/ langchain-ai/langchain, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/ langchain-ai/langchain, 2025

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:56.959184Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.247853Z digest=sha256:d2ca57be8a7fd8921fbeb8d24352eacb09e3e160399c408e1060517d60797264

Observation c4b42c7d-0607-4fb7-a58b-57977d943f40 · outbound

This paper cites https://smith.langchain.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://smith.langchain

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:56.680071Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.375746Z digest=sha256:cb7694a266a9c5063ae7fb9e4bbac862364b394916bf336c9579d8a823689d64

Observation fd510ae5-9a4f-45ff-87b9-2880b2328439 · outbound

This paper cites https://github.com/langflow-ai/ langflow, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/langflow-ai/ langflow, 2025

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:56.537349Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.530606Z digest=sha256:0e7c647b90f8dfbbb0638415a2f953091fcd927956b0cec9db0b89aeca989a9d

Observation 3caa2be8-a194-4254-9a1e-2113c9034922 · outbound

This paper cites https://github.com/langroid/ langroid, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/langroid/ langroid, 2025

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:56.155932Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.610299Z digest=sha256:dbe1dabb4aaf60b185729cbccec88bcc4cfae0950ed53cfaed1c4bbea28bc3b1

Observation 01bcf1c5-64f9-43f0-af4b-541025c769f5 · outbound

This paper cites https://github.com/letta-ai/letta, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/letta-ai/letta, 2025

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:55.864637Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.671570Z digest=sha256:b24c4b28c03d136fc1581da3b1c2852c9c9764a7d8da84f1dd03b9bf9c230d97

Observation 38880e9b-03fa-43da-a984-ab025b1572c6 · outbound

This paper cites https://ollama.com/library/ llama3, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://ollama.com/library/ llama3, 2025

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:55.594134Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.729559Z digest=sha256:56f34d87f745fcb5914798d65933fa8506a34f6c18bc62f68a38d9e531ddc2fb

Observation 774fb88d-fe6f-4edb-a053-bc88d3cd2c6f · outbound

This paper cites https://ollama.com/library/ llama3.1, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://ollama.com/library/ llama3.1, 2025

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:55.355031Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.787679Z digest=sha256:f381927f73da2d0b97cb08f9df9909c37301078cb3462259a32c10f3e191f4cf

Observation bea1b2e8-b021-42bd-90a9-0d0424e4133c · outbound

This paper cites https://ollama.com/library/ llama3.3, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://ollama.com/library/ llama3.3, 2025

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:55.224468Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.843105Z digest=sha256:8d9b8875318c937c976586e50836ceba52f2b3a378bf0f3b09a2514267df6e77

Observation 5dff1aad-8de1-4b4b-a9bd-6f2ecbebfb1d · outbound

This paper cites https://github.com/ run-llama/llama_index, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/ run-llama/llama_index, 2025

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:55.093764Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.920513Z digest=sha256:1139fc1f784613612393c8abae50c4f3d60362f8d011d8611e62ba0741255329

Observation f560ce3f-5cb2-49b2-b965-662037b18a0d · outbound

This paper cites https://github.com/geekan/ MetaGPT, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/geekan/ MetaGPT, 2025

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:54.966057Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:41.988145Z digest=sha256:deaf2d4dbdd42c29f685e800bd0f69547dff36cbd7c40ee214da42565a9b9f92

Observation 331e9879-3cfb-42c6-bc72-15c6f2bbccc9 · outbound

This paper cites https://github.com/ modelscope/modelscope-agent, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/ modelscope/modelscope-agent, 2025

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:54.835577Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.080663Z digest=sha256:4ab5f7202cc7bf3bc737c7bafa1d47eb7fab46af67531b59d2d2484ce01a1b4a

Observation b6c73ce3-92b6-4b32-aff2-36df355b3ee0 · outbound

This paper cites https://github.com/ openai/openai-agents-python, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://github.com/ openai/openai-agents-python, 2025

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:54.715219Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.158867Z digest=sha256:07a02178dc3468057367f28922d0556d35b52f74a051ccdcd88156ee363811d1

Observation 0bce9e23-2835-4030-926d-d028ee04c4db · outbound

This paper cites https://platform.openai.com/docs/ models/gpt-3.5-turbo, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://platform.openai.com/docs/ models/gpt-3.5-turbo, 2025

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:54.596039Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.230677Z digest=sha256:30e502ac35974e9759f066a2e62c4f6425342e747f0259127346fbd7d65bb9c5

Observation 8527c0bf-9b8a-4209-9c7f-d05b6bd568d8 · outbound

This paper cites https://platform.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents https://platform

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:54.473543Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.283132Z digest=sha256:9f586118676201c2b04abbe8270572f44690c72549c298df7cd1208422b7f0d3

Observation 28bd2bc9-173b-41c9-af0e-7a66edf6af81 · outbound

This paper cites Ackerman and Nina Panickssery.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Ackerman and Nina Panickssery

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:54.353565Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.353329Z digest=sha256:78b555ccf09b6884eb288f480e5a71f3d805e904b37b3f16a7192695cdab31c6

Observation 58a7e9f8-9ba4-426e-8abc-a23f8db8a107 · outbound

This paper cites Many-shot jail- breaking.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Many-shot jail- breaking

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:54.223491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.413177Z digest=sha256:3780787ecb804de48f80189e2ebd969c0775ce28863431f35bd0e0964fd087ba

Observation cc430696-05d6-4676-8570-a877ef986f86 · outbound

This paper cites Encrypted prompt: Securing llm applications against unauthorized actions, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Encrypted prompt: Securing llm applications against unauthorized actions, 2025

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:54.092528Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.471174Z digest=sha256:db976ef1d5f9d5461e9a56b51c2d27a121800b2aad1560020ea643c15ebd1101

Observation 3e565e81-465f-446c-8cbd-c6f4da856a0a · outbound

This paper cites The obvious invisible threat: Llm-powered gui agents’ vulnerability to fine-print injections, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents The obvious invisible threat: Llm-powered gui agents’ vulnerability to fine-print injections, 2025

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:53.985800Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.547687Z digest=sha256:73911e004eefbc5f6321431acee55dc6847610cab08aacb82b0b03900dc7ce53

Observation 3cd1eda8-e905-493b-ad6f-1e7677a8f15e · outbound

This paper cites Struq: Defending against prompt injection with structured queries, 2024.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Struq: Defending against prompt injection with structured queries, 2024

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:53.879562Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.623373Z digest=sha256:1572c64562bfccaa4d97ad55c59d3ea684921939c20c4bb0bdd477800264e260

Observation 76bd1828-0218-462d-8737-aa3c0025ec07 · outbound

This paper cites Secalign: Defending against prompt injection with preference optimization, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Secalign: Defending against prompt injection with preference optimization, 2025

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-06T20:29:42.698878Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T20:29:42.698878Z digest=sha256:89770ccbc98e5b0685051d87d20ecf32a0cc09f4116c10904bad890414ccf0ea

Observation dbaaacc6-72b5-485a-9f17-57ad00d65d9f · outbound

This paper cites Can indirect prompt injection attacks be detected and removed? arXiv preprint arXiv:2502.16580, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Can indirect prompt injection attacks be detected and removed? arXiv preprint arXiv:2502.16580, 2025

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-06T20:29:42.762552Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T20:29:42.762552Z digest=sha256:7cea012450dc6b6b20ed9f955a29031b1d60f0bd30dcf22c258c3bd8a9c12263

Observation fd5fa52d-0cce-4114-b75d-a6121d7e76ac · outbound

This paper cites Masterkey: Automated jail- breaking of large language model chatbots.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Masterkey: Automated jail- breaking of large language model chatbots

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:53.692485Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.830385Z digest=sha256:6747df23e76545ec56af8e3c8c6514ff6be2bbf54728b273578385515c73b2f6

Observation 7212e946-f51d-4d77-aec2-a859e482d917 · outbound

This paper cites The philosopher’s stone: Trojaning plugins of large language models, 2024.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents The philosopher’s stone: Trojaning plugins of large language models, 2024

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:53.546757Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.902031Z digest=sha256:88fc74b1545f027234a6a84298d232aab0bdc8fe5a43c5a4dc604521cceb6652

Observation 3675e98e-101b-42b6-a65d-b12b8f88ca0b · outbound

This paper cites Feature-aware mali- cious output detection and mitigation, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Feature-aware mali- cious output detection and mitigation, 2025

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:53.353399Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:42.966656Z digest=sha256:6c744ccbf01135ad39121f50f7b8b6adbf2d276e5ff574094ddef6061c028db4

Observation 1993f9fb-3a22-488e-9ff7-887d5ddd11db · outbound

This paper cites Struphantom: Evo- lutionary injection attacks on black-box tabular agents powered by large language models, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Struphantom: Evo- lutionary injection attacks on black-box tabular agents powered by large language models, 2025

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:53.161565Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.039729Z digest=sha256:4e7e72287ea1976eba64a1acc6e04ce28c162d3ffd13cd726b7dbcb0221d6ba6

Observation 1ec37b72-d1b2-4469-ac11-d096bc0e9d8d · outbound

This paper cites From assistants to agents in the llm era.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents From assistants to agents in the llm era

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:52.976226Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.116733Z digest=sha256:e2acfefabc85cbcc6e19423e7423a0577d66931dbdd9b87396dacd2af67ed98d

Observation 68b1a2c1-d589-42f8-9cc2-abe895d9eea8 · outbound

This paper cites Jbfuzz: Jailbreaking llms efficiently and effectively using fuzzing, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Jbfuzz: Jailbreaking llms efficiently and effectively using fuzzing, 2025

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:52.796476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.174126Z digest=sha256:9b4690875629f5ab238b17591481099815867f2a85aa5b0a4d3e290ea3b960a2

Observation 6c00e9a3-881b-49cb-a6f7-454fe4817775 · outbound

This paper cites Safety mis- alignment against large language models.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Safety mis- alignment against large language models

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:52.643089Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.257553Z digest=sha256:9d302703505e10698b6f57d31def1ad66d628d081ca8fd83d4de256f6c1dd3cf

Observation 9359093f-91d3-431a-b0b8-019c3f96d4b9 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:52.438121Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.302921Z digest=sha256:5c357ba714f7a8b028cd36142dd1cde03449d9d51abb738900caccc46fde93d6

Observation 1a92068a-1488-49d7-af50-b7e8402adefe · outbound

This paper cites Bypassing prompt injection and jailbreak detection in llm guardrails, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Bypassing prompt injection and jailbreak detection in llm guardrails, 2025

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:52.299856Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.307961Z digest=sha256:3b6c240ae55c6bd76c10384f2d37e1f26fdef8ba896eae41fa046e87dce9c582

Observation 1e5ae241-bfc9-46e4-a51c-82545cb68c5a · outbound

This paper cites Iterative prompting with persuasion skills in jailbreaking large language models, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Iterative prompting with persuasion skills in jailbreaking large language models, 2025

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:52.144885Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.312915Z digest=sha256:89e263b0e3cf6d3e2aad7b2cf9655280a47b8dcc20add7d49d640a51d803fcae

Observation 567dc867-d669-4c51-9e67-ec1fe3fe60e0 · outbound

This paper cites xjailbreak: Representation space guided reinforce- ment learning for interpretable llm jailbreaking, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents xjailbreak: Representation space guided reinforce- ment learning for interpretable llm jailbreaking, 2025

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:51.962477Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.321535Z digest=sha256:d71ad1f06cfaae08f4f41f21ea565b9e1e655d73cf74c5034b61ce8a3d5c9f34

Observation fdf92076-e0e8-4924-bc8f-353d12be5035 · outbound

This paper cites Multi- step jailbreaking privacy attacks on chatgpt, 2023.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Multi- step jailbreaking privacy attacks on chatgpt, 2023

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:51.787327Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.487076Z digest=sha256:968664c05a07f2ecc7e403ec4d5f2abf9489f7ef562fccdc02fdf2129fbb1781

Observation b5bda01e-3335-406a-828e-2ec43b2bb0f8 · outbound

This paper cites Separator injection attack: Uncovering dialogue bi- ases in large language models caused by role sepa- rators, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Separator injection attack: Uncovering dialogue bi- ases in large language models caused by role sepa- rators, 2025

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:51.629786Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.597757Z digest=sha256:83380d23d10568d483bf603d678d86ec9f5f88db31b81a8bc0a19af3a48f97a7

Observation 97dfebd2-8523-436b-b47a-4cb616b04a95 · outbound

This paper cites Pico: Jailbreaking multimodal large language models via Pictorial Code contextu- alization, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Pico: Jailbreaking multimodal large language models via Pictorial Code contextu- alization, 2025

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:51.447062Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.737401Z digest=sha256:b0961889c3396bbcde0a7f33cb6f83d4d8932a302de81be1d95a37ccb744e60f

Observation 2a7b2de6-f4f2-4289-b7cd-31c969ff61da · outbound

This paper cites Token-level constraint bound- ary search for jailbreaking text-to-image models, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Token-level constraint bound- ary search for jailbreaking text-to-image models, 2025

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:51.253691Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:43.906523Z digest=sha256:96deaf93450310bd13b15636931517550db0f78ed9a0687143423bd724bbde53

Observation 1740c6d6-dc88-40e8-94d8-aa6d04e59478 · outbound

This paper cites Demystifying rce vulnerabil- ities in llm-integrated apps.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Demystifying rce vulnerabil- ities in llm-integrated apps

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:51.095063Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:44.080880Z digest=sha256:245d1aa2955d16ad6b8af986fe2602a957e4d68b742609ffde88acbf95efe45f

Observation df3427e0-fa28-4fcc-bae9-c4db0edd6c3b · outbound

This paper cites Prompt injection attack against llm-integrated ap- plications, 2024.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Prompt injection attack against llm-integrated ap- plications, 2024

Reference 53

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:50.888421Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:44.235076Z digest=sha256:43f16af62d79d5c9198cafa85202dc94e55d0320af91b0e56cb84bedb2a1467a

Observation 40c9801e-07f1-4885-96dd-84ec5d5d3409 · outbound

This paper cites Formalizing and bench- marking prompt injection attacks and defenses, 2024.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Formalizing and bench- marking prompt injection attacks and defenses, 2024

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:50.658678Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:44.394416Z digest=sha256:98760ef07b4f814fa0e83bbbeffae6773df2d19da8890c0098465e9d66e49afb

Observation 0fe7c87b-91b5-40d4-9ab9-d7b153f000b0 · outbound

This paper cites Saro: Enhancing llm safety through reasoning- based alignment, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Saro: Enhancing llm safety through reasoning- based alignment, 2025

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:50.482598Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:44.575081Z digest=sha256:b7f479d52c45ac7c24691b7d446a09e459e1563226bf7c3875db5590c4d4d3b0

Observation 07fa3256-f73c-4154-b81f-5dc740010e0a · outbound

This paper cites From prompt injections to sql injec- tion attacks: How protected is your llm-integrated web application?, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents From prompt injections to sql injec- tion attacks: How protected is your llm-integrated web application?, 2025

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:50.302309Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:44.731561Z digest=sha256:7a0884d6279445e6b9a353537d6e0d9151bcb54b16c7797d0517ec8140f3c918

Observation 2f368d73-52b3-4171-9242-a776c8310e1d · outbound

This paper cites Ignore previous prompt: Attack techniques for language models, 2022.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Ignore previous prompt: Attack techniques for language models, 2022

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:50.132083Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:44.897942Z digest=sha256:f44c5088d029638a573309d763c751dd4725d489a6fffb582c53fa0f67fd8cb1

Observation 98aa6921-b5c0-48a2-a1f7-b80e57bc40b6 · outbound

This paper cites do anything now.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents do anything now

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-06T20:29:45.022255Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T20:29:45.022255Z digest=sha256:90c9239557aa992cc43072af8ad51f50052f775c8bf8f9afc8389acc917f159b

Observation 3ff28be2-30ac-40ee-b2a7-5f860b628710 · outbound

This paper cites Yurascanner: Leveraging llms for task-driven web app scanning.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Yurascanner: Leveraging llms for task-driven web app scanning

Reference 59

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:49.892278Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.162549Z digest=sha256:ad9d7a82fe24f0768cfdd7e75e4bdc02e06d6e8621343fa91513b15a711b0b06

Observation 2770a61e-afd2-4bbc-bacb-e3a6d55156bd · outbound

This paper cites Signed-prompt: A new approach to prevent prompt injection attacks against llm- integrated applications, 2024.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Signed-prompt: A new approach to prevent prompt injection attacks against llm- integrated applications, 2024

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:49.743513Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.259762Z digest=sha256:ba1b6cb5769ead88502127940601eaee1377e439fdd426bdf0dcbc337c9af101

Observation ca85aaf5-dc65-4e4c-8bae-159225f744f0 · outbound

This paper cites Email spoofing with smtp smuggling: How the shared email infrastructures magnify this vul- nerability.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Email spoofing with smtp smuggling: How the shared email infrastructures magnify this vul- nerability

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:49.455967Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.322347Z digest=sha256:693997f3c304e65913ac935a18ef93d818b00303b823ebb7a75baa362c7c6bc4

Observation 66654049-a55d-47a4-9268-f6e8dcb8456c · outbound

This paper cites Unity is strength: Collaborative llm-based agents for code reviewer recommendation.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Unity is strength: Collaborative llm-based agents for code reviewer recommendation

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:49.254390Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.401040Z digest=sha256:3179ab43861abf8a4728b4a221d4da59f4e6eaa932a7ead00bade81361e77378

Observation 420d02d8-212b-450e-be02-532d989229e1 · outbound

This paper cites Geneshift: Impact of different scenario shift on jailbreaking llm, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Geneshift: Impact of different scenario shift on jailbreaking llm, 2025

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:49.077460Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.493784Z digest=sha256:6168951dd38b345a60458f3a7f9cdfd00ef3240165c5e3ee82093f93fc09c5f6

Observation 865a1c7f-6f5d-4a34-88a1-7508db99206b · outbound

This paper cites Isolategpt: An exe- cution isolation architecture for llm-based agentic systems, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Isolategpt: An exe- cution isolation architecture for llm-based agentic systems, 2025

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:48.790571Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.575250Z digest=sha256:65253a3737697c08618bc6f73df9a5977079e1d24c18c961c2017d79d1e6f190

Observation 02f6f7fc-17ff-437b-bc69-8975d2d0be6e · outbound

This paper cites Sneakyprompt: Jailbreaking text-to- image generative models, 2023.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Sneakyprompt: Jailbreaking text-to- image generative models, 2023

Reference 65

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:48.568558Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.642214Z digest=sha256:ed155f11daca83c1a847a2dd52c2477123c33be9b741ef0694b6d2d80f382eaf

Observation 65d2f12b-a647-4e6b-9d70-b340a8604391 · outbound

This paper cites Lightdefense: A lightweight uncertainty-driven defense against jailbreaks via shifted token distribution, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Lightdefense: A lightweight uncertainty-driven defense against jailbreaks via shifted token distribution, 2025

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:48.369862Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.709709Z digest=sha256:4c10be5a4ef936a78f38d6cf2114a478b626f06ea26c722d345cf72015743a63

Observation 4110b923-f0b8-4f1c-b6bc-dbcbbf45c732 · outbound

This paper cites Poster: Repairing bugs with the introduction of new variables: A multi-agent large language model.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Poster: Repairing bugs with the introduction of new variables: A multi-agent large language model

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:48.090922Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.770925Z digest=sha256:e5d3cad8ce4920b57ff67accafc89e411123474f8f7c2b4a37e1f66b46171836

Observation bc87a13f-3c4b-420e-bc3d-e9bb14c7b73d · outbound

This paper cites Agent security bench (asb): Formalizing and benchmarking attacks and de- fenses in llm-based agents, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Agent security bench (asb): Formalizing and benchmarking attacks and de- fenses in llm-based agents, 2025

Reference 68

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:47.918350Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.905738Z digest=sha256:d662d9279f08a5d102ab8d3d24a2a2e2c2b858fb3fac26d5172eec9a03675b69

Observation 0d2f0ea6-0c43-4bea-917e-4f4caa148c3c · outbound

This paper cites TrojanSQL: SQL injection against natural language interface to database.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents TrojanSQL: SQL injection against natural language interface to database

Reference 69

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:47.712482Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:45.983465Z digest=sha256:f131833a94822d1d76aed7c1d9391fde93f3e3733c219068a9c6ecac06123485

Observation 4f4e8509-459a-40be-bc90-9fbef5a3554d · outbound

This paper cites Im- perceptible content poisoning in llm-powered ap- plications.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Im- perceptible content poisoning in llm-powered ap- plications

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:47.428850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:46.127398Z digest=sha256:b07e98e1d223cfd65870fa898cbf6d7c894fa192acf34ef6c824bc16fc1d7a65

Observation e081e15d-0047-4019-9041-beef43bafbfd · outbound

This paper cites Defense against prompt injection attacks via mixture of encodings, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Defense against prompt injection attacks via mixture of encodings, 2025

Reference 71

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:47.222555Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:46.221554Z digest=sha256:9b433c7fd87751bfee9a1270e3cfbc52445b125c41c8ca3e298895b2d9fd6546

Observation 8dfd4b89-4f76-4898-83f9-af1da43350a3 · outbound

This paper cites On large lan- guage models’ resilience to coercive interrogation.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents On large lan- guage models’ resilience to coercive interrogation

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:47.066157Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:46.315650Z digest=sha256:9082ec7d59b59b240065408677f7853e0720bfe37bddca09d9fa9611d57e17a9

Observation d447a5c3-abd9-4602-b2e8-fc2008f2aca0 · outbound

This paper cites Adasteer: Your aligned llm is inherently an adaptive jailbreak defender, 2025.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Adasteer: Your aligned llm is inherently an adaptive jailbreak defender, 2025

Reference 73

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:46.936132Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:46.403794Z digest=sha256:b8541342b24128e44e50e1dcd39bec1a682f2ff20264d724651c2244e0f39048

Observation 58d8b4bb-de90-4ebd-94c3-71d9b7da2cd2 · outbound

This paper cites [AGENT_NAME].

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents [AGENT_NAME]

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-08-06T20:29:46.758523Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-06T20:29:46.464523Z digest=sha256:dc7a3bf3973523ffb1f8327eb4b81d4f47fd07b6904258c2857007be58a2fed1

Observation 88a1f251-e6d5-49d6-944e-6fb98bc18a56 · outbound

This paper cites an unresolved cited work.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Unresolved cited work

Reference 2023

Resolution
unresolved
no resolver link, observed 2026-08-06T20:29:46.060837Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T20:29:46.060837Z digest=sha256:761e05c76501a4d63c67e6c2bb53b33425be4cdf7a7731874f97f447f8185db7

Observation e0d95ebe-01c9-4a61-bb29-f48f17396fcb · outbound

This paper cites an unresolved cited work.

Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents Unresolved cited work

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-06T20:29:45.840643Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T20:29:45.840643Z digest=sha256:9d13a766143e7e295d9142391f7c1848ecacd9508411457817e936d5f25a8818

Pith citing papers

Observation 97c55fa5-8be5-47a3-84d6-6f63219e8a96 · inbound

Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents cites this paper.

Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-20T10:53:13.365092Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-05-20T10:51:19.555985Z digest=sha256:52c6b2ba41339752aea7f00c4c1af308c86e3150711c8aa75d57bb675aec1ffa