Pith. sign in

Paper Citation Record · LEDGER

Imprompter: Tricking LLM Agents into Improper Tool Use

As of 20 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 29 inbound Pith citation observations for arXiv:2410.14923.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2410.14923 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 29 of 29 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 29 of 29 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T21:53:03.337378Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

2
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 7c7e1f4b-cc74-465c-a073-47852cc6e5dd · inbound

Universal and Context-Independent Triggers for Precise Control of LLM Outputs cites this paper.

Universal and Context-Independent Triggers for Precise Control of LLM Outputs Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-12T15:00:14.020558Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T15:00:14.020558Z digest=sha256:c0d2bbcdb5a510e752132fa56d24e08e0a76d19d4ee2e8bb875e3dc1599796a6

Observation 66e6083f-e437-47c3-874b-88c06a6b83e7 · inbound

Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions cites this paper.

Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-13T09:02:40.411688Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-13T09:02:40.294491Z digest=sha256:e7b942721e720d65351966b5e5b56d0ce36033fb9083b19002f9fb889139062e

Observation 10ad151a-1467-46ba-b882-f8d606028412 · inbound

TRAIL: Trace Reasoning and Agentic Issue Localization cites this paper.

TRAIL: Trace Reasoning and Agentic Issue Localization Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 2020

Resolution
unresolved
no resolver link, observed 2026-08-15T21:53:03.337378Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:53:03.337378Z digest=sha256:70f312e818e4ae6683608b183b355b0d486d923bf5ed6cc7d1245a92db0a958e

Observation ce873d7e-85cf-465e-859f-45ae035678b5 · inbound

Think Twice Before You Act: Enhancing Agent Behavioral Safety with Thought Correction cites this paper.

Think Twice Before You Act: Enhancing Agent Behavioral Safety with Thought Correction Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-15T21:05:35.041356Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T21:05:35.041356Z digest=sha256:1e184b513b01ff6b257b2f05cc103a14a173151a7754fb62c2d47a18f9a09561

Observation aab7e631-2d14-4b0c-921c-5c3990c973cf · inbound

Lessons from Defending Gemini Against Indirect Prompt Injections cites this paper.

Lessons from Defending Gemini Against Indirect Prompt Injections Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-07T15:37:51.603999Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:37:51.603999Z digest=sha256:64a9210dd85fcf3f5a14afa520b1d16cf1304fe1daa13fda3603044381b21898

Observation ac2626e6-3ed5-47fa-8f37-4d423204ba59 · inbound

Data-Centric Safety and Ethical Measures for Data and AI Governance cites this paper.

Data-Centric Safety and Ethical Measures for Data and AI Governance Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T04:34:08.000242Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T04:34:08.000242Z digest=sha256:b12ccd381e7247451b495e99d6316646e6d1172c78752815d57d32dee6fc3ba2

Observation 87ea844c-4b84-4efe-b22f-b0f8cc12c09b · inbound

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems cites this paper.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.507283Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.507283Z digest=sha256:c366928ebcf3a741b192d2783028e3c3e63d4d07a23aac87e099571965d1ff94

Observation ef7e3098-7e36-4660-b5c1-1aa73879559b · inbound

FaSTA$^*$: Fast-Slow Toolpath Agent with Subroutine Mining for Efficient Multi-turn Image Editing cites this paper.

FaSTA$^*$: Fast-Slow Toolpath Agent with Subroutine Mining for Efficient Multi-turn Image Editing Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-05-19T08:17:10.746601Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-19T08:17:08.223736Z digest=sha256:ebfef1c3945c7105b00df2691482ab54d646687c86b1ca6b6309d28f6c298ee8

Observation b8580e78-b2fc-44d8-ad47-fd96cdb4f583 · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 122

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:45.093922Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:45.093922Z digest=sha256:1741851b5ae86c7671f011f17bf23b2bad7e4e952aac24075895e4830e3e95af

Observation 757c4528-ba1f-4594-9e0b-f07bfcbb87e9 · inbound

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree cites this paper.

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-06T15:52:56.510579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T15:52:56.510579Z digest=sha256:4bc0b6490bcdac519821067ec8fe0551a33a96c91fe120fa67054f0e49b1d933

Observation 4a7c8dd4-d55a-448e-aa63-0896643f70a5 · inbound

On the Future of Software Reuse in the Era of AI Native Software Engineering cites this paper.

On the Future of Software Reuse in the Era of AI Native Software Engineering Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T15:29:05.783421Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T15:29:05.783421Z digest=sha256:c90f83ddbf20e6e56cb3dab2146eb1b4ea6c57c92263ca20eecc5f5cbaae51bc

Observation dc60bca4-8180-45eb-ab43-56784df000e4 · inbound

AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents cites this paper.

AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-04T21:44:12.278474Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T21:44:12.278474Z digest=sha256:fc5ff85d28779f1abc9dd3a2cf51226147bad96986282c0a891107c139875756

Observation 02c1bb54-0bef-4954-b47c-dde9e019eabb · inbound

AgentBound: Securing Execution Boundaries of AI Agents cites this paper.

AgentBound: Securing Execution Boundaries of AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
metadata mismatch
arxiv_id, observed 2026-05-18T05:15:54.156005Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-18T05:12:23.542793Z digest=sha256:c33daf8bbd3ce21eb82acee3233097affdee84504b608fe0302509d167528461

Observation 8fae375b-c2cf-4058-b1bf-1bed57620730 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 45

Resolution
metadata mismatch
arxiv_id, observed 2026-05-18T03:42:22.516285Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:758f57a635b6e193e1b739246d928aaac62f3b9e31d235a5c3357193002619e9

Observation 2f4b6a39-39f6-49ec-80b1-3cfe183eaf56 · inbound

GUIGuard-Bench: Toward a General Evaluation for Privacy-Preserving GUI Agents cites this paper.

GUIGuard-Bench: Toward a General Evaluation for Privacy-Preserving GUI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 56

Resolution
metadata mismatch
arxiv_id, observed 2026-05-16T11:32:48.257431Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-16T11:31:16.087579Z digest=sha256:565f879fab07374c0c56a569afe1416a04cdc7fb315f94d55c28ad6ccfd9986b

Observation 5d05004d-b4bb-4c5f-ad2c-0db093425c95 · inbound

Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP cites this paper.

Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 71

Resolution
verified exact
arxiv_id, observed 2026-05-16T05:07:20.812637Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-16T05:05:16.370606Z digest=sha256:0f32eb8f27197163cf416135d35e69c30807aa18858ec1ac6020ccfa722ec931

Observation fe22c24f-fdc2-4fff-94a8-7539659ed8de · inbound

From Storage to Steering: Memory Control Flow Attacks on LLM Agents cites this paper.

From Storage to Steering: Memory Control Flow Attacks on LLM Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 1

Resolution
unresolved
no resolver link, observed 2026-07-14T20:40:43.875392Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-14T20:40:43.875392Z digest=sha256:e0c0517021c97ef8991a7070702ae74b4fab8dd1decfb71a78b4c5cd6796a7b4

Observation f631d8a7-2d9a-4229-aa2a-57fef3addcd8 · inbound

How Your Credentials Are Leaked by LLM Agent Skills: An Empirical Study cites this paper.

How Your Credentials Are Leaked by LLM Agent Skills: An Empirical Study Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 18

Resolution
verified exact
arxiv_id, observed 2026-05-13T19:53:11.688398Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-13T19:51:29.230241Z digest=sha256:dbc90ec2a093b3851669950fb40ec6f99e4192d9993e441b371f16d67c305f0e

Observation 1fe5a63e-6a84-41a7-bcfe-92c99bfd40c2 · inbound

HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents? cites this paper.

HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents? Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-05-10T10:34:29.224645Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T10:32:37.967401Z digest=sha256:b5ece438129b7ff326232618e2d0471e3a64ba6c925264700ddb6665f8fbdafe

Observation bb9e389e-d419-4939-bb20-1b698435fbbf · inbound

WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections cites this paper.

WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 21

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T14:45:49.558073Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-30T20:16:13.413064Z digest=sha256:8e10b9eb0ac82925cbb837c3c07c195483e306f9f5f17fd568c08c648a7bdd25

Observation 432be1f4-7116-4eb1-a1ec-aeef85c35e84 · inbound

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety cites this paper.

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-05-22T05:51:07.946360Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-22T05:50:28.114140Z digest=sha256:52ae09a086f99cab1188a86d29eba4f7fb4cae01e8149e147dcf35b3158d64aa

Observation f4c8e78c-002a-4c01-bf51-b6d2680fb3ee · inbound

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety cites this paper.

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-05-25T06:06:43.046681Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-25T06:05:27.736494Z digest=sha256:9bf8a75333cefc3e35d10022c65e3d9a0217038ea418e2abc95f773e84fe4d0e

Observation a32cd385-442e-4221-ae45-5eeb7ecd29dd · inbound

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents cites this paper.

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 127

Resolution
verified exact
arxiv_id, observed 2026-06-28T19:42:36.161487Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-06-28T18:53:41.420255Z digest=sha256:74787530b9b0dab9ba15f8a49c44f44f47116cd3a530a188fd4427d80f3d70aa

Observation 79b665f1-26d8-4d01-bda8-fcab0f5f660b · inbound

Assessing Automated Prompt Injection Attacks in Agentic Environments cites this paper.

Assessing Automated Prompt Injection Attacks in Agentic Environments Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.981522Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:0e0b916dfe2d77599f1a30f4538a8052fb1cdc33641fa28924d57921900776a8

Observation 5486ad3f-d5bb-4798-af87-ff92b493f921 · inbound

SAIGuard: Communication-State Simulation for Proactive Defense of LLM Multi-Agent Systems cites this paper.

SAIGuard: Communication-State Simulation for Proactive Defense of LLM Multi-Agent Systems Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 17

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T13:28:18.842251Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-06-27T08:04:15.004591Z digest=sha256:cfb4ce2501e9f1fb46f4d85e495e52947705737f7fdab8ca47d53ce365914c69

Observation 8a2bfdbd-ac6d-49fe-a55a-265fd27b1e89 · inbound

AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents cites this paper.

AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 42

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T16:48:40.495135Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-27T04:57:54.827932Z digest=sha256:9d38c109d75a52728f991a5c3719b5b8a7de9a97f0c4560f8b07e7a72b629949

Observation c52f5f5f-d966-4c28-9e05-07c50195f8c3 · inbound

DualView: Preventing Indirect Prompt Injection in Personal AI Agents cites this paper.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 58

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:603753e6b26319d770a3a70fdd277ff2561544b0bacc7c13ae286fb7f937a04d

Observation aa3314d3-c3fa-4027-98e2-0b3b8e754aea · inbound

Agent Data Injection Attacks are Realistic Threats to AI Agents cites this paper.

Agent Data Injection Attacks are Realistic Threats to AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 8

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:5ab2b98b1c4135c0787a40e42e232ec4529df678e6b9959d881047f95ccfcf01

Observation 61022b50-8da0-46cb-85f6-ca54b0432b68 · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 269

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.607188Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.607188Z digest=sha256:114843071c04e98aee5ac0ff5651d2ffa041b53706f19c6cbcf9c46c99435c28