Pith. sign in

Paper Citation Record · LEDGER

SoK: The Attack Surface of Agentic AI - Tools and Autonomy

As of 13 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 10 inbound Pith citation observations for arXiv:2603.22928.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2603.22928 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 10 of 10 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-13T06:32:02.005865+00:00

measured 10 of 10 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-07-11T02:41:24.813416Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-11T02:47:50.254511Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation d8c7c313-37c3-4a08-900c-4c6e96e30665 · inbound

SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems cites this paper.

SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-13T20:14:56.132341Z digest=sha256:4e2fe7bcb1aac287db95ea4501959ddc9eeab54fe99a8dcef32f6269f77b4fc5

Observation b0cd2e70-8c58-432c-a4f2-2b8a17f50aa2 · inbound

A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms cites this paper.

A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-10T19:39:27.982512Z digest=sha256:6a918d19cb52888d10386d6bb31c31f3af606cde5bbb981a9af797269be08845

Observation 287fef8e-2eef-47bf-8305-0f94ee4cfeb9 · inbound

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments cites this paper.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:57eac0a485208c9d1cf335c9d54fa5d2b3f59626a463b2d56b358e43b2946f13

Observation 3ca4c3cd-6b4d-45fd-94ef-b44b234b9aba · inbound

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback cites this paper.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:206643d5b46400d721e397000cfb71479ec113ad6adc8ee198565f90a2cd533b

Observation 6ba71fd9-3176-440f-920a-78c49de5037b · inbound

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents cites this paper.

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-28T14:12:38.815852Z digest=sha256:75af3224f534ffef79fee800648f554b321e4d458c2698aab1d8034b2c728569

Observation 46d78f36-85f8-460d-960a-beefad30dab0 · inbound

A Five-Plane Reference Architecture for Runtime Governance of Production AI Agents cites this paper.

A Five-Plane Reference Architecture for Runtime Governance of Production AI Agents SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-27T10:09:35.461423Z digest=sha256:54dd458fcacc29385505174ee9c8b069737fe8cb031f149428d70ce3311177b2

Observation 5dacf644-5d70-4bf7-b504-9cceeaa683a1 · inbound

Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies cites this paper.

Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-26T08:11:30.091859Z digest=sha256:7f59aa70d7af306c7cc60770de692b89aa79312a8d138b9be49d62874054c98e

Observation c61486d8-28f7-4389-bc83-76da6b4aaa84 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 32

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:9dd086ecfdb6f5a5f07ff547043a9cfe06f3b1a8e62b4c6f4dccd80a1d1fa182

Observation 1cbc9a31-29ac-462c-ba18-8d4fd37b8fc8 · inbound

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems cites this paper.

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-01T04:44:23.543728Z digest=sha256:bfbbaac8d5538dc5002c203bb8ffe0730fd56ba501bef610b1bb49feccf6fdce

Observation a1ba4bd8-ba67-4e25-817a-e8c036be8f5f · inbound

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities cites this paper.

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 1

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-11T02:41:24.813416Z digest=sha256:be5cf4819aae6f91e65adc1fe01ecf71ca0026edf59620dc7b52a50a16dfe301