Pith. sign in

Paper Citation Record · LEDGER

SoK: The Attack Surface of Agentic AI - Tools and Autonomy

As of 20 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 10 inbound Pith citation observations for arXiv:2603.22928.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2603.22928 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 10 of 10 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-20T06:33:59.587034+00:00

measured 10 of 10 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-07-11T02:41:24.813416Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-11T02:47:50.254511Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation d8c7c313-37c3-4a08-900c-4c6e96e30665 · inbound

SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems cites this paper.

SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-13T20:14:56.132341Z digest=sha256:0d36f2a33a4e56a52e4868d1ae86589060ba263ac3173a80eb4d055dc37e5e74

Observation b0cd2e70-8c58-432c-a4f2-2b8a17f50aa2 · inbound

A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms cites this paper.

A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 27

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-10T19:39:27.982512Z digest=sha256:e778474e3f8164930cc50d6e4943e4ffd5c983df7aac39c1d63666cb9c3e0c86

Observation 287fef8e-2eef-47bf-8305-0f94ee4cfeb9 · inbound

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments cites this paper.

LITMUS: Benchmarking Behavioral Jailbreaks of LLM Agents in Real OS Environments SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-12T04:08:05.893904Z digest=sha256:a29aa0e2e3461cbfaac0104d4a7feb083de2fa3354e006e6de11e4b0fee7be39

Observation 3ca4c3cd-6b4d-45fd-94ef-b44b234b9aba · inbound

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback cites this paper.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:58f673a83601a95cccfd164739766af332815227aae4f62cc49e1a61add596c2

Observation 6ba71fd9-3176-440f-920a-78c49de5037b · inbound

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents cites this paper.

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-28T14:12:38.815852Z digest=sha256:b6682fc105778cda08ee8ed8b0692dbc7b5b05e46fa49a9d6471196a10ac4caf

Observation 46d78f36-85f8-460d-960a-beefad30dab0 · inbound

A Five-Plane Reference Architecture for Runtime Governance of Production AI Agents cites this paper.

A Five-Plane Reference Architecture for Runtime Governance of Production AI Agents SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-27T10:09:35.461423Z digest=sha256:de9f8c3809db19ce16631f2245962ec8637a5307f93fd08894b3b89742415be4

Observation 5dacf644-5d70-4bf7-b504-9cceeaa683a1 · inbound

Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies cites this paper.

Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-26T08:11:30.091859Z digest=sha256:5b7f91f74c60cc39c776ffde98b23e5dea62f4408bf4b607278beba7e4bd9412

Observation c61486d8-28f7-4389-bc83-76da6b4aaa84 · inbound

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents cites this paper.

Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 32

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-06-26T04:58:59.046289Z digest=sha256:8a2bad9a3a3fcabf24f2dcc8c5e0e4216447c63f523ea567a4bd74f4b137d22f

Observation 1cbc9a31-29ac-462c-ba18-8d4fd37b8fc8 · inbound

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems cites this paper.

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-07-01T04:44:23.543728Z digest=sha256:c4d9bc5f8e43e007d5cfefd8e7b735b92d44d9d742b0ddbd5a36fada69907c26

Observation a1ba4bd8-ba67-4e25-817a-e8c036be8f5f · inbound

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities cites this paper.

The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities SoK: The Attack Surface of Agentic AI - Tools and Autonomy

Reference 1

Resolution
verified exact
arxiv_id, observed 2026-08-12T02:24:10.274858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-20T06:33:59.587034+00:00.

source=pdf_text observed=2026-07-11T02:41:24.813416Z digest=sha256:8cc617271a57aed70a4ad70055cbac998269c84b8df4252529107cdfe033e107