Pith. sign in

Paper Citation Record · LEDGER

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales

As of 23 August 2026, this Paper Citation Record lists 42 of 42 outbound references and 0 inbound Pith citation observations for arXiv:2607.25364.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.25364 v2

Coverage vector

measured 42 of 42 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-01T02:43:24.479481Z

measured 42 of 42 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-22T06:32:14.747728+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

42 of 42 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved42
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 1ba4f6a6-30fb-481a-8f5a-90e59fa7c11e · outbound

This paper cites Language models don’t always say what they think: Unfaithful explanations in chain-of-thought prompting,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Language models don’t always say what they think: Unfaithful explanations in chain-of-thought prompting,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.352814Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.352814Z digest=sha256:c597d9efa2fea1c9a973fb38ea45f0ebbf56127f968b093784a787624f438f34

Observation 30f3eaf1-2751-44ea-8341-6fb671924c9c · outbound

This paper cites Measuring Faithfulness in Chain-of-Thought Reasoning.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Measuring Faithfulness in Chain-of-Thought Reasoning

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.356785Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.356785Z digest=sha256:532639bd9647894a0fee24977f0c5c58a3cb3f8932c3eb5cf605344bcef40b3e

Observation 1cceac1a-1566-4796-bcd4-e584f0a64e61 · outbound

This paper cites Dissociation of Faithful and Unfaithful Reasoning in LLMs.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Dissociation of Faithful and Unfaithful Reasoning in LLMs

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.360349Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.360349Z digest=sha256:14cbf8275e468eccc4148284d5cbcd1e83e3790fc7c380eaa3f75ef99c0e3f57

Observation 66d7d7b2-43c9-45ed-9df5-cfde15ee7be0 · outbound

This paper cites ReAct: Synergizing reasoning and acting in language models,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales ReAct: Synergizing reasoning and acting in language models,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.364143Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.364143Z digest=sha256:0279178511baca5313d3ff61f046b7ca1d3007d05b59a8583cf8ade6200d05fa

Observation b4fd514e-2589-4ef1-9f3a-63bc552d2159 · outbound

This paper cites Why should i trust you?: Explaining the predictions of any classifier,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Why should i trust you?: Explaining the predictions of any classifier,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.367334Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.367334Z digest=sha256:e6bba1b94fea9ec0b72eda12fcea53cdb8ad4091da06735b079358c4f2f08885

Observation 47aabdc4-0bb3-4bb7-84ad-5ae7e145b974 · outbound

This paper cites Explanation in artificial intelligence: Insights from the social sciences,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Explanation in artificial intelligence: Insights from the social sciences,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.370635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.370635Z digest=sha256:804653a761226ac5d17ab0351a0ddb20e3f36e3e216ed1b8a71fff73c53feb70

Observation 476171b9-768c-4051-8dc1-7c8216f482d3 · outbound

This paper cites The mythos of model interpretability,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales The mythos of model interpretability,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.374468Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.374468Z digest=sha256:f46c8b389f9304a91641b68ff5b1482733251861ee2ac07c6ce2813156b13592

Observation 79da502c-62ce-433c-8703-257314de1352 · outbound

This paper cites Interpreting interpretability: Understanding data scientists’ use of interpretability tools for machine learning,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Interpreting interpretability: Understanding data scientists’ use of interpretability tools for machine learning,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.377349Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.377349Z digest=sha256:b3a7923219bbc64069c5dbd136f9e1db0b66f7034ab154ab74616e9bf13ebc5a

Observation 2facfbaf-3ad0-45f4-809d-438e014232c2 · outbound

This paper cites Manipulating and measuring model interpretability,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Manipulating and measuring model interpretability,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.380532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.380532Z digest=sha256:b487e83495a65c374ff9ddcd3efd8a883584d36cf2848ac67a5185b41a51baf4

Observation 8474d2c9-58f9-4df3-9a52-9d220f5cc51e · outbound

This paper cites The protection of information in computer systems,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales The protection of information in computer systems,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.383451Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.383451Z digest=sha256:41dd219e6d1bb8eac49be68e379f75c0d88b4f1ea4b455520ba204c145adcca6

Observation 3c88cc5e-9ce7-4304-892a-5d7de42eb12b · outbound

This paper cites Guide to attribute based access control (ABAC) definition and considerations,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Guide to attribute based access control (ABAC) definition and considerations,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.386727Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.386727Z digest=sha256:6f52d9723cc54eb61afaea60f383ae02c4a8c55f1e8c9b96fa6caa743f71de8e

Observation aabd5ec7-50c3-437a-9504-4ce3315f49d3 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world LLM-Integrated applications with indirect prompt injection,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Not what you’ve signed up for: Compromising real-world LLM-Integrated applications with indirect prompt injection,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.389933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.389933Z digest=sha256:aa5d3eeec36705e314f1253958ab2fbcdfc2aaf3423c7b34ae0a00ba47aea00e

Observation 5b4eabb0-c7b8-4c40-9b63-5df472774372 · outbound

This paper cites Identifying the risks of LM agents with an LM-Emulated sandbox,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Identifying the risks of LM agents with an LM-Emulated sandbox,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.392897Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.392897Z digest=sha256:22882df0e2589d7a63dc14c80ed39506d20fcd197eefb26658a1b9f3c71d0792

Observation 6a6fcd77-073b-4781-9175-6342a5c34068 · outbound

This paper cites AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AgentDojo: A dynamic environment to evaluate prompt injection attacks and defenses for LLM agents,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.398938Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.398938Z digest=sha256:4f88ce8b5b5c38aaef984b90907cd10f991e319287e33b6dce7e6e1bbf1d7037

Observation a839a774-fff0-4a4e-9df9-a93eb081b0ec · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Injecagent: Benchmarking indirect prompt injections in tool-integrated large language model agents,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.401927Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.401927Z digest=sha256:4391d4ac806ce1c4649418005b68fe60bc1af0b97d03bb87a23c21af03681fb3

Observation e7adc28e-5ca5-46ae-80a4-90807afe7682 · outbound

This paper cites Prompt injection attack to tool selection in LLM agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Prompt injection attack to tool selection in LLM agents,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.404813Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.404813Z digest=sha256:6c7e059940d0938f21afbdfcca9e731ccf423c1a407a73416ec6097862873624

Observation 95438d9f-decf-490a-9b18-1353d82b4016 · outbound

This paper cites MCPTox: A benchmark for tool poisoning on real-world MCP servers,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales MCPTox: A benchmark for tool poisoning on real-world MCP servers,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.407651Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.407651Z digest=sha256:f6a050bb2dec8521b8fc2aa66b2dd0e160c74f45d21c1601b8520b533481630c

Observation e8bcb4a3-5204-483a-862b-dbba69d49b4e · outbound

This paper cites StruQ: Defending against prompt injection with structured queries,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales StruQ: Defending against prompt injection with structured queries,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.410667Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.410667Z digest=sha256:05c4c61606854006d7240b04366b37be72b5223fc6b88720d4dd5fc8674726d1

Observation 94859335-b483-49c4-af0b-ec5f630aaefe · outbound

This paper cites AttriGuard: Defeating indirect prompt injection in LLM agents via causal attribution of tool invocations,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AttriGuard: Defeating indirect prompt injection in LLM agents via causal attribution of tool invocations,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.413469Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.413469Z digest=sha256:1bc2550e1ed6f480103f30ad9377bdf76c51a2d57a93df673c346fbb160499aa

Observation f817ebf8-deca-4e8f-b4b7-7bfedb4edc14 · outbound

This paper cites Tools – model context protocol specification, 2025-11-25,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Tools – model context protocol specification, 2025-11-25,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.416234Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.416234Z digest=sha256:fa7e4efaa1bf04b0773ac91f6d4861a031e9a59df23d7fa1158d40338d7cf96b

Observation 59685e37-29d5-4330-a633-1756888f2d4b · outbound

This paper cites Authorization – model context protocol specification, 2025-11-25,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Authorization – model context protocol specification, 2025-11-25,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.418987Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.418987Z digest=sha256:f6c6958413e83563c5042e117ef1688a57d6aebd480d77474112d3c55901d9d4

Observation 7d7a5f4b-1740-4ebf-bef3-9af82886f3bc · outbound

This paper cites Artificial intelligence risk management framework: Generative artificial intelligence profile,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Artificial intelligence risk management framework: Generative artificial intelligence profile,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.421868Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.421868Z digest=sha256:7628f273e0f89ddbc212c1b9acc802b7c35f67ab36ad2b7f15ae00bd0060e994

Observation b48a26a1-8fed-4913-b31a-819a0130acb0 · outbound

This paper cites LLM01:2025 prompt injection,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales LLM01:2025 prompt injection,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.424764Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.424764Z digest=sha256:0ab37ed40e3a4451e092e585719d706c5c279183529563ea630fdb7eb0d54796

Observation b92a1314-4622-4363-9304-76ecd1f0775e · outbound

This paper cites Auditable Agents.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Auditable Agents

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.427810Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.427810Z digest=sha256:0b950bbdcc146fb41b49e501755816d5c565f98d4767150fbd638c6e8c989510

Observation 48b4a103-e437-4b03-bb7b-d4b1637d0ecd · outbound

This paper cites Agent audit: A security analysis system for LLM agent applications,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Agent audit: A security analysis system for LLM agent applications,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.430985Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.430985Z digest=sha256:72b6cdaf3b1d07a19d21c71b0901601ddb6358ae23916dc505a2a798a15ffef5

Observation 0b823ec3-0b7a-4043-8ba5-7206228ce627 · outbound

This paper cites JSON canonicalization scheme (JCS),.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales JSON canonicalization scheme (JCS),

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.433909Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.433909Z digest=sha256:cab8546c3bd10ccfa5f96f376167c6c8cdb8937c1086b0dc81f722f31398ada9

Observation 889e1901-795c-4aed-8869-f65b2837f1dd · outbound

This paper cites Intent-Governed Tool Authorization for AI Agents.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Intent-Governed Tool Authorization for AI Agents

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.437055Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.437055Z digest=sha256:c50fe2ca27052d71a8d0da031a678810683135c6f0616908981d69246d566e35

Observation 44635574-ed87-41ee-99d2-dc669a5f25ec · outbound

This paper cites To trust or to think: Cognitive forcing functions can reduce overreliance on AI in AI-Assisted decision-making,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales To trust or to think: Cognitive forcing functions can reduce overreliance on AI in AI-Assisted decision-making,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.440196Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.440196Z digest=sha256:471b78f17c3da98ca3367ace62928f6e3db76ca8e14f2e1de68cca7f3e093f64

Observation 36b9d225-6749-4868-bc36-00a4604e4379 · outbound

This paper cites Crying wolf: An empirical study of SSL warning effectiveness,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Crying wolf: An empirical study of SSL warning effectiveness,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.443194Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.443194Z digest=sha256:01b3043c5667977c757378aee92593ca87c4e4f03310f8ddb5cf86b348acce59

Observation 2f9267a9-b8da-498d-9839-c33c470e550f · outbound

This paper cites Guidelines for Human-AI interaction,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Guidelines for Human-AI interaction,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.446007Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.446007Z digest=sha256:e8c7d71ea268eaaaa4484d84e25d00aa4e0ba23c4e611831ebd3f6a8199d26b1

Observation 79a844e1-04aa-409d-af1c-55737551824e · outbound

This paper cites Explainable security,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Explainable security,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.448942Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.448942Z digest=sha256:49acd260b1611f47e84f760fbceb883279a6e5fa14cab80bf2b49a7058689e94

Observation 93087a73-a41e-4ee4-a334-ab858490967c · outbound

This paper cites Towards explainable access control [BlueSky Paper],.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Towards explainable access control [BlueSky Paper],

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.451918Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.451918Z digest=sha256:bfc2732429fe2d1ef992c5f6e35c27fa8d7ba323ce45c86f8b53f21596a55aed

Observation d8283456-f77a-43d9-8edb-0be319dba038 · outbound

This paper cites SmartAuth: User-centered authorization for the internet of things,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales SmartAuth: User-centered authorization for the internet of things,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.454854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.454854Z digest=sha256:92413db6fee5c8968f5135473289547839faf8ab8a278045c3416e214f6daa2c

Observation 5892d669-93d4-4927-8266-e12852075377 · outbound

This paper cites AWare: Preventing abuse of privacy-sensitive sensors via operation bindings,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AWare: Preventing abuse of privacy-sensitive sensors via operation bindings,

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.457964Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.457964Z digest=sha256:4ce8987f6b468b88e97f1d142303ba207b940b6c3c55b7030e8def195251324e

Observation 92cc9bb8-f2e2-4f13-ae0b-d9102364fe40 · outbound

This paper cites Decision provenance: Harnessing data flow for accountable systems,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Decision provenance: Harnessing data flow for accountable systems,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.461082Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.461082Z digest=sha256:b069bbc42f2c81d94fd2ab5656c7575e252be1b67500f3cbd4d4a7dc3d085968

Observation 58b99851-2307-4081-99b6-9c54c7d3e4fd · outbound

This paper cites ACCESSPROV: Tracking the provenance of access control decisions,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales ACCESSPROV: Tracking the provenance of access control decisions,

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.464227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.464227Z digest=sha256:8072c845fb0a903527a8945930dabad3f85a0cc4adee72f20a97b21147c43378

Observation 8dd6cb4f-e480-4019-89b8-bfcc21f5ff7c · outbound

This paper cites Defeating Prompt Injections by Design.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Defeating Prompt Injections by Design

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.467196Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.467196Z digest=sha256:1aac72d615af3da52bcaf152d9fdc649912d3736bb0de560a67ae489679ac626

Observation 1fe5df0a-f9df-4553-89ca-46a108e0a5e3 · outbound

This paper cites Securing AI Agents with Information-Flow Control.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Securing AI Agents with Information-Flow Control

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.470393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.470393Z digest=sha256:440276b44992aaf2f22358c6512a291c0d03b606af3e6e21ce38c690a2537bc5

Observation 972b83f8-82d8-4ab2-bf0e-d848e20dfd4a · outbound

This paper cites Securing agents with tracked capabilities,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Securing agents with tracked capabilities,

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.473769Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.473769Z digest=sha256:dcb2566a3fc329e2b7e13e17e4ae5a0ff95cde846b6828dd4ca9bbdc48dd3114

Observation 0f7f09be-02bd-42bf-9e67-f1b0cc3bbc2f · outbound

This paper cites AgentSpec: Customizable runtime enforcement for safe and reliable LLM agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales AgentSpec: Customizable runtime enforcement for safe and reliable LLM agents,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.476635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.476635Z digest=sha256:36fafe0b180ae735f010ac875fa6e6ae631eba876ccc9ec489c6266a6c52b4fc

Observation 1077a7db-9985-4860-b4de-c635c5cddfec · outbound

This paper cites Towards verifiably safe tool use for LLM agents,.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Towards verifiably safe tool use for LLM agents,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.479481Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.479481Z digest=sha256:fb43b5082531b8c530de3835f4eb2c6362cc33f35c06d29c1da5d42800b2353e

Observation 918492e6-a78d-40df-b636-7d4301aef83b · outbound

This paper cites Available: https://openreview.net/forum?id=GEcwtMk1uA.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Available: https://openreview.net/forum?id=GEcwtMk1uA

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.395876Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.395876Z digest=sha256:dde489fc5e3171806fed623253aed253d0621bb917ebf4b1d4012434bf45860b

Pith citing papers

No inbound Pith citation observations are available.