Pith. sign in

Paper Citation Record · LEDGER

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

As of 21 August 2026, this Paper Citation Record lists 49 of 49 outbound references and 11 inbound Pith citation observations for arXiv:2509.05755.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2509.05755 v6

Coverage vector

measured 49 of 49 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T05:09:40.020584Z

measured 60 of 60 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-21T06:32:19.484+00:00

measured 11 of 11 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-04T08:06:16.098981Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

49 of 49 outbound references displayed

  • verified exact2
  • verified fuzzy28
  • unresolved19
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation e9995044-7870-47d3-81cc-d43ac03c5082 · outbound

This paper cites https://jfrog.com/blog/p rompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://jfrog.com/blog/p rompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/, 2024

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.530979Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.717409Z digest=sha256:02e04bf0c2d9e201c514ac025144ec653cc236daf342f6ca1d731c5276a092ce

Observation 908d4b2e-401b-408b-ac44-14ea48069655 · outbound

This paper cites https://thehackernews.com/2024 /06/prompt-injection-flaw-in-vanna-ai.html, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://thehackernews.com/2024 /06/prompt-injection-flaw-in-vanna-ai.html, 2024

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.511326Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.724902Z digest=sha256:eb2943827eb1b4390fc360827ea1eb98f2220e936fd9b00b8c08fe9b62e09a63

Observation 97061c38-caf8-4dd3-952b-00931101f7fe · outbound

This paper cites https://www.cherry-ai.com/, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://www.cherry-ai.com/, 2025

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.485868Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.731021Z digest=sha256:d408add53bd51e950f08a78dd5b3fab3ca31552717843216fc4e80ef4d9bf8f7

Observation 62abf537-44cd-430f-976e-e005c318ed76 · outbound

This paper cites https://docs.anthropic.com/en/docs/claude-code/overview , 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.anthropic.com/en/docs/claude-code/overview , 2025

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.456265Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.737081Z digest=sha256:64896199886f0065df3b1c3081683727bc259a0ffc350fba906392efb9c7c2df

Observation cd49c8f8-9c8d-4051-9592-a3964d41fb86 · outbound

This paper cites https://docs.github.com/en/copil ot/using-github-copilot/copilot-chat, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.github.com/en/copil ot/using-github-copilot/copilot-chat, 2025

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.428727Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.743955Z digest=sha256:74c0bd4656888febc906194632aaeccd81a320dc9db7b232018213304b4b4c3b

Observation ad5068f1-0cd3-4a4d-ab91-481c6f494f4e · outbound

This paper cites https://owasp.org/www-proje ct-top-10-for-large-language-model-applications/, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://owasp.org/www-proje ct-top-10-for-large-language-model-applications/, 2025

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.400243Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.749409Z digest=sha256:3dee07c15ac59f24b37c0e0957291d4e5cfa8f9b2eebb4497726fb03195860d6

Observation 3588386c-dd77-41c4-8838-5966f11ef3dd · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.375616Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.755742Z digest=sha256:468a9467f1b703053619d2c90a58a007f084fddbbbe11c7b71f9426929e328a6

Observation 28026c98-05e1-415c-81ca-2b32d8c036a9 · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.352428Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.762358Z digest=sha256:146e046f04599b3a94c75c2ced077b80156178d719c845070feb30ed66df07fb

Observation 89f1ba3c-72ac-4fc3-b6d0-8f58e83df1ea · outbound

This paper cites Anthropic tool use and function calling.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Anthropic tool use and function calling

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.327200Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.768821Z digest=sha256:754c14b253a32431f6860375c0bf78df154f47b6d2964592b6df3be20491e878

Observation 9a0f2e10-81c2-45a2-83b3-573ddea70a5e · outbound

This paper cites Model context protocol.https://docs.anthropic.com/docs/mcp/, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Model context protocol.https://docs.anthropic.com/docs/mcp/, 2024

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.305113Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.776491Z digest=sha256:da3d85d86b1e9f89c405b3586b00643db96ed29f879128a49e699a85947bba2a

Observation c9179a97-7fa6-44f1-8062-1426bbf4cf12 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.782564Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.782564Z digest=sha256:b684d42d61ee33cc3360e9e773057fd46ae9bb3ea8afb0123698f787ac083da4

Observation 407c5235-9481-478b-9021-979d2501ae22 · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.278728Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.789182Z digest=sha256:12e836d2a185a6c60d301656f700699a79e25b7d26b8b2f489e962a4bae5e781

Observation 07079539-cf03-4ffe-a02d-24f475836e0e · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.256452Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.795361Z digest=sha256:9217a1e9b8ff0c3ac50912c24470976ba702b98079b07f3e25e40a37f005f53d

Observation f3762e53-3c9e-461c-a296-2888f147cbac · outbound

This paper cites The Llama 3 Herd of Models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment The Llama 3 Herd of Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.800933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.800933Z digest=sha256:0270a33c2fe9343b168ef971ef89a6a2f6d2bbe6aa0cf6a78cf829056db184b2

Observation 2a3bf3fe-ac71-45a1-bfe0-02f925a4b86e · outbound

This paper cites Conversational Prompt Engineering.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Conversational Prompt Engineering

Reference 15

Resolution
verified exact
local_arxiv, observed 2026-08-05T05:09:40.777379Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.806899Z digest=sha256:b3139bfbd3f512017e36e07a3cc2094c447faba1fbe39f48645d207cde3fea0e

Observation 0e8dfd11-281a-4c09-91c8-f6ef868ce623 · outbound

This paper cites WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.813876Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.813876Z digest=sha256:723005fbc14a13b0d53077fcc4706f527f9be58dd828158b5be59c487b70428c

Observation ef92fb38-1d05-47b3-8b4d-4afed1b45398 · outbound

This paper cites An Empirical Categorization of Prompting Techniques for Large Language Models: A Practitioner's Guide.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment An Empirical Categorization of Prompting Techniques for Large Language Models: A Practitioner's Guide

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.820844Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.820844Z digest=sha256:e72b6bde9800be60593ffba7423b558a44c3413d2c6014b541817810103c0fe2

Observation d868d79c-af93-469e-887d-e8428f51f636 · outbound

This paper cites What is prompt engineering? https://cloud.google.com/discover/what-is-promp t-engineering?hl=en#what-is-prompt-engineering, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is prompt engineering? https://cloud.google.com/discover/what-is-promp t-engineering?hl=en#what-is-prompt-engineering, 2025

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.232493Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.828635Z digest=sha256:2b781279060d4221e06e95ec724976e24730c2f62100adde520731cfe9a882e1

Observation b4656a5e-5286-4acb-a1d8-2dd5e5a89746 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.835452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.835452Z digest=sha256:3ebea61775ac696bf44256b64ae5fc284397dcf66c181189cc2f4d33b4d69dcb

Observation a43c34b6-1182-4430-99b8-28e4822e7418 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.841874Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.841874Z digest=sha256:a186880ed16ecc09c4a0cf7a9237af11197d81c4e7ddb9f8ee37a6ba6f538e4a

Observation 85e9ee6f-d778-4a05-a24d-147cab8a50b9 · outbound

This paper cites Promptshield: Deploy- able detection for prompt injection attacks.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Promptshield: Deploy- able detection for prompt injection attacks

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.193369Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.848575Z digest=sha256:812679d195b0cedce3e04342adc07b1a6121da5590ba714882ba1ce636b7dfb0

Observation 27b5fa44-5b19-4017-9c30-566884e56539 · outbound

This paper cites Kpmg ai quarterly pulse survey: From agent experimentation to rapid scale and deployment.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Kpmg ai quarterly pulse survey: From agent experimentation to rapid scale and deployment

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.172873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.855633Z digest=sha256:3b86ec810d52d2e53d6b829cd957c481fdf481e569dd44243511cb229b5e4cc7

Observation a3a3005c-09d3-4bc1-ac61-76dc3459c4f4 · outbound

This paper cites How to use chat models to call tools.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment How to use chat models to call tools

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.150660Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.861201Z digest=sha256:0bbd70a058d9ea424df76e56a8c04bdb69e7c1271eeec94e300b4032431bc788

Observation ae5f12df-493f-4ed9-ba60-7c71131e3ff7 · outbound

This paper cites EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.868193Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.868193Z digest=sha256:71c627e9bca78927e28d08a2f251679fb175f800f6c348a2e33a7c141e9d794a

Observation d7881e67-b55b-4f0a-a74f-5b1944d62543 · outbound

This paper cites Self-Reflection Makes Large Language Models Safer, Less Biased, and Ideologically Neutral.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Self-Reflection Makes Large Language Models Safer, Less Biased, and Ideologically Neutral

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.874576Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.874576Z digest=sha256:670d9306466c7d06f8c61092002003c963d6c9b54f1bb287091c6abe1ba9c542

Observation 4119c212-c675-408a-81e9-0e99ba7fe945 · outbound

This paper cites Demystifying rce vulnerabilities in llm-integrated apps.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Demystifying rce vulnerabilities in llm-integrated apps

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.126476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.879992Z digest=sha256:7126ca21027eccf413427ada41aea2a93561d8dc07e8ee2f016c56c46784e983

Observation c568f671-1bbd-4ccd-8da4-85eea6062524 · outbound

This paper cites What do you want? user-centric prompt generation for text-to-image synthesis via multi-turn guidance.arXiv preprint arXiv:2408.12910, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What do you want? user-centric prompt generation for text-to-image synthesis via multi-turn guidance.arXiv preprint arXiv:2408.12910, 2024

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.887000Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.887000Z digest=sha256:c2892648eb547f11ad5b4877f8e5f3fe3428ded07eb617335e211ec60b1f17b9

Observation d6f45d43-3a6d-4e11-bf11-4700c819a7f0 · outbound

This paper cites Formalizing and bench- marking prompt injection attacks and defenses.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Formalizing and bench- marking prompt injection attacks and defenses

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.098378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.892467Z digest=sha256:6f829723b9e5c83054174a7583a156942a5b3ba8cd4402178572159959c6b43f

Observation 6f1910d5-5138-4ac3-8888-c7e150c90193 · outbound

This paper cites LLM In-Context Recall is Prompt Dependent.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment LLM In-Context Recall is Prompt Dependent

Reference 29

Resolution
verified exact
local_arxiv, observed 2026-08-05T05:09:40.275758Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.897444Z digest=sha256:69c5f582d8b867d8d4bc4e2192945a1500a51ac1394e3da338c8250cbfbc5b78

Observation 71f603de-062e-4ca4-a6b1-0630cb42a9d4 · outbound

This paper cites Large Language Models Know Your Contextual Search Intent: A Prompting Framework for Conversational Search.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Large Language Models Know Your Contextual Search Intent: A Prompting Framework for Conversational Search

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.903821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.903821Z digest=sha256:e0c0f07eb202966c199213bb480ead671ad25ebc423c9a80ed19e9327ed68d9c

Observation 579ea73d-e38b-4363-bf91-7ade07ccf287 · outbound

This paper cites Llama-prompt-guard-2-22m.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama-prompt-guard-2-22m

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.073052Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.909568Z digest=sha256:e228a198e68693dfaaea58ed04fc7b44f4d48c75246e696bc0bb0217a6ea7bd6

Observation c5410c68-8013-4137-b1be-d3555ec15528 · outbound

This paper cites Augmented Language Models: a Survey.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Augmented Language Models: a Survey

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.915182Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.915182Z digest=sha256:4bf0d3c45e22f9e128a087e2e7c5507f4ea0d94e38e37af63efcab37cf180052

Observation 39e175ac-9b83-4922-9ee4-5ad3e26f625a · outbound

This paper cites A Closer Look at System Prompt Robustness.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment A Closer Look at System Prompt Robustness

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.921172Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.921172Z digest=sha256:66ad0b4560584f1cc6e76ecd78861a0e857876bb0d8cc1de90c994222e42ae65

Observation 7b8a8328-08ce-48a9-b6d4-25206be9f2d5 · outbound

This paper cites Position is power: System prompts as a mechanism of bias in large language models (llms).

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Position is power: System prompts as a mechanism of bias in large language models (llms)

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.046186Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.926761Z digest=sha256:329288af64603f3f3f7963abd8d8074a3dd0374d8c9b5eb1eef0986857a2b22f

Observation 51e69f08-bc38-41a7-9027-b8bb4893e81b · outbound

This paper cites What is agentic ai? https://blogs.nvidia.com/blog/what-is-agentic-ai/ , 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is agentic ai? https://blogs.nvidia.com/blog/what-is-agentic-ai/ , 2024

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.025647Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.933155Z digest=sha256:5df583c399082dc421efacacd3d7e6990282c893f5134e2a105ba6f0c0c3dc6c

Observation 85c1f51f-3a59-46e4-8458-194e521ee7ac · outbound

This paper cites Function Calling with LLMs.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Function Calling with LLMs

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.005989Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.939751Z digest=sha256:9ce10a9e6982490fd608bade92c3068ed3a2c127499b623275633aaa7476e78a

Observation c045c9d2-502b-4728-a01e-b20d81f1ed24 · outbound

This paper cites Openai assistants and tool use documentation.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Openai assistants and tool use documentation

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.984125Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.945109Z digest=sha256:ef828061d978022dcef780cc29dbf08e1d73c8f996323ace60daa97586b2fa4e

Observation d8150135-e2ca-4871-9c30-2ee3b1997c5e · outbound

This paper cites Pwc’s ai agent survey.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Pwc’s ai agent survey

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.964097Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.950807Z digest=sha256:5df4b2904277bea0e366cebacb22db79cde280a5cc83c927772225bf123172db

Observation ea544374-55c9-45f2-8a42-10ee93d2d637 · outbound

This paper cites Tool learning with large language models: A survey.Frontiers of Computer Science, 19(8):198343, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Tool learning with large language models: A survey.Frontiers of Computer Science, 19(8):198343, 2025

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.957253Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.957253Z digest=sha256:bf2c2acc6cd2ff5a8157228eecdc386343472f378b36bbc523958a02a3f77789

Observation 0caf3c5a-5e4a-4ec4-91c4-462359a1756b · outbound

This paper cites Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36:68539–68551, 2023.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36:68539–68551, 2023

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.933641Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.963689Z digest=sha256:ec8cf91ae17b292eb43f989f4e0c56e3e3cf05b9e14ced31c433c54a33e1bff1

Observation fe7e9087-75fb-4593-a0a9-62ffbe2bfc75 · outbound

This paper cites Cline — ai coding, open source and uncompromised.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Cline — ai coding, open source and uncompromised

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.911858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.969422Z digest=sha256:84f5bda31b83c9a3a16ea2c75238c92e06779770a177426b5cb31bb250282481

Observation 9c655096-f07b-42c1-b1cc-3548e9f88d27 · outbound

This paper cites AdvAgent: Controllable Blackbox Red-teaming on Web Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment AdvAgent: Controllable Blackbox Red-teaming on Web Agents

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.975185Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.975185Z digest=sha256:bc0c3ee605ca324c0ce37d82285676b81957515b610358bc1cb1c8388b967308

Observation aa5368bd-9afc-4180-b2ac-059056983a7a · outbound

This paper cites React: Synergizing reasoning and acting in language models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment React: Synergizing reasoning and acting in language models

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.981410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.981410Z digest=sha256:72a2f849b4f836f5946a02c17efb74d02138a6c446fd73209bddaa971b5fb4df

Observation 9acb4cc3-cf41-47ab-a028-ae5e1faf9068 · outbound

This paper cites Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.987143Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.987143Z digest=sha256:75c5a96e686c4abd42fbc27fb7291c923355e90e2d7add217def269005bcf408

Observation d981f5bf-91c7-408e-8196-88cd0ac27398 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated llm agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Injecagent: Benchmarking indirect prompt injections in tool-integrated llm agents

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.876491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:39.993267Z digest=sha256:8f2a595487a05dc42afe025c0daac46e688ced26519e9e091b12fe29f48e1737

Observation 06f34892-dbc4-47f3-a2d6-a25f7954bf0a · outbound

This paper cites SPRIG: Improving Large Language Model Performance by System Prompt Optimization.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment SPRIG: Improving Large Language Model Performance by System Prompt Optimization

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.998742Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.998742Z digest=sha256:b2e4b748565d4ba187555fbd0a21a40b91891d2278352185ca686a4242c0a7b3

Observation 7a67a165-bd3d-411e-82f6-82ce4ba28d9c · outbound

This paper cites a helpful assistant.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment a helpful assistant

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.850748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-08-05T05:09:40.007399Z digest=sha256:e48cef3958a3f3eb5b09c2be919507cef43772070147891e9ef8f3235cbec727

Observation 439ec31b-2370-422d-a5ee-527c586cfa08 · outbound

This paper cites Context-faithful Prompting for Large Language Models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Context-faithful Prompting for Large Language Models

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.014381Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.014381Z digest=sha256:862a8b9bb8ced178cd8b3841a710e9ba7adefdb1f890d8ea7c3d66d14410b0c8

Observation cf50d8e3-a96a-4a81-9b6d-0591876bad5e · outbound

This paper cites MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.020584Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.020584Z digest=sha256:1f03db7dc40f8455b83c1d53c04db167759a86d9a5cd6fa39204213b01267ff0

Pith citing papers

Observation 9d74020d-4276-44f4-972a-d140ebd224d1 · inbound

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem cites this paper.

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 50

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-05-18T18:43:35.072919Z digest=sha256:81efa3b792a95343e96fdf9164b5edce3a9d740681938b7b829be1587fc39485

Observation b2f37388-ce84-46df-a93e-5317fdf8e087 · inbound

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents cites this paper.

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-04T08:06:16.098981Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T08:06:16.098981Z digest=sha256:df3842d9b1d5d8ed71a5257b349f4b7078e2921cf21ded377e4a1d7cca4e521c

Observation 647942dc-86f7-4c34-b8d2-3c4975cffa7d · inbound

Verifiable Manifest Signing and Transparency Enforcement for Secure MCP-Based LLM Pipelines cites this paper.

Verifiable Manifest Signing and Transparency Enforcement for Secure MCP-Based LLM Pipelines Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-03T06:18:06.545883Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T06:18:06.545883Z digest=sha256:ed412b6e9fcc35459d3edd5a30bfb2f96ab0c08fcb9574d079021c411a1cc6c8

Observation aaad7391-b404-488a-bdc8-97f7d54d5713 · inbound

Security Considerations for Multi-agent Systems cites this paper.

Security Considerations for Multi-agent Systems Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 279

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-05-15T14:12:14.160789Z digest=sha256:8daf74aaf3d415abfba886ad504fe8d62ba396107a4ba88679839a4a0075f73f

Observation ca03258d-9fd1-4e78-b649-060698daa6bc · inbound

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents cites this paper.

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-05-08T18:42:06.418583Z digest=sha256:4377493f480b499ee1b3874bf360c7f5df4bdea122dc3582a301a43978bc6a1c

Observation ae2b9919-6ccc-4980-96d2-63039ece1e71 · inbound

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents cites this paper.

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T15:04:20.284238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T15:04:20.284238Z digest=sha256:bc27cb25862be8219a19514cae38d4bad962605e95a76317bc64df0fd9485be9

Observation e3a483f2-a692-4cf3-af23-03f439f78a3d · inbound

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents cites this paper.

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-06-30T16:24:55.067215Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-06-30T16:22:23.857438Z digest=sha256:0866d6f72884de1d209cf18ba4cd6170fca6105ffb43bc625579b06399fda95c

Observation eef9bcc5-a2fe-485b-ab8c-85086b0598ad · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 208

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:fa6a54760b6aa030f75a8771fdedc445108fe6bb5d135db52f44b09c501be414

Observation 09dc7c45-d270-4e7a-aa73-62ff2e95d091 · inbound

Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study cites this paper.

Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 100

Resolution
verified exact
local_arxiv, observed 2026-07-03T12:08:07.100919Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-06-27T09:06:12.868791Z digest=sha256:aa2d469970d465d973098002bde86ab78100ada9caa0db1c2592e35b73eb66a9

Observation 71ce2c75-eb1f-4265-a68f-6b6c27a541bd · inbound

ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP cites this paper.

ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 30

Resolution
verified exact
local_arxiv, observed 2026-07-04T14:19:54.256550Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=pdf_text observed=2026-06-26T04:07:14.506108Z digest=sha256:a3cac4b103c038d077e28ea0da479c96fdd95e315106b82009a7538971c38cb2

Observation 0c219119-2ba5-4ca1-8932-b9a863d5a04d · inbound

Where Is the Cost of Third-Party API Routers in Agentic Software Development? cites this paper.

Where Is the Cost of Third-Party API Routers in Agentic Software Development? Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 25

Resolution
unresolved
no resolver link, observed 2026-07-30T17:25:46.962117Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-30T17:25:46.962117Z digest=sha256:b93d74b5a7101b3f457eba3f76aabe4d21fd7741e02ee6baa6c92171a6778761