Pith. sign in

Paper Citation Record · LEDGER

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

As of 23 August 2026, this Paper Citation Record lists 49 of 49 outbound references and 11 inbound Pith citation observations for arXiv:2509.05755.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2509.05755 v6

Coverage vector

measured 49 of 49 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T05:09:40.020584Z

measured 60 of 60 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-23T06:30:58.430688+00:00

measured 11 of 11 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-04T08:06:16.098981Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

49 of 49 outbound references displayed

  • verified exact2
  • verified fuzzy28
  • unresolved19
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation e9995044-7870-47d3-81cc-d43ac03c5082 · outbound

This paper cites https://jfrog.com/blog/p rompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://jfrog.com/blog/p rompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/, 2024

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.530979Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.717409Z digest=sha256:745fff78b5814555b1028a429c77855b257c7f19c3be215a006e714fd729eaf0

Observation 908d4b2e-401b-408b-ac44-14ea48069655 · outbound

This paper cites https://thehackernews.com/2024 /06/prompt-injection-flaw-in-vanna-ai.html, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://thehackernews.com/2024 /06/prompt-injection-flaw-in-vanna-ai.html, 2024

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.511326Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.724902Z digest=sha256:2127de3c593904b336b75ca8d9114cfe91e0d5cd07d69932f379d70bbb246be1

Observation 97061c38-caf8-4dd3-952b-00931101f7fe · outbound

This paper cites https://www.cherry-ai.com/, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://www.cherry-ai.com/, 2025

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.485868Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.731021Z digest=sha256:f92aa97f4e22ba9ab0591e78f58b70c6ea2dfb400c3ea364cc8b019cbb72cb98

Observation 62abf537-44cd-430f-976e-e005c318ed76 · outbound

This paper cites https://docs.anthropic.com/en/docs/claude-code/overview , 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.anthropic.com/en/docs/claude-code/overview , 2025

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.456265Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.737081Z digest=sha256:de2afd8a5e933d18b159a53dfa54958181fa282b662444979c2062adbd9bae54

Observation cd49c8f8-9c8d-4051-9592-a3964d41fb86 · outbound

This paper cites https://docs.github.com/en/copil ot/using-github-copilot/copilot-chat, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.github.com/en/copil ot/using-github-copilot/copilot-chat, 2025

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.428727Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.743955Z digest=sha256:673bf3e6729c7d56fa5cc7b1bc05fa3a5921ec1fc2c48559fc6aeec1144baa85

Observation ad5068f1-0cd3-4a4d-ab91-481c6f494f4e · outbound

This paper cites https://owasp.org/www-proje ct-top-10-for-large-language-model-applications/, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://owasp.org/www-proje ct-top-10-for-large-language-model-applications/, 2025

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.400243Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.749409Z digest=sha256:503273debd35c2b82bbcc7bab1528ca6f98677672d8124990afb0f845fc6d7a6

Observation 3588386c-dd77-41c4-8838-5966f11ef3dd · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.375616Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.755742Z digest=sha256:0844d2e75ec9665b4ee4b483d921f958bc41abb97f4ceef278ef38c5444c74fd

Observation 28026c98-05e1-415c-81ca-2b32d8c036a9 · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.352428Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.762358Z digest=sha256:14f3b0b3cd97e1c6236314437530277c718039eb40fd9de1fed199830a445231

Observation 89f1ba3c-72ac-4fc3-b6d0-8f58e83df1ea · outbound

This paper cites Anthropic tool use and function calling.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Anthropic tool use and function calling

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.327200Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.768821Z digest=sha256:3c238fc62eeae124232e55df64e93181d7e9f098521f64080bd94ac759b66a22

Observation 9a0f2e10-81c2-45a2-83b3-573ddea70a5e · outbound

This paper cites Model context protocol.https://docs.anthropic.com/docs/mcp/, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Model context protocol.https://docs.anthropic.com/docs/mcp/, 2024

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.305113Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.776491Z digest=sha256:37caf634231901fa96e3e63cd53374bccc4f21c60a43c1c15ef2798301f9ab74

Observation c9179a97-7fa6-44f1-8062-1426bbf4cf12 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.782564Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.782564Z digest=sha256:b684d42d61ee33cc3360e9e773057fd46ae9bb3ea8afb0123698f787ac083da4

Observation 407c5235-9481-478b-9021-979d2501ae22 · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.278728Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.789182Z digest=sha256:799c19d758d077f5c0ef7c49fae35b97e8804276ee0aa97ad8bb795f2b625842

Observation 07079539-cf03-4ffe-a02d-24f475836e0e · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.256452Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.795361Z digest=sha256:196cf3aba27e29a5c21092cd626a3b1d85cac10f9a96e26e0178a61d2b726cdb

Observation f3762e53-3c9e-461c-a296-2888f147cbac · outbound

This paper cites The Llama 3 Herd of Models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment The Llama 3 Herd of Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.800933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.800933Z digest=sha256:0270a33c2fe9343b168ef971ef89a6a2f6d2bbe6aa0cf6a78cf829056db184b2

Observation 2a3bf3fe-ac71-45a1-bfe0-02f925a4b86e · outbound

This paper cites Conversational Prompt Engineering.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Conversational Prompt Engineering

Reference 15

Resolution
verified exact
local_arxiv, observed 2026-08-05T05:09:40.777379Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.806899Z digest=sha256:8c3d576343f7268f68830f3706458f05f9867738e356f88cbf6236668a9ab1cf

Observation 0e8dfd11-281a-4c09-91c8-f6ef868ce623 · outbound

This paper cites WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.813876Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.813876Z digest=sha256:723005fbc14a13b0d53077fcc4706f527f9be58dd828158b5be59c487b70428c

Observation ef92fb38-1d05-47b3-8b4d-4afed1b45398 · outbound

This paper cites An Empirical Categorization of Prompting Techniques for Large Language Models: A Practitioner's Guide.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment An Empirical Categorization of Prompting Techniques for Large Language Models: A Practitioner's Guide

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.820844Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.820844Z digest=sha256:e72b6bde9800be60593ffba7423b558a44c3413d2c6014b541817810103c0fe2

Observation d868d79c-af93-469e-887d-e8428f51f636 · outbound

This paper cites What is prompt engineering? https://cloud.google.com/discover/what-is-promp t-engineering?hl=en#what-is-prompt-engineering, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is prompt engineering? https://cloud.google.com/discover/what-is-promp t-engineering?hl=en#what-is-prompt-engineering, 2025

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.232493Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.828635Z digest=sha256:e3e7535b7fe99bf235cc9dffc1b0c9b60052476fa521503607f3e775a811cfd8

Observation b4656a5e-5286-4acb-a1d8-2dd5e5a89746 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.835452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.835452Z digest=sha256:3ebea61775ac696bf44256b64ae5fc284397dcf66c181189cc2f4d33b4d69dcb

Observation a43c34b6-1182-4430-99b8-28e4822e7418 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.841874Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.841874Z digest=sha256:a186880ed16ecc09c4a0cf7a9237af11197d81c4e7ddb9f8ee37a6ba6f538e4a

Observation 85e9ee6f-d778-4a05-a24d-147cab8a50b9 · outbound

This paper cites Promptshield: Deploy- able detection for prompt injection attacks.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Promptshield: Deploy- able detection for prompt injection attacks

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.193369Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.848575Z digest=sha256:bfe23e952d4d41231b75d5008e46379b721f07e16b70c537dd45b71c557b36bc

Observation 27b5fa44-5b19-4017-9c30-566884e56539 · outbound

This paper cites Kpmg ai quarterly pulse survey: From agent experimentation to rapid scale and deployment.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Kpmg ai quarterly pulse survey: From agent experimentation to rapid scale and deployment

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.172873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.855633Z digest=sha256:d876a5411e081d5644fb7cbfcf4d4869735491f8f0eb5ec19d8c188d9fad8b33

Observation a3a3005c-09d3-4bc1-ac61-76dc3459c4f4 · outbound

This paper cites How to use chat models to call tools.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment How to use chat models to call tools

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.150660Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.861201Z digest=sha256:b3090c1641e157dc72f422ffc39cc2dc8c596e81ad72835c1e9d44f8a99bf057

Observation ae5f12df-493f-4ed9-ba60-7c71131e3ff7 · outbound

This paper cites EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.868193Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.868193Z digest=sha256:71c627e9bca78927e28d08a2f251679fb175f800f6c348a2e33a7c141e9d794a

Observation d7881e67-b55b-4f0a-a74f-5b1944d62543 · outbound

This paper cites Self-Reflection Makes Large Language Models Safer, Less Biased, and Ideologically Neutral.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Self-Reflection Makes Large Language Models Safer, Less Biased, and Ideologically Neutral

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.874576Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.874576Z digest=sha256:670d9306466c7d06f8c61092002003c963d6c9b54f1bb287091c6abe1ba9c542

Observation 4119c212-c675-408a-81e9-0e99ba7fe945 · outbound

This paper cites Demystifying rce vulnerabilities in llm-integrated apps.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Demystifying rce vulnerabilities in llm-integrated apps

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.126476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.879992Z digest=sha256:b0d9db87f359f887a0274e131b6d8e8291949037b3640aeb9d7775add20e65c0

Observation c568f671-1bbd-4ccd-8da4-85eea6062524 · outbound

This paper cites What do you want? user-centric prompt generation for text-to-image synthesis via multi-turn guidance.arXiv preprint arXiv:2408.12910, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What do you want? user-centric prompt generation for text-to-image synthesis via multi-turn guidance.arXiv preprint arXiv:2408.12910, 2024

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.887000Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.887000Z digest=sha256:c2892648eb547f11ad5b4877f8e5f3fe3428ded07eb617335e211ec60b1f17b9

Observation d6f45d43-3a6d-4e11-bf11-4700c819a7f0 · outbound

This paper cites Formalizing and bench- marking prompt injection attacks and defenses.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Formalizing and bench- marking prompt injection attacks and defenses

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.098378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.892467Z digest=sha256:3a5f8d5a2b647f706c6f988c4307126e72a0cfc9fecf561af3d8c4dffbbd60fb

Observation 6f1910d5-5138-4ac3-8888-c7e150c90193 · outbound

This paper cites LLM In-Context Recall is Prompt Dependent.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment LLM In-Context Recall is Prompt Dependent

Reference 29

Resolution
verified exact
local_arxiv, observed 2026-08-05T05:09:40.275758Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.897444Z digest=sha256:0ef1eec33243102fcce856d4669134fa9dab64f794263d3481ebe273fb1cef43

Observation 71f603de-062e-4ca4-a6b1-0630cb42a9d4 · outbound

This paper cites Large Language Models Know Your Contextual Search Intent: A Prompting Framework for Conversational Search.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Large Language Models Know Your Contextual Search Intent: A Prompting Framework for Conversational Search

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.903821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.903821Z digest=sha256:6879bcf9d60f3fccb7648972c0c7f524657ab484e4bd9763365181518d14879c

Observation 579ea73d-e38b-4363-bf91-7ade07ccf287 · outbound

This paper cites Llama-prompt-guard-2-22m.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama-prompt-guard-2-22m

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.073052Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.909568Z digest=sha256:e9804d609c8bdde1ea0470ab7bff42a2aa173903b7dba4a78c82c1fd9e15fdaa

Observation c5410c68-8013-4137-b1be-d3555ec15528 · outbound

This paper cites Augmented Language Models: a Survey.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Augmented Language Models: a Survey

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.915182Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.915182Z digest=sha256:4bf0d3c45e22f9e128a087e2e7c5507f4ea0d94e38e37af63efcab37cf180052

Observation 39e175ac-9b83-4922-9ee4-5ad3e26f625a · outbound

This paper cites A Closer Look at System Prompt Robustness.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment A Closer Look at System Prompt Robustness

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.921172Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.921172Z digest=sha256:66ad0b4560584f1cc6e76ecd78861a0e857876bb0d8cc1de90c994222e42ae65

Observation 7b8a8328-08ce-48a9-b6d4-25206be9f2d5 · outbound

This paper cites Position is power: System prompts as a mechanism of bias in large language models (llms).

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Position is power: System prompts as a mechanism of bias in large language models (llms)

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.046186Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.926761Z digest=sha256:060f0d6a6a8322b5e4a1495d3a810a6e841c585d14fbf1ab42ddacc6edd15d85

Observation 51e69f08-bc38-41a7-9027-b8bb4893e81b · outbound

This paper cites What is agentic ai? https://blogs.nvidia.com/blog/what-is-agentic-ai/ , 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is agentic ai? https://blogs.nvidia.com/blog/what-is-agentic-ai/ , 2024

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.025647Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.933155Z digest=sha256:dc75e9c173b84740cee9a2345c6c81385b45e44a7d42738b2ec2116ad0db60e0

Observation 85c1f51f-3a59-46e4-8458-194e521ee7ac · outbound

This paper cites Function Calling with LLMs.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Function Calling with LLMs

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.005989Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.939751Z digest=sha256:467690c1d19f9ad89e52f15f9e4ead0942c4a904b7051cecf9bb14845e21d1c3

Observation c045c9d2-502b-4728-a01e-b20d81f1ed24 · outbound

This paper cites Openai assistants and tool use documentation.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Openai assistants and tool use documentation

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.984125Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.945109Z digest=sha256:d0ec242fb02896b58bdba3bcaf5d0a410b64b43d9d37169b7805b65e51d3198b

Observation d8150135-e2ca-4871-9c30-2ee3b1997c5e · outbound

This paper cites Pwc’s ai agent survey.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Pwc’s ai agent survey

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.964097Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.950807Z digest=sha256:8e7dfa2f41dfbd557fde39161aab8da4a7e021fff3e6fa3e82231881783a3beb

Observation ea544374-55c9-45f2-8a42-10ee93d2d637 · outbound

This paper cites Tool learning with large language models: A survey.Frontiers of Computer Science, 19(8):198343, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Tool learning with large language models: A survey.Frontiers of Computer Science, 19(8):198343, 2025

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.957253Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.957253Z digest=sha256:bf2c2acc6cd2ff5a8157228eecdc386343472f378b36bbc523958a02a3f77789

Observation 0caf3c5a-5e4a-4ec4-91c4-462359a1756b · outbound

This paper cites Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36:68539–68551, 2023.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36:68539–68551, 2023

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.933641Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.963689Z digest=sha256:af25b67fb61d00c28ba008c8a121be5d93c8c09a01a0315ef6a517a317e239b7

Observation fe7e9087-75fb-4593-a0a9-62ffbe2bfc75 · outbound

This paper cites Cline — ai coding, open source and uncompromised.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Cline — ai coding, open source and uncompromised

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.911858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.969422Z digest=sha256:f66b387278e9c5c9670156ee66f07cce77f739883afa9da9e621ffac5ed4f731

Observation 9c655096-f07b-42c1-b1cc-3548e9f88d27 · outbound

This paper cites AdvAgent: Controllable Blackbox Red-teaming on Web Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment AdvAgent: Controllable Blackbox Red-teaming on Web Agents

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.975185Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.975185Z digest=sha256:bc0c3ee605ca324c0ce37d82285676b81957515b610358bc1cb1c8388b967308

Observation aa5368bd-9afc-4180-b2ac-059056983a7a · outbound

This paper cites React: Synergizing reasoning and acting in language models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment React: Synergizing reasoning and acting in language models

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.981410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.981410Z digest=sha256:72a2f849b4f836f5946a02c17efb74d02138a6c446fd73209bddaa971b5fb4df

Observation 9acb4cc3-cf41-47ab-a028-ae5e1faf9068 · outbound

This paper cites Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.987143Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.987143Z digest=sha256:75c5a96e686c4abd42fbc27fb7291c923355e90e2d7add217def269005bcf408

Observation d981f5bf-91c7-408e-8196-88cd0ac27398 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated llm agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Injecagent: Benchmarking indirect prompt injections in tool-integrated llm agents

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.876491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:39.993267Z digest=sha256:88af4ba7cacf66ccbdf64f2de2a6cc4ea43d033a3f0868c1e757223a92260670

Observation 06f34892-dbc4-47f3-a2d6-a25f7954bf0a · outbound

This paper cites SPRIG: Improving Large Language Model Performance by System Prompt Optimization.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment SPRIG: Improving Large Language Model Performance by System Prompt Optimization

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.998742Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.998742Z digest=sha256:b2e4b748565d4ba187555fbd0a21a40b91891d2278352185ca686a4242c0a7b3

Observation 7a67a165-bd3d-411e-82f6-82ce4ba28d9c · outbound

This paper cites a helpful assistant.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment a helpful assistant

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.850748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T05:09:40.007399Z digest=sha256:448e21a9dcd0d8d4c1326f31e4e8bf4edfd4360ebbb5435a5c87f6e2ad0b3c32

Observation 439ec31b-2370-422d-a5ee-527c586cfa08 · outbound

This paper cites Context-faithful Prompting for Large Language Models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Context-faithful Prompting for Large Language Models

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.014381Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.014381Z digest=sha256:862a8b9bb8ced178cd8b3841a710e9ba7adefdb1f890d8ea7c3d66d14410b0c8

Observation cf50d8e3-a96a-4a81-9b6d-0591876bad5e · outbound

This paper cites MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.020584Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.020584Z digest=sha256:1f03db7dc40f8455b83c1d53c04db167759a86d9a5cd6fa39204213b01267ff0

Pith citing papers

Observation 9d74020d-4276-44f4-972a-d140ebd224d1 · inbound

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem cites this paper.

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 50

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-05-18T18:43:35.072919Z digest=sha256:7dac7afc129d47a04844e55c91dc891207947ed4ca033c3fbda2f4d22003f219

Observation b2f37388-ce84-46df-a93e-5317fdf8e087 · inbound

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents cites this paper.

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-04T08:06:16.098981Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T08:06:16.098981Z digest=sha256:df3842d9b1d5d8ed71a5257b349f4b7078e2921cf21ded377e4a1d7cca4e521c

Observation 647942dc-86f7-4c34-b8d2-3c4975cffa7d · inbound

Verifiable Manifest Signing and Transparency Enforcement for Secure MCP-Based LLM Pipelines cites this paper.

Verifiable Manifest Signing and Transparency Enforcement for Secure MCP-Based LLM Pipelines Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-03T06:18:06.545883Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T06:18:06.545883Z digest=sha256:ed412b6e9fcc35459d3edd5a30bfb2f96ab0c08fcb9574d079021c411a1cc6c8

Observation aaad7391-b404-488a-bdc8-97f7d54d5713 · inbound

Security Considerations for Multi-agent Systems cites this paper.

Security Considerations for Multi-agent Systems Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 279

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-05-15T14:12:14.160789Z digest=sha256:9d761b7f3cdea51fa1fa815666d9e7a8d265cc4462c25fe5fd0880a69a333441

Observation ca03258d-9fd1-4e78-b649-060698daa6bc · inbound

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents cites this paper.

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-05-08T18:42:06.418583Z digest=sha256:eaadcd55d77ac0c49e50e932438b78c91ca280af87fb163a4465430785ec99b1

Observation ae2b9919-6ccc-4980-96d2-63039ece1e71 · inbound

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents cites this paper.

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T15:04:20.284238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T15:04:20.284238Z digest=sha256:bc27cb25862be8219a19514cae38d4bad962605e95a76317bc64df0fd9485be9

Observation e3a483f2-a692-4cf3-af23-03f439f78a3d · inbound

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents cites this paper.

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-06-30T16:24:55.067215Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-06-30T16:22:23.857438Z digest=sha256:d568543e4f04063e5cc2787830b23f6c18f287589247b9bbcc5d231ceabbf9e7

Observation eef9bcc5-a2fe-485b-ab8c-85086b0598ad · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 208

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:81a45414a44a848cd0b5bcdaf45ba0860aee28abea199b56a9112a1af6e630f0

Observation 09dc7c45-d270-4e7a-aa73-62ff2e95d091 · inbound

Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study cites this paper.

Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 100

Resolution
verified exact
local_arxiv, observed 2026-07-03T12:08:07.100919Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-06-27T09:06:12.868791Z digest=sha256:3c72aeaf9543020666c868dba89dd9bc00129857c54b50d4efa05dc91e119409

Observation 71ce2c75-eb1f-4265-a68f-6b6c27a541bd · inbound

ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP cites this paper.

ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 30

Resolution
verified exact
local_arxiv, observed 2026-07-04T14:19:54.256550Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-06-26T04:07:14.506108Z digest=sha256:a5c4dce547106cfcb4ac45a7adf90b520acda86cff711cbc63ef7dd9f7a6333c

Observation 0c219119-2ba5-4ca1-8932-b9a863d5a04d · inbound

Where Is the Cost of Third-Party API Routers in Agentic Software Development? cites this paper.

Where Is the Cost of Third-Party API Routers in Agentic Software Development? Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 25

Resolution
unresolved
no resolver link, observed 2026-07-30T17:25:46.962117Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-30T17:25:46.962117Z digest=sha256:b93d74b5a7101b3f457eba3f76aabe4d21fd7741e02ee6baa6c92171a6778761