Pith. sign in

Paper Citation Record · LEDGER

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

As of 20 August 2026, this Paper Citation Record lists 27 of 27 outbound references and 25 inbound Pith citation observations for arXiv:2502.08586.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2502.08586 v1

Coverage vector

measured 27 of 27 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-08T04:37:28.867597Z

measured 52 of 52 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 25 of 25 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-16T00:54:24.077872Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-03T15:48:35.883148Z

Reference resolution

27 of 27 outbound references displayed

  • verified exact0
  • verified fuzzy2
  • unresolved25
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation c7440ac4-45e3-4bb7-a91f-820a2aed8b14 · outbound

This paper cites Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.268054Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.268054Z digest=sha256:56eaa4d1c63b5619672e533b905033326f9004aa2f6c4114beffa0958b6ce22e

Observation e852125b-d6ff-4489-a04b-a77da23ae6c3 · outbound

This paper cites Tianyu Cui, Yanling Wang, Chuanpu Fu, Yong Xiao, Sijia Li, Xinhao Deng, Yunpeng Liu, Qinglin Zhang, Ziyi Qiu, Peiyang Li, et al.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Tianyu Cui, Yanling Wang, Chuanpu Fu, Yong Xiao, Sijia Li, Xinhao Deng, Yunpeng Liu, Qinglin Zhang, Ziyi Qiu, Peiyang Li, et al

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.368156Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.368156Z digest=sha256:2c44b1d9481db05b4cb688ad3795dab772a5f285485f825c80376941f73df2e4

Observation 9480e77a-efff-4347-abae-590188524f7c · outbound

This paper cites Security and Privacy Challenges of Large Language Models: A Survey.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Security and Privacy Challenges of Large Language Models: A Survey

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.371361Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.371361Z digest=sha256:e69af3a56a19d108355a742db9432b6fb64de25227ec19daa7a771240075cecd

Observation bbfe858a-5d44-41c9-b60b-bc90690c4f1b · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.375477Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.375477Z digest=sha256:337b43638b32729c2b72776970881dcc35b624cfebbe2869ad719fdc05c7ece4

Observation bc7e9b01-f2a8-4054-9ba0-f5b095ca68cf · outbound

This paper cites RLPrompt: Optimizing Discrete Text Prompts with Reinforcement Learning.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks RLPrompt: Optimizing Discrete Text Prompts with Reinforcement Learning

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.378324Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.378324Z digest=sha256:475e116584ac20615b230adc647ec11e6fdd6db52a295c1310a4e265976ff206

Observation 684061cc-aec2-4e2a-b6d7-3144133a965a · outbound

This paper cites Feng He, Tianqing Zhu, Dayong Ye, Bo Liu, Wanlei Zhou, and Philip S Yu.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Feng He, Tianqing Zhu, Dayong Ye, Bo Liu, Wanlei Zhou, and Philip S Yu

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.385457Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.385457Z digest=sha256:af646ac5c1cb7a998129fe4af0dd950cfc9fa5a1bbb3e9dbba9b3d411c15a0c9

Observation 98431140-7e89-4d59-ab0a-9a96b91afff6 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.388533Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.388533Z digest=sha256:fa8cdba414b77c214b5d695b00a38d9c42d708b36fbc426e3571553e3da739be

Observation 7a1455d9-0caa-4766-8dd8-7b9a09263566 · outbound

This paper cites Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.391836Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.391836Z digest=sha256:6179dbb41af7613a9331dd78e8000dc62e71a8e3c5e2cbadaa007cbd2082da04

Observation a1327166-0d8e-46ff-ab58-1c332a735972 · outbound

This paper cites Red Teaming Language Models with Language Models.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Red Teaming Language Models with Language Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.406491Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.406491Z digest=sha256:648fb6be74c8ddd67f02359d4cf61ee448c72efd119ad414824e93fe58a48d5c

Observation 7334860c-ab06-4cda-ae72-f58a63806e3b · outbound

This paper cites Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Agent Q: Advanced Reasoning and Learning for Autonomous AI Agents

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.463591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.463591Z digest=sha256:c6087b8e43bebc2b8c09d6d7b4b537174642f4b1f4d6ec59b52fc82a786a11c5

Observation 8cde1543-df87-4c5d-817a-1cfe0574c2f7 · outbound

This paper cites Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.522854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.522854Z digest=sha256:8a7fec061eba7a66c605181d802d5bf1649ee254683ac48e023dc061bb269367

Observation 0d2695b8-6189-4fba-a967-dad5b534717a · outbound

This paper cites Language agents achieve superhuman synthesis of scientific knowledge.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Language agents achieve superhuman synthesis of scientific knowledge

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.580674Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.580674Z digest=sha256:90d370ea051ba64066e2b800cc0d3ddb0592df6da87f316631aa7bb5efd4344f

Observation eda3da75-5be5-4065-9e7c-fa974e876269 · outbound

This paper cites Evil Geniuses: Delving into the Safety of LLM-based Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Evil Geniuses: Delving into the Safety of LLM-based Agents

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.636620Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.636620Z digest=sha256:5515e4fb887573962f68f03fecf76f301cab93faa6cf05809248ca113b2bb250

Observation 0d3f6b33-8f2f-4906-9e14-19c0ec4db78b · outbound

This paper cites Data poisoning attacks against federated learn- ing systems.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Data poisoning attacks against federated learn- ing systems

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T04:37:29.230122Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-08T04:37:28.666591Z digest=sha256:a52e6b03ef59e359e8e4fd57739ecba6b6f75c38213ac1181c17d8e64e106397

Observation 662ad39e-bce8-4c2a-9cfd-0c3fe35e30f1 · outbound

This paper cites Jiaqi Xue, Mengxin Zheng, Ting Hua, Yilin Shen, Yepeng Liu, Ladislau B¨ol¨oni, and Qian Lou.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Jiaqi Xue, Mengxin Zheng, Ting Hua, Yilin Shen, Yepeng Liu, Ladislau B¨ol¨oni, and Qian Lou

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-08T04:37:29.220363Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-08-08T04:37:28.734617Z digest=sha256:43780315d001bb6b94fa41e4f1b50cb5c47a6613d30f84982dcdcca5234f2596

Observation 1f68dc76-45a4-4ecf-8a2c-213780f94de8 · outbound

This paper cites Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based Agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.771627Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.771627Z digest=sha256:a084e5b05c1e9578405224395269226443a0aed093024b93311c8e79fb96c3a2

Observation 7efd6251-11e5-49d5-8b67-2007d2b53ac3 · outbound

This paper cites The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG).

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG)

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.809380Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.809380Z digest=sha256:772ca468164c6d8e51be6bdc67eead3a55f31748331630c2c4109a7f4a9feaff

Observation 75e283ae-38ba-4953-92f4-67cd737699ad · outbound

This paper cites Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.833682Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.833682Z digest=sha256:1b620a73436433701f0def2c59e0fcb2b385e283258c7d92bfe0406df182d44b

Observation eaaceb16-a8fe-4fb8-8a94-57705e2572ee · outbound

This paper cites WebArena: A Realistic Web Environment for Building Autonomous Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks WebArena: A Realistic Web Environment for Building Autonomous Agents

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.861187Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.861187Z digest=sha256:b76ab3928dfeb39c3c236bc4d57d90a5b493bfe3eec5ac19bcbd3a27f47a00eb

Observation 1f195015-f753-4464-a947-6a6c78bc07e5 · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.864419Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.864419Z digest=sha256:7dac36edf6f6d035f8bf17f9265a9ca59358eae02029895515968554ea616b49

Observation e82cbe66-f7fa-4f7e-89ff-287c47565931 · outbound

This paper cites PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.867597Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.867597Z digest=sha256:78f191e92dd7f3338ff9cae1a7685cbe7f5bb7149a1d2e38ce4b94861368f4b9

Observation 7d3be1a2-b8fb-4a6e-849c-808561abf87a · outbound

This paper cites AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 2017

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.364091Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.364091Z digest=sha256:362f3144cc2aca38bf81a669fb761f0674577a94376440cd73c39217c51e3699

Observation 6b8f9803-dfee-4eb5-832e-dde61e6a10e5 · outbound

This paper cites BadAgent: Inserting and Activating Backdoor Attacks in LLM Agents.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks BadAgent: Inserting and Activating Backdoor Attacks in LLM Agents

Reference 2020

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.696356Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.696356Z digest=sha256:b0cdc2addc72d29a2d4ea69ba887e368f8271f03caf4bb2bfc3af8595979e4f0

Observation 71d462d9-5a9b-43a1-aea4-39010fe76e3e · outbound

This paper cites A Real-World WebAgent with Planning, Long Context Understanding, and Program Synthesis.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks A Real-World WebAgent with Planning, Long Context Understanding, and Program Synthesis

Reference 2022

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.381640Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.381640Z digest=sha256:d1082f7c7a886db3f552839f0ae017a6ce42d4139cdd53a12ee4c91926b8e9d7

Observation c78bb0e7-56c5-4300-8fbf-19f51297f658 · outbound

This paper cites Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning

Reference 2023

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.330264Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.330264Z digest=sha256:60254391e1ad221b99d0ab08d196954157bde6b939bae43fedda8fddab2055a4

Observation 86005911-1a78-45d4-baa8-42fdf1046c33 · outbound

This paper cites ChemCrow: Augmenting large-language models with chemistry tools.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks ChemCrow: Augmenting large-language models with chemistry tools

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.294013Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.294013Z digest=sha256:e0af219642bf6c8d0400fb17b38d46d6d5792d362e1b135576160f5363afedf7

Observation b0ddb43a-d175-449f-ae19-ea1f7c0025f3 · outbound

This paper cites Scalable Extraction of Training Data from (Production) Language Models.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks Scalable Extraction of Training Data from (Production) Language Models

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.394855Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.394855Z digest=sha256:f9d580d080a4ca13fe0ddebbe0fd1b10fe45e3ac9fbc4442d562af7cbbc47d33

Pith citing papers

Observation 253b84ab-1d66-4a3a-9997-cb0a75bd596f · inbound

Large Language Model Agent: A Survey on Methodology, Applications and Challenges cites this paper.

Large Language Model Agent: A Survey on Methodology, Applications and Challenges Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 175

Resolution
verified exact
arxiv_id, observed 2026-05-22T21:52:10.416569Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-22T21:51:34.309870Z digest=sha256:43377d92b90dcacf4242a91715a85db7d2e58dc35739376f3be5969bae734df7

Observation 096b64cd-4a1f-4eed-95d0-a459a6f70acb · inbound

Unveiling the Landscape of LLM Deployment in the Wild: An Empirical Study cites this paper.

Unveiling the Landscape of LLM Deployment in the Wild: An Empirical Study Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-16T00:54:24.077872Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T00:54:24.077872Z digest=sha256:8db8f72f66281b5cfc46d547378fc29848c7e69a085443403238f69eb8026bfd

Observation be51e42f-0e70-476d-9a6d-26463ffa2c86 · inbound

Invisible Tokens, Visible Bills: The Urgent Need to Audit Hidden Operations in Opaque LLM Services cites this paper.

Invisible Tokens, Visible Bills: The Urgent Need to Audit Hidden Operations in Opaque LLM Services Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T14:34:34.815687Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:34:34.815687Z digest=sha256:30ba40222af80d69721a54da9980d84c49f8e44caa26fd00bf2ec691944f7c73

Observation 4de0b938-f923-4b0a-8e57-4b32cf438f03 · inbound

MLA-Trust: Benchmarking Trustworthiness of Multimodal LLM Agents in GUI Environments cites this paper.

MLA-Trust: Benchmarking Trustworthiness of Multimodal LLM Agents in GUI Environments Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T11:42:33.151323Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:42:33.151323Z digest=sha256:5aef41fcfd5d564bab1a1975ac0f852a9161d9d77db441da90c1555ca8321aed

Observation 5f9b130e-a6b8-4e84-a6b8-d2fa89e8e789 · inbound

A Red Teaming Roadmap Towards System-Level Safety cites this paper.

A Red Teaming Roadmap Towards System-Level Safety Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T12:11:20.746079Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:11:20.746079Z digest=sha256:8c52cea5caf4177a80de21b759eb8c855bf1d5c1173db3e4efe7cceb2a494ce7

Observation d2036883-0a11-4792-ba90-bc10698481e9 · inbound

Levels of Autonomy for AI Agents cites this paper.

Levels of Autonomy for AI Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-07T00:52:41.842278Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:52:41.842278Z digest=sha256:68342b1d6b9df2062f863a979456d645fc3dc9c201100b6ef56f5cf5913b1b5d

Observation 4a01d0f6-66ab-4bb4-bdc9-77680eb4f755 · inbound

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems cites this paper.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.575227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.575227Z digest=sha256:73c34799c36b98533bd6d51d2887b7126a09332f90781c1ab74efb1c4ec998d9

Observation 26006061-4145-4732-9dd9-8613a9c4af73 · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:41.058806Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:41.058806Z digest=sha256:f3cfc06dfe99db6aea5476e11275a95c56d884d68699e3fc81136686f8a8b5c2

Observation f34403d8-64b3-4b77-bb38-3907e4f94c74 · inbound

Throttling Web Agents Using Reasoning Gates cites this paper.

Throttling Web Agents Using Reasoning Gates Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-05T12:28:04.262824Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:28:04.262824Z digest=sha256:54c7cc8f753c80c96ca1c059630af84ffd31da79031af7a473b00c3345e0518b

Observation f01aec10-85e1-4790-83b8-2ae442ff8fba · inbound

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents cites this paper.

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-04T08:06:11.330207Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T08:06:11.330207Z digest=sha256:dc780944fab9a583d6fbfd9e600d9d51294dbfbb76942e964fcec730b5a04ac7

Observation 0f547531-39aa-44f7-bad3-35e3f742389d · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.464757Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:670a086ac5bef7f028c4680e9b2279e71b835a930023edf8d9a181f12ae23908

Observation e36b5551-e79c-4033-9e44-68fbdd28bc08 · inbound

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels cites this paper.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.041872Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.041872Z digest=sha256:df80d1a08e22aae162275d9c6134c1da8212c158d9fbbb3fd3d93233a9e57d75

Observation eae352de-994f-46ac-b9b6-3eb072c67fb0 · inbound

CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents cites this paper.

CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-03T10:32:31.300703Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T10:32:31.300703Z digest=sha256:6db2843e062299254e174d6b50eefa117acbfc6b84254ec8561d189a38f025d4

Observation 98b32e61-f9b1-48ef-955d-d23a9baee00c · inbound

Agents at Risk: How Users Unwittingly Undermine LLM Safety cites this paper.

Agents at Risk: How Users Unwittingly Undermine LLM Safety Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-03T10:45:18.132433Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T10:45:18.132433Z digest=sha256:dd9b577b482744821558737c342dcd5a13bea4cde529f7ad4357204e4c0a015e

Observation 74e5a25f-89fd-455c-b8cd-06a8e35d706f · inbound

LLM-AutoDP: Automatic Data Processing via LLM Agents for Model Fine-tuning cites this paper.

LLM-AutoDP: Automatic Data Processing via LLM Agents for Model Fine-tuning Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-05-16T10:57:46.854305Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-16T10:54:22.183741Z digest=sha256:4f843197d07a3f34844a3bad252565b4a6c90fd8e3f47346c511bdd11e2d163e

Observation 6353e071-8de9-4ae8-bddb-063f71c72e15 · inbound

OS-SPEAR: A Toolkit for the Safety, Performance,Efficiency, and Robustness Analysis of OS Agents cites this paper.

OS-SPEAR: A Toolkit for the Safety, Performance,Efficiency, and Robustness Analysis of OS Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-05-11T21:56:11.842563Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-08T03:51:54.310805Z digest=sha256:5e7dacd385f54919c512f13ff1a172fcdb07679dc5990617487f161cf3dc743e

Observation b563fa63-c81c-4092-865f-be3c916bf6c8 · inbound

Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security cites this paper.

Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 99

Resolution
verified exact
arxiv_id, observed 2026-06-30T19:45:01.661562Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-30T19:18:40.244556Z digest=sha256:f43e327f93aa037016f32983ba806d9c0b43fdaafb97288ba4013b2d2b6748fb

Observation 28206dc5-9048-4a28-8234-857c0250edde · inbound

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents cites this paper.

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-06-30T16:24:55.140269Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-30T16:22:23.857438Z digest=sha256:5c78e5d47703ffec4be8472418f5928e2b53c284c72b609742124da4edf2f795

Observation feca9d20-b067-4135-afa2-fb5e6e604f1d · inbound

Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents cites this paper.

Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-07-03T15:48:35.884551Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-27T06:20:04.789341Z digest=sha256:919690e816360d25af2903cf394d788853cfe4e403074f893dfa512dda3815e1

Observation 88883738-429d-418b-9449-9a44d034f077 · inbound

Why Trust Your Agent? Empirical Security Gains from TRiSM-Guided Agentic Workflows in Healthcare cites this paper.

Why Trust Your Agent? Empirical Security Gains from TRiSM-Guided Agentic Workflows in Healthcare Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-06-30T12:44:39.617898Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-30T10:17:02.425849Z digest=sha256:3dfa7fa284d5c6f4b6ffbfe7b721a7f6731ad8b8e0fe6f241c041c36a1056289

Observation 82e558c9-e23d-48c4-ae91-8a16c5ac1b37 · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 268

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.602164Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.602164Z digest=sha256:b27b94fe505d9fefdd9a12468bcabedac821019b9c56b1dadc09d33f94b6f80a

Observation 6c261576-7405-40f9-bbb1-2588d573b740 · inbound

One Anchor for All: Unified Multilingual and Multimodal Safety Alignment for LVLMs cites this paper.

One Anchor for All: Unified Multilingual and Multimodal Safety Alignment for LVLMs Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 17

Resolution
unresolved
no resolver link, observed 2026-07-31T23:07:37.594638Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-07-31T23:07:37.594638Z digest=sha256:f79ba26cb240cd76cb04b0b1315c38eecab417e36933066aa907026ae2113a8b

Observation b5d24510-d72f-4e28-a4a8-9a1a0f87e169 · inbound

Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents cites this paper.

Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-04T16:36:53.593030Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T16:36:53.593030Z digest=sha256:b969568cd25def9376f8880baf274895d9af24b1a9df983ca9dae83c5c9e9e8a

Observation f9c7f59c-9fc1-4e6e-b474-ad1fb264f142 · inbound

Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents cites this paper.

Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T00:59:39.874950Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:59:39.874950Z digest=sha256:2d055f31a41b54111f7d4a2588841d493b2ec6f7ac650e3077fb79b7df5458da

Observation 39a8ec91-4374-48f9-80f7-73e24dbbf8c2 · inbound

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure cites this paper.

Your Agentic LLMs Secretly Encode Latent Signals of Indirect Prompt-Injection Exposure Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-05T00:54:57.371881Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T00:54:57.371881Z digest=sha256:e2534c66fc952f25a5b3f9b84b1631cc2b6ecbbc92bd62d3811af0f229007523