Pith. sign in

Paper Citation Record · LEDGER

MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

As of 19 August 2026, this Paper Citation Record lists 1 of 1 outbound references and 33 inbound Pith citation observations for arXiv:2508.14925.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2508.14925 v1

Coverage vector

measured 1 of 1 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T18:59:53.055489Z

measured 34 of 34 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 33 of 33 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T19:23:24.332483Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

1 of 1 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved1
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation 74f68912-7c38-4f8f-9b1d-db5eb8c2db34 · outbound

This paper cites MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers.

MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-05T18:59:53.055489Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T18:59:53.055489Z digest=sha256:b150e23243684edcaae1f15bd5bf51cd8c5c78f2e4eca3195fa18d689606113b

Pith citing papers

Observation 74f68912-7c38-4f8f-9b1d-db5eb8c2db34 · inbound

MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers cites this paper.

MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-05T18:59:53.055489Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T18:59:53.055489Z digest=sha256:b150e23243684edcaae1f15bd5bf51cd8c5c78f2e4eca3195fa18d689606113b

Observation 63e9ffe8-108a-41c2-89b7-9223ea87983a · inbound

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem cites this paper.

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 48

Resolution
verified exact
arxiv_id, observed 2026-05-18T18:46:45.305941Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-18T18:43:35.072919Z digest=sha256:80f81ad55add4eae69c083d69780ed60a1b499d078c072b57f4a41f855cfd4e9

Observation 280f776d-be11-4d24-ac11-78371288c7bd · inbound

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools cites this paper.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.789590Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.789590Z digest=sha256:74fe8c9fa93bac60a54ca8b7d477acee5cd3fb13889313b4563a264d9f6d0040

Observation 5ad4840d-8d02-4b3b-84ab-d6e80204cc48 · inbound

Bridging Protocol and Production: Design Patterns for Deploying AI Agents with Model Context Protocol cites this paper.

Bridging Protocol and Production: Design Patterns for Deploying AI Agents with Model Context Protocol MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-15T11:59:59.368965Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-15T11:58:18.020389Z digest=sha256:6b58a2cd09c98c2ad0e01affbc7cb76860c18d2907a1132671b83ac324951f9a

Observation 4f6be4f1-d1b5-4026-ad19-0902aa710d67 · inbound

A Systematic Security Evaluation of OpenClaw and Its Variants cites this paper.

A Systematic Security Evaluation of OpenClaw and Its Variants MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 7

Resolution
verified exact
arxiv_id, observed 2026-05-13T19:38:10.680308Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-13T19:33:29.341895Z digest=sha256:806744a20ff0b99fe197a7c293ab174808d887925615266d46a221b1f0566637

Observation b2136d16-8ffc-47ea-b3c5-a8d0aefd8508 · inbound

ShieldNet: Network-Level Guardrails against Emerging Supply-Chain Injections in Agentic Systems cites this paper.

ShieldNet: Network-Level Guardrails against Emerging Supply-Chain Injections in Agentic Systems MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 8

Resolution
verified exact
arxiv_id, observed 2026-05-10T21:55:53.026950Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T20:25:58.113363Z digest=sha256:7e4421c1464c04bbaad7283e68b35e87b290415f6feaeffa67a659c2db2e1c67

Observation f07e0b5e-6a0b-4a0f-b2b8-b5390e8e0a91 · inbound

Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw cites this paper.

Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-10T23:05:49.116124Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T19:20:52.845052Z digest=sha256:64cafd02a13884d0d729054ed70e62a7ced416959441ebbc027282bf97473aa4

Observation e9743a8a-b306-4736-8a05-51ad514ae750 · inbound

A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms cites this paper.

A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-10T22:40:50.288852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T19:39:27.982512Z digest=sha256:3c8a32657652c61a916e72cdc1e371d86385ae2a75431285fbc14eaf0be0dd53

Observation 6de11461-dfc6-4a74-9244-8368755b80d4 · inbound

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security cites this paper.

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 54

Resolution
verified exact
arxiv_id, observed 2026-05-10T21:10:46.940903Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T17:10:50.283791Z digest=sha256:9155b914a1f30e955f45e4df0fc765965c7bd7801dd12dfa585603d28a561466

Observation 5e074be1-2a67-4a94-a846-26556f984d7e · inbound

ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection cites this paper.

ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-11T09:20:59.960245Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T16:05:47.517157Z digest=sha256:0228ddba514d5620d9c7ec2e867c1bfb83314064f6350baa8bf9dff830c0eb36

Observation 9089443f-c93e-48a5-8b0f-cda089c4f70e · inbound

ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection cites this paper.

ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-12T06:26:25.210503Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-12T04:17:07.080092Z digest=sha256:6c786c9dcbacd060cebca8dc75f13ef1d5e017092341c214429cbe7f92f73358

Observation a8b738dc-2e96-4193-a5ba-bbb4fcffa7e5 · inbound

CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems cites this paper.

CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-10T06:11:20.456096Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T06:07:01.732928Z digest=sha256:a769a65316fa38aba121cfd8924e386b74f5463c9fac35e6c1c6d7a975c58c57

Observation 43b36547-6ae3-4f89-b79f-cf1cb2a10430 · inbound

Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning cites this paper.

Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 25

Resolution
verified exact
arxiv_id, observed 2026-05-12T07:37:04.063019Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-12T02:27:06.805794Z digest=sha256:005e6f88595d3bd5a8873bf02b6f5aed2de528bb97cc120d0bb8ad970c1bd082

Observation eafed71a-bbc8-4adf-8993-ad0ed76593c3 · inbound

Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols cites this paper.

Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-05-13T00:57:00.345076Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-13T00:56:02.786795Z digest=sha256:486c99284c734f11e71c4236503268bac7a9bd7ff4aa287f8aef3d64e9f81664

Observation 7a5c36b5-6d15-46e6-918c-a3bacf590c57 · inbound

Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols cites this paper.

Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:17:58.633112Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-14T21:17:10.373607Z digest=sha256:49351263df2ddd3dfe79c1078052bcc2967d85f78496caf3ef4106e3255d4424

Observation 0bcc9a05-4e61-4fe2-be25-3c2f554c5d92 · inbound

Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols cites this paper.

Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-05-25T06:00:23.541536Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-25T05:57:22.726910Z digest=sha256:711274f632a370be1dbcf2c01c997869d8b82e32adf980a3af431705aeabf35d

Observation b57b6ff4-4735-4c6c-bd57-5309cd075be4 · inbound

Five Attacks on x402 Agentic Payment Protocol cites this paper.

Five Attacks on x402 Agentic Payment Protocol MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-13T05:52:22.105049Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-13T05:51:03.724580Z digest=sha256:855815cb33a3e159cd1b238c42a9cd56d6a46059fd65728253b1ccbc3b13a01a

Observation 134c0bd8-f035-4a6c-9a87-648ce23b9738 · inbound

From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI cites this paper.

From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 137

Resolution
verified exact
arxiv_id, observed 2026-05-20T18:08:50.435308Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-20T18:08:24.901025Z digest=sha256:1e194e6ce6ee61484071e1fc832a801bc37c3e0ffa8dfba8d8493a6f04ebfc58

Observation ed513a7c-7cfb-4e25-9757-4157bba206be · inbound

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback cites this paper.

Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-19T23:27:52.575901Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-19T23:26:15.658106Z digest=sha256:4b0d6db17ee50305d32c222184d568a58a3c6c6d409bde8cd9ffc5b19dabf83d

Observation af80a512-1d00-4f55-a30f-11138deb5572 · inbound

Security, Privacy, and Ethical Risks in OpenClaw cites this paper.

Security, Privacy, and Ethical Risks in OpenClaw MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-05-25T04:26:37.695288Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-25T04:25:49.102385Z digest=sha256:34a2307599ec0a88306cc24c42dc832a3159b600977472ea4bd1d600483b6473

Observation cdb55672-5b6a-4da0-bf83-09e15e5a578a · inbound

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents cites this paper.

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-06-30T16:24:55.050510Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-30T16:22:23.857438Z digest=sha256:fdd0f7cb54ba1517bd2d62646d54e15fa366cd888b3045ea21ecba66b510a077

Observation d77bd3ab-780d-4b1e-be5d-e03684c2350f · inbound

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models cites this paper.

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 1

Resolution
metadata mismatch
arxiv_id, observed 2026-06-28T19:22:34.421669Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-06-28T19:19:17.673497Z digest=sha256:f3d29b8f39ac8d13a82ad956e11cbfe94581cb0e726d6964f12113fb65651118

Observation 56855ef6-7237-4d8a-a0d3-cc662f613dfb · inbound

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents cites this paper.

What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-07-01T23:36:22.950725Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-28T14:12:38.815852Z digest=sha256:48b9178bb46555a7039a8ef010c0508b4f7ddabd212e7b4fab3d81c945e5031a

Observation 30496f84-987f-4837-977d-f10af2c875f5 · inbound

Description-Code Inconsistency in Real-world MCP Servers: Measurement, Detection, and Security Implications cites this paper.

Description-Code Inconsistency in Real-world MCP Servers: Measurement, Detection, and Security Implications MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-07-02T08:36:47.849562Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-28T05:57:36.882346Z digest=sha256:7a8aaa43dcafdcef27bcbc378e94078ad0300463321d112afa7db8f4cbd04a62

Observation 46979fa4-ae33-4eac-bec3-c99537fec36a · inbound

Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning cites this paper.

Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 2

Resolution
verified exact
arxiv_id, observed 2026-07-04T04:59:36.366539Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-06-26T16:32:09.625729Z digest=sha256:3df0bce6a98b68c4d3b644a654a700aa0e46240e637b22c7eecb65dedac43a57

Observation 8f8612d3-5e29-43fa-bafd-57e9560a459b · inbound

Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents cites this paper.

Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 51

Resolution
verified exact
arxiv_id, observed 2026-07-04T09:19:43.601015Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-26T10:13:31.405238Z digest=sha256:837398282431fe258504e6cae916940a105a380fbd4c9473017cba27fae8f097

Observation 0203a68e-7eb9-4579-a41c-4795d7cdbb4a · inbound

!Imperio, smolVLA: The Implications of Data Poisoning on Open Source Robotics cites this paper.

!Imperio, smolVLA: The Implications of Data Poisoning on Open Source Robotics MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 17

Resolution
unresolved
no resolver link, observed 2026-07-11T21:22:51.640124Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T21:22:51.640124Z digest=sha256:50b92acdde9da78e31d8c22108258bacc990fda1df74192f2f6a4994068483a4

Observation fe764729-0262-4633-9e61-773d06580b74 · inbound

Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations cites this paper.

Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 10

Resolution
verified exact
local_arxiv, observed 2026-07-11T02:47:51.220579Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-07-11T02:40:13.068295Z digest=sha256:1eebaf174babcee3487868e56f47cde2acd7a41e59238623961036bc452fb80d

Observation 055f4f6f-9039-42e0-9bd4-0ceebc8b5744 · inbound

Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability cites this paper.

Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 61

Resolution
unresolved
no resolver link, observed 2026-07-14T07:09:56.559355Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-14T07:09:56.559355Z digest=sha256:fed0463082d6f9ac0d4866aa88ba65b3b4bc3c58a3c9ef49eb84062d824c0e2c

Observation 3dd529ba-2ded-4228-b98c-d4a75e503ce7 · inbound

FlowGuard: From Signals to Evidence for MCP Security Detection cites this paper.

FlowGuard: From Signals to Evidence for MCP Security Detection MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-02T01:12:23.830265Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:12:23.830265Z digest=sha256:64bdfee3299446c6d71d4404cb20c1ab745553f788be340ede376f1302778f44

Observation 7bc600cf-6912-4448-b7f8-232140c568e0 · inbound

CAGE: Certified Authorization under Typed-Return Uncertainty for Tool-Using Agents cites this paper.

CAGE: Certified Authorization under Typed-Return Uncertainty for Tool-Using Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-03T12:01:13.263106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-03T12:01:13.263106Z digest=sha256:4e21a70a5ca149c044aececa648a6725efb23d11afad713362188738f36beca1

Observation c6000436-ab45-4b5b-9128-e2de2cc16494 · inbound

Persistent Semantic Entities in Tool-Augmented LLM Systems cites this paper.

Persistent Semantic Entities in Tool-Augmented LLM Systems MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-12T00:47:18.092284Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-12T00:47:18.092284Z digest=sha256:2a5b13d0549bc81b1908d84b5d160b6f3dff80da7be76770a95c71ce72efeaba

Observation 3130b42d-3d50-4847-af82-fc87021e75b9 · inbound

Beyond Handcrafted Security: Towards Self-Evolving Defense for LLM Agents cites this paper.

Beyond Handcrafted Security: Towards Self-Evolving Defense for LLM Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-15T19:23:24.332483Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T19:23:24.332483Z digest=sha256:ccfa5d9d0ff2c37de3a6f1485513807827d459be59fd765860eea952d2b95629