Pith. sign in

Paper Citation Record · LEDGER

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents

As of 8 August 2026, this Paper Citation Record lists 32 of 32 outbound references and 0 inbound Pith citation observations for arXiv:2608.05884.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.05884 v1

Coverage vector

measured 32 of 32 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T21:46:23.185376Z

measured 32 of 32 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

32 of 32 outbound references displayed

  • verified exact0
  • verified fuzzy15
  • unresolved11
  • parse uncertain2
  • malformed identifier0
  • metadata mismatch4

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 5415756e-7ed2-4c3c-9b3b-729ecdec0aea · outbound

This paper cites Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.737672Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.031735Z digest=sha256:43f8871176c8c6fbd9f28985e7bf3ca7d4ab3cb6155a3b3767cae70c1714ea6f

Observation 1c2e7a2d-8b3d-499c-aed1-a17b73d9d6bd · outbound

This paper cites Accelerating the adoption of software and artificial intelligence agent identity and authorization.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Accelerating the adoption of software and artificial intelligence agent identity and authorization

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.726853Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.037423Z digest=sha256:36f05df27f0eca46bcf37493afca9b8880c92738bd671a0418c3c3b6cb20bdb8

Observation 64eb9206-c389-450c-bcd7-87fe3c47336f · outbound

This paper cites CVE program glossary.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents CVE program glossary

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.716191Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.046348Z digest=sha256:50d4dedec9d8c9bfefad3fa1cf739756640f1b0a6ddb55b5315eccd726728617

Observation 930953cb-2ee5-4d72-bb2e-5c977f8edd12 · outbound

This paper cites Agent baseline: Six security outcomes for safely building, deploying and operating AI agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Agent baseline: Six security outcomes for safely building, deploying and operating AI agents

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.705198Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.050508Z digest=sha256:e365ab8cab9e5a136b5cf26a7db640c89fc93c580e3c1a617b04dde23dbb55f2

Observation 1f5feeca-7050-4879-8650-638a5c4ffaa4 · outbound

This paper cites Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.693093Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.054324Z digest=sha256:8c2d52d0c95af9f1b62c4daf67fbd6d555909ca752878dd3cff1e37aa7e7bd37

Observation abecf350-9b96-4983-9a10-a0ac1664572d · outbound

This paper cites LLM06:2025 Excessive Agency.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents LLM06:2025 Excessive Agency

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.681955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.066092Z digest=sha256:6585d44dfda459f80ca1cc731ad1ff48972a644cc18db192b57d064de4c0ddfc

Observation 42e2e241-18c1-4abd-a900-e0060a5efa35 · outbound

This paper cites Complete Dictionary Learning via $\ell_p$-norm Maximization.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Complete Dictionary Learning via $\ell_p$-norm Maximization

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.078142Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.078142Z digest=sha256:9cc2ba3b67ed3b7187293cde29e7ac928de6f2384f8d4381607b9b18d68bf842

Observation 932b6529-685a-418a-9d9c-4184cb5f23aa · outbound

This paper cites Guide to enterprise patch management planning: Preventive maintenance for technology.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Guide to enterprise patch management planning: Preventive maintenance for technology

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.671347Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.082061Z digest=sha256:b09b66b0beccedbfad32611383567bf2625ab2f407bd23d481b433ae217d3300

Observation 75c001a0-a75b-47d6-a6e3-251beac83376 · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.092713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.092713Z digest=sha256:eb954e532b2637e86c5f66aafe67002e7b590088ec9b504729c0a3d97fb8e96c

Observation 96f6e19c-3e4f-4f76-b2e7-3adf4810215a · outbound

This paper cites Cyber defense matrix.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Cyber defense matrix

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.660898Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.104328Z digest=sha256:cdc05206bc9f00a5046c80979af7d851196e236641751bfc9e640a718960b532

Observation cb7c2515-45dd-4fd0-ac2c-e99a6953accf · outbound

This paper cites AI agent remote code execution.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents AI agent remote code execution

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.650229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.107898Z digest=sha256:8e27bc73386b7534f4cf7e493dd6b29888065884f9a0dec0b8e9b9729caef97f

Observation 3276b1c2-7c82-4d44-9fcf-66944c7e54c9 · outbound

This paper cites , howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents , howpublished =

Reference 22

Resolution
parse uncertain
no resolver link, observed 2026-08-07T21:46:23.115180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.115180Z digest=sha256:3953dedaf0c74ef3308b23a2abd324dcd4baad4e97d0a15516547c36858875a1

Observation b5cd30f9-2f84-4298-b025-caca076eeb17 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 23

Resolution
parse uncertain
no resolver link, observed 2026-08-07T21:46:23.118904Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.118904Z digest=sha256:acfd1890ab45dafe1743aad9bfd9bfa6863820bd63975bde558fe7435c27fb8c

Observation ebee3091-c85d-4e25-95d4-22842858a8b5 · outbound

This paper cites 2026 , month = jul, howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2026 , month = jul, howpublished =

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.624209Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.122223Z digest=sha256:479fd0f22dd847f1ea82a0df3b116c7909e56ac81d9d374c4722aa07b0d4720a

Observation 739dbcfe-6dbf-4919-ab1a-3ffa606b8483 · outbound

This paper cites 2025 , month = aug, howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2025 , month = aug, howpublished =

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.613044Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.125718Z digest=sha256:8a7bf11f63bf0b59f2efccb8ab844e73afa59bc1e8a55f162fbfd63241276588

Observation 7fb36911-593c-41d2-a412-80ee9afb4ae5 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.129671Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.129671Z digest=sha256:2d714cc743f870107c76d4f53efd33a4eaf86bd7a348d2eb79e06196a59efb55

Observation 18313a73-227c-434a-906c-35357144d502 · outbound

This paper cites 2022 , month = apr, doi =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2022 , month = apr, doi =

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.594302Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.133320Z digest=sha256:002d2ff7495fa93188e8562a46210da9c3be852ce6d9b4e3450bcc3be899ef70

Observation bdc2018d-2675-4b72-bef5-1e09df9862da · outbound

This paper cites Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.136931Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.136931Z digest=sha256:322ce188717453e3425e227224e1973e86f83cea7619a83a86648edad0aeb577

Observation 1f2dd371-a2fd-47a6-afc7-f937b711a170 · outbound

This paper cites Haines and Somesh Jha and Richard P.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Haines and Somesh Jha and Richard P

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.583226Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.140659Z digest=sha256:bafa405ae323fd8b91cdbe1b6073c91063e4175df6ed0018e4273da1e09f6e32

Observation 217393ac-46d8-491c-b418-cec6ad2f4f7c · outbound

This paper cites 2026 , month = feb, type =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2026 , month = feb, type =

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.571886Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.144245Z digest=sha256:e0431aaceae37f5c867fc2dc23f44a2af8a510055701689eb6b1c2fa228cf221

Observation 74dc51d4-9edb-4f76-955e-d8249283dfd3 · outbound

This paper cites Authenticated Delegation and Authorized AI Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Authenticated Delegation and Authorized AI Agents

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.147775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.147775Z digest=sha256:9b85f67f624b4f4df0839529df95f94aed6c490dc8aea1f025e73940e6dfeceb

Observation 512a8847-7ec1-4824-8100-9a21d45e4ff9 · outbound

This paper cites Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.151426Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.151426Z digest=sha256:9514ad012a0883108c462d18f382746560b39bc6bb56627932119397d09ba137

Observation 1ff63302-8548-4a26-bae3-05156959092a · outbound

This paper cites The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents

Reference 33

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.263208Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.154924Z digest=sha256:df65f1ba677b60a7436beb0ba7b0bc710c109604623eb79c71e7614649077c28

Observation d11472dd-044d-4900-b953-607a114f83cf · outbound

This paper cites Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.158456Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.158456Z digest=sha256:6b814c5cec4aaa8f625f9dc20f79df78a44b2c8ec4d777f750f2c7693693e916

Observation b8763d81-1b0f-432a-8070-936b747ebbee · outbound

This paper cites Do Coding Agents Understand Least-Privilege Authorization?.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Do Coding Agents Understand Least-Privilege Authorization?

Reference 35

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.249319Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.161803Z digest=sha256:2b15d6b56cbfc817191a2768ee2418f837fbb1bcb6362eb7e5e68902cc583790

Observation afc2c480-0158-4566-a2af-738301c2cfc6 · outbound

This paper cites Poskitt and Jun Sun , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Poskitt and Jun Sun , title =

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.560382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.165381Z digest=sha256:746cb5912f3458fdbe329047da1edcf411d90bc6458803eb64ae986668c5a49d

Observation 9507c2c8-4bcb-4209-9305-bc8766478b75 · outbound

This paper cites arXiv preprint arXiv:2603.20953 , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents arXiv preprint arXiv:2603.20953 , year =

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.168974Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.168974Z digest=sha256:29540f675041d4840464fc3e03d564687ae3f9de6a647a4f4d351e196acafb1c

Observation 488b57ee-d62f-4920-9e3f-555d9d1be740 · outbound

This paper cites Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.172245Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.172245Z digest=sha256:e24c8583351c3a5155c6cc00a842fe2642899c128793110b2cafe54b0814b926

Observation 64c2d950-463b-454b-99b2-7d8d55e974cd · outbound

This paper cites arXiv preprint arXiv:2603.16586 , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents arXiv preprint arXiv:2603.16586 , year =

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.175452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.175452Z digest=sha256:8d054ae6bbee0e34e6d4ac0fe52936dfb7797e65f353fd78e5fc52daeab5e45c

Observation fdc261ba-1e82-46d5-a9b2-c2aa5dc85c59 · outbound

This paper cites Intent-Governed Tool Authorization for AI Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Intent-Governed Tool Authorization for AI Agents

Reference 40

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.233895Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.178867Z digest=sha256:f70b914beb4377a7dc05f6e5574c908f0185a8603d18ccc443186be0272a1d25

Observation b3f1c257-8c23-4208-ad9e-4c2310f8b43e · outbound

This paper cites When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents

Reference 41

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.447632Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.182040Z digest=sha256:a549d2ef01ac7be70026d4f2f86d70a01f629f6794ef60c38c304e33b7352f8e

Observation 1217cedd-1aae-45d6-8cb5-7b32995a9e36 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 42

Resolution
unresolved
raw_fallback, observed 2026-08-07T21:46:23.549537Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.185376Z digest=sha256:56db7cc57d22612357f6013041e46b337d83b76c540da9e956d8d76fd553e500

Pith citing papers

No inbound Pith citation observations are available.