Pith. sign in

Paper Citation Record · LEDGER

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents

As of 21 August 2026, this Paper Citation Record lists 32 of 32 outbound references and 0 inbound Pith citation observations for arXiv:2608.05884.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.05884 v1

Coverage vector

measured 32 of 32 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T21:46:23.185376Z

measured 32 of 32 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-21T06:32:19.484+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

32 of 32 outbound references displayed

  • verified exact0
  • verified fuzzy15
  • unresolved11
  • parse uncertain2
  • malformed identifier0
  • metadata mismatch4

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 5415756e-7ed2-4c3c-9b3b-729ecdec0aea · outbound

This paper cites Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.737672Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.031735Z digest=sha256:3803d21cfdc4e4931e69d385c45da70c2a2c665742fdae9bdcdf1784ba31597a

Observation 1c2e7a2d-8b3d-499c-aed1-a17b73d9d6bd · outbound

This paper cites Accelerating the adoption of software and artificial intelligence agent identity and authorization.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Accelerating the adoption of software and artificial intelligence agent identity and authorization

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.726853Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.037423Z digest=sha256:795c2e259e89fa0d1c5fa44a90a346073fcaf21a37fa47ef8b974bb04e185eab

Observation 64eb9206-c389-450c-bcd7-87fe3c47336f · outbound

This paper cites CVE program glossary.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents CVE program glossary

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.716191Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.046348Z digest=sha256:61bb826f0d08ef4f40ea26cbbf0bb44f262966e0f26e7cbe1b6431f28a7bec06

Observation 930953cb-2ee5-4d72-bb2e-5c977f8edd12 · outbound

This paper cites Agent baseline: Six security outcomes for safely building, deploying and operating AI agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Agent baseline: Six security outcomes for safely building, deploying and operating AI agents

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.705198Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.050508Z digest=sha256:8a125819fca856c5d7e0d4cb3fd8344738ed878b0339203550f1bd5ace086f42

Observation 1f5feeca-7050-4879-8650-638a5c4ffaa4 · outbound

This paper cites Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.693093Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.054324Z digest=sha256:702cf44505eda872edfe2c9449af46acdaa774c417bf2de32b6581d48ee5895c

Observation abecf350-9b96-4983-9a10-a0ac1664572d · outbound

This paper cites LLM06:2025 Excessive Agency.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents LLM06:2025 Excessive Agency

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.681955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.066092Z digest=sha256:888c3a4c1b0a84d4886b49a913166cac200ebe140d15b934f631a7e90dcb1ff9

Observation 42e2e241-18c1-4abd-a900-e0060a5efa35 · outbound

This paper cites Complete Dictionary Learning via $\ell_p$-norm Maximization.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Complete Dictionary Learning via $\ell_p$-norm Maximization

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.078142Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.078142Z digest=sha256:e77bcad92d542e9ede1406a9f95c6e58d2a72f96bae06b2e8c4a1cfdff3caea4

Observation 932b6529-685a-418a-9d9c-4184cb5f23aa · outbound

This paper cites Guide to enterprise patch management planning: Preventive maintenance for technology.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Guide to enterprise patch management planning: Preventive maintenance for technology

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.671347Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.082061Z digest=sha256:068da6cfeb96ce650fc9d5d8e96748d398638939f7f5330169e6c2d3bac74d6c

Observation 75c001a0-a75b-47d6-a6e3-251beac83376 · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.092713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.092713Z digest=sha256:cef9539659448b2b3fdbf14e9a4cb3cf68fc43be1953d4fb88f3f656fb7f3df0

Observation 96f6e19c-3e4f-4f76-b2e7-3adf4810215a · outbound

This paper cites Cyber defense matrix.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Cyber defense matrix

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.660898Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.104328Z digest=sha256:8ae2a2f7a645c9d1b5dd1bdc08722f4d9625fbd855d3434c28a3f3ba07ef5c30

Observation cb7c2515-45dd-4fd0-ac2c-e99a6953accf · outbound

This paper cites AI agent remote code execution.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents AI agent remote code execution

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.650229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.107898Z digest=sha256:3f27af17d81d9fab903b8c1b52269bf26d49be7de1d0b49470f18ed6cfc2a8c5

Observation 3276b1c2-7c82-4d44-9fcf-66944c7e54c9 · outbound

This paper cites , howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents , howpublished =

Reference 22

Resolution
parse uncertain
no resolver link, observed 2026-08-07T21:46:23.115180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.115180Z digest=sha256:5e825ae71dafe0d4eece83aea2b6aea89b9d469ae748eb9b3f2806ed35fc5f7f

Observation b5cd30f9-2f84-4298-b025-caca076eeb17 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 23

Resolution
parse uncertain
no resolver link, observed 2026-08-07T21:46:23.118904Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.118904Z digest=sha256:ab9a24143abf33936a3478735effa451b0c5de3759099e6030ca05938f397fdc

Observation ebee3091-c85d-4e25-95d4-22842858a8b5 · outbound

This paper cites 2026 , month = jul, howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2026 , month = jul, howpublished =

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.624209Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.122223Z digest=sha256:93bb8eed23cfa8645a4efdf496aa67214fcfa40d67f980b60b11162643de1ce2

Observation 739dbcfe-6dbf-4919-ab1a-3ffa606b8483 · outbound

This paper cites 2025 , month = aug, howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2025 , month = aug, howpublished =

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.613044Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.125718Z digest=sha256:290dbbd6c088e79d8b4882533e9d9a7b3327fd430ebf2936aef8154cebd93c96

Observation 7fb36911-593c-41d2-a412-80ee9afb4ae5 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.129671Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.129671Z digest=sha256:7e5ec423c6dcb89ea6dd67687140719f02bd749a45496cb18b7d2fa69ba4e5be

Observation 18313a73-227c-434a-906c-35357144d502 · outbound

This paper cites 2022 , month = apr, doi =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2022 , month = apr, doi =

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.594302Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.133320Z digest=sha256:31c6d217e27c401e31a8c82b00e1e2c0a023e3ea93b09fd094b1a13a7d76324f

Observation bdc2018d-2675-4b72-bef5-1e09df9862da · outbound

This paper cites Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.136931Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.136931Z digest=sha256:646224b23a9fade2d3c9eae33ba00d9b6667de590836eb73855f7606fc1c96f4

Observation 1f2dd371-a2fd-47a6-afc7-f937b711a170 · outbound

This paper cites Haines and Somesh Jha and Richard P.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Haines and Somesh Jha and Richard P

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.583226Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.140659Z digest=sha256:f5cd47a5f72324ee615e6087c32d198b6468d34dcee74e2fcb9c46f8617312bb

Observation 217393ac-46d8-491c-b418-cec6ad2f4f7c · outbound

This paper cites 2026 , month = feb, type =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2026 , month = feb, type =

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.571886Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.144245Z digest=sha256:7cf3b190c53d3c2bdd734dfbaba7d6311328902d6f93c32fa4c8ad596efe7355

Observation 74dc51d4-9edb-4f76-955e-d8249283dfd3 · outbound

This paper cites Authenticated Delegation and Authorized AI Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Authenticated Delegation and Authorized AI Agents

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.147775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.147775Z digest=sha256:665d1343dae6ea65a9dfebdc73f0563c9034c1aa9e25249e4c66fe064e9127c0

Observation 512a8847-7ec1-4824-8100-9a21d45e4ff9 · outbound

This paper cites Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.151426Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.151426Z digest=sha256:d2438f70ae8e8edefeb277583a6ee76978dccfbef1f3a921a5b4ae22f2fea2df

Observation 1ff63302-8548-4a26-bae3-05156959092a · outbound

This paper cites The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents

Reference 33

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.263208Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.154924Z digest=sha256:1f864bab8aafe269510f6c01d30ec13c7870a9f095d565e2bc0ba82e06f74852

Observation d11472dd-044d-4900-b953-607a114f83cf · outbound

This paper cites Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.158456Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.158456Z digest=sha256:60a9c2c2a83b1e8c8a42a675139f5e4ca8ff498dc3c3b8d9b27f6d5e4be20c5d

Observation b8763d81-1b0f-432a-8070-936b747ebbee · outbound

This paper cites Do Coding Agents Understand Least-Privilege Authorization?.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Do Coding Agents Understand Least-Privilege Authorization?

Reference 35

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.249319Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.161803Z digest=sha256:2b5021617f247038cee20412fe75d8c47c3967fbf10a7e5c3c15f09924799905

Observation afc2c480-0158-4566-a2af-738301c2cfc6 · outbound

This paper cites Poskitt and Jun Sun , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Poskitt and Jun Sun , title =

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.560382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.165381Z digest=sha256:3f92309b596788996ccad31845207af66cb2d381bcbb5d519966d656397c5125

Observation 9507c2c8-4bcb-4209-9305-bc8766478b75 · outbound

This paper cites arXiv preprint arXiv:2603.20953 , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents arXiv preprint arXiv:2603.20953 , year =

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.168974Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.168974Z digest=sha256:edd19ec97f2ed77f60988efce2729a76873b0afade12194ac9779e6e32b638a5

Observation 488b57ee-d62f-4920-9e3f-555d9d1be740 · outbound

This paper cites Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.172245Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.172245Z digest=sha256:7bcf4e594c84fccd0014408f4b72dc00b54ae9b9b1dd4d0d1308a0dcf49f29f8

Observation 64c2d950-463b-454b-99b2-7d8d55e974cd · outbound

This paper cites arXiv preprint arXiv:2603.16586 , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents arXiv preprint arXiv:2603.16586 , year =

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.175452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.175452Z digest=sha256:a2b00bc525d38cc727bd100fc973a32c163aa04261a28aad1a81713604f85bd0

Observation fdc261ba-1e82-46d5-a9b2-c2aa5dc85c59 · outbound

This paper cites Intent-Governed Tool Authorization for AI Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Intent-Governed Tool Authorization for AI Agents

Reference 40

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.233895Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.178867Z digest=sha256:0b618abc706561b99e11acedaee5382b8596bd8564155508f1690fd6ea6ec92c

Observation b3f1c257-8c23-4208-ad9e-4c2310f8b43e · outbound

This paper cites When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents

Reference 41

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.447632Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.182040Z digest=sha256:cde279eab58f0231c4585a16139b2a9e794a6292541281e2e37449109effab67

Observation 1217cedd-1aae-45d6-8cb5-7b32995a9e36 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 42

Resolution
unresolved
raw_fallback, observed 2026-08-07T21:46:23.549537Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-21T06:32:19.484+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.185376Z digest=sha256:240c27bfad4abdfa0896cf36408d19e9705a5ca3dc465683e7e58bc51f9c1a13

Pith citing papers

No inbound Pith citation observations are available.