{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:57FCLJVJ2ZQWW7M6SIAJIVBF4V","short_pith_number":"pith:57FCLJVJ","schema_version":"1.0","canonical_sha256":"efca25a6a9d6616b7d9e9200945425e5465152aa45286af9339495956d2b8a0e","source":{"kind":"arxiv","id":"2607.02873","version":1},"attestation_state":"computed","paper":{"title":"Determinants and Limits of LLM Security-Tool Orchestration: A Study with HexStrike-AI","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.SE","authors_text":"Assmaa Zeghaider, Romain Gerard, Yan Guo","submitted_at":"2026-07-03T02:20:04Z","abstract_excerpt":"Large language model agents driving security tool suites over the Model Context Protocol are increasingly common. Yet the factors that bound their capability remain poorly characterized: how much depends on the model versus the client that drives it, whether constraining the agent to the orchestrator's own tools helps, and where capability is limited by reasoning rather than by missing tools. Using HexStrikeAI, an open-source orchestrator that exposes 150+ tools, as a testbed, we follow a methodology that evaluates the system, diagnoses its failures, and applies targeted improvements. We run 8"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2607.02873","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.SE","submitted_at":"2026-07-03T02:20:04Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"5094187745637258a2bc41ad26e58b1114ebeb6fa004d18c7fbc505b31fe74f0","abstract_canon_sha256":"11401872b8f84226c5b8c2bbda99a802e347c82cefb2e558d52160dda47acfeb"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-07T01:16:35.019025Z","signature_b64":"zNiNM9EIW7ge5l1kS4UM2gZy218mxx8Mob6DYyK3K3VvL2GsA+xuB1jWdt2L/CYOLknVgaSU5xu8pXKUftHhAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"efca25a6a9d6616b7d9e9200945425e5465152aa45286af9339495956d2b8a0e","last_reissued_at":"2026-07-07T01:16:35.018505Z","signature_status":"signed_v1","first_computed_at":"2026-07-07T01:16:35.018505Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Determinants and Limits of LLM Security-Tool Orchestration: A Study with HexStrike-AI","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.SE","authors_text":"Assmaa Zeghaider, Romain Gerard, Yan Guo","submitted_at":"2026-07-03T02:20:04Z","abstract_excerpt":"Large language model agents driving security tool suites over the Model Context Protocol are increasingly common. Yet the factors that bound their capability remain poorly characterized: how much depends on the model versus the client that drives it, whether constraining the agent to the orchestrator's own tools helps, and where capability is limited by reasoning rather than by missing tools. Using HexStrikeAI, an open-source orchestrator that exposes 150+ tools, as a testbed, we follow a methodology that evaluates the system, diagnoses its failures, and applies targeted improvements. We run 8"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.02873","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2607.02873/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2607.02873","created_at":"2026-07-07T01:16:35.018571+00:00"},{"alias_kind":"arxiv_version","alias_value":"2607.02873v1","created_at":"2026-07-07T01:16:35.018571+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.02873","created_at":"2026-07-07T01:16:35.018571+00:00"},{"alias_kind":"pith_short_12","alias_value":"57FCLJVJ2ZQW","created_at":"2026-07-07T01:16:35.018571+00:00"},{"alias_kind":"pith_short_16","alias_value":"57FCLJVJ2ZQWW7M6","created_at":"2026-07-07T01:16:35.018571+00:00"},{"alias_kind":"pith_short_8","alias_value":"57FCLJVJ","created_at":"2026-07-07T01:16:35.018571+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/57FCLJVJ2ZQWW7M6SIAJIVBF4V","json":"https://pith.science/pith/57FCLJVJ2ZQWW7M6SIAJIVBF4V.json","graph_json":"https://pith.science/api/pith-number/57FCLJVJ2ZQWW7M6SIAJIVBF4V/graph.json","events_json":"https://pith.science/api/pith-number/57FCLJVJ2ZQWW7M6SIAJIVBF4V/events.json","paper":"https://pith.science/paper/57FCLJVJ"},"agent_actions":{"view_html":"https://pith.science/pith/57FCLJVJ2ZQWW7M6SIAJIVBF4V","download_json":"https://pith.science/pith/57FCLJVJ2ZQWW7M6SIAJIVBF4V.json","view_paper":"https://pith.science/paper/57FCLJVJ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2607.02873&json=true","fetch_graph":"https://pith.science/api/pith-number/57FCLJVJ2ZQWW7M6SIAJIVBF4V/graph.json","fetch_events":"https://pith.science/api/pith-number/57FCLJVJ2ZQWW7M6SIAJIVBF4V/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/57FCLJVJ2ZQWW7M6SIAJIVBF4V/action/timestamp_anchor","attest_storage":"https://pith.science/pith/57FCLJVJ2ZQWW7M6SIAJIVBF4V/action/storage_attestation","attest_author":"https://pith.science/pith/57FCLJVJ2ZQWW7M6SIAJIVBF4V/action/author_attestation","sign_citation":"https://pith.science/pith/57FCLJVJ2ZQWW7M6SIAJIVBF4V/action/citation_signature","submit_replication":"https://pith.science/pith/57FCLJVJ2ZQWW7M6SIAJIVBF4V/action/replication_record"}},"created_at":"2026-07-07T01:16:35.018571+00:00","updated_at":"2026-07-07T01:16:35.018571+00:00"}