{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:6FTGK7YXWDN2YEN4IATTQGJO2I","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"57766ba333d69c2b77c76ab470f5ab07b4bcdcf70b7d6795bdfe3d82a40f1ed7","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-25T13:35:28Z","title_canon_sha256":"5ae9c82cfb81ad643993ea187c0e8ead12e165a39eeaa05dcf7127a09bf4551f"},"schema_version":"1.0","source":{"id":"2606.27027","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.27027","created_at":"2026-06-26T01:16:07Z"},{"alias_kind":"arxiv_version","alias_value":"2606.27027v1","created_at":"2026-06-26T01:16:07Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.27027","created_at":"2026-06-26T01:16:07Z"},{"alias_kind":"pith_short_12","alias_value":"6FTGK7YXWDN2","created_at":"2026-06-26T01:16:07Z"},{"alias_kind":"pith_short_16","alias_value":"6FTGK7YXWDN2YEN4","created_at":"2026-06-26T01:16:07Z"},{"alias_kind":"pith_short_8","alias_value":"6FTGK7YX","created_at":"2026-06-26T01:16:07Z"}],"graph_snapshots":[{"event_id":"sha256:efead3cb2be0d6c01cdfa678c966cfa55e6385c96ab8a027251346fa60b28364","target":"graph","created_at":"2026-06-26T01:16:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.27027/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"With the rapid evolution of LLM-driven agents, Model Context Protocol (MCP), an open protocol bridging LLMs with external tools, has quickly become foundational to modern agent ecosystems. However, the expanding adoption of MCP has also introduced novel security concerns such as Tool Poisoning Attack (TPA), which exploit LLM-server interactions to inject malicious prompts. Existing poisoning schemes typically adopt a monolithic plaintext embedding paradigm, which fails to withstand manual inspection or automated detectors. Current research still lacks a systematic analysis on multi-tool poison","authors_text":"Liwei Liu, Na Ruan, Tianzhu Han, Zijian Liu, Zishu Dong","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-25T13:35:28Z","title":"ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.27027","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:3c45026666e96d269f52c25fc9a4149f2423eae0d3c4ce1ae90875d5b5a7542b","target":"record","created_at":"2026-06-26T01:16:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"57766ba333d69c2b77c76ab470f5ab07b4bcdcf70b7d6795bdfe3d82a40f1ed7","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-25T13:35:28Z","title_canon_sha256":"5ae9c82cfb81ad643993ea187c0e8ead12e165a39eeaa05dcf7127a09bf4551f"},"schema_version":"1.0","source":{"id":"2606.27027","kind":"arxiv","version":1}},"canonical_sha256":"f166657f17b0dbac11bc402738192ed218631635f19693ff22e4f852326935ba","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f166657f17b0dbac11bc402738192ed218631635f19693ff22e4f852326935ba","first_computed_at":"2026-06-26T01:16:07.413526Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-26T01:16:07.413526Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"fjcoSsGiQf04fr9NUDgyTScXTHLMKUGiDm2XiH/0rpTO+R/nQ3CCodnninEQh473BZ1R3fZYB1h7ynuRjoqVDQ==","signature_status":"signed_v1","signed_at":"2026-06-26T01:16:07.413953Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.27027","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:3c45026666e96d269f52c25fc9a4149f2423eae0d3c4ce1ae90875d5b5a7542b","sha256:efead3cb2be0d6c01cdfa678c966cfa55e6385c96ab8a027251346fa60b28364"],"state_sha256":"37fa9df0b8e7cee896b9a0c914be68f77b08f9714a7105311a6f7bd84d8b40d6"}