{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:B5VW62PTP6Y2XCECOX4ESZ3BVG","short_pith_number":"pith:B5VW62PT","schema_version":"1.0","canonical_sha256":"0f6b6f69f37fb1ab888275f8496761a9a74ac02eb4cb154a54bb0d2a365d24ec","source":{"kind":"arxiv","id":"2506.13666","version":1},"attestation_state":"computed","paper":{"title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Haokai Ma, Junfeng Fang, Ruipeng Wang, Tat-Seng Chua, Xiang Wang, Zijun Yao","submitted_at":"2025-06-16T16:24:31Z","abstract_excerpt":"The development of large language models (LLMs) has entered in a experience-driven era, flagged by the emergence of environment feedback-driven learning via reinforcement learning and tool-using agents. This encourages the emergenece of model context protocol (MCP), which defines the standard on how should a LLM interact with external services, such as \\api and data. However, as MCP becomes the de facto standard for LLM agent systems, it also introduces new safety risks. In particular, MCP introduces third-party services, which are not controlled by the LLM developers, into the agent systems. "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2506.13666","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2025-06-16T16:24:31Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"59667ae0517a8d4427135e8d838cc7a0a10b74b993653dbbfdd54667136decd5","abstract_canon_sha256":"3525d7b5d1f4466428167ff5403b6ebd3fe2434bc18649b2642f40e277c2c9cc"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:22:24.558365Z","signature_b64":"4hpbK1Gombx9Hb34yWRa5nkpTVW9L5BGi+GMjRqweVTQAjafiNLxmF8GL9UPZs8WlzZOMs+6pQheW40qbG+RAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0f6b6f69f37fb1ab888275f8496761a9a74ac02eb4cb154a54bb0d2a365d24ec","last_reissued_at":"2026-07-05T11:22:24.557793Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:22:24.557793Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Haokai Ma, Junfeng Fang, Ruipeng Wang, Tat-Seng Chua, Xiang Wang, Zijun Yao","submitted_at":"2025-06-16T16:24:31Z","abstract_excerpt":"The development of large language models (LLMs) has entered in a experience-driven era, flagged by the emergence of environment feedback-driven learning via reinforcement learning and tool-using agents. This encourages the emergenece of model context protocol (MCP), which defines the standard on how should a LLM interact with external services, such as \\api and data. However, as MCP becomes the de facto standard for LLM agent systems, it also introduces new safety risks. In particular, MCP introduces third-party services, which are not controlled by the LLM developers, into the agent systems. "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.13666","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.13666/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2506.13666","created_at":"2026-07-05T11:22:24.557852+00:00"},{"alias_kind":"arxiv_version","alias_value":"2506.13666v1","created_at":"2026-07-05T11:22:24.557852+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.13666","created_at":"2026-07-05T11:22:24.557852+00:00"},{"alias_kind":"pith_short_12","alias_value":"B5VW62PTP6Y2","created_at":"2026-07-05T11:22:24.557852+00:00"},{"alias_kind":"pith_short_16","alias_value":"B5VW62PTP6Y2XCEC","created_at":"2026-07-05T11:22:24.557852+00:00"},{"alias_kind":"pith_short_8","alias_value":"B5VW62PT","created_at":"2026-07-05T11:22:24.557852+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.21338","citing_title":"\"What Happens Locally, Leaks Globally\": Detecting Privacy Leakage Risks in MCP Servers","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2604.01905","citing_title":"From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers","ref_index":16,"is_internal_anchor":false},{"citing_arxiv_id":"2510.21236","citing_title":"AgentBound: Securing Execution Boundaries of AI Agents","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2507.13334","citing_title":"A Survey of Context Engineering for Large Language Models","ref_index":268,"is_internal_anchor":false},{"citing_arxiv_id":"2604.07551","citing_title":"MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security","ref_index":10,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/B5VW62PTP6Y2XCECOX4ESZ3BVG","json":"https://pith.science/pith/B5VW62PTP6Y2XCECOX4ESZ3BVG.json","graph_json":"https://pith.science/api/pith-number/B5VW62PTP6Y2XCECOX4ESZ3BVG/graph.json","events_json":"https://pith.science/api/pith-number/B5VW62PTP6Y2XCECOX4ESZ3BVG/events.json","paper":"https://pith.science/paper/B5VW62PT"},"agent_actions":{"view_html":"https://pith.science/pith/B5VW62PTP6Y2XCECOX4ESZ3BVG","download_json":"https://pith.science/pith/B5VW62PTP6Y2XCECOX4ESZ3BVG.json","view_paper":"https://pith.science/paper/B5VW62PT","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2506.13666&json=true","fetch_graph":"https://pith.science/api/pith-number/B5VW62PTP6Y2XCECOX4ESZ3BVG/graph.json","fetch_events":"https://pith.science/api/pith-number/B5VW62PTP6Y2XCECOX4ESZ3BVG/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/B5VW62PTP6Y2XCECOX4ESZ3BVG/action/timestamp_anchor","attest_storage":"https://pith.science/pith/B5VW62PTP6Y2XCECOX4ESZ3BVG/action/storage_attestation","attest_author":"https://pith.science/pith/B5VW62PTP6Y2XCECOX4ESZ3BVG/action/author_attestation","sign_citation":"https://pith.science/pith/B5VW62PTP6Y2XCECOX4ESZ3BVG/action/citation_signature","submit_replication":"https://pith.science/pith/B5VW62PTP6Y2XCECOX4ESZ3BVG/action/replication_record"}},"created_at":"2026-07-05T11:22:24.557852+00:00","updated_at":"2026-07-05T11:22:24.557852+00:00"}