{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:BRMTLP6OB6NJL4XD5FAGYC2GHL","short_pith_number":"pith:BRMTLP6O","schema_version":"1.0","canonical_sha256":"0c5935bfce0f9a95f2e3e9406c0b463afd8d57514c2c7998e226dc915254042a","source":{"kind":"arxiv","id":"2309.10254","version":2},"attestation_state":"computed","paper":{"title":"LLM Platform Security: Applying a Systematic Evaluation Framework to OpenAI's ChatGPT Plugins","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CY","cs.LG"],"primary_cat":"cs.CR","authors_text":"Franziska Roesner, Tadayoshi Kohno, Umar Iqbal","submitted_at":"2023-09-19T02:20:10Z","abstract_excerpt":"Large language model (LLM) platforms, such as ChatGPT, have recently begun offering an app ecosystem to interface with third-party services on the internet. While these apps extend the capabilities of LLM platforms, they are developed by arbitrary third parties and thus cannot be implicitly trusted. Apps also interface with LLM platforms and users using natural language, which can have imprecise interpretations. In this paper, we propose a framework that lays a foundation for LLM platform designers to analyze and improve the security, privacy, and safety of current and future third-party integ"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2309.10254","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2023-09-19T02:20:10Z","cross_cats_sorted":["cs.AI","cs.CL","cs.CY","cs.LG"],"title_canon_sha256":"c9e3f224c5aed3c1fc0d2ccefedf3cf944a4a0823bb09a5cc21cc92aa25b34b7","abstract_canon_sha256":"de8e9f155a8d6664c188df20b5da33d5893df8d1afcbc6b2d196289d23105750"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:48:58.351366Z","signature_b64":"EghiVgl2bIHVhXOmSsHtqPxKoFoTESA7RLN4GLhRX0aMjeg4gWsHmoR/jqjieWq3caUaWnqdlLUQKPhk86SrBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0c5935bfce0f9a95f2e3e9406c0b463afd8d57514c2c7998e226dc915254042a","last_reissued_at":"2026-07-05T08:48:58.350953Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:48:58.350953Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"LLM Platform Security: Applying a Systematic Evaluation Framework to OpenAI's ChatGPT Plugins","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CY","cs.LG"],"primary_cat":"cs.CR","authors_text":"Franziska Roesner, Tadayoshi Kohno, Umar Iqbal","submitted_at":"2023-09-19T02:20:10Z","abstract_excerpt":"Large language model (LLM) platforms, such as ChatGPT, have recently begun offering an app ecosystem to interface with third-party services on the internet. While these apps extend the capabilities of LLM platforms, they are developed by arbitrary third parties and thus cannot be implicitly trusted. Apps also interface with LLM platforms and users using natural language, which can have imprecise interpretations. In this paper, we propose a framework that lays a foundation for LLM platform designers to analyze and improve the security, privacy, and safety of current and future third-party integ"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2309.10254","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2309.10254/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2309.10254","created_at":"2026-07-05T08:48:58.351007+00:00"},{"alias_kind":"arxiv_version","alias_value":"2309.10254v2","created_at":"2026-07-05T08:48:58.351007+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2309.10254","created_at":"2026-07-05T08:48:58.351007+00:00"},{"alias_kind":"pith_short_12","alias_value":"BRMTLP6OB6NJ","created_at":"2026-07-05T08:48:58.351007+00:00"},{"alias_kind":"pith_short_16","alias_value":"BRMTLP6OB6NJL4XD","created_at":"2026-07-05T08:48:58.351007+00:00"},{"alias_kind":"pith_short_8","alias_value":"BRMTLP6O","created_at":"2026-07-05T08:48:58.351007+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.23416","citing_title":"Detecting Malicious Agent Skills in the Wild using Attention","ref_index":18,"is_internal_anchor":false},{"citing_arxiv_id":"2504.20984","citing_title":"ACE: A Security Architecture for LLM-Integrated App Systems","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2605.00314","citing_title":"Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis","ref_index":15,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/BRMTLP6OB6NJL4XD5FAGYC2GHL","json":"https://pith.science/pith/BRMTLP6OB6NJL4XD5FAGYC2GHL.json","graph_json":"https://pith.science/api/pith-number/BRMTLP6OB6NJL4XD5FAGYC2GHL/graph.json","events_json":"https://pith.science/api/pith-number/BRMTLP6OB6NJL4XD5FAGYC2GHL/events.json","paper":"https://pith.science/paper/BRMTLP6O"},"agent_actions":{"view_html":"https://pith.science/pith/BRMTLP6OB6NJL4XD5FAGYC2GHL","download_json":"https://pith.science/pith/BRMTLP6OB6NJL4XD5FAGYC2GHL.json","view_paper":"https://pith.science/paper/BRMTLP6O","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2309.10254&json=true","fetch_graph":"https://pith.science/api/pith-number/BRMTLP6OB6NJL4XD5FAGYC2GHL/graph.json","fetch_events":"https://pith.science/api/pith-number/BRMTLP6OB6NJL4XD5FAGYC2GHL/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/BRMTLP6OB6NJL4XD5FAGYC2GHL/action/timestamp_anchor","attest_storage":"https://pith.science/pith/BRMTLP6OB6NJL4XD5FAGYC2GHL/action/storage_attestation","attest_author":"https://pith.science/pith/BRMTLP6OB6NJL4XD5FAGYC2GHL/action/author_attestation","sign_citation":"https://pith.science/pith/BRMTLP6OB6NJL4XD5FAGYC2GHL/action/citation_signature","submit_replication":"https://pith.science/pith/BRMTLP6OB6NJL4XD5FAGYC2GHL/action/replication_record"}},"created_at":"2026-07-05T08:48:58.351007+00:00","updated_at":"2026-07-05T08:48:58.351007+00:00"}