{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:EBMLSOKGHDS7KPYAMBB3TK5KR4","short_pith_number":"pith:EBMLSOKG","schema_version":"1.0","canonical_sha256":"2058b9394638e5f53f006043b9abaa8f2d7dd06c5761281b92142fc63061305f","source":{"kind":"arxiv","id":"2507.02699","version":1},"attestation_state":"computed","paper":{"title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Jiangrong Wu, Jianliang Wu, Yuhong Nan, Zibin Zheng, Zitong Yao","submitted_at":"2025-07-03T15:09:40Z","abstract_excerpt":"The increasing capabilities of LLMs have led to the rapid proliferation of LLM agent apps, where developers enhance LLMs with access to external resources to support complex task execution. Among these, LLM email agent apps represent one of the widely used categories, as email remains a critical communication medium for users. LLM email agents are capable of managing and responding to email using LLM-driven reasoning and autonomously executing user instructions via external email APIs (e.g., send email). However, despite their growing deployment and utility, the security mechanism of LLM email"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2507.02699","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-07-03T15:09:40Z","cross_cats_sorted":[],"title_canon_sha256":"2b265790c340f9d1d782ec8b0f95e1a61b85fc626f9e72ab00e7d0680be50c6f","abstract_canon_sha256":"9a21ad48b6291d9157516d87f1836c0088e012c31677f2ffb64fe2da14d03793"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:31:33.364334Z","signature_b64":"npgu0xN8OvD6uzNy2MFRloDF5Q4r0zjDr1efn6QIxJabjnkx3yZePt2RALJqE614z2Y/ZCkmlEZ0sWGqZ2BxAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2058b9394638e5f53f006043b9abaa8f2d7dd06c5761281b92142fc63061305f","last_reissued_at":"2026-07-05T11:31:33.363946Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:31:33.363946Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Jiangrong Wu, Jianliang Wu, Yuhong Nan, Zibin Zheng, Zitong Yao","submitted_at":"2025-07-03T15:09:40Z","abstract_excerpt":"The increasing capabilities of LLMs have led to the rapid proliferation of LLM agent apps, where developers enhance LLMs with access to external resources to support complex task execution. Among these, LLM email agent apps represent one of the widely used categories, as email remains a critical communication medium for users. LLM email agents are capable of managing and responding to email using LLM-driven reasoning and autonomously executing user instructions via external email APIs (e.g., send email). However, despite their growing deployment and utility, the security mechanism of LLM email"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.02699","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.02699/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2507.02699","created_at":"2026-07-05T11:31:33.364007+00:00"},{"alias_kind":"arxiv_version","alias_value":"2507.02699v1","created_at":"2026-07-05T11:31:33.364007+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.02699","created_at":"2026-07-05T11:31:33.364007+00:00"},{"alias_kind":"pith_short_12","alias_value":"EBMLSOKGHDS7","created_at":"2026-07-05T11:31:33.364007+00:00"},{"alias_kind":"pith_short_16","alias_value":"EBMLSOKGHDS7KPYA","created_at":"2026-07-05T11:31:33.364007+00:00"},{"alias_kind":"pith_short_8","alias_value":"EBMLSOKG","created_at":"2026-07-05T11:31:33.364007+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.17830","citing_title":"Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents","ref_index":24,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/EBMLSOKGHDS7KPYAMBB3TK5KR4","json":"https://pith.science/pith/EBMLSOKGHDS7KPYAMBB3TK5KR4.json","graph_json":"https://pith.science/api/pith-number/EBMLSOKGHDS7KPYAMBB3TK5KR4/graph.json","events_json":"https://pith.science/api/pith-number/EBMLSOKGHDS7KPYAMBB3TK5KR4/events.json","paper":"https://pith.science/paper/EBMLSOKG"},"agent_actions":{"view_html":"https://pith.science/pith/EBMLSOKGHDS7KPYAMBB3TK5KR4","download_json":"https://pith.science/pith/EBMLSOKGHDS7KPYAMBB3TK5KR4.json","view_paper":"https://pith.science/paper/EBMLSOKG","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2507.02699&json=true","fetch_graph":"https://pith.science/api/pith-number/EBMLSOKGHDS7KPYAMBB3TK5KR4/graph.json","fetch_events":"https://pith.science/api/pith-number/EBMLSOKGHDS7KPYAMBB3TK5KR4/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/EBMLSOKGHDS7KPYAMBB3TK5KR4/action/timestamp_anchor","attest_storage":"https://pith.science/pith/EBMLSOKGHDS7KPYAMBB3TK5KR4/action/storage_attestation","attest_author":"https://pith.science/pith/EBMLSOKGHDS7KPYAMBB3TK5KR4/action/author_attestation","sign_citation":"https://pith.science/pith/EBMLSOKGHDS7KPYAMBB3TK5KR4/action/citation_signature","submit_replication":"https://pith.science/pith/EBMLSOKGHDS7KPYAMBB3TK5KR4/action/replication_record"}},"created_at":"2026-07-05T11:31:33.364007+00:00","updated_at":"2026-07-05T11:31:33.364007+00:00"}