{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:FGL563RZDIHQNOBDIO47VS2EQX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"99b9f76eede9a50b12dba6f006a3bf5d7879c1bd7a22757408fdeca17b8b1ede","cross_cats_sorted":["cs.PL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-27T15:27:25Z","title_canon_sha256":"f10991904f207e010151e63f19622bb0af02eae1f1093cd75bc26b57ac347c0c"},"schema_version":"1.0","source":{"id":"2605.28617","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.28617","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"arxiv_version","alias_value":"2605.28617v1","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.28617","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"pith_short_12","alias_value":"FGL563RZDIHQ","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"pith_short_16","alias_value":"FGL563RZDIHQNOBD","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"pith_short_8","alias_value":"FGL563RZ","created_at":"2026-05-28T02:04:57Z"}],"graph_snapshots":[{"event_id":"sha256:cd44d174d885e8608d6cf63b83de3cb1804219db4b5014fd8d7e96395ce5b601","target":"graph","created_at":"2026-05-28T02:04:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.28617/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"LLM agents increasingly act by writing code, yet a split persists between the runtime that drives the agent and the code the model writes. The runtime owns the loop, context, and control flow, and the model has little say over any of them. Letting model-written code shape the runtime itself would make agents more expressive, but it would also sharpen safety problems. A model can be diverted by a prompt injection, call the wrong tool, or fail partway and leave an inconsistent state, and each such failure reaches further when the code shapes the runtime than when it expresses a single action. We","authors_text":"Cao Nguyen Pham, Frank Zhengqing Wu, Martin Odersky, Oliver Bra\\v{c}evac, Yaoyu Zhao, Yichen Xu","cross_cats":["cs.PL"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-27T15:27:25Z","title":"LACUNA: Safe Agents as Recursive Program Holes"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.28617","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:52992711d35501c1112a504beaa0bd535a82d4b5bae6ba53e00142dd6c2d4ee3","target":"record","created_at":"2026-05-28T02:04:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"99b9f76eede9a50b12dba6f006a3bf5d7879c1bd7a22757408fdeca17b8b1ede","cross_cats_sorted":["cs.PL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-27T15:27:25Z","title_canon_sha256":"f10991904f207e010151e63f19622bb0af02eae1f1093cd75bc26b57ac347c0c"},"schema_version":"1.0","source":{"id":"2605.28617","kind":"arxiv","version":1}},"canonical_sha256":"2997df6e391a0f06b82343b9facb4485e1c7a892fea48c6f18616bd7fcfc0e79","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2997df6e391a0f06b82343b9facb4485e1c7a892fea48c6f18616bd7fcfc0e79","first_computed_at":"2026-05-28T02:04:57.875909Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-28T02:04:57.875909Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Dvvsaqe62LFYe48idi+73G6QEZKJWv12YWlGEtlSLLgx26LMrOQ8ElR5/4NJn91tB2iRtQUDC1/DpeL2havZCA==","signature_status":"signed_v1","signed_at":"2026-05-28T02:04:57.876368Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.28617","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:52992711d35501c1112a504beaa0bd535a82d4b5bae6ba53e00142dd6c2d4ee3","sha256:cd44d174d885e8608d6cf63b83de3cb1804219db4b5014fd8d7e96395ce5b601"],"state_sha256":"269400055e15bff41fc0efd45752990d80831dff9762b9ed3166270a58af1d3a"}