{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:II6EHVHNMK5U6DWK7LOZRFVNNL","short_pith_number":"pith:II6EHVHN","schema_version":"1.0","canonical_sha256":"423c43d4ed62bb4f0ecafadd9896ad6ae6f1bb8ba76cd4b042413af6e64fb08f","source":{"kind":"arxiv","id":"2601.21233","version":2},"attestation_state":"computed","paper":{"title":"Just Ask: Curious Code Agents Reveal System Prompts in Frontier LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"Bo Li, Cong Wang, Hanxun Huang, Xiang Zheng, Xingjun Ma, Yige Li, Yu-Gang Jiang, Yutao Wu","submitted_at":"2026-01-29T03:53:25Z","abstract_excerpt":"Autonomous code agents built on large language models are reshaping software and AI development through tool use, long-horizon reasoning, and self-directed interaction. However, this autonomy introduces a previously unrecognized security risk: agentic interaction fundamentally expands the LLM attack surface, enabling systematic probing and recovery of hidden system prompts that guide model behavior. We identify system prompt extraction as an emergent vulnerability intrinsic to code agents and present \\textbf{\\textsc{JustAsk}}, a self-evolving framework that autonomously discovers effective ext"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2601.21233","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-01-29T03:53:25Z","cross_cats_sorted":[],"title_canon_sha256":"d7daf8f8d39f27ec36754b3429229e27bac9d596cf1971d5f0e662a25dd089a4","abstract_canon_sha256":"10638c1ea3b32a8c8b1a67c15f4478df8b2689f030caea6abd35e4f0d5add471"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-29T01:14:28.377045Z","signature_b64":"8xtFGDR1oVI9EaPVJAMzkSqvG/0iR0tW5aHWTwCcNf8G8FRz/DvBxh7ltkJYHT0cFM7fAmxr+j0TC+irQFDvDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"423c43d4ed62bb4f0ecafadd9896ad6ae6f1bb8ba76cd4b042413af6e64fb08f","last_reissued_at":"2026-06-29T01:14:28.376544Z","signature_status":"signed_v1","first_computed_at":"2026-06-29T01:14:28.376544Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Just Ask: Curious Code Agents Reveal System Prompts in Frontier LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"Bo Li, Cong Wang, Hanxun Huang, Xiang Zheng, Xingjun Ma, Yige Li, Yu-Gang Jiang, Yutao Wu","submitted_at":"2026-01-29T03:53:25Z","abstract_excerpt":"Autonomous code agents built on large language models are reshaping software and AI development through tool use, long-horizon reasoning, and self-directed interaction. However, this autonomy introduces a previously unrecognized security risk: agentic interaction fundamentally expands the LLM attack surface, enabling systematic probing and recovery of hidden system prompts that guide model behavior. We identify system prompt extraction as an emergent vulnerability intrinsic to code agents and present \\textbf{\\textsc{JustAsk}}, a self-evolving framework that autonomously discovers effective ext"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2601.21233","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2601.21233/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2601.21233","created_at":"2026-06-29T01:14:28.376603+00:00"},{"alias_kind":"arxiv_version","alias_value":"2601.21233v2","created_at":"2026-06-29T01:14:28.376603+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2601.21233","created_at":"2026-06-29T01:14:28.376603+00:00"},{"alias_kind":"pith_short_12","alias_value":"II6EHVHNMK5U","created_at":"2026-06-29T01:14:28.376603+00:00"},{"alias_kind":"pith_short_16","alias_value":"II6EHVHNMK5U6DWK","created_at":"2026-06-29T01:14:28.376603+00:00"},{"alias_kind":"pith_short_8","alias_value":"II6EHVHN","created_at":"2026-06-29T01:14:28.376603+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL","json":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL.json","graph_json":"https://pith.science/api/pith-number/II6EHVHNMK5U6DWK7LOZRFVNNL/graph.json","events_json":"https://pith.science/api/pith-number/II6EHVHNMK5U6DWK7LOZRFVNNL/events.json","paper":"https://pith.science/paper/II6EHVHN"},"agent_actions":{"view_html":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL","download_json":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL.json","view_paper":"https://pith.science/paper/II6EHVHN","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2601.21233&json=true","fetch_graph":"https://pith.science/api/pith-number/II6EHVHNMK5U6DWK7LOZRFVNNL/graph.json","fetch_events":"https://pith.science/api/pith-number/II6EHVHNMK5U6DWK7LOZRFVNNL/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/action/timestamp_anchor","attest_storage":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/action/storage_attestation","attest_author":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/action/author_attestation","sign_citation":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/action/citation_signature","submit_replication":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/action/replication_record"}},"created_at":"2026-06-29T01:14:28.376603+00:00","updated_at":"2026-06-29T01:14:28.376603+00:00"}