{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:II6EHVHNMK5U6DWK7LOZRFVNNL","short_pith_number":"pith:II6EHVHN","canonical_record":{"source":{"id":"2601.21233","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-01-29T03:53:25Z","cross_cats_sorted":[],"title_canon_sha256":"d7daf8f8d39f27ec36754b3429229e27bac9d596cf1971d5f0e662a25dd089a4","abstract_canon_sha256":"10638c1ea3b32a8c8b1a67c15f4478df8b2689f030caea6abd35e4f0d5add471"},"schema_version":"1.0"},"canonical_sha256":"423c43d4ed62bb4f0ecafadd9896ad6ae6f1bb8ba76cd4b042413af6e64fb08f","source":{"kind":"arxiv","id":"2601.21233","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2601.21233","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"arxiv_version","alias_value":"2601.21233v2","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2601.21233","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"pith_short_12","alias_value":"II6EHVHNMK5U","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"pith_short_16","alias_value":"II6EHVHNMK5U6DWK","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"pith_short_8","alias_value":"II6EHVHN","created_at":"2026-06-29T01:14:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:II6EHVHNMK5U6DWK7LOZRFVNNL","target":"record","payload":{"canonical_record":{"source":{"id":"2601.21233","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-01-29T03:53:25Z","cross_cats_sorted":[],"title_canon_sha256":"d7daf8f8d39f27ec36754b3429229e27bac9d596cf1971d5f0e662a25dd089a4","abstract_canon_sha256":"10638c1ea3b32a8c8b1a67c15f4478df8b2689f030caea6abd35e4f0d5add471"},"schema_version":"1.0"},"canonical_sha256":"423c43d4ed62bb4f0ecafadd9896ad6ae6f1bb8ba76cd4b042413af6e64fb08f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-29T01:14:28.377045Z","signature_b64":"8xtFGDR1oVI9EaPVJAMzkSqvG/0iR0tW5aHWTwCcNf8G8FRz/DvBxh7ltkJYHT0cFM7fAmxr+j0TC+irQFDvDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"423c43d4ed62bb4f0ecafadd9896ad6ae6f1bb8ba76cd4b042413af6e64fb08f","last_reissued_at":"2026-06-29T01:14:28.376544Z","signature_status":"signed_v1","first_computed_at":"2026-06-29T01:14:28.376544Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2601.21233","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-29T01:14:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+1IbCbn+p1mjQswVwYOO2ahlGpPZiiWj74KqEiAb88SS5zxa/uOt14bu92vhrBTiAHEVdezeiu0m+n17JZSEAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-01T21:05:41.708443Z"},"content_sha256":"5f55d84af081a4a74b12f86161b7beb10d703950e2b5bdd4cea3e6e21db1a785","schema_version":"1.0","event_id":"sha256:5f55d84af081a4a74b12f86161b7beb10d703950e2b5bdd4cea3e6e21db1a785"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:II6EHVHNMK5U6DWK7LOZRFVNNL","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Just Ask: Curious Code Agents Reveal System Prompts in Frontier LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"Bo Li, Cong Wang, Hanxun Huang, Xiang Zheng, Xingjun Ma, Yige Li, Yu-Gang Jiang, Yutao Wu","submitted_at":"2026-01-29T03:53:25Z","abstract_excerpt":"Autonomous code agents built on large language models are reshaping software and AI development through tool use, long-horizon reasoning, and self-directed interaction. However, this autonomy introduces a previously unrecognized security risk: agentic interaction fundamentally expands the LLM attack surface, enabling systematic probing and recovery of hidden system prompts that guide model behavior. We identify system prompt extraction as an emergent vulnerability intrinsic to code agents and present \\textbf{\\textsc{JustAsk}}, a self-evolving framework that autonomously discovers effective ext"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2601.21233","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2601.21233/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-29T01:14:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"g5FGNNktAmBAybgSI5Ut4sNtjClvAnwhp2ltn2WjUudpYmbRVDgMcXLaUlcrEsLTtoAh8jRzA7VquB883YOPDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-01T21:05:41.708820Z"},"content_sha256":"5782e22eaeafb3b08e7fc164931ffdfcbab0fc3c839d9b6e9b4eb3303006b4d0","schema_version":"1.0","event_id":"sha256:5782e22eaeafb3b08e7fc164931ffdfcbab0fc3c839d9b6e9b4eb3303006b4d0"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/bundle.json","state_url":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-01T21:05:41Z","links":{"resolver":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL","bundle":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/bundle.json","state":"https://pith.science/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/state.json","well_known_bundle":"https://pith.science/.well-known/pith/II6EHVHNMK5U6DWK7LOZRFVNNL/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:II6EHVHNMK5U6DWK7LOZRFVNNL","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"10638c1ea3b32a8c8b1a67c15f4478df8b2689f030caea6abd35e4f0d5add471","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-01-29T03:53:25Z","title_canon_sha256":"d7daf8f8d39f27ec36754b3429229e27bac9d596cf1971d5f0e662a25dd089a4"},"schema_version":"1.0","source":{"id":"2601.21233","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2601.21233","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"arxiv_version","alias_value":"2601.21233v2","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2601.21233","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"pith_short_12","alias_value":"II6EHVHNMK5U","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"pith_short_16","alias_value":"II6EHVHNMK5U6DWK","created_at":"2026-06-29T01:14:28Z"},{"alias_kind":"pith_short_8","alias_value":"II6EHVHN","created_at":"2026-06-29T01:14:28Z"}],"graph_snapshots":[{"event_id":"sha256:5782e22eaeafb3b08e7fc164931ffdfcbab0fc3c839d9b6e9b4eb3303006b4d0","target":"graph","created_at":"2026-06-29T01:14:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2601.21233/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Autonomous code agents built on large language models are reshaping software and AI development through tool use, long-horizon reasoning, and self-directed interaction. However, this autonomy introduces a previously unrecognized security risk: agentic interaction fundamentally expands the LLM attack surface, enabling systematic probing and recovery of hidden system prompts that guide model behavior. We identify system prompt extraction as an emergent vulnerability intrinsic to code agents and present \\textbf{\\textsc{JustAsk}}, a self-evolving framework that autonomously discovers effective ext","authors_text":"Bo Li, Cong Wang, Hanxun Huang, Xiang Zheng, Xingjun Ma, Yige Li, Yu-Gang Jiang, Yutao Wu","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-01-29T03:53:25Z","title":"Just Ask: Curious Code Agents Reveal System Prompts in Frontier LLMs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2601.21233","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5f55d84af081a4a74b12f86161b7beb10d703950e2b5bdd4cea3e6e21db1a785","target":"record","created_at":"2026-06-29T01:14:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"10638c1ea3b32a8c8b1a67c15f4478df8b2689f030caea6abd35e4f0d5add471","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-01-29T03:53:25Z","title_canon_sha256":"d7daf8f8d39f27ec36754b3429229e27bac9d596cf1971d5f0e662a25dd089a4"},"schema_version":"1.0","source":{"id":"2601.21233","kind":"arxiv","version":2}},"canonical_sha256":"423c43d4ed62bb4f0ecafadd9896ad6ae6f1bb8ba76cd4b042413af6e64fb08f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"423c43d4ed62bb4f0ecafadd9896ad6ae6f1bb8ba76cd4b042413af6e64fb08f","first_computed_at":"2026-06-29T01:14:28.376544Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-29T01:14:28.376544Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"8xtFGDR1oVI9EaPVJAMzkSqvG/0iR0tW5aHWTwCcNf8G8FRz/DvBxh7ltkJYHT0cFM7fAmxr+j0TC+irQFDvDg==","signature_status":"signed_v1","signed_at":"2026-06-29T01:14:28.377045Z","signed_message":"canonical_sha256_bytes"},"source_id":"2601.21233","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5f55d84af081a4a74b12f86161b7beb10d703950e2b5bdd4cea3e6e21db1a785","sha256:5782e22eaeafb3b08e7fc164931ffdfcbab0fc3c839d9b6e9b4eb3303006b4d0"],"state_sha256":"c72bd9145c4185b651a122d8335bbae4ebd09f3bef8a6c49cf22d46a273173c7"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2sQbDwuR0iFqrf6Sou1pC/qUlpLF+l7YK1OVdOXYS3lQ8DoNdo2Bjpsn7Qpwh8X20vbU7f6F4VQmcZA3p5ajDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-01T21:05:41.710834Z","bundle_sha256":"073dc38687c2e37f64234e8d50c19aa89f284fcd4ceb3b0fb04757ce0ecc530f"}}