{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:SKDQ3O5SHZ7VIYKUFS2GS2WAJP","short_pith_number":"pith:SKDQ3O5S","schema_version":"1.0","canonical_sha256":"92870dbbb23e7f5461542cb4696ac04bf9318fb4357bec18f05b4b1ecaf9f31b","source":{"kind":"arxiv","id":"2509.25624","version":3},"attestation_state":"computed","paper":{"title":"STAC: When Innocent Tools Form Dangerous Chains for LLM Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Chao Shang, Devang Kulshreshtha, Hang Su, Jianfeng He, Jing-Jing Li, Sandesh Swamy, Xun Xian, Yanjun Qi, Yi Zhang","submitted_at":"2025-09-30T00:31:44Z","abstract_excerpt":"As LLMs advance into autonomous agents with tool-use capabilities, they introduce security challenges that extend beyond traditional content-based LLM safety concerns. This paper introduces Sequential Tool Attack Chaining (\\STAC), a novel multi-turn attack framework that exploits agent tool use. \\STAC chains together tool calls that each appear harmless in isolation but, when combined, collectively enable harmful operations that only become apparent at the final execution step. At the core of \\STAC is an automated, closed-loop pipeline that synthesizes executable multi-step tool chains, valida"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2509.25624","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-09-30T00:31:44Z","cross_cats_sorted":["cs.AI","cs.CL","cs.LG"],"title_canon_sha256":"001ae28bcec3bcc52e0cba3a1c58a15b8c3f466a9da69c85581b42645f5165b4","abstract_canon_sha256":"788a16a8a28eb9a951ebdc643975a1331b7b1ad0298ad5cfbc527358b25cd9d3"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-21T01:20:37.540418Z","signature_b64":"PhDk8tsH3hWxvmP3KnFDqQ1CSq1qQujhXXUmdnYkgAGF/b5VRfnnUUFeapv7P2F+k/uQvPad2CJZSTYkA9qEAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"92870dbbb23e7f5461542cb4696ac04bf9318fb4357bec18f05b4b1ecaf9f31b","last_reissued_at":"2026-07-21T01:20:37.539390Z","signature_status":"signed_v1","first_computed_at":"2026-07-21T01:20:37.539390Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"STAC: When Innocent Tools Form Dangerous Chains for LLM Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Chao Shang, Devang Kulshreshtha, Hang Su, Jianfeng He, Jing-Jing Li, Sandesh Swamy, Xun Xian, Yanjun Qi, Yi Zhang","submitted_at":"2025-09-30T00:31:44Z","abstract_excerpt":"As LLMs advance into autonomous agents with tool-use capabilities, they introduce security challenges that extend beyond traditional content-based LLM safety concerns. This paper introduces Sequential Tool Attack Chaining (\\STAC), a novel multi-turn attack framework that exploits agent tool use. \\STAC chains together tool calls that each appear harmless in isolation but, when combined, collectively enable harmful operations that only become apparent at the final execution step. At the core of \\STAC is an automated, closed-loop pipeline that synthesizes executable multi-step tool chains, valida"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2509.25624","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2509.25624/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2509.25624","created_at":"2026-07-21T01:20:37.539855+00:00"},{"alias_kind":"arxiv_version","alias_value":"2509.25624v3","created_at":"2026-07-21T01:20:37.539855+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2509.25624","created_at":"2026-07-21T01:20:37.539855+00:00"},{"alias_kind":"pith_short_12","alias_value":"SKDQ3O5SHZ7V","created_at":"2026-07-21T01:20:37.539855+00:00"},{"alias_kind":"pith_short_16","alias_value":"SKDQ3O5SHZ7VIYKU","created_at":"2026-07-21T01:20:37.539855+00:00"},{"alias_kind":"pith_short_8","alias_value":"SKDQ3O5S","created_at":"2026-07-21T01:20:37.539855+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":7,"internal_anchor_count":7,"sample":[{"citing_arxiv_id":"2605.23989","citing_title":"Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security","ref_index":100,"is_internal_anchor":true},{"citing_arxiv_id":"2605.25435","citing_title":"Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures","ref_index":68,"is_internal_anchor":true},{"citing_arxiv_id":"2605.29224","citing_title":"Relevance as a Vulnerability: How Web Retrieval Degrades Safety Alignment in LLM Agents","ref_index":16,"is_internal_anchor":true},{"citing_arxiv_id":"2605.29251","citing_title":"Provably Secure Agent Guardrail","ref_index":29,"is_internal_anchor":true},{"citing_arxiv_id":"2603.09002","citing_title":"Security Considerations for Multi-agent Systems","ref_index":201,"is_internal_anchor":true},{"citing_arxiv_id":"2605.02900","citing_title":"Safety in Embodied AI: A Survey of Risks, Attacks, and Defenses","ref_index":223,"is_internal_anchor":true},{"citing_arxiv_id":"2604.02767","citing_title":"SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems","ref_index":12,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/SKDQ3O5SHZ7VIYKUFS2GS2WAJP","json":"https://pith.science/pith/SKDQ3O5SHZ7VIYKUFS2GS2WAJP.json","graph_json":"https://pith.science/api/pith-number/SKDQ3O5SHZ7VIYKUFS2GS2WAJP/graph.json","events_json":"https://pith.science/api/pith-number/SKDQ3O5SHZ7VIYKUFS2GS2WAJP/events.json","paper":"https://pith.science/paper/SKDQ3O5S"},"agent_actions":{"view_html":"https://pith.science/pith/SKDQ3O5SHZ7VIYKUFS2GS2WAJP","download_json":"https://pith.science/pith/SKDQ3O5SHZ7VIYKUFS2GS2WAJP.json","view_paper":"https://pith.science/paper/SKDQ3O5S","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2509.25624&json=true","fetch_graph":"https://pith.science/api/pith-number/SKDQ3O5SHZ7VIYKUFS2GS2WAJP/graph.json","fetch_events":"https://pith.science/api/pith-number/SKDQ3O5SHZ7VIYKUFS2GS2WAJP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/SKDQ3O5SHZ7VIYKUFS2GS2WAJP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/SKDQ3O5SHZ7VIYKUFS2GS2WAJP/action/storage_attestation","attest_author":"https://pith.science/pith/SKDQ3O5SHZ7VIYKUFS2GS2WAJP/action/author_attestation","sign_citation":"https://pith.science/pith/SKDQ3O5SHZ7VIYKUFS2GS2WAJP/action/citation_signature","submit_replication":"https://pith.science/pith/SKDQ3O5SHZ7VIYKUFS2GS2WAJP/action/replication_record"}},"created_at":"2026-07-21T01:20:37.539855+00:00","updated_at":"2026-07-21T01:20:37.539855+00:00"}