{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:UIU77J2G5RRYOA5FY7LF4QDLDW","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e2281d290fcda23c0c033b713cecabda9c2ee7657f54b43923d2d29f374e79f4","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-27T20:17:43Z","title_canon_sha256":"7ac05c76ba082e573951e2925487881c7850dc8e31185a5ea3e1baf8c24e5da8"},"schema_version":"1.0","source":{"id":"2606.29073","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.29073","created_at":"2026-06-30T01:17:51Z"},{"alias_kind":"arxiv_version","alias_value":"2606.29073v1","created_at":"2026-06-30T01:17:51Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.29073","created_at":"2026-06-30T01:17:51Z"},{"alias_kind":"pith_short_12","alias_value":"UIU77J2G5RRY","created_at":"2026-06-30T01:17:51Z"},{"alias_kind":"pith_short_16","alias_value":"UIU77J2G5RRYOA5F","created_at":"2026-06-30T01:17:51Z"},{"alias_kind":"pith_short_8","alias_value":"UIU77J2G","created_at":"2026-06-30T01:17:51Z"}],"graph_snapshots":[{"event_id":"sha256:eae788fee33a416ef0384c28a478644d98eac10abc32876c1556cadec998bff9","target":"graph","created_at":"2026-06-30T01:17:51Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.29073/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Model Context Protocol (MCP)-style ecosystems give language-model applications a practical connection layer for tools, resources, prompts, and transports. As agents move from connection to execution, security decisions often remain split across clients, servers, prompts, approval dialogs, OAuth deployments, and logs. This paper asks whether a runtime can make execution-layer invariants explicit and testable while preserving MCP-like workflows. We define eight invariants: metadata non-authority, grant-backed approval, canonical resources, principal binding, scoped capability invocation, source-","authors_text":"Ting Liu","cross_cats":["cs.AI"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-27T20:17:43Z","title":"From Tool Connection to Execution Control: Benchmarking Security Invariants in MCP-Style Agent Runtimes"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.29073","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:6aa62f28ae5d63d0cc5f331bac4410f30afa685ac2fa1af27ce42646f7980f04","target":"record","created_at":"2026-06-30T01:17:51Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e2281d290fcda23c0c033b713cecabda9c2ee7657f54b43923d2d29f374e79f4","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-27T20:17:43Z","title_canon_sha256":"7ac05c76ba082e573951e2925487881c7850dc8e31185a5ea3e1baf8c24e5da8"},"schema_version":"1.0","source":{"id":"2606.29073","kind":"arxiv","version":1}},"canonical_sha256":"a229ffa746ec638703a5c7d65e406b1da629ab7c0d8156037c09c0cbbedf5a9d","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a229ffa746ec638703a5c7d65e406b1da629ab7c0d8156037c09c0cbbedf5a9d","first_computed_at":"2026-06-30T01:17:51.688264Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-30T01:17:51.688264Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"k3nuiaaIE96fqOdvvPT1VpeURcx7kKndfDMfjLKZ7yfh30/iV0bVnSTop4Bp9wzsEuimEc9v+iMvmXNk+SzhAg==","signature_status":"signed_v1","signed_at":"2026-06-30T01:17:51.688748Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.29073","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:6aa62f28ae5d63d0cc5f331bac4410f30afa685ac2fa1af27ce42646f7980f04","sha256:eae788fee33a416ef0384c28a478644d98eac10abc32876c1556cadec998bff9"],"state_sha256":"b69b6632898b430e3616d77be6a091a11067ab080281cb4cb5b3843a7da9449f"}