{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:URNCTAMJJJQLNEKDRU5XSKUUDQ","short_pith_number":"pith:URNCTAMJ","canonical_record":{"source":{"id":"2606.01991","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-01T09:48:41Z","cross_cats_sorted":["cs.CL","cs.CY"],"title_canon_sha256":"06f75344ee91c506fd18093bb9f010cd2dccbe34b774bb0adfc3a81eba7766c8","abstract_canon_sha256":"239a338451d2676edd5e76be83a106511801482a2f513424add385c093ac465f"},"schema_version":"1.0"},"canonical_sha256":"a45a2981894a60b691438d3b792a941c21420625043fc6fa7e72269393b40909","source":{"kind":"arxiv","id":"2606.01991","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.01991","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"arxiv_version","alias_value":"2606.01991v1","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.01991","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"pith_short_12","alias_value":"URNCTAMJJJQL","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"pith_short_16","alias_value":"URNCTAMJJJQLNEKD","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"pith_short_8","alias_value":"URNCTAMJ","created_at":"2026-06-02T02:05:02Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:URNCTAMJJJQLNEKDRU5XSKUUDQ","target":"record","payload":{"canonical_record":{"source":{"id":"2606.01991","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-01T09:48:41Z","cross_cats_sorted":["cs.CL","cs.CY"],"title_canon_sha256":"06f75344ee91c506fd18093bb9f010cd2dccbe34b774bb0adfc3a81eba7766c8","abstract_canon_sha256":"239a338451d2676edd5e76be83a106511801482a2f513424add385c093ac465f"},"schema_version":"1.0"},"canonical_sha256":"a45a2981894a60b691438d3b792a941c21420625043fc6fa7e72269393b40909","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-02T02:05:02.969443Z","signature_b64":"YkcXiqQG3DumZ33/7BEeqFlU5wEY84qpjt6Mq6ruKGZCx0dl5A9o4xgCfXTH3Npi+O4Ivh1pHr02fcbMIS9YDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a45a2981894a60b691438d3b792a941c21420625043fc6fa7e72269393b40909","last_reissued_at":"2026-06-02T02:05:02.968960Z","signature_status":"signed_v1","first_computed_at":"2026-06-02T02:05:02.968960Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.01991","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T02:05:02Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"r+s/ZnOSlslknGphagNJD6Jn9HrAdCcjmifgnx25Zh2rW1KBxqDGHuXaIfMUJ29ojHBSfdaTqDEuCoQNNzTCDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T19:24:24.827075Z"},"content_sha256":"3291752fe63b52f88352a4122c93965c411ac956a543affc0352f15970e7f66b","schema_version":"1.0","event_id":"sha256:3291752fe63b52f88352a4122c93965c411ac956a543affc0352f15970e7f66b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:URNCTAMJJJQLNEKDRU5XSKUUDQ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"SafeMCP: Proactive Power Regulation for LLM Agent Defense via Environment-Grounded Look-Ahead Reasoning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL","cs.CY"],"primary_cat":"cs.AI","authors_text":"Chi Harold Liu, Jiaming Ji, Juntao Dai, Lichao Wang, Tianzhuo Yang, Yaodong Yang, Zhaoxing Ren","submitted_at":"2026-06-01T09:48:41Z","abstract_excerpt":"As Large Language Model (LLM) agents increasingly leverage the Model Context Protocol (MCP) to operate in complex environments, the expansion of their action spaces offers agents unsafe capabilities and underscores the risk of power-seeking. While broad action space and greater environment influence are essential for task fulfillment, they create a fragile risk surface where minor errors or hallucinations are magnified into catastrophic failures. In response, we propose SafeMCP, a {server-side} defense plugin that constrains tool acquisition via predictive reasoning regarding future safety ris"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.01991","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.01991/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T02:05:02Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"B2nDlLpeBqai78zq8gZ+ketdZJS6s7xo9MEHd5oirOJUMnRNA9KiBvpAQKJLPyuUgBcC/sAeLUwhMOrNn0ZmCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T19:24:24.827456Z"},"content_sha256":"f150abb1c7b155632342db6d190f3baca97944b5d8ade2250527666ec0dfee1c","schema_version":"1.0","event_id":"sha256:f150abb1c7b155632342db6d190f3baca97944b5d8ade2250527666ec0dfee1c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/URNCTAMJJJQLNEKDRU5XSKUUDQ/bundle.json","state_url":"https://pith.science/pith/URNCTAMJJJQLNEKDRU5XSKUUDQ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/URNCTAMJJJQLNEKDRU5XSKUUDQ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-02T19:24:24Z","links":{"resolver":"https://pith.science/pith/URNCTAMJJJQLNEKDRU5XSKUUDQ","bundle":"https://pith.science/pith/URNCTAMJJJQLNEKDRU5XSKUUDQ/bundle.json","state":"https://pith.science/pith/URNCTAMJJJQLNEKDRU5XSKUUDQ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/URNCTAMJJJQLNEKDRU5XSKUUDQ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:URNCTAMJJJQLNEKDRU5XSKUUDQ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"239a338451d2676edd5e76be83a106511801482a2f513424add385c093ac465f","cross_cats_sorted":["cs.CL","cs.CY"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-01T09:48:41Z","title_canon_sha256":"06f75344ee91c506fd18093bb9f010cd2dccbe34b774bb0adfc3a81eba7766c8"},"schema_version":"1.0","source":{"id":"2606.01991","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.01991","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"arxiv_version","alias_value":"2606.01991v1","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.01991","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"pith_short_12","alias_value":"URNCTAMJJJQL","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"pith_short_16","alias_value":"URNCTAMJJJQLNEKD","created_at":"2026-06-02T02:05:02Z"},{"alias_kind":"pith_short_8","alias_value":"URNCTAMJ","created_at":"2026-06-02T02:05:02Z"}],"graph_snapshots":[{"event_id":"sha256:f150abb1c7b155632342db6d190f3baca97944b5d8ade2250527666ec0dfee1c","target":"graph","created_at":"2026-06-02T02:05:02Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.01991/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"As Large Language Model (LLM) agents increasingly leverage the Model Context Protocol (MCP) to operate in complex environments, the expansion of their action spaces offers agents unsafe capabilities and underscores the risk of power-seeking. While broad action space and greater environment influence are essential for task fulfillment, they create a fragile risk surface where minor errors or hallucinations are magnified into catastrophic failures. In response, we propose SafeMCP, a {server-side} defense plugin that constrains tool acquisition via predictive reasoning regarding future safety ris","authors_text":"Chi Harold Liu, Jiaming Ji, Juntao Dai, Lichao Wang, Tianzhuo Yang, Yaodong Yang, Zhaoxing Ren","cross_cats":["cs.CL","cs.CY"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-01T09:48:41Z","title":"SafeMCP: Proactive Power Regulation for LLM Agent Defense via Environment-Grounded Look-Ahead Reasoning"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.01991","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:3291752fe63b52f88352a4122c93965c411ac956a543affc0352f15970e7f66b","target":"record","created_at":"2026-06-02T02:05:02Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"239a338451d2676edd5e76be83a106511801482a2f513424add385c093ac465f","cross_cats_sorted":["cs.CL","cs.CY"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-01T09:48:41Z","title_canon_sha256":"06f75344ee91c506fd18093bb9f010cd2dccbe34b774bb0adfc3a81eba7766c8"},"schema_version":"1.0","source":{"id":"2606.01991","kind":"arxiv","version":1}},"canonical_sha256":"a45a2981894a60b691438d3b792a941c21420625043fc6fa7e72269393b40909","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a45a2981894a60b691438d3b792a941c21420625043fc6fa7e72269393b40909","first_computed_at":"2026-06-02T02:05:02.968960Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-02T02:05:02.968960Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"YkcXiqQG3DumZ33/7BEeqFlU5wEY84qpjt6Mq6ruKGZCx0dl5A9o4xgCfXTH3Npi+O4Ivh1pHr02fcbMIS9YDA==","signature_status":"signed_v1","signed_at":"2026-06-02T02:05:02.969443Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.01991","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:3291752fe63b52f88352a4122c93965c411ac956a543affc0352f15970e7f66b","sha256:f150abb1c7b155632342db6d190f3baca97944b5d8ade2250527666ec0dfee1c"],"state_sha256":"cd22bebad35fdee991c94ae8ca37089b885b0e30b18e6a7b47bb0d3b32d04e65"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"s1Gv2fXrXEhSVA4bDvqxP63Z7BVG6+m4ylfvBpoQfA8Mh8cTmq32DDSkNorAxM5fkEXiDIDYwof9vJX0iYpPAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-02T19:24:24.829432Z","bundle_sha256":"0fa59955ba76e281a9f38da7be790aba12541e750503acd3788dc7c364d55517"}}