{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","short_pith_number":"pith:XHFUQAS7","canonical_record":{"source":{"id":"2605.21392","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-20T16:46:51Z","cross_cats_sorted":[],"title_canon_sha256":"04c98b0d91a629d14606062d0693ea291b16a3860667693bb54623f2589ebc75","abstract_canon_sha256":"d185d4d019c4a9b7988c9fd071d7ad7d69bfc19c6b0fd035ae1ac47d9d34f72f"},"schema_version":"1.0"},"canonical_sha256":"b9cb48025fb8be76d76e3a794993473797cc7c562d806f0250dee238c49772bc","source":{"kind":"arxiv","id":"2605.21392","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.21392","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"arxiv_version","alias_value":"2605.21392v1","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.21392","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"pith_short_12","alias_value":"XHFUQAS7XC7H","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"pith_short_16","alias_value":"XHFUQAS7XC7HNV3O","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"pith_short_8","alias_value":"XHFUQAS7","created_at":"2026-05-21T02:05:32Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"record","payload":{"canonical_record":{"source":{"id":"2605.21392","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-20T16:46:51Z","cross_cats_sorted":[],"title_canon_sha256":"04c98b0d91a629d14606062d0693ea291b16a3860667693bb54623f2589ebc75","abstract_canon_sha256":"d185d4d019c4a9b7988c9fd071d7ad7d69bfc19c6b0fd035ae1ac47d9d34f72f"},"schema_version":"1.0"},"canonical_sha256":"b9cb48025fb8be76d76e3a794993473797cc7c562d806f0250dee238c49772bc","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-21T02:05:32.544201Z","signature_b64":"Bo1bQgJLvq/OeCxp1PJB/V8A32mAA6Lag2+VtPEfcrU/9SrhxiylGd53hs0cH86oBaCu/wKCIBKkeVrb4mvPDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b9cb48025fb8be76d76e3a794993473797cc7c562d806f0250dee238c49772bc","last_reissued_at":"2026-05-21T02:05:32.543431Z","signature_status":"signed_v1","first_computed_at":"2026-05-21T02:05:32.543431Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.21392","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T02:05:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DttJ0EQEFjE7/5CuPOz0u3vSruWezucF8ZkEuOK8MduAKaG0Wgotl7wqBggBiMFtr83Wf1wxcn2d7N7/qp9kBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.759359Z"},"content_sha256":"c682f4bc9f5329ea887c0390de497d34da1b440b13cb96cfdd2a2b4f9f027d82","schema_version":"1.0","event_id":"sha256:c682f4bc9f5329ea887c0390de497d34da1b440b13cb96cfdd2a2b4f9f027d82"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Dakun Shen, Enhao Huang, Pengyu Sun, Qishu Jin, Song Li, Xin Liu, Zifeng Kang","submitted_at":"2026-05-20T16:46:51Z","abstract_excerpt":"Model Context Protocol (MCP) has emerged as a standard interface for connecting LLM agents to external tools. Because MCP servers expose privileged operations such as shell execution, network access, and file-system manipulation to agent-driven invocation, implementation flaws in tool handlers can create a direct path from natural-language input to security-sensitive sinks, potentially granting attackers remote code execution or full system compromise. Existing approaches either produce unconfirmed static alerts without dynamic validation, or rely on fixed template libraries that lack code-lev"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.21392","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.21392/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T02:05:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"rVZvIys5Jq5TagdizfYAka2yrSVFETUkKe7FB+AlHUIaBTc1vXtq9iflfOHsYqDpqwj24LNklN4eX4eRIEm3Aw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.759746Z"},"content_sha256":"0ab51ee21ef8392e4919eaca9c8423c598e9581599eae412e1d0e5feb51d7513","schema_version":"1.0","event_id":"sha256:0ab51ee21ef8392e4919eaca9c8423c598e9581599eae412e1d0e5feb51d7513"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://arxiv.org/abs/2603' returned status 404 (Not Found) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://arxiv.org/abs/2603","final_url":"https://arxiv.org/abs/2603","host_kind":"arxiv","status_code":404,"status_text":"Not Found","verdict_class":"incontrovertible","checked_at_unix":1779384924.8708959},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T17:35:26.875153Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://arxiv.org/abs/2603","finding_type":"dead_url","evidence_hash":"d470fcda4bae01d87a61abd9bd53f0ceed089dee854a2187fd6a11861c8779fb","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":6046,"payload_sha256":"a4a264b9ab6b57bf06ef6074c14ad7b84c9eaf63e1d11b6368ecab94f347e50e","signature_b64":"gfI822FGj88jO89u8pDQ13A6o7mx47+Ky6PiAib77xbBaeu6RKuUSUMd2hxJfsXMX1FGUiQFGXO+IhQGMLyHBw==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T17:39:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"njwK5owXmWxEVT5p90h/50EveDnaG6AaksW8EBrUkqsti84fSDYsJEzj4+mhxnzWfpZQ10mFrZIstrzfeLIWCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.760884Z"},"content_sha256":"b9b6c68835cdf52c57db1481f53b84531d6878719cf63b08f9ec3ad3948ee315","schema_version":"1.0","event_id":"sha256:b9b6c68835cdf52c57db1481f53b84531d6878719cf63b08f9ec3ad3948ee315"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://github' returned status transport error (transport error: [Errno -3] Temporary failure in name resolution) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://github","final_url":null,"host_kind":"website","status_code":0,"status_text":"transport error: [Errno -3] Temporary failure in name resolution","verdict_class":"incontrovertible","checked_at_unix":1779384924.8504748},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T17:35:26.875153Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://github","finding_type":"dead_url","evidence_hash":"251de1960f77ea368287bc59bbcd3557cec1d46c0e9ca8999752dc4d99f78f30","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":6045,"payload_sha256":"d63936ee779bcbfee776f297c2e7e6029cd35c0c7493e4ce0a2cab49ceee9ab9","signature_b64":"Xgp1xuukxbHFtxnok3HSlY6TG4aXeW78gMQH519qNpg306RXD5tyWkrzXVzue526bgXGhCK9ywqAs2UpOFILDQ==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T17:39:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"bhOKUckANWtLWINmJOqPpFkYmySjwljqgIyzF3UDx11l4Cjcw1ScZnpNTWsk6pPZ6fUDJeY206ajifSytoHOBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.761166Z"},"content_sha256":"bda99282a2618fad743e457f86e289d8c8373788a7eef4e59446945c6e001c0f","schema_version":"1.0","event_id":"sha256:bda99282a2618fad743e457f86e289d8c8373788a7eef4e59446945c6e001c0f"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://www.usenix.org/confere' returned status 404 (Not Found) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://www.usenix.org/confere","final_url":"https://www.usenix.org/confere","host_kind":"website","status_code":404,"status_text":"Not Found","verdict_class":"incontrovertible","checked_at_unix":1779384924.4455874},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T17:35:26.875153Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://www.usenix.org/confere","finding_type":"dead_url","evidence_hash":"2668dbace0084afafdfd6952150cfa985b5ea04e54b8b44853b0bc6f3176aa44","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":6044,"payload_sha256":"5a67259466e1ce83a4d26ae3590a0eff8054b6933ca337d74cfce9f478494b1b","signature_b64":"oOGt9GEii+Oc6M42SS3vLfWtLRzWrG8FLDtWzEP2T4Z4dvnfJ0wgzPwy7iJJPewGpUp/bgeSmtfg6lR6+IWwAg==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T17:39:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"M5H++8zj6NHcvKqDMH/YROpqEtXhvA/+pSV2XEi5/mtl/a0N3vouzpWMxEQVG2qAjwzLfi6Xdyj/nE65XaZPCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.761456Z"},"content_sha256":"858e7b2c96a79d471938be92661657b1f744e4d0249b6f53890cbc431a2cde96","schema_version":"1.0","event_id":"sha256:858e7b2c96a79d471938be92661657b1f744e4d0249b6f53890cbc431a2cde96"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://www.pulsemcp' returned status transport error (transport error: [Errno -2] Name or service not known) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://www.pulsemcp","final_url":null,"host_kind":"website","status_code":0,"status_text":"transport error: [Errno -2] Name or service not known","verdict_class":"incontrovertible","checked_at_unix":1779384924.3467252},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T17:35:26.875153Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://www.pulsemcp","finding_type":"dead_url","evidence_hash":"6bcacfd4a6e0d6e069926e19045f0a8d770cffd093db414d585eca2fe5065724","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":6043,"payload_sha256":"307996a4ce276ca45eb18eac43f4029fcacb906b48fa7f09126fb5c3e0507814","signature_b64":"DC6aqLD41VoHWPgaKgZ8k64I5Io25IIz0Sd8FUAv92WN0AeKNUSAdNUxB423pfX05jSwZn2iX/ywVehtpVquAw==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T17:39:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"txYp0hBoDwXtGPE+Y9e57srAcVVzHvrIOoBAPqjoyRZcHSZbAm/k1qrh/DdZRo+lzTcVCh8vbDkCKFMd0iRcDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.761725Z"},"content_sha256":"fff7de610caee9367c34bc78c6940d23ca500fbfb12d40c8219604b591490b00","schema_version":"1.0","event_id":"sha256:fff7de610caee9367c34bc78c6940d23ca500fbfb12d40c8219604b591490b00"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://docs.crewai.co' returned status transport error (transport error: [SSL: TLSV1_UNRECOGNIZED_NAME] tlsv1 unrecognized name (_ssl.c:1010)) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://docs.crewai.co","final_url":null,"host_kind":"website","status_code":0,"status_text":"transport error: [SSL: TLSV1_UNRECOGNIZED_NAME] tlsv1 unrecognized name (_ssl.c:1010)","verdict_class":"incontrovertible","checked_at_unix":1779384923.9417334},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T17:35:26.875153Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://docs.crewai.co","finding_type":"dead_url","evidence_hash":"c8e62e2d57c32c52cd5d6cb23cf72a736da271a977ae55f6db257df1be95b6f8","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":6042,"payload_sha256":"f9f476ad9393dc2b572e0bf2af4d3d9b1d36e4efabeb2caef0e6264e9320b8c1","signature_b64":"PQVtQst4uY8FYfSnAnPLpq77icpdUOxX2E9ASgpN+rClJfdVcuUW2z/aKCtTdWWcbIFOOBOMOUQsdi+hL2ZRBw==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T17:39:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"gDt1vHYPQrZ2AhgIoxjKfPVI0/Rb82awzQ5CEcA1B/6iHM6SFkJPqFhOGAsCLpsI98ltb1Bloe/DY6dUATjgBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.761990Z"},"content_sha256":"37baefb3167231cc138349c6fbccd53c121e21cbced0bbd4afd7f9dc4fe69c3d","schema_version":"1.0","event_id":"sha256:37baefb3167231cc138349c6fbccd53c121e21cbced0bbd4afd7f9dc4fe69c3d"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://github.com/langchain-a' returned status 404 (Not Found) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://github.com/langchain-a","final_url":"https://github.com/langchain-a","host_kind":"github","status_code":404,"status_text":"Not Found","verdict_class":"incontrovertible","checked_at_unix":1779384923.6891632},"severity":"critical","ref_index":null,"audited_at":"2026-05-21T17:35:26.875153Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://github.com/langchain-a","finding_type":"dead_code_link","evidence_hash":"46a1c271ceafca0750e036f5b5a1e30fdb4b15141be41740ec0ea9c88bc61d27","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":6041,"payload_sha256":"a543a08943e77b558912cfe29d69918d2ad35c53acc9e76476ab08fa274a4a66","signature_b64":"ekOFq/FsyMhdQMeVQ1tboL7TjnEpS4mOOA9Fv9TH8+yILKLVc+LyJ90IiWJrZA/Y23XQnN6GMBM8W2x8z/ZxCw==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T17:39:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"NeKAedO1f/Yw6p7fqfVH5/s314OhRROoq/8BSBc2V5bwYYFeJq/jgbZM8myncrVaI32QsY9/yphsWGeJdgoYAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.762253Z"},"content_sha256":"93f572cadce29807dac14a3498077ef741d992aaeab49531485fef4d06da9af8","schema_version":"1.0","event_id":"sha256:93f572cadce29807dac14a3498077ef741d992aaeab49531485fef4d06da9af8"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://modelcontext' returned status transport error (transport error: [Errno -3] Temporary failure in name resolution) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://modelcontext","final_url":null,"host_kind":"website","status_code":0,"status_text":"transport error: [Errno -3] Temporary failure in name resolution","verdict_class":"incontrovertible","checked_at_unix":1779384923.687922},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T17:35:26.875153Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://modelcontext","finding_type":"dead_url","evidence_hash":"cb198ac8c515f54131716fcc3f922934a7d1b8f84e44561bdea88f9155632cb7","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":6040,"payload_sha256":"06a6c51942c72d0bde65c3f68ac639343125ebac0e1dcb8fc9f39cbf52d695e0","signature_b64":"qxTyDI/TlLqxitNM16+hy8WIwl0Cw5xXWKHdWZNTfVF1+Vn22/2DE7m4nbzAx1DaIsv27n5mepm/dS2WHCk1Ag==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T17:39:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"f2DIGKMSW0zSnYXFHFGzcpBQz8elGA3pU38wMj4/2LuCRISoFrFOg35DPNh8s68H5WILheRHdSwexih6MbzVBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.762534Z"},"content_sha256":"29a76a7e462f31e5c98414bc553a3f5401e6ecfb2521dace5009b808749c452f","schema_version":"1.0","event_id":"sha256:29a76a7e462f31e5c98414bc553a3f5401e6ecfb2521dace5009b808749c452f"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://arxiv.org/abs/2603' returned status 404 (Not Found) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://arxiv.org/abs/2603","final_url":"https://arxiv.org/abs/2603","host_kind":"arxiv","status_code":404,"status_text":"Not Found","verdict_class":"incontrovertible","checked_at_unix":1779341709.3310318},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T05:35:11.410912Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://arxiv.org/abs/2603","finding_type":"dead_url","evidence_hash":"814e73a32720ac6016ca399377a299e13812ea84e59bd6483218023152f78ef4","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":5772,"payload_sha256":"391e97750d12bcbb27199a02c16b559d370fe00f4031261c0f1e737d370434c7","signature_b64":"QMcVkZnkzlnNEiAX8ubTv9YbkxvHyXxf9Uz2gOvGiEispMmUbWNY8L22y1fz+0OFVyGhLvsGc2eWfuJybeTBAA==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T05:39:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"KNeNNZTaDskNH0QURc7ytoOG+El9h9ZoJYDTZRuZvqYriqut3V2mRvOR3qwLqYyICnecipPrVe5Wfh4PGi4UBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.762800Z"},"content_sha256":"6a52437e66dd06765223cb90c8a3176ef391dbb106d726eec93206e47247469b","schema_version":"1.0","event_id":"sha256:6a52437e66dd06765223cb90c8a3176ef391dbb106d726eec93206e47247469b"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://github' returned status transport error (transport error: [Errno -3] Temporary failure in name resolution) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://github","final_url":null,"host_kind":"website","status_code":0,"status_text":"transport error: [Errno -3] Temporary failure in name resolution","verdict_class":"incontrovertible","checked_at_unix":1779341709.2521667},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T05:35:11.410912Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://github","finding_type":"dead_url","evidence_hash":"d0a60b198d75fea3d208f6c336c95a965a1293ae0ea2cf54e8579515cc8ed50c","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":5771,"payload_sha256":"cee1aea1c158b9fac9a2b06a63ea35b076a3d5cbe19d9b7acf9ae52a81a04d08","signature_b64":"JP8SINRYlMCfna6j8Y47vq0+XpCAM3UEOURLh+ITSpB6q7U/ojNxZpYkVgqUmxWZL4xfba051/xsqFyJBbuFBQ==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T05:39:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"J+lJ2SmCzdOdOAsPmVqFrLqrT/0pJjtvJPFiEZUlCPDErjBME5q2h2XQq0PWDu2ZY72DsaKLpoyOYkqsvTnSAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.763064Z"},"content_sha256":"df0788fdabd4be9478848b8d262fb3a028d56714761a851bfaeb0011142141e8","schema_version":"1.0","event_id":"sha256:df0788fdabd4be9478848b8d262fb3a028d56714761a851bfaeb0011142141e8"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://www.usenix.org/confere' returned status 404 (Not Found) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://www.usenix.org/confere","final_url":"https://www.usenix.org/confere","host_kind":"website","status_code":404,"status_text":"Not Found","verdict_class":"incontrovertible","checked_at_unix":1779341708.8830256},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T05:35:11.410912Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://www.usenix.org/confere","finding_type":"dead_url","evidence_hash":"6f114fd7be6e7ab26eb5af3b6135d713d3791d3f35a88e377765d48b32351d86","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":5770,"payload_sha256":"0896842ac80e8d8f6989b3e296ce856ca793b41c4a81f6ccace50706cc2d8e44","signature_b64":"7pngAaJxEgsTmqxK7yMRgwu1bIUQE0kZ+52G7641Bz9uEixxCrDzlyGbOW+Ai938tqnZKNyKx20sKjHequjhCw==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T05:39:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZA83sM34xUVyFoVAqD2SVd/CvA+4pisP4tW+Kf6Ev7G9gbPc0HYXsGHJ5J6Y5qbCxCTYO++uAhdDlxASWbaOBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.763340Z"},"content_sha256":"dbc580579f0d4d643f0e60eea05c74057a199f330e87a19135e19900c3018054","schema_version":"1.0","event_id":"sha256:dbc580579f0d4d643f0e60eea05c74057a199f330e87a19135e19900c3018054"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://www.pulsemcp' returned status transport error (transport error: [Errno -2] Name or service not known) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://www.pulsemcp","final_url":null,"host_kind":"website","status_code":0,"status_text":"transport error: [Errno -2] Name or service not known","verdict_class":"incontrovertible","checked_at_unix":1779341708.851999},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T05:35:11.410912Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://www.pulsemcp","finding_type":"dead_url","evidence_hash":"f8633b51e6eb4275170feb7441a41ac97793893bae86a71000200cb390e20b1c","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":5769,"payload_sha256":"92a19eeaa3ef6e8a6579a4782dbb53f9ff056e2c615beab04213509f1ae55bb6","signature_b64":"Mstg9O53FBSaHhhZj3EZRgdQeoZZAljIYGxc+QXWhX0uBGYm4NOi5LMesiyV+lI1Szx1b6FL/g1Kv0+bfMWfBg==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T05:39:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"qh/068tqr7PawxrNsAZKL9qqE+Oy150APnC6m5n0WG2+bJQD52aEv/iHjetNhcISzqNyyoFgcfgjm2aS7P+bCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.763608Z"},"content_sha256":"f75be70c8f9839b10ab75fb834694e72feb6e66c4346ce19a1912677e5b71e17","schema_version":"1.0","event_id":"sha256:f75be70c8f9839b10ab75fb834694e72feb6e66c4346ce19a1912677e5b71e17"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://docs.crewai.co' returned status transport error (transport error: [SSL: TLSV1_UNRECOGNIZED_NAME] tlsv1 unrecognized name (_ssl.c:1010)) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://docs.crewai.co","final_url":null,"host_kind":"website","status_code":0,"status_text":"transport error: [SSL: TLSV1_UNRECOGNIZED_NAME] tlsv1 unrecognized name (_ssl.c:1010)","verdict_class":"incontrovertible","checked_at_unix":1779341708.228052},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T05:35:11.410912Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://docs.crewai.co","finding_type":"dead_url","evidence_hash":"4eada8df7e0c01cf9f2abbfb0a7aa3085b83e6edeed0c1f171c873657754a628","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":5768,"payload_sha256":"edd2022757618d4c5f4b265f080085f983fa2f66c62576631d69fea0837151bd","signature_b64":"JNZQFaikZNkh5XmPKiv8d5Kmfz11++jXw2s2yMKH2kKPnOdbncfmUuKD1VrhqJSmO0YqFS4f3DVrVmqmmzyfCw==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T05:39:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"abMO80TgmTzQV6CLrW89aA5b29EmKINm96ng7VUmGHr1lvJgAYtfM9o76bEhGwFv0kzuKDEXANRAigVFzwknDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.763870Z"},"content_sha256":"cb9424d8bd902a936484dcef84a7afb7abedfd856c982a6c8cebe6cf623187da","schema_version":"1.0","event_id":"sha256:cb9424d8bd902a936484dcef84a7afb7abedfd856c982a6c8cebe6cf623187da"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://github.com/langchain-a' returned status 404 (Not Found) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://github.com/langchain-a","final_url":"https://github.com/langchain-a","host_kind":"github","status_code":404,"status_text":"Not Found","verdict_class":"incontrovertible","checked_at_unix":1779341707.9360952},"severity":"critical","ref_index":null,"audited_at":"2026-05-21T05:35:11.410912Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://github.com/langchain-a","finding_type":"dead_code_link","evidence_hash":"c598131d30e39379e626578d2b3a6ed015496fde11f3ef0f9fe400a6205d4ce9","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":5767,"payload_sha256":"5a533081fef4aaddc59a3e3cbb3f67aef14a8855a88c486bfef4b304dacf0bf4","signature_b64":"MyRTHZtxxJpiXFkG2GAP/NoX6X7uz3ZFp8KO+3n07mdD5i5JCC4iN9Rd/DyWdbYkFg/kX8u/EBVrFUWw4aeJBg==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T05:39:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"U++nBKvpjaN3UN6bvqaqK2/ChsDbLlZjo6bK1KTi5YZU9+fwUBq2NyPTYLaijlovVKXOEG/TW+xJgMCIhVadBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.764131Z"},"content_sha256":"ef92a2349071fb3de1a8a25ed1a590f06a5c112dd5c642ecc2e48e76c85f7fae","schema_version":"1.0","event_id":"sha256:ef92a2349071fb3de1a8a25ed1a590f06a5c112dd5c642ecc2e48e76c85f7fae"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","target":"integrity","payload":{"note":"URL 'https://modelcontext' returned status transport error (transport error: [Errno -3] Temporary failure in name resolution) at last check.","snippet":null,"arxiv_id":"2605.21392","detector":"external_links","evidence":{"url":"https://modelcontext","final_url":null,"host_kind":"website","status_code":0,"status_text":"transport error: [Errno -3] Temporary failure in name resolution","verdict_class":"incontrovertible","checked_at_unix":1779341707.9341953},"severity":"advisory","ref_index":null,"audited_at":"2026-05-21T05:35:11.410912Z","event_type":"pith.integrity.v1","detected_doi":null,"detector_url":"https://pith.science/pith-integrity-protocol#external_links","external_url":"https://modelcontext","finding_type":"dead_url","evidence_hash":"14c2867f1ca606fc487f037c42af68f9e7dca9d009bd12a3c35f272aed4f7034","paper_version":1,"verdict_class":"incontrovertible","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":5766,"payload_sha256":"c14980d2fe70003140876109f1e88e99fb1c5306f9a4952f46658265cd3c3374","signature_b64":"3+pCo+3w7v4i2LdDTbP8gZxa0KkMJCN4Pmy6RdpnQVuxWYNCBLoN1EY3/ZcRt2CdN8BzipuaPcee841C40D+Ag==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T05:39:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"HUQrUv8qON1tZuZcVMqMJ4wZY4y2bEhFPHtBbb1+kEGIylaTQwfnVwiIa5BA/KPfA2viuALLt7/fjsmzLwv4Cg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T05:25:56.764400Z"},"content_sha256":"ae2748c6a639dc17d0833bc0edb987bd4e791ba273ff1dec3b56254cd5c2ceeb","schema_version":"1.0","event_id":"sha256:ae2748c6a639dc17d0833bc0edb987bd4e791ba273ff1dec3b56254cd5c2ceeb"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XHFUQAS7XC7HNV3OHJ4UTE2HG6/bundle.json","state_url":"https://pith.science/pith/XHFUQAS7XC7HNV3OHJ4UTE2HG6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XHFUQAS7XC7HNV3OHJ4UTE2HG6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-28T05:25:56Z","links":{"resolver":"https://pith.science/pith/XHFUQAS7XC7HNV3OHJ4UTE2HG6","bundle":"https://pith.science/pith/XHFUQAS7XC7HNV3OHJ4UTE2HG6/bundle.json","state":"https://pith.science/pith/XHFUQAS7XC7HNV3OHJ4UTE2HG6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XHFUQAS7XC7HNV3OHJ4UTE2HG6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:XHFUQAS7XC7HNV3OHJ4UTE2HG6","merge_version":"pith-open-graph-merge-v1","event_count":16,"valid_event_count":16,"invalid_event_count":0,"equivocation_count":1,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d185d4d019c4a9b7988c9fd071d7ad7d69bfc19c6b0fd035ae1ac47d9d34f72f","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-20T16:46:51Z","title_canon_sha256":"04c98b0d91a629d14606062d0693ea291b16a3860667693bb54623f2589ebc75"},"schema_version":"1.0","source":{"id":"2605.21392","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.21392","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"arxiv_version","alias_value":"2605.21392v1","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.21392","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"pith_short_12","alias_value":"XHFUQAS7XC7H","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"pith_short_16","alias_value":"XHFUQAS7XC7HNV3O","created_at":"2026-05-21T02:05:32Z"},{"alias_kind":"pith_short_8","alias_value":"XHFUQAS7","created_at":"2026-05-21T02:05:32Z"}],"graph_snapshots":[{"event_id":"sha256:0ab51ee21ef8392e4919eaca9c8423c598e9581599eae412e1d0e5feb51d7513","target":"graph","created_at":"2026-05-21T02:05:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.21392/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Model Context Protocol (MCP) has emerged as a standard interface for connecting LLM agents to external tools. Because MCP servers expose privileged operations such as shell execution, network access, and file-system manipulation to agent-driven invocation, implementation flaws in tool handlers can create a direct path from natural-language input to security-sensitive sinks, potentially granting attackers remote code execution or full system compromise. Existing approaches either produce unconfirmed static alerts without dynamic validation, or rely on fixed template libraries that lack code-lev","authors_text":"Dakun Shen, Enhao Huang, Pengyu Sun, Qishu Jin, Song Li, Xin Liu, Zifeng Kang","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-20T16:46:51Z","title":"VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.21392","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:c682f4bc9f5329ea887c0390de497d34da1b440b13cb96cfdd2a2b4f9f027d82","target":"record","created_at":"2026-05-21T02:05:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d185d4d019c4a9b7988c9fd071d7ad7d69bfc19c6b0fd035ae1ac47d9d34f72f","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-20T16:46:51Z","title_canon_sha256":"04c98b0d91a629d14606062d0693ea291b16a3860667693bb54623f2589ebc75"},"schema_version":"1.0","source":{"id":"2605.21392","kind":"arxiv","version":1}},"canonical_sha256":"b9cb48025fb8be76d76e3a794993473797cc7c562d806f0250dee238c49772bc","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b9cb48025fb8be76d76e3a794993473797cc7c562d806f0250dee238c49772bc","first_computed_at":"2026-05-21T02:05:32.543431Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-21T02:05:32.543431Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Bo1bQgJLvq/OeCxp1PJB/V8A32mAA6Lag2+VtPEfcrU/9SrhxiylGd53hs0cH86oBaCu/wKCIBKkeVrb4mvPDQ==","signature_status":"signed_v1","signed_at":"2026-05-21T02:05:32.544201Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.21392","source_kind":"arxiv","source_version":1}}},"equivocations":[{"signer_id":"pith.science","event_type":"integrity_finding","target":"integrity","event_ids":["sha256:29a76a7e462f31e5c98414bc553a3f5401e6ecfb2521dace5009b808749c452f","sha256:37baefb3167231cc138349c6fbccd53c121e21cbced0bbd4afd7f9dc4fe69c3d","sha256:6a52437e66dd06765223cb90c8a3176ef391dbb106d726eec93206e47247469b","sha256:858e7b2c96a79d471938be92661657b1f744e4d0249b6f53890cbc431a2cde96","sha256:93f572cadce29807dac14a3498077ef741d992aaeab49531485fef4d06da9af8","sha256:ae2748c6a639dc17d0833bc0edb987bd4e791ba273ff1dec3b56254cd5c2ceeb","sha256:b9b6c68835cdf52c57db1481f53b84531d6878719cf63b08f9ec3ad3948ee315","sha256:bda99282a2618fad743e457f86e289d8c8373788a7eef4e59446945c6e001c0f","sha256:cb9424d8bd902a936484dcef84a7afb7abedfd856c982a6c8cebe6cf623187da","sha256:dbc580579f0d4d643f0e60eea05c74057a199f330e87a19135e19900c3018054","sha256:df0788fdabd4be9478848b8d262fb3a028d56714761a851bfaeb0011142141e8","sha256:ef92a2349071fb3de1a8a25ed1a590f06a5c112dd5c642ecc2e48e76c85f7fae","sha256:f75be70c8f9839b10ab75fb834694e72feb6e66c4346ce19a1912677e5b71e17","sha256:fff7de610caee9367c34bc78c6940d23ca500fbfb12d40c8219604b591490b00"]}],"invalid_events":[],"applied_event_ids":["sha256:c682f4bc9f5329ea887c0390de497d34da1b440b13cb96cfdd2a2b4f9f027d82","sha256:0ab51ee21ef8392e4919eaca9c8423c598e9581599eae412e1d0e5feb51d7513"],"state_sha256":"b37d0daa81b69da30f38849bf55e69bcb301dc2c91f15b61531d989f93dfedbe"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"A91pFLYZUfE73JrWzqHLv7am8R2urlrujYbTWyeIi6HTPyP+VWDc723p6b/xRCWVPSIl/She5dZzuHVCxRdwBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-28T05:25:56.769027Z","bundle_sha256":"f6b2ec11cd1a9e6fb7178d47314029d3870581d08d8f99ca0832eecec2bf6e23"}}