{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:YCBZLY5ZKA4D6GUMWRDAXBWNDK","short_pith_number":"pith:YCBZLY5Z","canonical_record":{"source":{"id":"2606.11672","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T05:31:24Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"1668c64a80531ff27375aac759a67ce10715d8930416254814f2146077f8937a","abstract_canon_sha256":"4e74ae60d423859cfce0b66e9c4b78944667cc86488b1834d7082c9a464f80eb"},"schema_version":"1.0"},"canonical_sha256":"c08395e3b950383f1a8cb4460b86cd1ab4120f9cc2ca8f9337388d49ffcdfdbc","source":{"kind":"arxiv","id":"2606.11672","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.11672","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"arxiv_version","alias_value":"2606.11672v1","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.11672","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"pith_short_12","alias_value":"YCBZLY5ZKA4D","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"pith_short_16","alias_value":"YCBZLY5ZKA4D6GUM","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"pith_short_8","alias_value":"YCBZLY5Z","created_at":"2026-06-11T01:10:02Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:YCBZLY5ZKA4D6GUMWRDAXBWNDK","target":"record","payload":{"canonical_record":{"source":{"id":"2606.11672","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T05:31:24Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"1668c64a80531ff27375aac759a67ce10715d8930416254814f2146077f8937a","abstract_canon_sha256":"4e74ae60d423859cfce0b66e9c4b78944667cc86488b1834d7082c9a464f80eb"},"schema_version":"1.0"},"canonical_sha256":"c08395e3b950383f1a8cb4460b86cd1ab4120f9cc2ca8f9337388d49ffcdfdbc","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-11T01:10:02.051027Z","signature_b64":"PMpJT0PVZj/vwGQC5w3h2ixd4KhAFu4jwA1O430VPgbWrJdQSG+pteC1iyDzdy7hnSOhvo6phNDCMbTAqUzjBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c08395e3b950383f1a8cb4460b86cd1ab4120f9cc2ca8f9337388d49ffcdfdbc","last_reissued_at":"2026-06-11T01:10:02.050241Z","signature_status":"signed_v1","first_computed_at":"2026-06-11T01:10:02.050241Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.11672","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-11T01:10:02Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"p8s3a1CZ4lQ5IDEs3t1O1VoGI4N20j0JKUt4FbggGfglQmB2+YnVHscwzmKzqFpLaHYLVIlEZf3xOblb7UynDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T07:41:38.214671Z"},"content_sha256":"ff032583834189677eec7e5ccc4b216e46114fbff92b8ee7bc2b9e55003e81ec","schema_version":"1.0","event_id":"sha256:ff032583834189677eec7e5ccc4b216e46114fbff92b8ee7bc2b9e55003e81ec"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:YCBZLY5ZKA4D6GUMWRDAXBWNDK","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Can Open-Source LLM Agents Replace Static Application Security Testing Tools? An Empirical Assessment","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Derek Yohn, Khaled Slhoub, Luke Flancher, Mirajul Islam","submitted_at":"2026-06-10T05:31:24Z","abstract_excerpt":"This paper explores the value of agentic AI tools for cybersecurity purposes. We evaluate the efficacy of a general-purpose GenAI Large Language Model- (GenAI-) based agent when powered by three different Ollama-hosted general-purpose open source models. We assess each agent's performance using precision, recall, false positive count, and a calculated composite score based upon the interplay of the captured metrics, against the baseline performance of an existing, vetted Static Application Security Testing (SAST) tool, Bandit. Our findings refute the notion that a modern open-source GenAI LLM-"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.11672","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.11672/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-11T01:10:02Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"84WknjAZtfwy9yA2e9GkmbDIuO56cLLWT27983vH3QDvr7F6PtKlQRlU2IAM+gDYSdFg7arL8kX/c1ps/7M7Dw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T07:41:38.215146Z"},"content_sha256":"a53b85df260ba54a3365b1b8638a5d1032824be7150311787a41f661d5d19cb6","schema_version":"1.0","event_id":"sha256:a53b85df260ba54a3365b1b8638a5d1032824be7150311787a41f661d5d19cb6"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/YCBZLY5ZKA4D6GUMWRDAXBWNDK/bundle.json","state_url":"https://pith.science/pith/YCBZLY5ZKA4D6GUMWRDAXBWNDK/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/YCBZLY5ZKA4D6GUMWRDAXBWNDK/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-28T07:41:38Z","links":{"resolver":"https://pith.science/pith/YCBZLY5ZKA4D6GUMWRDAXBWNDK","bundle":"https://pith.science/pith/YCBZLY5ZKA4D6GUMWRDAXBWNDK/bundle.json","state":"https://pith.science/pith/YCBZLY5ZKA4D6GUMWRDAXBWNDK/state.json","well_known_bundle":"https://pith.science/.well-known/pith/YCBZLY5ZKA4D6GUMWRDAXBWNDK/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:YCBZLY5ZKA4D6GUMWRDAXBWNDK","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"4e74ae60d423859cfce0b66e9c4b78944667cc86488b1834d7082c9a464f80eb","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T05:31:24Z","title_canon_sha256":"1668c64a80531ff27375aac759a67ce10715d8930416254814f2146077f8937a"},"schema_version":"1.0","source":{"id":"2606.11672","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.11672","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"arxiv_version","alias_value":"2606.11672v1","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.11672","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"pith_short_12","alias_value":"YCBZLY5ZKA4D","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"pith_short_16","alias_value":"YCBZLY5ZKA4D6GUM","created_at":"2026-06-11T01:10:02Z"},{"alias_kind":"pith_short_8","alias_value":"YCBZLY5Z","created_at":"2026-06-11T01:10:02Z"}],"graph_snapshots":[{"event_id":"sha256:a53b85df260ba54a3365b1b8638a5d1032824be7150311787a41f661d5d19cb6","target":"graph","created_at":"2026-06-11T01:10:02Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.11672/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"This paper explores the value of agentic AI tools for cybersecurity purposes. We evaluate the efficacy of a general-purpose GenAI Large Language Model- (GenAI-) based agent when powered by three different Ollama-hosted general-purpose open source models. We assess each agent's performance using precision, recall, false positive count, and a calculated composite score based upon the interplay of the captured metrics, against the baseline performance of an existing, vetted Static Application Security Testing (SAST) tool, Bandit. Our findings refute the notion that a modern open-source GenAI LLM-","authors_text":"Derek Yohn, Khaled Slhoub, Luke Flancher, Mirajul Islam","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T05:31:24Z","title":"Can Open-Source LLM Agents Replace Static Application Security Testing Tools? An Empirical Assessment"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.11672","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ff032583834189677eec7e5ccc4b216e46114fbff92b8ee7bc2b9e55003e81ec","target":"record","created_at":"2026-06-11T01:10:02Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"4e74ae60d423859cfce0b66e9c4b78944667cc86488b1834d7082c9a464f80eb","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T05:31:24Z","title_canon_sha256":"1668c64a80531ff27375aac759a67ce10715d8930416254814f2146077f8937a"},"schema_version":"1.0","source":{"id":"2606.11672","kind":"arxiv","version":1}},"canonical_sha256":"c08395e3b950383f1a8cb4460b86cd1ab4120f9cc2ca8f9337388d49ffcdfdbc","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c08395e3b950383f1a8cb4460b86cd1ab4120f9cc2ca8f9337388d49ffcdfdbc","first_computed_at":"2026-06-11T01:10:02.050241Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-11T01:10:02.050241Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"PMpJT0PVZj/vwGQC5w3h2ixd4KhAFu4jwA1O430VPgbWrJdQSG+pteC1iyDzdy7hnSOhvo6phNDCMbTAqUzjBA==","signature_status":"signed_v1","signed_at":"2026-06-11T01:10:02.051027Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.11672","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ff032583834189677eec7e5ccc4b216e46114fbff92b8ee7bc2b9e55003e81ec","sha256:a53b85df260ba54a3365b1b8638a5d1032824be7150311787a41f661d5d19cb6"],"state_sha256":"51076170ef0c61b3f4dbe41fc4907cf11a841f049edd9ad2e106a1953d732cf4"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jKm/pR9DKa5um2bT8vHVox+q9wu/uYXvSRDbYnQh74L3KJHV32BCx7eIGZorZS4lSzpNaPK5ld7K4I2KMMSYAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-28T07:41:38.217021Z","bundle_sha256":"7722de987475a53f29a96902ae5e2c40f47e0e396ebeab844db94765286ce8e8"}}