{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:YRFCYASBTZX6LU2R4U3AMHMSA3","short_pith_number":"pith:YRFCYASB","canonical_record":{"source":{"id":"2605.30521","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-28T19:57:28Z","cross_cats_sorted":[],"title_canon_sha256":"2cfbe00f86666888c3195545ba83c5c658812dd536b1d8a490702756cf9e3398","abstract_canon_sha256":"e987c28ec55787d742e56ddba794eee4d6802bb965fe75a796bbbd5537a5dfae"},"schema_version":"1.0"},"canonical_sha256":"c44a2c02419e6fe5d351e536061d9206dce536e98d0d55ccb589bcbfa83767e3","source":{"kind":"arxiv","id":"2605.30521","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.30521","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"arxiv_version","alias_value":"2605.30521v1","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.30521","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"pith_short_12","alias_value":"YRFCYASBTZX6","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"pith_short_16","alias_value":"YRFCYASBTZX6LU2R","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"pith_short_8","alias_value":"YRFCYASB","created_at":"2026-06-01T01:02:58Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:YRFCYASBTZX6LU2R4U3AMHMSA3","target":"record","payload":{"canonical_record":{"source":{"id":"2605.30521","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-28T19:57:28Z","cross_cats_sorted":[],"title_canon_sha256":"2cfbe00f86666888c3195545ba83c5c658812dd536b1d8a490702756cf9e3398","abstract_canon_sha256":"e987c28ec55787d742e56ddba794eee4d6802bb965fe75a796bbbd5537a5dfae"},"schema_version":"1.0"},"canonical_sha256":"c44a2c02419e6fe5d351e536061d9206dce536e98d0d55ccb589bcbfa83767e3","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-01T01:02:58.849212Z","signature_b64":"AzieqrQZpqnXkotz5QaTEJsyrn5BUZx9Rz29baKSIn/RvfPw+Ml1SqvZ6706vhIYu0IYrzDAhwhSjMPxI8F8Aw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c44a2c02419e6fe5d351e536061d9206dce536e98d0d55ccb589bcbfa83767e3","last_reissued_at":"2026-06-01T01:02:58.848111Z","signature_status":"signed_v1","first_computed_at":"2026-06-01T01:02:58.848111Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.30521","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-01T01:02:58Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"pKbcDVn+vu/lMMzgciB54tNF8FN//UGmcL2mQUbw6OWIJIj4yYtGF/j4cPzlDGBAco86vp0yqGHElNo1SDiHBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T19:51:48.465831Z"},"content_sha256":"b8e35be791046f4bd41c966dcc9780cef28b9132492867ec641346e777097b63","schema_version":"1.0","event_id":"sha256:b8e35be791046f4bd41c966dcc9780cef28b9132492867ec641346e777097b63"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:YRFCYASBTZX6LU2R4U3AMHMSA3","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Evaluating using Mock Tool Calls to Quarantine Untrusted Prompt Inputs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Adam Gleave, David Gros","submitted_at":"2026-05-28T19:57:28Z","abstract_excerpt":"Large language models must frequently process untrusted inputs, such as judging an answer from another model or running tasks like spam and harm classifiers while under adversarial pressure. These inputs are often string-formatted directly into a prompt template, leaving systems fragile to manipulation. Current LLM specs from major providers like OpenAI distinguish trustworthiness along an Instruction Hierarchy, from System messages (most trusted) to Tool Results (least trusted). A possible natural mitigation is to wrap untrusted content in a mock tool call as a quarantine. We explore this hyp"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.30521","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.30521/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-01T01:02:58Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jqaxSJ6T5FxJ8jl9hbNPIktt3askmRRfyv9puA7Xo6Q1p3ctHYXbMrEGQA9Ry0SFfEMdzpRoM4tQuGd6pyd8Bw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T19:51:48.466210Z"},"content_sha256":"9b483d2f7297e80e44b0ce8dfdd32c1af39b67987188d616f1f941b8ea03a543","schema_version":"1.0","event_id":"sha256:9b483d2f7297e80e44b0ce8dfdd32c1af39b67987188d616f1f941b8ea03a543"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/YRFCYASBTZX6LU2R4U3AMHMSA3/bundle.json","state_url":"https://pith.science/pith/YRFCYASBTZX6LU2R4U3AMHMSA3/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/YRFCYASBTZX6LU2R4U3AMHMSA3/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-10T19:51:48Z","links":{"resolver":"https://pith.science/pith/YRFCYASBTZX6LU2R4U3AMHMSA3","bundle":"https://pith.science/pith/YRFCYASBTZX6LU2R4U3AMHMSA3/bundle.json","state":"https://pith.science/pith/YRFCYASBTZX6LU2R4U3AMHMSA3/state.json","well_known_bundle":"https://pith.science/.well-known/pith/YRFCYASBTZX6LU2R4U3AMHMSA3/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:YRFCYASBTZX6LU2R4U3AMHMSA3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e987c28ec55787d742e56ddba794eee4d6802bb965fe75a796bbbd5537a5dfae","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-28T19:57:28Z","title_canon_sha256":"2cfbe00f86666888c3195545ba83c5c658812dd536b1d8a490702756cf9e3398"},"schema_version":"1.0","source":{"id":"2605.30521","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.30521","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"arxiv_version","alias_value":"2605.30521v1","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.30521","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"pith_short_12","alias_value":"YRFCYASBTZX6","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"pith_short_16","alias_value":"YRFCYASBTZX6LU2R","created_at":"2026-06-01T01:02:58Z"},{"alias_kind":"pith_short_8","alias_value":"YRFCYASB","created_at":"2026-06-01T01:02:58Z"}],"graph_snapshots":[{"event_id":"sha256:9b483d2f7297e80e44b0ce8dfdd32c1af39b67987188d616f1f941b8ea03a543","target":"graph","created_at":"2026-06-01T01:02:58Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.30521/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language models must frequently process untrusted inputs, such as judging an answer from another model or running tasks like spam and harm classifiers while under adversarial pressure. These inputs are often string-formatted directly into a prompt template, leaving systems fragile to manipulation. Current LLM specs from major providers like OpenAI distinguish trustworthiness along an Instruction Hierarchy, from System messages (most trusted) to Tool Results (least trusted). A possible natural mitigation is to wrap untrusted content in a mock tool call as a quarantine. We explore this hyp","authors_text":"Adam Gleave, David Gros","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-28T19:57:28Z","title":"Evaluating using Mock Tool Calls to Quarantine Untrusted Prompt Inputs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.30521","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:b8e35be791046f4bd41c966dcc9780cef28b9132492867ec641346e777097b63","target":"record","created_at":"2026-06-01T01:02:58Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e987c28ec55787d742e56ddba794eee4d6802bb965fe75a796bbbd5537a5dfae","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-28T19:57:28Z","title_canon_sha256":"2cfbe00f86666888c3195545ba83c5c658812dd536b1d8a490702756cf9e3398"},"schema_version":"1.0","source":{"id":"2605.30521","kind":"arxiv","version":1}},"canonical_sha256":"c44a2c02419e6fe5d351e536061d9206dce536e98d0d55ccb589bcbfa83767e3","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c44a2c02419e6fe5d351e536061d9206dce536e98d0d55ccb589bcbfa83767e3","first_computed_at":"2026-06-01T01:02:58.848111Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-01T01:02:58.848111Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"AzieqrQZpqnXkotz5QaTEJsyrn5BUZx9Rz29baKSIn/RvfPw+Ml1SqvZ6706vhIYu0IYrzDAhwhSjMPxI8F8Aw==","signature_status":"signed_v1","signed_at":"2026-06-01T01:02:58.849212Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.30521","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:b8e35be791046f4bd41c966dcc9780cef28b9132492867ec641346e777097b63","sha256:9b483d2f7297e80e44b0ce8dfdd32c1af39b67987188d616f1f941b8ea03a543"],"state_sha256":"a2c2d9115601a374aac82f80fa18e6d55aa12b02cc6b0ce2ef68b16e0fd9ef7e"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"s51Eb4/IioFgih5DqSqP+lMoRakSnzy+lAgmz94sppCjCbrsiLqwBV6ZsH8Q+RMK9kEJ5faZpobXUkuWZyVrBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-10T19:51:48.468463Z","bundle_sha256":"cef233c2544812f0168516cff27d47639b51c03fa57fe27c23d2f3ac847a0586"}}