{"as_of":"2026-08-12T15:22:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:76f48a4583c9497a28d309799df9575a5905d1a88805b147aee51495341a0b52","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":7,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":7,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-12T06:34:41.77262+00:00","state":"measured"},{"denominator":7,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":7,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-11T16:17:43.467187Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":2,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2402.10753","last_updated":"2024-08-16T04:12:00Z","snapshot_observed_at":"2026-08-07T05:22:38.113689Z","submitted_at":"2024-02-16T15:19:46Z","title":"ToolSword: Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages","version":2},"cited_work":{"arxiv_id":"2402.10753","doi":"10.48550/arxiv.2402.10753","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.10753","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"ToolSword : Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages , August 2024","venue":"arXiv (Cornell University)","work_id":"3ce9e404-4c20-4729-a6d2-4e35ff696716","year":2024},"citing_paper":{"arxiv_id":"2410.07283","last_updated":"2024-10-09T11:01:29Z","snapshot_observed_at":"2026-08-11T20:32:18.138792Z","submitted_at":"2024-10-09T11:01:29Z","title":"Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems","version":1},"reference_index":47,"source":"arxiv_source","source_observed_at":"2026-05-15T19:32:19.405615Z"},"links":{"cited_paper":"/paper/2402.10753","citing_paper":"/paper/2410.07283"},"observation_digest":"sha256:e8d2b5cde7e922b7f66d45b9ebc8961fcd7a08c674589e6140e82def41dbf7ee","observation_id":"a9370a34-a9a9-40b2-98db-e898b1e69bf9","resolution":{"observed_at":"2026-05-15T19:32:19.552364Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.10753","last_updated":"2024-08-16T04:12:00Z","snapshot_observed_at":"2026-08-07T05:22:38.113689Z","submitted_at":"2024-02-16T15:19:46Z","title":"ToolSword: Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages","version":2},"cited_work":{"arxiv_id":"2402.10753","doi":"10.48550/arxiv.2402.10753","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.10753","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"ToolSword : Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages , August 2024","venue":"arXiv (Cornell University)","work_id":"3ce9e404-4c20-4729-a6d2-4e35ff696716","year":2024},"citing_paper":{"arxiv_id":"2410.07283","last_updated":"2024-10-09T11:01:29Z","snapshot_observed_at":"2026-08-11T20:32:18.138792Z","submitted_at":"2024-10-09T11:01:29Z","title":"Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems","version":1},"reference_index":91,"source":"arxiv_source","source_observed_at":"2026-05-15T19:32:19.405615Z"},"links":{"cited_paper":"/paper/2402.10753","citing_paper":"/paper/2410.07283"},"observation_digest":"sha256:215658e3e5ce46693abea4a80f4bdc5792845edee65465b0dcfbf0688d19e416","observation_id":"1830dac3-fb12-466b-9f02-e2e46ef46e44","resolution":{"observed_at":"2026-05-15T19:32:19.661130Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.10753","last_updated":"2024-08-16T04:12:00Z","snapshot_observed_at":"2026-08-07T05:22:38.113689Z","submitted_at":"2024-02-16T15:19:46Z","title":"ToolSword: Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.10753","snapshot_observed_at":"2026-08-11T16:17:43.467187Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2412.10198","last_updated":"2025-02-07T13:26:18Z","snapshot_observed_at":"2026-08-12T09:14:59.029526Z","submitted_at":"2024-12-13T15:15:24Z","title":"From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection","version":2},"reference_index":24,"source":"arxiv_source","source_observed_at":"2026-08-11T16:17:43.467187Z"},"links":{"cited_paper":"/paper/2402.10753","citing_paper":"/paper/2412.10198"},"observation_digest":"sha256:db5d5e4ccacdfb51db07deab8afd9074106a771d8c04bb9f26dff1d403063c9e","observation_id":"6f96c74a-9cef-4953-9504-08f9c33184e1","resolution":{"observed_at":"2026-08-11T16:17:43.467187Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.10753","last_updated":"2024-08-16T04:12:00Z","snapshot_observed_at":"2026-08-07T05:22:38.113689Z","submitted_at":"2024-02-16T15:19:46Z","title":"ToolSword: Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages","version":2},"cited_work":{"arxiv_id":"2402.10753","doi":"10.48550/arxiv.2402.10753","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.10753","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"ToolSword : Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages , August 2024","venue":"arXiv (Cornell University)","work_id":"3ce9e404-4c20-4729-a6d2-4e35ff696716","year":2024},"citing_paper":{"arxiv_id":"2503.23278","last_updated":"2025-10-07T07:13:32Z","snapshot_observed_at":"2026-08-12T15:09:08.519195Z","submitted_at":"2025-03-30T01:58:22Z","title":"Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions","version":3},"reference_index":77,"source":"pdf_text","source_observed_at":"2026-05-13T09:02:40.294491Z"},"links":{"cited_paper":"/paper/2402.10753","citing_paper":"/paper/2503.23278"},"observation_digest":"sha256:956a4fd3f41f43c3514d4684cf87f7fc3e05aba44ac896c862d74a36f3a1430a","observation_id":"96907386-5e41-48d1-bba7-1f6966552bb6","resolution":{"observed_at":"2026-05-13T09:02:40.359422Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.10753","last_updated":"2024-08-16T04:12:00Z","snapshot_observed_at":"2026-08-07T05:22:38.113689Z","submitted_at":"2024-02-16T15:19:46Z","title":"ToolSword: Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.10753","snapshot_observed_at":"2026-08-07T12:06:27.595232Z","title":"Toolsword: Unveiling safety issues of large language models in tool learning across three stages.arXiv preprint arXiv:2402.10753, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.00618","last_updated":"2025-06-20T01:24:06Z","snapshot_observed_at":"2026-08-10T07:10:47.014132Z","submitted_at":"2025-05-31T16:04:59Z","title":"RiOSWorld: Benchmarking the Risk of Multimodal Computer-Use Agents","version":3},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-07T12:06:27.595232Z"},"links":{"cited_paper":"/paper/2402.10753","citing_paper":"/paper/2506.00618"},"observation_digest":"sha256:88d42843b2f3c17b29873111b569c9bfdba7d8535f6da084d5594560bdccfaca","observation_id":"24801c2b-85b4-4807-9e59-e076dfa33945","resolution":{"observed_at":"2026-08-07T12:06:27.595232Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.10753","last_updated":"2024-08-16T04:12:00Z","snapshot_observed_at":"2026-08-07T05:22:38.113689Z","submitted_at":"2024-02-16T15:19:46Z","title":"ToolSword: Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2402.10753","snapshot_observed_at":"2026-08-06T15:39:59.000880Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.15296","last_updated":"2025-07-21T06:55:37Z","snapshot_observed_at":"2026-08-10T16:16:26.896079Z","submitted_at":"2025-07-21T06:55:37Z","title":"Butterfly Effects in Toolchains: A Comprehensive Analysis of Failed Parameter Filling in LLM Tool-Agent Systems","version":1},"reference_index":26,"source":"arxiv_source","source_observed_at":"2026-08-06T15:39:59.000880Z"},"links":{"cited_paper":"/paper/2402.10753","citing_paper":"/paper/2507.15296"},"observation_digest":"sha256:cde29abda3c00c3aced36cd2db9a666eff683cbdde0fe74d472796089b4ad06c","observation_id":"685b145e-471b-42ad-8cfa-d2d6695d3892","resolution":{"observed_at":"2026-08-06T15:39:59.000880Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2402.10753","last_updated":"2024-08-16T04:12:00Z","snapshot_observed_at":"2026-08-07T05:22:38.113689Z","submitted_at":"2024-02-16T15:19:46Z","title":"ToolSword: Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages","version":2},"cited_work":{"arxiv_id":"2402.10753","doi":"10.48550/arxiv.2402.10753","metadata_source":"arxiv_reference","pith_arxiv_id":"2402.10753","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"ToolSword : Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages , August 2024","venue":"arXiv (Cornell University)","work_id":"3ce9e404-4c20-4729-a6d2-4e35ff696716","year":2024},"citing_paper":{"arxiv_id":"2606.09692","last_updated":"2026-06-08T16:10:05Z","snapshot_observed_at":"2026-08-10T17:02:06.876878Z","submitted_at":"2026-06-08T16:10:05Z","title":"Observability for Delegated Execution in Agentic AI Systems","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-06-27T16:20:33.798752Z"},"links":{"cited_paper":"/paper/2402.10753","citing_paper":"/paper/2606.09692"},"observation_digest":"sha256:b5dfedf428bccb529e82703ab6e1e12db1ad612c5ccf706c6f363c22f5336d55","observation_id":"04d8944f-17b8-4a3d-bac3-de77b31e8f75","resolution":{"observed_at":"2026-07-03T01:47:31.265413Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2402.10753/citation-record","integrity":"/paper/2402.10753/integrity","json":"/paper/2402.10753/citation-record.json","paper":"/paper/2402.10753"},"outbound":[],"paper":{"arxiv_id":"2402.10753","last_updated":"2024-08-16T04:12:00Z","latest_version":2,"primary_category":"cs.CL","snapshot_observed_at":"2026-08-07T05:22:38.113689Z","submitted_at":"2024-02-16T15:19:46Z","title":"ToolSword: Unveiling Safety Issues of Large Language Models in Tool Learning Across Three Stages"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"thesis":"As of 12 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 7 inbound Pith citation observations for arXiv:2402.10753."}