Pith. sign in

Paper Citation Record · LEDGER

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

As of 17 August 2026, this Paper Citation Record lists 100 of 107 outbound references and 10 inbound Pith citation observations for arXiv:2506.13666.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.13666 v1

Coverage vector

measured 100 of 107 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T00:32:36.760608Z

measured 110 of 110 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 10 of 10 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-06T21:44:54.864170Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

100 of 107 outbound references displayed

  • verified exact0
  • verified fuzzy13
  • unresolved87
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation cab8fd2c-7197-4197-b0fc-fef0587b23a5 · outbound

This paper cites Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.443050Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.443050Z digest=sha256:fe6029e69d049c1b610c35cf52dabddd56f7cd46995bbc0703b2e3d0779cc917

Observation da9cb528-7157-4b44-8b73-00c0227eb123 · outbound

This paper cites Introducing the model context protocol.https://www.anthropic.com/news/ model-context-protocol, November 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Introducing the model context protocol.https://www.anthropic.com/news/ model-context-protocol, November 2024

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.447486Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.447486Z digest=sha256:b9ecdd511b8eb199ccd51d96328432c997fe163d241f8d0ffaaf195b61894c2d

Observation e62633f9-e83d-4a72-b74f-41265a3c4fd3 · outbound

This paper cites Foundational Challenges in Assuring Alignment and Safety of Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Foundational Challenges in Assuring Alignment and Safety of Large Language Models

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.451035Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.451035Z digest=sha256:8bdce7fb55cae1b63aec77dd26f647f551361d7904e67df1efb6aea6a6589912

Observation db8f1793-bf40-42a1-9c1f-9efc77144c16 · outbound

This paper cites Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.454938Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.454938Z digest=sha256:9bf5352bcc2df9572ab906057f73b1fd8f55c0d0819970f67398fc52e6c2b84c

Observation e8dd5d7a-7962-493e-b320-9fbace30b48a · outbound

This paper cites Safety-tuned LLaMAs: Lessons from improving the safety of large language models that follow instructions.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety-tuned LLaMAs: Lessons from improving the safety of large language models that follow instructions

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.458413Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.458413Z digest=sha256:27824395e242bf7136575afd777c0c9bb166703dc650f71003af797d1a82a4e9

Observation 1a387885-bd0a-4de2-9931-609e4c15616b · outbound

This paper cites an unresolved cited work.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Unresolved cited work

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.461485Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.461485Z digest=sha256:70a3912ad39677ac5d9c2d6a20d57338d4cb08ee2534db80661b929f4aebccbc

Observation 89437d5c-6824-41ee-9761-7ae1f94654d8 · outbound

This paper cites Highlights from lex fridman’s interview of yann lecun, March.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Highlights from lex fridman’s interview of yann lecun, March

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.464997Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.464997Z digest=sha256:58129b07af4f689c4aca1f68b91660813a847d61dae926729a54b717e0a421ec

Observation c256f18c-5b5b-4146-88f5-2b3a8045b973 · outbound

This paper cites A survey on evaluation of large language models.ACM transactions on intelligent systems and technology, 15(3):1–45, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey on evaluation of large language models.ACM transactions on intelligent systems and technology, 15(3):1–45, 2024

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.471713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.471713Z digest=sha256:4f50f8cfd3a0770fb62f5ab3c68191d8493a1f37ba0cace91b609b1d688a90ca

Observation 11cc4119-caec-474e-968a-138ed5374a77 · outbound

This paper cites Pappas, Florian Tramèr, Hamed Hassani, and Eric Wong.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Pappas, Florian Tramèr, Hamed Hassani, and Eric Wong

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.474958Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.474958Z digest=sha256:b10a7828c842d38a4944ea7b0c9615fb2dc7dc1cad7237c4a265c9580f765f37

Observation 4c2d0d40-1d6a-4979-80f0-8940a1819874 · outbound

This paper cites Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases.Advances in Neural Information Processing Systems, 37:130185–130213, 2025

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.477590Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.477590Z digest=sha256:f6650767f465f0d60c5d3ada5c8dbd8da95598c7bfd43d53c5109c1c7735df78

Observation 599af7df-89b2-426a-9af3-6f744f976cd4 · outbound

This paper cites Safety-aware fine-tuning of large language models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety-aware fine-tuning of large language models

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.480493Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.480493Z digest=sha256:9920b8a4b69025fd13476e00023f59e595eb50e4b8bf5c6ffb6ec2e43e66a112

Observation 349a1758-8d22-4163-8e06-8da4d2fdd95d · outbound

This paper cites Scaling instruction-finetuned language models.Journal of Machine Learning Research, 25(70):1–53, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Scaling instruction-finetuned language models.Journal of Machine Learning Research, 25(70):1–53, 2024

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.483792Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.483792Z digest=sha256:339c7c7bec7794809fea74809365db1f01a6b7f5cf642512fca9f6721ba0def6

Observation 4cb8a155-06a1-4f7e-ac1c-f3da080f6365 · outbound

This paper cites Textworld: A learning environment for text-based games.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Textworld: A learning environment for text-based games

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.486870Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.486870Z digest=sha256:770ded21da99589929c7a8a803bf602d5f7fc677efb82962f66f9d2db24226fc

Observation 47c933f4-d52b-4cd3-a619-3aae05a6b0ad · outbound

This paper cites DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.489432Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.489432Z digest=sha256:c9da7ad50dc1c7f01418db2fe9524c582f2e5b8dabaae99c558b8f88770125bb

Observation b12f1fb7-e970-4920-862b-1ac01661ce5c · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Ai agents under threat: A survey of key security challenges and future pathways

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.492579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.492579Z digest=sha256:4fbb037afd024e9b3c0c8e1798b559ac9a899b15afd314ba84d0a572dc60ea63

Observation 5d55cfb2-91e3-4329-b16a-8462d561c64c · outbound

This paper cites Bert: Pre-training of deep bidirectional transformers for language understanding.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Bert: Pre-training of deep bidirectional transformers for language understanding

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.495577Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.495577Z digest=sha256:b81b22bba378d9a7bdd9ebb738d26cdb046cd1398d37ed0ff3333ad65b424e72

Observation e7069162-a4b2-4c9d-8d8a-ab81d166a0c9 · outbound

This paper cites A Wolf in Sheep's Clothing: Generalized Nested Jailbreak Prompts can Fool Large Language Models Easily.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Wolf in Sheep's Clothing: Generalized Nested Jailbreak Prompts can Fool Large Language Models Easily

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.498449Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.498449Z digest=sha256:76f1bcb0b29c40283660dd0fff994fd08e4cb6c6cfe0c7c1573abea87b0bb41c

Observation 8888b506-9c6e-4569-bb1b-e1f604fda046 · outbound

This paper cites A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP).

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.501355Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.501355Z digest=sha256:6582a4320b43cacba8a9772db9c0fc5235a61108d653fd647efb7ed415c40730

Observation 82bac543-6e04-41e9-8fa1-0d01ddab0f31 · outbound

This paper cites Pawan Kumar, and Adel Bibi.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Pawan Kumar, and Adel Bibi

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.504729Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.504729Z digest=sha256:62718e2ca6963250d2d61131da46ae0f3475fe5c83e20b342e3d4a80c7b5ab99

Observation 87ea844c-4b84-4efe-b22f-b0f8cc12c09b · outbound

This paper cites Imprompter: Tricking LLM Agents into Improper Tool Use.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.507283Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.507283Z digest=sha256:c366928ebcf3a741b192d2783028e3c3e63d4d07a23aac87e099571965d1ff94

Observation b2baea63-0248-4742-94a6-3ba85ab31972 · outbound

This paper cites Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.510129Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.510129Z digest=sha256:008f0d18e4c039c2849e82806f550f8d06b91d9531ed83fdb5a72f858c3a258b

Observation 71d669d1-12cd-4a41-869c-ffc4f118f42d · outbound

This paper cites Textbooks Are All You Need.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Textbooks Are All You Need

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.512749Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.512749Z digest=sha256:c65561ba20055c9b4e6abab6adfbc39df9a3e61b832c338de2c196d9f9f54a83

Observation 6338beed-56ee-4479-b1ce-ca417488e76c · outbound

This paper cites Large Language Model based Multi-Agents: A Survey of Progress and Challenges.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Large Language Model based Multi-Agents: A Survey of Progress and Challenges

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.515911Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.515911Z digest=sha256:b68bff5dfd3d402b93c6406cf8d780a0aa93419b7495a37e5ecdb3ea9f6fb14a

Observation 15daf63a-56cd-4b96-afdb-15cb2ff8a771 · outbound

This paper cites Regulating chatgpt and other large generative ai models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Regulating chatgpt and other large generative ai models

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.519516Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.519516Z digest=sha256:9ab3002ad9548b3e0129e09134d50a2a45a30c36ca79986abe5ef205bed3536b

Observation 74fbc7fb-4214-4ff9-92f1-0361627e54d6 · outbound

This paper cites A survey on large language models: Applications, challenges, limitations, and practical usage.Authorea Preprints, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey on large language models: Applications, challenges, limitations, and practical usage.Authorea Preprints, 2023

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.522302Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.522302Z digest=sha256:b32782bd7901f62d3992e28bda70c3851bf89035b4f12c0489201f406fcbc4ff

Observation c9306aa5-16ba-4a9d-985a-e15869da3867 · outbound

This paper cites What is in Your Safe Data? Identifying Benign Data that Breaks Safety.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems What is in Your Safe Data? Identifying Benign Data that Breaks Safety

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.525213Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.525213Z digest=sha256:fef1a1db91a03c10980406d098c3e7caf6919bd40faca3e70d800ec76cc3851b

Observation 73b9fd81-05b3-489c-b34b-cac9663ac932 · outbound

This paper cites Red-Teaming LLM Multi-Agent Systems via Communication Attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Red-Teaming LLM Multi-Agent Systems via Communication Attacks

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.528134Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.528134Z digest=sha256:3f07cf0b78c531e5528efab9149bdc89b2cb45fe880d5f87ec95ef45b0cc9a12

Observation ed2a81ee-4b17-4cac-8223-bbed55d65379 · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.535179Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.535179Z digest=sha256:8b86dfc56575d1de077aba0b1480397c68df58643af70e50d5a6d967c458e0d0

Observation ecd65069-43f6-4e93-b30d-fac8feff78d3 · outbound

This paper cites T1: Advancing Language Model Reasoning through Reinforcement Learning and Inference Scaling.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems T1: Advancing Language Model Reasoning through Reinforcement Learning and Inference Scaling

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.538291Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.538291Z digest=sha256:2e0044c325c97d8ee6b837698e640d1599f9ab39c941ef54a4b2752dae536436

Observation 3ed7c96d-4758-44d2-816c-28d632e2b569 · outbound

This paper cites Scaling Trends in Language Model Robustness.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Scaling Trends in Language Model Robustness

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.541321Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.541321Z digest=sha256:1da4ab9c0b461a6b20f1f889cc5170e168eb3697990afccb4c0b6a1fa92cab8b

Observation 740059a3-efc9-4b55-8bda-5f99777f08ed · outbound

This paper cites A survey of safety and trustworthiness of large language models through the lens of verification and validation.Artificial Intelligence Review, 57(7):175, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey of safety and trustworthiness of large language models through the lens of verification and validation.Artificial Intelligence Review, 57(7):175, 2024

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.544502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.544502Z digest=sha256:2f98e43dc6a3fef4fff4278cccd0663f8d1162c0e8760f75b7c1827d10e0d6f4

Observation abacfcb5-873b-48ac-93bf-9f014ab7eb00 · outbound

This paper cites Babyai 1.1, 2020.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Babyai 1.1, 2020

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.547224Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.547224Z digest=sha256:098f09b530b35c2147bba32e5e771d1906f8244b068c78acf685810128d79142

Observation 427cf786-071f-45a2-b516-8bde402013dc · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.550081Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.550081Z digest=sha256:79b8bea8dc57c23ea45f0bd53eabfd3fba2598ad53dbaf14345239a1eb5cb997

Observation ec439bd0-f2ff-4c1a-a184-71b64c84c100 · outbound

This paper cites Mcp security notification: Tool poisoning attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Mcp security notification: Tool poisoning attacks

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.553330Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.553330Z digest=sha256:0fb6a0a34180ea33f327c9b6b254846a6d97c63720faa5dba15486ab420b05e9

Observation 1244253f-4154-4114-bd33-9b4ed1d2517d · outbound

This paper cites SafeChain: Safety of Language Models with Long Chain-of-Thought Reasoning Capabilities.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems SafeChain: Safety of Language Models with Long Chain-of-Thought Reasoning Capabilities

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.556165Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.556165Z digest=sha256:e440adbe61356f00cd865bf4c75ffc037f55a05d552f56e83fed6f402dbea825

Observation bdb8422b-033e-43a6-89cf-c0bda4e306b9 · outbound

This paper cites Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Flooding Spread of Manipulated Knowledge in LLM-Based Multi-Agent Communities

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.559678Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.559678Z digest=sha256:d1f9f38c9879813275b365d4499a570c743ae5d97940f3fdf953239dd0b760bc

Observation 19c5409f-c863-4e40-9a1b-ee970cc44425 · outbound

This paper cites Llm-mod: Can large language models assist content moderation? InExtended Abstracts of the CHI Conference on Human Factors in Computing Systems.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Llm-mod: Can large language models assist content moderation? InExtended Abstracts of the CHI Conference on Human Factors in Computing Systems

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.563012Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.563012Z digest=sha256:0231a3e81c8c24c20e4c42c359f8a1277f316937f2f3bfd64633527d20f6c7db

Observation 7f1e61ea-52c3-40fa-a6f5-62f2bf479779 · outbound

This paper cites Watch your language: Investigating content moderation with large language models.Proceedings of the International AAAI Conference on Web and Social Media, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Watch your language: Investigating content moderation with large language models.Proceedings of the International AAAI Conference on Web and Social Media, 2024

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.565644Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.565644Z digest=sha256:0c15720e0feacd4715c3d90d2f60cc23a76e50308d65475953eb35bdaaa8bcc9

Observation 511c0034-a37f-4235-b47d-765d0119c364 · outbound

This paper cites MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.568714Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.568714Z digest=sha256:2befc12ad1300b7141d92e95093424f82e045e08dd1ab80297addcc49468f2af

Observation 1d46beab-1ba3-4821-9853-c92ee7fc1333 · outbound

This paper cites How not to be stupid about ai, with yann lecun.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems How not to be stupid about ai, with yann lecun

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.571929Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.571929Z digest=sha256:c1a1be993d8f5e6f3548d48f5ce2ebaa5412ff8553304db021023cd57939fd44

Observation 4a01d0f6-66ab-4bb4-bdc9-77680eb4f755 · outbound

This paper cites Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.575227Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.575227Z digest=sha256:73c34799c36b98533bd6d51d2887b7126a09332f90781c1ab74efb1c4ec998d9

Observation 59802d7a-0a03-4b0c-9a71-8ec832f81fca · outbound

This paper cites Common 7B Language Models Already Possess Strong Math Capabilities.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Common 7B Language Models Already Possess Strong Math Capabilities

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.578494Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.578494Z digest=sha256:f3d8ea23239449221f9ce418abfc28d552a51e075d5ab90c49b60bf6b6e0d71a

Observation c8132a73-f252-428c-96ae-e33004d5b5c2 · outbound

This paper cites Camel: Communicative agents for" mind" exploration of large language model society.Advances in Neural Information Processing Systems, 36:51991–52008, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Camel: Communicative agents for" mind" exploration of large language model society.Advances in Neural Information Processing Systems, 36:51991–52008, 2023

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.581487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.581487Z digest=sha256:9786cb349db6e6c77e6ba00bb7e2f9b153f7b8c7cbbd7796e554a90989d33ded

Observation 9a00be52-d04d-4e03-ab77-9f90bda7a673 · outbound

This paper cites DeepInception: Hypnotize Large Language Model to Be Jailbreaker.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems DeepInception: Hypnotize Large Language Model to Be Jailbreaker

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.584165Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.584165Z digest=sha256:930ebe57a3696c5678de51356c9afcc0537aa98be63095813d70ef3c071f7afe

Observation a299b3ba-ca64-428c-a5f5-87a036e037af · outbound

This paper cites The Unlocking Spell on Base LLMs: Rethinking Alignment via In-Context Learning.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The Unlocking Spell on Base LLMs: Rethinking Alignment via In-Context Learning

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.587266Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.587266Z digest=sha256:640002e9c571aa7b2649995576275d3ecfcf7da1b790227959393812cb5a2f80

Observation feffbfcf-e616-4ee4-a8e2-f837a306ebf3 · outbound

This paper cites Understanding and enhancing the transferability of jailbreaking attacks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Understanding and enhancing the transferability of jailbreaking attacks

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.590175Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.590175Z digest=sha256:10bf1f4f6a726e7123e4b20ba48cb1fc9b45eb50475993572b6940529241a7cb

Observation 5f27bde5-03c1-4068-bc86-5710b3f6facc · outbound

This paper cites ToolACE: Winning the Points of LLM Function Calling.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ToolACE: Winning the Points of LLM Function Calling

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.593020Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.593020Z digest=sha256:5e66121ee5f9432ed13607ec98f051d7c93534b9034f1838c316a6ae3f88eee3

Observation 64067349-a619-4bd7-b98d-afd287c03953 · outbound

This paper cites Autodan: Generating stealthy jailbreak prompts on aligned large language models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Autodan: Generating stealthy jailbreak prompts on aligned large language models

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.595996Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.595996Z digest=sha256:365420c3e35b6f747e366d03a49a04460c0c948d0b6d8b48e082971ea4315b97

Observation f578c017-50af-4261-9762-8f77c9152e97 · outbound

This paper cites Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.598721Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.598721Z digest=sha256:6d5d680322692e021ce6a8d2c6ab70131ced30c175f234e8cbfd81d94e14c348

Observation bbfc070e-c4aa-4838-bdd6-01e020769a5f · outbound

This paper cites RobustFT: Robust Supervised Fine-tuning for Large Language Models under Noisy Response.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems RobustFT: Robust Supervised Fine-tuning for Large Language Models under Noisy Response

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.601660Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.601660Z digest=sha256:186e9c27c147b95f22f145edefda662dcdb017c11ea4ae201c62088c1cc6e75f

Observation f700f20c-b668-4c99-a7fc-334e65e65551 · outbound

This paper cites CodeChameleon: Personalized Encryption Framework for Jailbreaking Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems CodeChameleon: Personalized Encryption Framework for Jailbreaking Large Language Models

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.604717Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.604717Z digest=sha256:19c268f11c20f2e531635ea568d7835b11bcc33a60c1114a864cc339ad986d2c

Observation 7954f0b0-91d6-43a7-8bd6-2edf9f2652f8 · outbound

This paper cites Agentboard: An analytical evaluation board of multi-turn llm agents, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Agentboard: An analytical evaluation board of multi-turn llm agents, 2024

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.607632Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.607632Z digest=sha256:c1f6f05678d318bbe5171da2c381cc04e162dd1cc94d5c65b64c09659303b5f7

Observation f5dc2dfc-0fac-4b1a-b621-b202218ea1a0 · outbound

This paper cites Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.610249Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.610249Z digest=sha256:3794818f1afebf4e6c79ed6b4f41a6dd31a2e3f461c5b0bb0ecf4e265eff3895

Observation 7b9f233f-ddce-4c8d-9b52-39901c78a083 · outbound

This paper cites AgentSafe: Safeguarding Large Language Model-based Multi-agent Systems via Hierarchical Data Management.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems AgentSafe: Safeguarding Large Language Model-based Multi-agent Systems via Hierarchical Data Management

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.613450Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.613450Z digest=sha256:1013fc1d76c195c0666090f14cdff22c0a23263d102e6e8a4105664364e4bb49

Observation c7de98e6-ed07-46f7-a216-adaf5a45e658 · outbound

This paper cites an unresolved cited work.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Unresolved cited work

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.617161Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.617161Z digest=sha256:24f97484815344d641d98c928012e50fcdd3c85e8a50d62881c98bccfbeab2ed

Observation 4540d3ec-8f76-41be-b476-e4d565fa9ffe · outbound

This paper cites A Comprehensive Overview of Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Comprehensive Overview of Large Language Models

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.619901Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.619901Z digest=sha256:445724a6a92856294ecefd3d3ad613096a07be6d8e4f6090e8a5afca076c4a96

Observation 26ca70b2-80f0-4e90-9655-1d19342371e8 · outbound

This paper cites GPT-4 technical report.CoRR, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems GPT-4 technical report.CoRR, 2023

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.623242Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.623242Z digest=sha256:cad71d25ca030238f83900253f0a467e07417a15d23e69e5b543db8f3fd5850e

Observation 93a25dfa-c201-4bb1-aaef-b423ed7d83e6 · outbound

This paper cites Training language models to follow instructions with human feedback.Advances in neural information processing systems, 35:27730–27744, 2022.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Training language models to follow instructions with human feedback.Advances in neural information processing systems, 35:27730–27744, 2022

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.626365Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.626365Z digest=sha256:ef23b3b1fbbb6b893c50ad5563683fb9b03e2cf8bbc881906c7fb68a4c3b1c26

Observation 5153d8fc-048f-4b5a-a9a7-4b814de674f6 · outbound

This paper cites Self-alignment of large language models via monopolylogue-based social scene sim- ulation.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Self-alignment of large language models via monopolylogue-based social scene sim- ulation

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.618797Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.629215Z digest=sha256:ee69125ad49ee89c8af82ccd1e85100af4fcfafb748864e558ec99957d21afb6

Observation 9e7ec986-2242-46b0-b1ce-329bf2db8fb7 · outbound

This paper cites A survey on agent-based modelling assisted by machine learning.Expert Systems, 42(1):e13325, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A survey on agent-based modelling assisted by machine learning.Expert Systems, 42(1):e13325, 2025

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.608506Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.632627Z digest=sha256:e65ef300e651a78797fcad6a2bbbb12cfd45f21baf7c4583f73e1be93980dbca

Observation b9f45d87-fa24-49cb-852f-836ec4551680 · outbound

This paper cites ADaPT: As-Needed Decomposition and Planning with Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ADaPT: As-Needed Decomposition and Planning with Language Models

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.635903Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.635903Z digest=sha256:5549e4a9d165be2519d4f2c6e6e8f2293ee9e487a78c24ea4fe9aa9247a48283

Observation bfe99cd4-0424-4e95-bcd6-a7d4a6e6dd80 · outbound

This paper cites Fine-tuning Aligned Language Models Compromises Safety, Even When Users Do Not Intend To!.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Fine-tuning Aligned Language Models Compromises Safety, Even When Users Do Not Intend To!

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.639515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.639515Z digest=sha256:360506594bf2c1433eb16391650e0d20378cee67284e5719f0ff9ddca32aeb23

Observation fc79b600-34e2-42f3-bf03-69748daac3d7 · outbound

This paper cites Safety alignment should be made more than just a few tokens deep.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Safety alignment should be made more than just a few tokens deep

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.598823Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.642841Z digest=sha256:d69fb3004d9ccb1273e11aa39ce39fffc76a6a75e0c991ae3b4a6a6b6dd8d2ff

Observation 54ba21df-c8af-47e0-a521-de0985373cb3 · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.645879Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.645879Z digest=sha256:784f11fd2a62130692149839cc66fe1da2865ad584f1d6c6a8a67e027574736a

Observation a26c16fc-22fc-46ef-83f1-d36f03a32ea9 · outbound

This paper cites Tptu: Task planning and tool usage of large language model-based ai agents.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Tptu: Task planning and tool usage of large language model-based ai agents

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.588649Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.648975Z digest=sha256:e62b830917a65bcde1f21de0d8499c4f404937f827906e6a739c2077a9e67d79

Observation eee225d5-1ecd-48db-83f4-59c3f3eb83e2 · outbound

This paper cites Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36: 68539–68551, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36: 68539–68551, 2023

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.651630Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.651630Z digest=sha256:c81bb476045ebdfdff60eae867a76ae66dfafaafcd626650ee356d61d39b4015

Observation 95941cb5-c39b-4245-9ab4-f38416c441f1 · outbound

This paper cites Large Language Model Safety: A Holistic Survey.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Large Language Model Safety: A Holistic Survey

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.657747Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.657747Z digest=sha256:3cb55a513b7de65e4873872a594000c0b32f3aae928eff748fc6007566772709

Observation e38e1f26-8af7-43dc-846e-f22688ba3362 · outbound

This paper cites Welcome to the era of experience.Google AI, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Welcome to the era of experience.Google AI, 2025

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.572748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.660554Z digest=sha256:7e1bfb0d2742f1e514e0769d743788b04a021a50c6c9c4c1f3ff3cffb50c6b91

Observation bc18e7db-d374-4fb0-bf7f-cce0c18a9f5c · outbound

This paper cites Large language model (chatgpt) as a support tool for breast tumor board.NPJ Breast Cancer, 9(1):44, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Large language model (chatgpt) as a support tool for breast tumor board.NPJ Breast Cancer, 9(1):44, 2023

Reference 71

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.563133Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.663467Z digest=sha256:95c6750c92a3749dfd00bda4e2647bac8c156b758e9c172568325044996e9e01

Observation 068ee5fd-9a41-438b-bcaa-82dc516b2131 · outbound

This paper cites ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.666302Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.666302Z digest=sha256:2864995ec62f9b7cfd0680567dba23de1119670e7829111a8ef97de523062c78

Observation f034a09e-e2fa-4274-ab49-808463f0e4b1 · outbound

This paper cites A Survey on Post-training of Large Language Models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Survey on Post-training of Large Language Models

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.669532Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.669532Z digest=sha256:21f02f25727d7bac9f45a1b97b3b9529a7707899d392a1d6fe71180bf861a43d

Observation e49dc2bf-5595-4833-a4fd-4f0d3ee92e48 · outbound

This paper cites Multi-Agent Collaboration Mechanisms: A Survey of LLMs.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Multi-Agent Collaboration Mechanisms: A Survey of LLMs

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.672515Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.672515Z digest=sha256:38b6a3ad0b480c5173d882153da3daefd73fc3677de8f2c74b7141b7a974df7a

Observation 036f6ddd-16e2-4554-a054-a056ef1b0c3c · outbound

This paper cites House Committee on Oversight and Accountability.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems House Committee on Oversight and Accountability

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.553788Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.675669Z digest=sha256:c000f9904de1939251738356ed48b964f36d9c3dc6922a6a0b52194805ccb1ba

Observation 6ba5b7ab-5472-4f04-ba3b-bd5d1c00b471 · outbound

This paper cites From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.678358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.678358Z digest=sha256:540cea90ea275e803da5dea32f20a8b36380003c7973013f41c0495403257948

Observation 6fe0c16b-c9c5-4686-b103-ddb0ced94a13 · outbound

This paper cites Backdooralign: Mitigating fine-tuning based jailbreak attack with backdoor enhanced safety alignment.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Backdooralign: Mitigating fine-tuning based jailbreak attack with backdoor enhanced safety alignment

Reference 77

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.544261Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.682146Z digest=sha256:03f68c24e28297bac2cf6c26ee47a70992fda712449bb4cf6cbb728e2c3bd136

Observation 1cd39cb2-ad4d-4097-9cd9-44ea269ef0ba · outbound

This paper cites A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.685699Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.685699Z digest=sha256:856b676524cbfb2bbcba917d9cdde729e2327306688d33ca2063060869894bf7

Observation be9ee4a7-10a0-4f4b-a793-d24b6bec5b18 · outbound

This paper cites ScienceWorld: Is your Agent Smarter than a 5th Grader?.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems ScienceWorld: Is your Agent Smarter than a 5th Grader?

Reference 79

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.689405Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.689405Z digest=sha256:f51172a8df2af9729c44baa6f4a158991f779e531d0fedb214137b693fd599d9

Observation 785cfa32-51aa-4d6f-ad78-502d0157a6af · outbound

This paper cites G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent Systems.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent Systems

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.692682Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.692682Z digest=sha256:900e0370f676bb58025b86d279fb30629df509d5d77a851ebc22cdcdeaea1e4b

Observation b61d1d5a-cf4b-4993-a884-8647f3aef8da · outbound

This paper cites Augmenting language models with long-term memory.Advances in Neural Information Processing Systems, 36:74530–74543, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Augmenting language models with long-term memory.Advances in Neural Information Processing Systems, 36:74530–74543, 2023

Reference 81

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.695853Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.695853Z digest=sha256:a0051adc256dba3ec0013bc002930d1f2aa84ffe9a9575710c7b6763ada7a330

Observation c81ab498-e158-400f-84ac-8be0fcd0581e · outbound

This paper cites AgentGym: Evolving Large Language Model-based Agents across Diverse Environments.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems AgentGym: Evolving Large Language Model-based Agents across Diverse Environments

Reference 82

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.698999Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.698999Z digest=sha256:bebc285b3f4c3bcd998b4eff639783682f5dea97642071b08fb020ad81f6eb2a

Observation e48af40e-acf2-42d8-b9d9-dd4fc079521b · outbound

This paper cites The rise and potential of large language model based agents: A survey.Science China Information Sciences, 68(2):121101, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The rise and potential of large language model based agents: A survey.Science China Information Sciences, 68(2):121101, 2025

Reference 83

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.702156Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.702156Z digest=sha256:2a40904f39c14dd045215358bf41bc8cdffdc0e73b1acd87e6e81e4f764c12fe

Observation f96d077d-7cfb-4ecc-949e-513f4ebb4f35 · outbound

This paper cites Certifiably robust rag against retrieval corruption.arXiv preprint arXiv:2405.15556, 2024.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Certifiably robust rag against retrieval corruption.arXiv preprint arXiv:2405.15556, 2024

Reference 84

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.704889Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.704889Z digest=sha256:231e26a4d342d65a60f02fe2fd0d632aacdc86ea39730b9637d7dd938aa895ee

Observation 380e6eee-66c5-484b-86ee-9f201f1e5933 · outbound

This paper cites Bag of tricks: Benchmarking of jailbreak attacks on llms.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Bag of tricks: Benchmarking of jailbreak attacks on llms

Reference 85

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.521751Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.707657Z digest=sha256:d5b7341072bcf07e96f0af62189b12452322485e4b5f99833e8f6a266754a7fe

Observation 74828f52-df54-443a-8638-be1165b46fcd · outbound

This paper cites Qwen3 Technical Report.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Qwen3 Technical Report

Reference 86

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.710457Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.710457Z digest=sha256:b02763a8fb27910686dcfcd6d1fefe4145c2916ee39b4cff5f15f2f2d25b4677

Observation 95703251-2882-404c-9a50-c7e497ae4a07 · outbound

This paper cites Gpt4tools: Teaching large language model to use tools via self-instruction.Advances in Neural Information Processing Systems, 36:71995–72007, 2023.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Gpt4tools: Teaching large language model to use tools via self-instruction.Advances in Neural Information Processing Systems, 36:71995–72007, 2023

Reference 87

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.713245Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.713245Z digest=sha256:11d1bb325cd0e9d4cd0b8e5731712d832a4c73dc685e9cebf7cdf6be466a958e

Observation a19666c5-0f5d-45e7-a5fb-c9349549add3 · outbound

This paper cites The second half.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The second half

Reference 88

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.506455Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.716985Z digest=sha256:b3d623730f259cd69c92c0c7a82f78c2c1b94192ed7314f09cf036c3f1e80052

Observation 7f61f150-b491-4527-9a47-b62e72b3d17d · outbound

This paper cites Webshop: Towards scalable real-world web interaction with grounded language agents.Advances in Neural Information Processing Systems, 35:20744–20757, 2022.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Webshop: Towards scalable real-world web interaction with grounded language agents.Advances in Neural Information Processing Systems, 35:20744–20757, 2022

Reference 89

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.719731Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.719731Z digest=sha256:be2d58e14c46cdadb8405ea77c46fb087903d01170adab276b6490b250249fac

Observation fea6eceb-7aa5-4c7c-b05d-1c583cb0e5d6 · outbound

This paper cites On the vulnerability of safety alignment in open-access llms.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems On the vulnerability of safety alignment in open-access llms

Reference 90

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.490297Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.722464Z digest=sha256:fc4713bfc8c55097c11dc9c39510d64c8a263bcd2333ae243c8e5a2be8985dd9

Observation adf6ba7d-7317-400d-a0e8-27f41b4d2700 · outbound

This paper cites NetSafe: Exploring the Topological Safety of Multi-agent Networks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems NetSafe: Exploring the Topological Safety of Multi-agent Networks

Reference 91

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.725488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.725488Z digest=sha256:edacfb0a7e3f061fdeefc8c61dd49fdca118b4f2c3b5d3a6290b1a39d19fb256

Observation 658a354a-f690-49f2-985f-f7672cd019dc · outbound

This paper cites A Survey on Trustworthy LLM Agents: Threats and Countermeasures.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Survey on Trustworthy LLM Agents: Threats and Countermeasures

Reference 92

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.728262Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.728262Z digest=sha256:4149a7c920dd78809ad2ab4190f81a6541cf1036b25b31fb978520a6c78c401c

Observation 1524d6e6-286a-43ba-93ef-3b2fef453951 · outbound

This paper cites GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher

Reference 93

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.731379Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.731379Z digest=sha256:259492117ac9bac06dd8e539b600073aee31863cdc1efce4765d217bdb2c0c27

Observation 00c62709-3317-40a3-b346-442a63fdae42 · outbound

This paper cites The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG).

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG)

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.734755Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.734755Z digest=sha256:82dffd57ec08391f5ca3f6157269886cad0b98b1a9495407bdc428e1e27d9b91

Observation f589ac32-fc8d-4d1b-96e3-5b2e30bd4aa3 · outbound

This paper cites Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification

Reference 95

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.737890Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.737890Z digest=sha256:e5e44c63e9bb2898fa965018ef507d3be3ba032dc280562f6ef0de9c33c684c9

Observation ab6de568-c470-4aab-88e5-dea0578791ba · outbound

This paper cites Cut the Crap: An Economical Communication Pipeline for LLM-based Multi-Agent Systems.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Cut the Crap: An Economical Communication Pipeline for LLM-based Multi-Agent Systems

Reference 96

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.740954Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.740954Z digest=sha256:e519c88a2171689a559268a120608b74a885279d0ded2b07c8151ac8a7efb082

Observation e4edd56d-f9ec-49a4-953c-f24c4b7be12c · outbound

This paper cites G-Designer: Architecting Multi-agent Communication Topologies via Graph Neural Networks.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems G-Designer: Architecting Multi-agent Communication Topologies via Graph Neural Networks

Reference 97

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.744658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.744658Z digest=sha256:e976f8f9c41b9d6c2be4349ef099851e0bc4e0e4f4119170d811dc6c601197ed

Observation 957146b2-5704-4b00-aba6-c0e9972dae84 · outbound

This paper cites Multi-agent Architecture Search via Agentic Supernet.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Multi-agent Architecture Search via Agentic Supernet

Reference 98

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.747826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.747826Z digest=sha256:1eb2c5ff6b9b821702eb1189b80d40f524c7c36d7a4c7e06f447ddaaa0704558

Observation 135758a2-101f-46b2-b1b3-b9f34e775ef4 · outbound

This paper cites On large language models safety, security, and privacy: A survey.Journal of Electronic Science and Technology, page 100301, 2025.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems On large language models safety, security, and privacy: A survey.Journal of Electronic Science and Technology, page 100301, 2025

Reference 99

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.480624Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.751306Z digest=sha256:18860578232cbfb1374713249220b6a77e3a64ef6233959ea5d2047c8f01e114

Observation 345cee46-9e13-41d1-b269-df216f2781e7 · outbound

This paper cites A Survey on the Memory Mechanism of Large Language Model based Agents.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems A Survey on the Memory Mechanism of Large Language Model based Agents

Reference 100

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.754225Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.754225Z digest=sha256:2881f80458734d68f9932a3d3e21d4bb8f45673fef21833d9d647ed137c7c9cb

Observation 076583d6-15c9-4396-a3d0-44469bf491fb · outbound

This paper cites Agent-SafetyBench: Evaluating the Safety of LLM Agents.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Agent-SafetyBench: Evaluating the Safety of LLM Agents

Reference 101

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.757251Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.757251Z digest=sha256:4c893c3c065394b151c49402ab9550b034f38c7c6f69f1e993acdb75adbbc48a

Observation 3a8ecb07-4fc3-4a68-ab6a-ff2bac3b1b42 · outbound

This paper cites Weak-to-strong jailbreaking on large language models.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Weak-to-strong jailbreaking on large language models

Reference 102

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:32:37.470778Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-07T00:32:36.760608Z digest=sha256:de514963a57286ca4ad1b40aef542d101ed87f79f0924f054a789822e7643a19

Pith citing papers

Observation 90e1e1ed-8764-4e66-a8d9-6960ea2c0b21 · inbound

A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis cites this paper.

A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-06T21:44:54.864170Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:44:54.864170Z digest=sha256:a28bc5de24f4cd3ea41d95739cac1deb14e68d0f4b2e37533613f7bdaa92076b

Observation cfe0e7e8-93f6-4771-ad9f-5e537f17e30b · inbound

A Survey of Context Engineering for Large Language Models cites this paper.

A Survey of Context Engineering for Large Language Models We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 268

Resolution
verified exact
arxiv_id, observed 2026-05-13T20:58:45.454680Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-13T20:58:45.060041Z digest=sha256:78942e9883e7b7df92bad040b76daa653f0742c320f3fb7edce17c816bc83cd3

Observation e0d13b95-ba3d-45c4-a254-a4f2d61dcdb2 · inbound

Quantifying Conversation Drift in MCP via Latent Polytope cites this paper.

Quantifying Conversation Drift in MCP via Latent Polytope We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-05T22:51:28.082763Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T22:51:28.082763Z digest=sha256:9f7e3b1ed764e9b2a26bb4e8cee07c5af4287d1bc71c8f9424ce0f4098dfb1e7

Observation 20c9401e-5b28-422d-ba1a-9243586357e2 · inbound

SafeSearch: Automated Red-Teaming of LLM-Based Search Agents cites this paper.

SafeSearch: Automated Red-Teaming of LLM-Based Search Agents We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-04T14:43:49.514734Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T14:43:49.514734Z digest=sha256:07810882443deff28a6fe5956db38b82862e54b31c2f262be33b30b6dc03ba5d

Observation fefa0c54-1a93-4642-b570-953c2be5843e · inbound

AgentBound: Securing Execution Boundaries of AI Agents cites this paper.

AgentBound: Securing Execution Boundaries of AI Agents We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-18T05:15:54.194195Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-18T05:12:23.542793Z digest=sha256:bdf522fe81195f84ae87328b363dbcb47cabfe46f13265298760983f8b17190f

Observation 3124087a-1487-43c7-acf0-c3166b8bb612 · inbound

BalDRO: A Distributionally Robust Optimization based Framework for Large Language Model Unlearning cites this paper.

BalDRO: A Distributionally Robust Optimization based Framework for Large Language Model Unlearning We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-03T10:45:41.323277Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T10:45:41.323277Z digest=sha256:74f601f961d2080d7587c9d5c8fe95c609c76481b72f8320072673ed51d7d846

Observation 99d5a936-f809-49ba-9bd3-93cff40c539c · inbound

Combating Data Laundering in LLM Training cites this paper.

Combating Data Laundering in LLM Training We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 16

Resolution
unresolved
no resolver link, observed 2026-07-13T14:08:35.474488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-13T14:08:35.474488Z digest=sha256:5e54f5238901dfa6d6956f16e8ceecf62168b9f273edb2fde06eb65f0c1c6a8a

Observation 480a69b4-2b84-4ec8-a628-112915abefca · inbound

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers cites this paper.

From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-21T10:44:07.943736Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-21T10:41:17.307952Z digest=sha256:5ed0614973cd8b878702595dfbed010b5db38c9c7ac615df9b6cc44d6fa10ef4

Observation 90f557b0-dd05-47fa-bd65-952d9dc1467e · inbound

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security cites this paper.

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-10T21:10:46.722140Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-05-10T17:10:50.283791Z digest=sha256:98e5268708aaea379966a256e4cec85f3bc6b2854aa9a29c1442f3fb5c92be84

Observation 6bfb7f42-7003-402d-9b36-9ebc80aaad4c · inbound

"What Happens Locally, Leaks Globally": Detecting Privacy Leakage Risks in MCP Servers cites this paper.

"What Happens Locally, Leaks Globally": Detecting Privacy Leakage Risks in MCP Servers We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems

Reference 9

Resolution
metadata mismatch
arxiv_id, observed 2026-07-04T06:49:38.283917Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-06-26T14:07:59.170493Z digest=sha256:e49e1dc90b02797299b82f907b462077ec0f6cce56e06d673c5dc9585d6f4e83