Pith. sign in

Paper Citation Record · LEDGER

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

As of 15 August 2026, this Paper Citation Record lists 49 of 49 outbound references and 11 inbound Pith citation observations for arXiv:2509.05755.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2509.05755 v6

Coverage vector

measured 49 of 49 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T05:09:40.020584Z

measured 60 of 60 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-15T06:32:42.880941+00:00

measured 11 of 11 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-04T08:06:16.098981Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

49 of 49 outbound references displayed

  • verified exact2
  • verified fuzzy28
  • unresolved19
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation e9995044-7870-47d3-81cc-d43ac03c5082 · outbound

This paper cites https://jfrog.com/blog/p rompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://jfrog.com/blog/p rompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/, 2024

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.530979Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.717409Z digest=sha256:6e842881c245fc5a52fbf55e2f016acec506e4b927d65a5024096244c5bbc230

Observation 908d4b2e-401b-408b-ac44-14ea48069655 · outbound

This paper cites https://thehackernews.com/2024 /06/prompt-injection-flaw-in-vanna-ai.html, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://thehackernews.com/2024 /06/prompt-injection-flaw-in-vanna-ai.html, 2024

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.511326Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.724902Z digest=sha256:22058a9a3f7288a1aef4991e4f0c183929a14ac24c33990353f921dcefff30d4

Observation 97061c38-caf8-4dd3-952b-00931101f7fe · outbound

This paper cites https://www.cherry-ai.com/, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://www.cherry-ai.com/, 2025

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.485868Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.731021Z digest=sha256:93c4f1c6728a7e41588591b601621fc6e72dd772e02341d2f175ebd88088da5f

Observation 62abf537-44cd-430f-976e-e005c318ed76 · outbound

This paper cites https://docs.anthropic.com/en/docs/claude-code/overview , 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.anthropic.com/en/docs/claude-code/overview , 2025

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.456265Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.737081Z digest=sha256:ac45a835b5f70a33225cf947f580d2eafe92488c7534a49c20137a727319eeb0

Observation cd49c8f8-9c8d-4051-9592-a3964d41fb86 · outbound

This paper cites https://docs.github.com/en/copil ot/using-github-copilot/copilot-chat, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://docs.github.com/en/copil ot/using-github-copilot/copilot-chat, 2025

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.428727Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.743955Z digest=sha256:792d230518e83a12be95e7c14ab97a5cc0b6407838c26284ba0358006aea1f7a

Observation ad5068f1-0cd3-4a4d-ab91-481c6f494f4e · outbound

This paper cites https://owasp.org/www-proje ct-top-10-for-large-language-model-applications/, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment https://owasp.org/www-proje ct-top-10-for-large-language-model-applications/, 2025

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.400243Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.749409Z digest=sha256:b7881498c584939c16090a0d92b37a3e8949d3c7975fbdf385572b755a2c688e

Observation 3588386c-dd77-41c4-8838-5966f11ef3dd · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.375616Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.755742Z digest=sha256:6808f5f174c6426356dc1c0d525bb52b855ba2c8f8f5d21ee8580d53e9ce2191

Observation 28026c98-05e1-415c-81ca-2b32d8c036a9 · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.352428Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.762358Z digest=sha256:2325e90446fcb8524c260cac9fb0abf332dc2cea5646edf71877ca46d51f35dc

Observation 89f1ba3c-72ac-4fc3-b6d0-8f58e83df1ea · outbound

This paper cites Anthropic tool use and function calling.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Anthropic tool use and function calling

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.327200Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.768821Z digest=sha256:7bcee264727603709fcdb25d4e559906eeace164cd27736388d761baa9b60008

Observation 9a0f2e10-81c2-45a2-83b3-573ddea70a5e · outbound

This paper cites Model context protocol.https://docs.anthropic.com/docs/mcp/, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Model context protocol.https://docs.anthropic.com/docs/mcp/, 2024

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.305113Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.776491Z digest=sha256:c1411e1a4894f75a1fd403b56733913620f7ddef40e3a5bfa449379ff7a9a21d

Observation c9179a97-7fa6-44f1-8062-1426bbf4cf12 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.782564Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.782564Z digest=sha256:3178473763f4438b26f3ca9afd90f142acdabc74901ab2834a88188fd4ed36b4

Observation 407c5235-9481-478b-9021-979d2501ae22 · outbound

This paper cites Accessed 2025-08-26.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Accessed 2025-08-26

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.278728Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.789182Z digest=sha256:aff8d81725081736ca8ab742449693dcad438f117aac3ff7812ed9006d68da80

Observation 07079539-cf03-4ffe-a02d-24f475836e0e · outbound

This paper cites Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Agentdojo: A dynamic environment to evaluate prompt injection attacks and defenses for llm agents.Advances in Neural Information Processing Systems, 37:82895–82920, 2024

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.256452Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.795361Z digest=sha256:3995acf61441d884d6aaab2ef66660e66e4262684c2cdd35dfe9f3068309c617

Observation f3762e53-3c9e-461c-a296-2888f147cbac · outbound

This paper cites The Llama 3 Herd of Models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment The Llama 3 Herd of Models

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.800933Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.800933Z digest=sha256:76cef93d869c99e2fcd9d0d23692159d5b7e6002c77d349b4c7a9a3fe44e8e10

Observation 2a3bf3fe-ac71-45a1-bfe0-02f925a4b86e · outbound

This paper cites Conversational Prompt Engineering.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Conversational Prompt Engineering

Reference 15

Resolution
verified exact
local_arxiv, observed 2026-08-05T05:09:40.777379Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.806899Z digest=sha256:f5a446aae298c1833e31c0fcbe796edc168fe559dc8cdb8bb716db39176f8728

Observation 0e8dfd11-281a-4c09-91c8-f6ef868ce623 · outbound

This paper cites WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.813876Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.813876Z digest=sha256:a52a48bd7205f1ade93cd9abb60827fde3df7186802c24c082c0895d200ac116

Observation ef92fb38-1d05-47b3-8b4d-4afed1b45398 · outbound

This paper cites An Empirical Categorization of Prompting Techniques for Large Language Models: A Practitioner's Guide.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment An Empirical Categorization of Prompting Techniques for Large Language Models: A Practitioner's Guide

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.820844Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.820844Z digest=sha256:953b1166e784df2f6b1a5b0e1afe0e5537c6871cbaad6f226fda8762d854c020

Observation d868d79c-af93-469e-887d-e8428f51f636 · outbound

This paper cites What is prompt engineering? https://cloud.google.com/discover/what-is-promp t-engineering?hl=en#what-is-prompt-engineering, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is prompt engineering? https://cloud.google.com/discover/what-is-promp t-engineering?hl=en#what-is-prompt-engineering, 2025

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.232493Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.828635Z digest=sha256:f5480f2ed5c73a8d16968562fbef9b731f6a1caafec2028d52c489d41f520e36

Observation b4656a5e-5286-4acb-a1d8-2dd5e5a89746 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.835452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.835452Z digest=sha256:ca20a99253b2084da41c5db5e54b30cf6a508850f8ff3da8e8c1e933c4ed3f00

Observation a43c34b6-1182-4430-99b8-28e4822e7418 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.841874Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.841874Z digest=sha256:073cf21b20304e8c30df4716d1a1d87176c9d2f6b875979d4d9c66e16b07a9cb

Observation 85e9ee6f-d778-4a05-a24d-147cab8a50b9 · outbound

This paper cites Promptshield: Deploy- able detection for prompt injection attacks.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Promptshield: Deploy- able detection for prompt injection attacks

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.193369Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.848575Z digest=sha256:0024bd695e45a8ba8bcae789f2a08f99caf285d9d3ef33cb6e8b54a8ac363654

Observation 27b5fa44-5b19-4017-9c30-566884e56539 · outbound

This paper cites Kpmg ai quarterly pulse survey: From agent experimentation to rapid scale and deployment.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Kpmg ai quarterly pulse survey: From agent experimentation to rapid scale and deployment

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.172873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.855633Z digest=sha256:395a41707f3ec84c0440e159d7caa218191beae40eed6e2885110195ff072a18

Observation a3a3005c-09d3-4bc1-ac61-76dc3459c4f4 · outbound

This paper cites How to use chat models to call tools.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment How to use chat models to call tools

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.150660Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.861201Z digest=sha256:756cd3d89651b0754a343616c3df5cf6ebf6836120ca9f8ab8a2a58d53899fb5

Observation ae5f12df-493f-4ed9-ba60-7c71131e3ff7 · outbound

This paper cites EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.868193Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.868193Z digest=sha256:94a8db3a36ea2c9f1046f6a822469b411c107dfb2c545f1d372a03a2c2bf6f7a

Observation d7881e67-b55b-4f0a-a74f-5b1944d62543 · outbound

This paper cites Self-Reflection Makes Large Language Models Safer, Less Biased, and Ideologically Neutral.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Self-Reflection Makes Large Language Models Safer, Less Biased, and Ideologically Neutral

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.874576Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.874576Z digest=sha256:cd4fedda2449d96582c953786d9e3aad1e05127ae228e94295bb381223a7ed4c

Observation 4119c212-c675-408a-81e9-0e99ba7fe945 · outbound

This paper cites Demystifying rce vulnerabilities in llm-integrated apps.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Demystifying rce vulnerabilities in llm-integrated apps

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.126476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.879992Z digest=sha256:58dee89c3da6ce329ee3c3934ef5fdd1abe9bd4b5c8833ca447495d3a5106381

Observation c568f671-1bbd-4ccd-8da4-85eea6062524 · outbound

This paper cites What do you want? user-centric prompt generation for text-to-image synthesis via multi-turn guidance.arXiv preprint arXiv:2408.12910, 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What do you want? user-centric prompt generation for text-to-image synthesis via multi-turn guidance.arXiv preprint arXiv:2408.12910, 2024

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.887000Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.887000Z digest=sha256:341db2d2fb45158272989f544887de07a932089e54f31cc5e35843c6e4dfc0dc

Observation d6f45d43-3a6d-4e11-bf11-4700c819a7f0 · outbound

This paper cites Formalizing and bench- marking prompt injection attacks and defenses.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Formalizing and bench- marking prompt injection attacks and defenses

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.098378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.892467Z digest=sha256:8b0cb5a59112a035041709badba658d2559632b893a5c557a2cba8fbc7020492

Observation 6f1910d5-5138-4ac3-8888-c7e150c90193 · outbound

This paper cites LLM In-Context Recall is Prompt Dependent.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment LLM In-Context Recall is Prompt Dependent

Reference 29

Resolution
verified exact
local_arxiv, observed 2026-08-05T05:09:40.275758Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.897444Z digest=sha256:8954fafe859b48ac76ecbe67b782f3727c5c9fef8739e7fda99777764a1f5e3b

Observation 71f603de-062e-4ca4-a6b1-0630cb42a9d4 · outbound

This paper cites Large Language Models Know Your Contextual Search Intent: A Prompting Framework for Conversational Search.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Large Language Models Know Your Contextual Search Intent: A Prompting Framework for Conversational Search

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.903821Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.903821Z digest=sha256:038166d46a26dc8c5b7eea4441ccaf9c7126663232d95baa3f852bd0d826c0df

Observation 579ea73d-e38b-4363-bf91-7ade07ccf287 · outbound

This paper cites Llama-prompt-guard-2-22m.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Llama-prompt-guard-2-22m

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.073052Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.909568Z digest=sha256:755a295a1393c5c690d68f49465ddbc74926e96a47dc03011fd66ff95911f692

Observation c5410c68-8013-4137-b1be-d3555ec15528 · outbound

This paper cites Augmented Language Models: a Survey.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Augmented Language Models: a Survey

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.915182Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.915182Z digest=sha256:e40897c4fcb6f71c309ddee0bb434c4d485499c16754c9a2814fa5d54de34af0

Observation 39e175ac-9b83-4922-9ee4-5ad3e26f625a · outbound

This paper cites A Closer Look at System Prompt Robustness.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment A Closer Look at System Prompt Robustness

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.921172Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.921172Z digest=sha256:ff5a9b6ab55b15fd1a34c80bbaf712091022d9996f9997b609701a1752294201

Observation 7b8a8328-08ce-48a9-b6d4-25206be9f2d5 · outbound

This paper cites Position is power: System prompts as a mechanism of bias in large language models (llms).

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Position is power: System prompts as a mechanism of bias in large language models (llms)

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.046186Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.926761Z digest=sha256:6d79f03d4b788ec136db116a8dc147ee7cf1e8d129f75d9856c851db77b1436e

Observation 51e69f08-bc38-41a7-9027-b8bb4893e81b · outbound

This paper cites What is agentic ai? https://blogs.nvidia.com/blog/what-is-agentic-ai/ , 2024.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment What is agentic ai? https://blogs.nvidia.com/blog/what-is-agentic-ai/ , 2024

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.025647Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.933155Z digest=sha256:b32dce7ca09e0d601366c07689630ae4b795f233fb1d9a7b803f0d2520de8b9d

Observation 85c1f51f-3a59-46e4-8458-194e521ee7ac · outbound

This paper cites Function Calling with LLMs.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Function Calling with LLMs

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:41.005989Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.939751Z digest=sha256:1d8f79fff4e284dcaa084d70dbb2502a40edf9173d98a2027ad35e9847d5e3c9

Observation c045c9d2-502b-4728-a01e-b20d81f1ed24 · outbound

This paper cites Openai assistants and tool use documentation.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Openai assistants and tool use documentation

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.984125Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.945109Z digest=sha256:9bf940cfe709a8c588f92f348f57cefc5e8834815f566417301a17edcb90984a

Observation d8150135-e2ca-4871-9c30-2ee3b1997c5e · outbound

This paper cites Pwc’s ai agent survey.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Pwc’s ai agent survey

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.964097Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.950807Z digest=sha256:a47d8034d7ebd8f6dd289f4b1b33926c9573da01573a88dc906f2228d7deeb60

Observation ea544374-55c9-45f2-8a42-10ee93d2d637 · outbound

This paper cites Tool learning with large language models: A survey.Frontiers of Computer Science, 19(8):198343, 2025.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Tool learning with large language models: A survey.Frontiers of Computer Science, 19(8):198343, 2025

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.957253Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.957253Z digest=sha256:6115afbad32497be98db84c90728786eb36e5aef460df03a77c3348fa296d889

Observation 0caf3c5a-5e4a-4ec4-91c4-462359a1756b · outbound

This paper cites Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36:68539–68551, 2023.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Toolformer: Language models can teach themselves to use tools.Advances in Neural Information Processing Systems, 36:68539–68551, 2023

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.933641Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.963689Z digest=sha256:761dd659849daf6e5f48f4b7194892f4214a2dec60c1462b7401a7943c7d02ed

Observation fe7e9087-75fb-4593-a0a9-62ffbe2bfc75 · outbound

This paper cites Cline — ai coding, open source and uncompromised.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Cline — ai coding, open source and uncompromised

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.911858Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.969422Z digest=sha256:b0ff83b91d7b54774328721221457fa333c5ef499a59e600272f47022b8d4ede

Observation 9c655096-f07b-42c1-b1cc-3548e9f88d27 · outbound

This paper cites AdvAgent: Controllable Blackbox Red-teaming on Web Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment AdvAgent: Controllable Blackbox Red-teaming on Web Agents

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.975185Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.975185Z digest=sha256:9b13c49b7d1e55772c99e60f661d6cd325868d461eca6ab75f699ca71ef596ed

Observation aa5368bd-9afc-4180-b2ac-059056983a7a · outbound

This paper cites React: Synergizing reasoning and acting in language models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment React: Synergizing reasoning and acting in language models

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.981410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.981410Z digest=sha256:b67b906bbc460c8a82295bba04e01b6d3839e51592854f82e5adb0e353bc7a57

Observation 9acb4cc3-cf41-47ab-a028-ae5e1faf9068 · outbound

This paper cites Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.987143Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.987143Z digest=sha256:b155a9181fe4ec04009827c76c41442e4be18762dedc6ba96fbd7b3812c017c1

Observation d981f5bf-91c7-408e-8196-88cd0ac27398 · outbound

This paper cites Injecagent: Benchmarking indirect prompt injections in tool-integrated llm agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Injecagent: Benchmarking indirect prompt injections in tool-integrated llm agents

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.876491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:39.993267Z digest=sha256:4854952a5928e2c57e1be9d64371cdc886a00ab8769e177c59f9338493c7cd18

Observation 06f34892-dbc4-47f3-a2d6-a25f7954bf0a · outbound

This paper cites SPRIG: Improving Large Language Model Performance by System Prompt Optimization.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment SPRIG: Improving Large Language Model Performance by System Prompt Optimization

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:39.998742Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:39.998742Z digest=sha256:bab7cdc24ab50f36a695a26700459481190f372655becf1e6a7cdef8e9cb3d4c

Observation 7a67a165-bd3d-411e-82f6-82ce4ba28d9c · outbound

This paper cites a helpful assistant.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment a helpful assistant

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T05:09:40.850748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-08-05T05:09:40.007399Z digest=sha256:49f227c00cb1bcdeed58d35b9f73a8ec7981fcc51626ba6a5a9f1feca5ffe1e2

Observation 439ec31b-2370-422d-a5ee-527c586cfa08 · outbound

This paper cites Context-faithful Prompting for Large Language Models.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment Context-faithful Prompting for Large Language Models

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.014381Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.014381Z digest=sha256:86e1e5106613c2e5525297f96b14a72e0eadf3481f7f81b95ca23cba878d4189

Observation cf50d8e3-a96a-4a81-9b6d-0591876bad5e · outbound

This paper cites MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents.

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-05T05:09:40.020584Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T05:09:40.020584Z digest=sha256:d61f644e6ada97b88b60ea38ce41e7e8141caefd5c2e494ff1654218db95929b

Pith citing papers

Observation 9d74020d-4276-44f4-972a-d140ebd224d1 · inbound

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem cites this paper.

Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 50

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-18T18:43:35.072919Z digest=sha256:ed0aeee57c6802827f8d79d335d1e7778ac7fde3c8737ae59e4fe583bdac9ee4

Observation b2f37388-ce84-46df-a93e-5317fdf8e087 · inbound

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents cites this paper.

When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 94

Resolution
unresolved
no resolver link, observed 2026-08-04T08:06:16.098981Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T08:06:16.098981Z digest=sha256:05872e992a59e8db495a64f278eb174aaf1e8050de285929f34eede9060c14f0

Observation 647942dc-86f7-4c34-b8d2-3c4975cffa7d · inbound

Verifiable Manifest Signing and Transparency Enforcement for Secure MCP-Based LLM Pipelines cites this paper.

Verifiable Manifest Signing and Transparency Enforcement for Secure MCP-Based LLM Pipelines Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-03T06:18:06.545883Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T06:18:06.545883Z digest=sha256:02042a1667feeb7329334c5d92bb8e621d1d35ca839c2ab7baa93f6a5c5975ce

Observation aaad7391-b404-488a-bdc8-97f7d54d5713 · inbound

Security Considerations for Multi-agent Systems cites this paper.

Security Considerations for Multi-agent Systems Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 279

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-15T14:12:14.160789Z digest=sha256:99491cf6ff8aaa05f51172b1508f82c00a1cbd5d6a06637e8244f356989e001b

Observation ca03258d-9fd1-4e78-b649-060698daa6bc · inbound

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents cites this paper.

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-05-08T18:42:06.418583Z digest=sha256:a103946bd0a378d4bb136f315daf89dabd32c29e8dde568fb3cf16054af3e4ec

Observation ae2b9919-6ccc-4980-96d2-63039ece1e71 · inbound

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents cites this paper.

Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T15:04:20.284238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T15:04:20.284238Z digest=sha256:b28deeed0343298fb139eed45927a150180935019ba7e62d044894c1336e0fd2

Observation e3a483f2-a692-4cf3-af23-03f439f78a3d · inbound

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents cites this paper.

When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 16

Resolution
verified exact
local_arxiv, observed 2026-06-30T16:24:55.067215Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-06-30T16:22:23.857438Z digest=sha256:a6be96272997687b8c31920fd4372da0186c5f4bdd4eca1b2b3d6a565d3a8ee4

Observation eef9bcc5-a2fe-485b-ab8c-85086b0598ad · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 208

Resolution
verified exact
arxiv_id, observed 2026-06-30T02:16:09.705257Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:86523e6463d6b5a9ae0f45a910640616ff6e930d4d34c4b527b9d24b80e99280

Observation 09dc7c45-d270-4e7a-aa73-62ff2e95d091 · inbound

Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study cites this paper.

Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 100

Resolution
verified exact
local_arxiv, observed 2026-07-03T12:08:07.100919Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-06-27T09:06:12.868791Z digest=sha256:d871d3618034f941ec193d3f69a3ad53cdbc90e779eae86030326f551fc90a66

Observation 71ce2c75-eb1f-4265-a68f-6b6c27a541bd · inbound

ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP cites this paper.

ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 30

Resolution
verified exact
local_arxiv, observed 2026-07-04T14:19:54.256550Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.

source=pdf_text observed=2026-06-26T04:07:14.506108Z digest=sha256:d9a4b94a42637adcd13ec2e141ff0711ae4c56d04d427c0f648acb97b334f63d

Observation 0c219119-2ba5-4ca1-8932-b9a863d5a04d · inbound

Where Is the Cost of Third-Party API Routers in Agentic Software Development? cites this paper.

Where Is the Cost of Third-Party API Routers in Agentic Software Development? Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Reference 25

Resolution
unresolved
no resolver link, observed 2026-07-30T17:25:46.962117Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-30T17:25:46.962117Z digest=sha256:cc5ec079f059b61f9a95831c4380e68ff41d297deb6b426163316619bf24a883