{"as_of":"2026-08-15T21:30:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:ece65143e2373b00f06302f5ada874e5ad3bf43b25d74997d32e734096dd5a06","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":14,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":14,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-15T06:32:42.880941+00:00","state":"measured"},{"denominator":14,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":14,"source":"paper_references, paper_reference_links","source_observed_at":"2026-07-10T12:20:03.672480Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":1,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2602.17753","last_updated":"2026-05-06T13:43:46Z","snapshot_observed_at":"2026-08-06T12:13:42.632788Z","submitted_at":"2026-02-19T18:57:43Z","title":"The 2025 AI Agent Index: Documenting Technical and Safety Features of Deployed Agentic AI Systems","version":2},"reference_index":139,"source":"pdf_text","source_observed_at":"2026-05-15T20:41:49.137745Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2602.17753"},"observation_digest":"sha256:6c6cc100518c16e639eb2df436f6723c439c66f54a16785ab23eac33c548ad2e","observation_id":"ec163114-becf-44a3-93ab-fe9b0a9c4a98","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2603.09002","last_updated":"2026-04-26T14:13:48Z","snapshot_observed_at":"2026-08-14T21:45:56.224919Z","submitted_at":"2026-03-09T22:46:27Z","title":"Security Considerations for Multi-agent Systems","version":2},"reference_index":128,"source":"pdf_text","source_observed_at":"2026-05-15T14:12:14.160789Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2603.09002"},"observation_digest":"sha256:65154c9e39c0f1421484ca946d312b32b733e7959279bb1a48e743e05418a216","observation_id":"baf82be7-dfea-4b6b-8cd6-4670ce1b7429","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2603.12230","last_updated":"2026-04-05T08:33:19Z","snapshot_observed_at":"2026-08-04T04:27:19.804842Z","submitted_at":"2026-03-12T17:49:39Z","title":"Security Considerations for Artificial Intelligence Agents","version":2},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-05-15T12:37:27.153365Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2603.12230"},"observation_digest":"sha256:dc96aa3e050f0d4a7d8afe24d8cb6e9e81757638b00d63db51d4f798b24af289","observation_id":"da654f9d-7022-4680-9295-d23daa2bc74c","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2604.07536","last_updated":"2026-04-08T19:18:11Z","snapshot_observed_at":"2026-08-15T07:23:04.232775Z","submitted_at":"2026-04-08T19:18:11Z","title":"TRUSTDESC: Preventing Tool Poisoning in LLM Applications via Trusted Description Generation","version":1},"reference_index":76,"source":"pdf_text","source_observed_at":"2026-05-10T17:16:35.875601Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2604.07536"},"observation_digest":"sha256:0906d40c3d6c04dc6bc3fbba35199f13ac7f8663fce0b1f148419220c40923fe","observation_id":"d7e137b8-c2d8-4911-adc2-736c8e256432","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2604.27202","last_updated":"2026-04-29T21:09:21Z","snapshot_observed_at":"2026-08-11T13:56:31.818773Z","submitted_at":"2026-04-29T21:09:21Z","title":"Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives","version":1},"reference_index":97,"source":"pdf_text","source_observed_at":"2026-05-07T08:55:39.589773Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2604.27202"},"observation_digest":"sha256:0a115882c09c744d586aa597464b73c638834a95538b55a2d42600390a1655f0","observation_id":"773fa62e-314f-4ca0-8b5b-8efa398cc30a","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.01644","last_updated":"2026-05-02T23:34:32Z","snapshot_observed_at":"2026-08-11T15:49:43.658949Z","submitted_at":"2026-05-02T23:34:32Z","title":"Toward a Principled Framework for Agent Safety Measurement","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-05-09T13:59:04.866706Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.01644"},"observation_digest":"sha256:cf1d76e49748608a66e252f2482bf2e2f1354a8a75cb443ce1192cc0852f5369","observation_id":"d0eae604-3357-4766-a29f-6d9294fc6bb5","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.05509","last_updated":"2026-05-06T23:19:38Z","snapshot_observed_at":"2026-08-12T21:27:11.076034Z","submitted_at":"2026-05-06T23:19:38Z","title":"WAAA! Web Adversaries Against Agentic Browsers","version":1},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-05-08T16:08:51.850890Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.05509"},"observation_digest":"sha256:9c47fdb1808cfefc227951674b0580ae2bc6dcec6a7b8f8aed6e137b9c9b86c7","observation_id":"7b423caf-0233-4add-b9cb-150bac94caa5","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.07110","last_updated":"2026-05-08T01:38:46Z","snapshot_observed_at":"2026-07-06T23:19:30.387067Z","submitted_at":"2026-05-08T01:38:46Z","title":"Securing Computer-Use Agents: A Unified Architecture-Lifecycle Framework for Deployment-Grounded Reliability","version":1},"reference_index":191,"source":"pdf_text","source_observed_at":"2026-05-11T01:15:19.239355Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.07110"},"observation_digest":"sha256:1dba343225bf068cc3dbc005b7e67bdbfaee95ce48306725661dd02356cc999b","observation_id":"27dd033b-ee7d-416e-8881-03289350d7e4","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.14290","last_updated":"2026-05-14T02:48:57Z","snapshot_observed_at":"2026-08-15T03:56:40.702016Z","submitted_at":"2026-05-14T02:48:57Z","title":"Web Agents Should Adopt the Plan-Then-Execute Paradigm","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-05-15T02:42:05.644536Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.14290"},"observation_digest":"sha256:9298825ac32ae51e7f60effc618a8ac49fcaa18c6d5ed7e3994ebb908795a6de","observation_id":"e903b718-ddd9-484f-8d4d-39f3ae39dbc1","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.15030","last_updated":"2026-05-14T16:26:27Z","snapshot_observed_at":"2026-08-13T15:20:39.475290Z","submitted_at":"2026-05-14T16:26:27Z","title":"WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections","version":1},"reference_index":78,"source":"pdf_text","source_observed_at":"2026-06-30T20:16:13.413064Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.15030"},"observation_digest":"sha256:34400f2adef1512146fbe91eb251a4acddb610cd0de536a8fa0ff7e2422f568b","observation_id":"a9f8880c-dfec-4ced-aff0-e506b530688d","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2605.17453","last_updated":"2026-05-17T13:51:34Z","snapshot_observed_at":"2026-08-15T04:30:18.612754Z","submitted_at":"2026-05-17T13:51:34Z","title":"Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-05-19T23:26:15.658106Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2605.17453"},"observation_digest":"sha256:85105289076659b662e5c33a8e2464b9fcc022f4d25d7f2ca4676f0bc5727660","observation_id":"6a8e7267-cf47-44be-b914-0f8d010ee7d7","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2606.14027","last_updated":"2026-06-30T01:10:08Z","snapshot_observed_at":"2026-08-02T09:41:26.926011Z","submitted_at":"2026-06-12T02:01:38Z","title":"Same-Origin Policy for Agentic Browsers","version":3},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-07-01T07:29:08.355105Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2606.14027"},"observation_digest":"sha256:d7d5b68d22cc04ec0ac63338d633ffa7eb014d3c45a060199637a28c19f26e1b","observation_id":"beaaeae9-eb3c-42f4-9656-2dfc7c89dad6","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2606.30783","last_updated":"2026-06-29T18:11:17Z","snapshot_observed_at":"2026-08-13T06:58:39.597212Z","submitted_at":"2026-06-29T18:11:17Z","title":"Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense","version":1},"reference_index":87,"source":"arxiv_source","source_observed_at":"2026-07-01T01:44:07.700127Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2606.30783"},"observation_digest":"sha256:f5461a7fc16bb442c2ca9226b9ef3cd9c3eff5a45a084c8edb868f036c1e743e","observation_id":"a3f6ca82-9601-47c5-b96a-4c7e8323c4ab","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents","version":2},"cited_work":{"arxiv_id":"2511.20597","doi":"10.48550/arxiv.2511.20597","metadata_source":"arxiv_reference","pith_arxiv_id":"2511.20597","snapshot_observed_at":"2026-08-13T01:24:45.972029Z","title":"Browsesafe: Understanding and preventing prompt injection within ai browser agents","venue":"ArXiv.org","work_id":"a0d67379-2d33-454a-adc9-f11a80f22f99","year":2025},"citing_paper":{"arxiv_id":"2607.08147","last_updated":"2026-07-09T06:37:52Z","snapshot_observed_at":"2026-08-07T03:47:57.753615Z","submitted_at":"2026-07-09T06:37:52Z","title":"Prismata: Confining Cross-Site Prompt Injection in Web Agents","version":1},"reference_index":97,"source":"pdf_text","source_observed_at":"2026-07-10T12:20:03.672480Z"},"links":{"cited_paper":"/paper/2511.20597","citing_paper":"/paper/2607.08147"},"observation_digest":"sha256:18b2e16f08dcb7c8500837c73f08a4bb29f4c484391edfdef9ced2e2ef217abd","observation_id":"6267cd72-2123-43bd-a78a-12204f61f320","resolution":{"observed_at":"2026-08-13T01:24:45.972029Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2511.20597/citation-record","integrity":"/paper/2511.20597/integrity","json":"/paper/2511.20597/citation-record.json","paper":"/paper/2511.20597"},"outbound":[],"paper":{"arxiv_id":"2511.20597","last_updated":"2026-08-12T00:08:22Z","latest_version":2,"primary_category":"cs.LG","snapshot_observed_at":"2026-08-15T21:09:09.605089Z","submitted_at":"2025-11-25T18:28:35Z","title":"BrowseSafe: Understanding and Preventing Prompt Injection Within AI Browser Agents"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"thesis":"As of 15 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 14 inbound Pith citation observations for arXiv:2511.20597."}