Pith. sign in

Paper Citation Record · LEDGER

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools

As of 19 August 2026, this Paper Citation Record lists 20 of 20 outbound references and 3 inbound Pith citation observations for arXiv:2601.01241.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2601.01241 v2

Coverage vector

measured 20 of 20 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-03T12:56:37.815027Z

measured 23 of 23 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 3 of 3 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-02T01:12:23.894152Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-05T02:28:24.338817Z

Reference resolution

20 of 20 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved20
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-05T02:28:24.338817Z

Outbound references

Observation 6c5b5c1a-e5af-48f2-852e-1f30ff8984c2 · outbound

This paper cites Introducing the model context protocol.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Introducing the model context protocol

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.757404Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.757404Z digest=sha256:f31642ef66509b474f654931b9a1f60962c26ff47a876b56176362fe73a87a0e

Observation dc2ce85d-f3d7-4003-8bb0-b165ef12929e · outbound

This paper cites Agent based modelling and simulation tools: A review of the state-of-art software,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Agent based modelling and simulation tools: A review of the state-of-art software,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.761151Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.761151Z digest=sha256:906a37719d3592a5ee2aedb47011fdc7030520ad358247a96cba862b9ecb6bb5

Observation 2a5e6bf6-46fc-45a3-9196-61a3f0614b78 · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.766883Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.766883Z digest=sha256:4cec4109b2b33cfefa478fd8acd49bcb8f98b0840a4d50def9e1e6a8c565b302

Observation 48247f33-2864-46e3-9dce-e3834ef283c8 · outbound

This paper cites MCIP: Protecting MCP safety via model contextual integrity protocol,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCIP: Protecting MCP safety via model contextual integrity protocol,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.770369Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.770369Z digest=sha256:8cd8045e1e1e53df43e2a858b5ee7221bdaa57c3cca40f29705711f35e483df3

Observation 7710cfb9-551a-46ed-83ea-bac9a10370ca · outbound

This paper cites Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.773738Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.773738Z digest=sha256:64aee2a1d7c0c19e05778a096c7d870fa4b440ca9d3ecba584ebec2f1e5db768

Observation 1e9127bc-7581-4138-8135-2b3b32451f1d · outbound

This paper cites Mcpscan,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Mcpscan,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.777268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.777268Z digest=sha256:e4631e06f745ab1321e3f72703954258c96576ed1bdc792ceb47c2aea23b6f71

Observation b816419c-d77d-4e91-914f-029cd2f04888 · outbound

This paper cites Scansat: Unlocking static and dynamic scan obfuscation,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Scansat: Unlocking static and dynamic scan obfuscation,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.780243Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.780243Z digest=sha256:e765706cdc193be022471c5160b658b12ab370c52d1634f376dd28082707c94b

Observation af362f7a-3a24-41f5-b5e4-13e119abff33 · outbound

This paper cites Wave: a verifiably secure webassembly sandboxing runtime,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Wave: a verifiably secure webassembly sandboxing runtime,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.783379Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.783379Z digest=sha256:a9b00f5a16d979091cf2c30333022009ca173594807bc9bfaf25d2c02815f01c

Observation 30e4925e-7a17-4116-aa3a-2b590c23223b · outbound

This paper cites Mcp-sandboxscan (anonymous github repository),.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Mcp-sandboxscan (anonymous github repository),

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.786645Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.786645Z digest=sha256:93a9edf729866eb92ad928d353327df06d4025937387b8975136fc09d32dd540

Observation 280f776d-be11-4d24-ac11-78371288c7bd · outbound

This paper cites MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.789590Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.789590Z digest=sha256:3f99439747db0008d7d9166aa9ce6ef0b3c109dda7cc3eb391e8186141fa4de1

Observation 7444a582-fad4-4f66-bc9a-7bb07a5a207c · outbound

This paper cites (2025, May) Mcp: Untrusted servers and confused clients, plus a sneaky exploit.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools (2025, May) Mcp: Untrusted servers and confused clients, plus a sneaky exploit

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.792816Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.792816Z digest=sha256:659041d54fe88719c3c5b9a89258a355e02166da7cb4548c0af761ea33f9f4de

Observation 6c9029d0-1fbb-491b-84c8-e4d153af2acc · outbound

This paper cites Model context protocol (mcp): Landscape, security threats, and future research directions,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Model context protocol (mcp): Landscape, security threats, and future research directions,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.795677Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.795677Z digest=sha256:78b3b657a0e8a20a2a172fef75dc34a43f082b5bf18b3949bd2cbf81b80e5588

Observation 904b91d8-d520-4a7c-8241-a59de5581ea2 · outbound

This paper cites Defeating prompt injections by design,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Defeating prompt injections by design,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.801880Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.801880Z digest=sha256:9fe2442ea56ab3c8ba2e8434f5eec0f19811c6d587504de3c7994504ff5991e6

Observation 02695385-888e-48b7-afce-4879b6fd0d5c · outbound

This paper cites toxic flows,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools toxic flows,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.804547Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.804547Z digest=sha256:b62e63e31d8a3097acc98f6cc4d9d34ea95404984593834f5a967e1901488fd0

Observation 915d489b-3776-463f-b502-91dc5ac9b88f · outbound

This paper cites Cheatsheet – a practical guide for securely using third-party mcp servers 1.0,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Cheatsheet – a practical guide for securely using third-party mcp servers 1.0,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.807218Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.807218Z digest=sha256:4366a2b2502e026351bb5c67133fa541ee212079359581a55ee2c4f2f487f29c

Observation e22bce47-ee37-42bb-9e4c-1d939a477d19 · outbound

This paper cites Wasmbox: A lightweight wasm-based runtime for trustworthy multi-tenant embedded systems,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Wasmbox: A lightweight wasm-based runtime for trustworthy multi-tenant embedded systems,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.809750Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.809750Z digest=sha256:2c11146f31941e88020e44fef9b950d8cbe7dfe75a015792e2c75c8c80e9526c

Observation 6d75229a-b35c-4666-9baf-573d65519fde · outbound

This paper cites Sledge: a serverless-first, light-weight wasm runtime for the edge,.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Sledge: a serverless-first, light-weight wasm runtime for the edge,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.812388Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.812388Z digest=sha256:c0b26b5cf86a50dbb016a577ef8420d6513827996f2fa448d75013189ea6f7ed

Observation 9880b784-3879-4a9b-a146-10b28cb8d448 · outbound

This paper cites MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.815027Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.815027Z digest=sha256:2f96d6add6e386e95a4d4e511c691b15d0756d41c9c356600d5d73ad4c3cac56

Observation 4fb683bb-6132-4a0d-8405-ca7826cc23ce · outbound

This paper cites Available: https://www.sciencedirect.com/science/articl e/pii/S1574013716301198.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Available: https://www.sciencedirect.com/science/articl e/pii/S1574013716301198

Reference 2017

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.764045Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.764045Z digest=sha256:36957c0e8dff55ef1817ca947be018e971814e89d3dbb460223495ac60ea4b0a

Observation 81bdfb01-99dd-437e-83f5-5b5b4e47af74 · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-03T12:56:37.798775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T12:56:37.798775Z digest=sha256:a8a123be1f28644cc58597c6377b939b5db4caeed5559b1d1356d444b79d491d

Pith citing papers

Observation ed1db894-ad93-4d8e-83a0-b231967ef15b · inbound

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security cites this paper.

MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools

Reference 49

Resolution
verified exact
arxiv_id, observed 2026-06-23T04:13:43.712185Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T17:10:50.283791Z digest=sha256:8a5fb866d0565b411aa9406e72479792892243e29d9a2d11b1a293ed87c9e7c1

Observation 5a41c41c-68f9-44bf-83ba-d80483b520d7 · inbound

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation cites this paper.

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools

Reference 166

Resolution
verified exact
local_arxiv, observed 2026-06-27T13:20:56.864193Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-27T12:55:22.831264Z digest=sha256:9bb17227e91c6364cf6a1146a0460804af36fdd18013503095caa374c4c68f7b

Observation 70707f31-365b-4b5a-91ef-abab78b83267 · inbound

FlowGuard: From Signals to Evidence for MCP Security Detection cites this paper.

FlowGuard: From Signals to Evidence for MCP Security Detection MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-02T01:12:23.894152Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T01:12:23.894152Z digest=sha256:9fc84a1a8cd9c4eb8a4c6b751d2664d3aaf7303cd91a878fc800c358f69a6ad5