Pith. sign in

Paper Citation Record · LEDGER

Owner-Harm: A Missing Threat Model for AI Agent Safety

As of 5 August 2026, this Paper Citation Record lists 14 of 14 outbound references and 1 inbound Pith citation observation for arXiv:2604.18658.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2604.18658 v1

Coverage vector

measured 14 of 14 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-10T04:39:28.683739Z

measured 15 of 15 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-05T06:32:48.257954+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-07-10T08:08:21.077290Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-07-10T08:16:58.827525Z

Reference resolution

14 of 14 outbound references displayed

  • verified exact11
  • verified fuzzy2
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch1

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 8f9b6d11-d022-4b50-ae14-893f74b99d87 · outbound

This paper cites SeqAR: Jailbreak LLMs with Sequential Auto-Generated Characters.

Owner-Harm: A Missing Threat Model for AI Agent Safety SeqAR: Jailbreak LLMs with Sequential Auto-Generated Characters

Reference 1

Resolution
verified exact
arxiv_id, observed 2026-05-10T12:10:22.218058Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:eb8cc83f397670d530dbc680638199513b970d470a5184462d2870560f04f6f7

Observation ce736c1a-5b78-48fb-87f6-596d30ddc4f3 · outbound

This paper cites British Columbia Civil Resolution Tribunal.

Owner-Harm: A Missing Threat Model for AI Agent Safety British Columbia Civil Resolution Tribunal

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-22T03:15:59.122977Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:648d4cc2e4f36b3facaabf49d3e4b1828968afae51b24503e0c2e02aeb8089f3

Observation 8d39b097-1bd4-4971-9b0f-47023e0e4ae2 · outbound

This paper cites arXiv preprint arXiv:2503.22738 , year=.

Owner-Harm: A Missing Threat Model for AI Agent Safety arXiv preprint arXiv:2503.22738 , year=

Reference 3

Resolution
metadata mismatch
arxiv_id, observed 2026-05-10T12:10:22.204545Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:884a653b366af01958289ac4527568a3e88d829701489b5b53e624884327d65b

Observation c0a4e646-a4f9-4fef-a2b7-5b960b6898b8 · outbound

This paper cites Defeating Prompt Injections by Design.

Owner-Harm: A Missing Threat Model for AI Agent Safety Defeating Prompt Injections by Design

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:58:51.233859Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:19ad2e069fbae1c6be9788b66d3bc88bb5fb3ad21179552bc34775d485192a69

Observation 4163506f-ad31-4575-8092-d5658ecd0e61 · outbound

This paper cites Towards verifiably safe tool use for LLM agents.

Owner-Harm: A Missing Threat Model for AI Agent Safety Towards verifiably safe tool use for LLM agents

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-05-22T03:15:59.117749Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:d34c66c6c5663836c4359d225d6d78c9eda5e2c061394a3f3ab37f5e3b6d5ca5

Observation 858e86c6-35f4-42e2-9e97-8ecf7f24873e · outbound

This paper cites Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection.

Owner-Harm: A Missing Threat Model for AI Agent Safety Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-05-11T17:17:55.937474Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:59c80c42d7ca4cdc66f136dda83d3de9b09a3e41335b9c5e6cc5396d6e263654

Observation 0b998ebc-d827-4ca8-9b3a-77b86360fcf9 · outbound

This paper cites ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction.

Owner-Harm: A Missing Threat Model for AI Agent Safety ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction

Reference 7

Resolution
verified exact
arxiv_id, observed 2026-08-04T02:29:49.790599Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:5c93fe3ddc8e4c5fb9652f830916d11c77f9adf70858c01d4d3e266b481cb075

Observation ead2d801-e4f1-4a0f-a1f4-8c1b34704c0d · outbound

This paper cites TrustAgent: Towards Safe and Trustworthy LLM-based Agents.

Owner-Harm: A Missing Threat Model for AI Agent Safety TrustAgent: Towards Safe and Trustworthy LLM-based Agents

Reference 8

Resolution
verified exact
arxiv_id, observed 2026-05-10T12:05:23.714931Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:17039aa640ba9e669b1fc7ea7bd90d71c8d7026f46c334b0fc42b8d79068d4b3

Observation 8f71e343-edcd-4e3e-bf07-c0b9e3660a60 · outbound

This paper cites AGrail: A Lifelong Agent Guardrail with Effective and Adaptive Safety Detection.

Owner-Harm: A Missing Threat Model for AI Agent Safety AGrail: A Lifelong Agent Guardrail with Effective and Adaptive Safety Detection

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-05-10T12:05:23.720803Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:4db9eaccb7d7224464338287cc1bb1e3c1fef7d483c21397fdc22a03f0170d92

Observation 1b997b60-645d-4916-97af-8a1e208bbe08 · outbound

This paper cites Formal Policy Enforcement for Real-World Agentic Systems.

Owner-Harm: A Missing Threat Model for AI Agent Safety Formal Policy Enforcement for Real-World Agentic Systems

Reference 10

Resolution
verified exact
arxiv_id, observed 2026-05-12T01:43:58.132331Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:96940ced15c95f4bc5a7d628470d6748439a7412e6fd25d31ffe6b5973c82a80

Observation bd8a9450-48a5-4335-91bf-925f2485d2c4 · outbound

This paper cites Solver-Aided Verification of Policy Compliance in Tool-Augmented.

Owner-Harm: A Missing Threat Model for AI Agent Safety Solver-Aided Verification of Policy Compliance in Tool-Augmented

Reference 11

Resolution
verified exact
arxiv_id, observed 2026-05-10T12:10:22.213708Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:a71815ce08866f811718f7c3c799ec6fccf9ea78a0c58d433eedd587fb24afe5

Observation ab98cf10-9220-490e-92b6-cf5224ae1d23 · outbound

This paper cites Provably safe systems: the only path to controllable AGI.

Owner-Harm: A Missing Threat Model for AI Agent Safety Provably safe systems: the only path to controllable AGI

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-05-10T12:05:23.703516Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:f9d64ca2a4c71f101d9e0d79f45e8115af53f352e3f0ae85217468094183e2a0

Observation 7517a153-a402-40c9-9f2f-4fd30dc46167 · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

Owner-Harm: A Missing Threat Model for AI Agent Safety AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:24:32.777586Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:019e705fa65c5e56a7df8caba1986f2c999ca1c32e4f31046541fbe69a4ff2ab

Observation 4f5929c5-f341-42a8-82e0-90264ec1db98 · outbound

This paper cites On the relation between the three Reidemeister moves and the three gauge groups.

Owner-Harm: A Missing Threat Model for AI Agent Safety On the relation between the three Reidemeister moves and the three gauge groups

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-05-10T12:05:23.708880Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=pdf_text observed=2026-05-10T04:39:28.683739Z digest=sha256:642266208d4327c95c9bf9ae5d65cb2560bd591814257e1ce032e7fd45052a6b

Pith citing papers

Observation 93c07458-c99a-4d5b-b8d6-6341f4fd33e4 · inbound

Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents cites this paper.

Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents Owner-Harm: A Missing Threat Model for AI Agent Safety

Reference 37

Resolution
verified exact
local_arxiv, observed 2026-07-10T08:16:58.828971Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.

source=arxiv_source observed=2026-07-10T08:08:21.077290Z digest=sha256:4a2046cbf7e4e225b7aacedb4311047249c299745954a7267b09eaa71d4bdb91