{"as_of":"2026-08-05T15:57:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:f2625a2d591ab5b80b91c96bf455f4b1783c6c2197ef60d1a99dc26f3c579dbc","coverage":[{"denominator":14,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":14,"source":"paper_references, paper_reference_links","source_observed_at":"2026-05-10T04:39:28.683739Z","state":"measured"},{"denominator":15,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":15,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-05T06:32:48.257954+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-07-10T08:08:21.077290Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"pith","source_observed_at":"2026-07-10T08:16:58.827525Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"cited_work":{"arxiv_id":"2604.18658","doi":null,"metadata_source":"pith","pith_arxiv_id":"2604.18658","snapshot_observed_at":"2026-07-10T08:16:58.827525Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","venue":"cs.CR","work_id":"458d07aa-0dd5-42cc-b2c7-07cf1dae753d","year":2026},"citing_paper":{"arxiv_id":"2607.08395","last_updated":"2026-07-09T12:18:40Z","snapshot_observed_at":"2026-07-12T23:18:29.773153Z","submitted_at":"2026-07-09T12:18:40Z","title":"Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents","version":1},"reference_index":37,"source":"arxiv_source","source_observed_at":"2026-07-10T08:08:21.077290Z"},"links":{"cited_paper":"/paper/2604.18658","citing_paper":"/paper/2607.08395"},"observation_digest":"sha256:4a2046cbf7e4e225b7aacedb4311047249c299745954a7267b09eaa71d4bdb91","observation_id":"93c07458-c99a-4d5b-b8d6-6341f4fd33e4","resolution":{"observed_at":"2026-07-10T08:16:58.828971Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2604.18658/citation-record","integrity":"/paper/2604.18658/integrity","json":"/paper/2604.18658/citation-record.json","paper":"/paper/2604.18658"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2407.01902","last_updated":"2025-03-02T06:28:59Z","snapshot_observed_at":"2026-08-04T23:27:54.542148Z","submitted_at":"2024-07-02T02:58:29Z","title":"SeqAR: Jailbreak LLMs with Sequential Auto-Generated Characters","version":2},"cited_work":{"arxiv_id":"2407.01902","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2407.01902","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"(ab)using LLMs: Adversarial attacks on LLM-based agents","venue":null,"work_id":"5d013c85-a5c3-4bfe-9604-dbc2a0a574f1","year":null},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2407.01902","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:eb8cc83f397670d530dbc680638199513b970d470a5184462d2870560f04f6f7","observation_id":"8f9b6d11-d022-4b50-ae14-893f74b99d87","resolution":{"observed_at":"2026-05-10T12:10:22.218058Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"British Columbia Civil Resolution Tribunal","venue":null,"work_id":"abe793c4-66e4-4e79-b8ce-1cf4db57a5b8","year":2023},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:648d4cc2e4f36b3facaabf49d3e4b1828968afae51b24503e0c2e02aeb8089f3","observation_id":"ce736c1a-5b78-48fb-87f6-596d30ddc4f3","resolution":{"observed_at":"2026-05-22T03:15:59.122977Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2503.22738","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-07-04T00:29:16.330261Z","title":"arXiv preprint arXiv:2503.22738 , year=","venue":null,"work_id":"d6d755e8-beb8-4208-aea4-da7adbea2446","year":2025},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:884a653b366af01958289ac4527568a3e88d829701489b5b53e624884327d65b","observation_id":"8d39b097-1bd4-4971-9b0f-47023e0e4ae2","resolution":{"observed_at":"2026-05-10T12:10:22.204545Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2503.18813","last_updated":"2025-06-24T08:05:33Z","snapshot_observed_at":"2026-07-31T05:16:05.607957Z","submitted_at":"2025-03-24T15:54:10Z","title":"Defeating Prompt Injections by Design","version":2},"cited_work":{"arxiv_id":"2503.18813","doi":"10.48550/arxiv.2503.18813","metadata_source":"pith","pith_arxiv_id":"2503.18813","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Defeating Prompt Injections by Design","venue":"cs.CR","work_id":"86405b86-1c51-4042-9b04-aff0b6541411","year":2025},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2503.18813","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:19ad2e069fbae1c6be9788b66d3bc88bb5fb3ad21179552bc34775d485192a69","observation_id":"c0a4e646-a4f9-4fef-a2b7-5b960b6898b8","resolution":{"observed_at":"2026-05-13T06:58:51.233859Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-07-15T18:20:36.91954+00:00","source":"crossref_status_cache"},{"observed_at":"2026-07-15T18:20:36.91954+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Towards verifiably safe tool use for LLM agents","venue":null,"work_id":"ea54ee80-20c1-4b52-97f2-5e86c934ab62","year":2026},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:d34c66c6c5663836c4359d225d6d78c9eda5e2c061394a3f3ab37f5e3b6d5ca5","observation_id":"4163506f-ad31-4575-8092-d5658ecd0e61","resolution":{"observed_at":"2026-05-22T03:15:59.117749Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2302.12173","last_updated":"2023-05-05T14:26:17Z","snapshot_observed_at":"2026-07-06T14:55:08.682906Z","submitted_at":"2023-02-23T17:14:38Z","title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","version":2},"cited_work":{"arxiv_id":"2302.12173","doi":"10.1109/sp61157.2025.00250","metadata_source":"pith","pith_arxiv_id":"2302.12173","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection","venue":"cs.CR","work_id":"7a8cfce1-ada7-4a7a-8516-6f16b1bd077b","year":2023},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2302.12173","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:59c80c42d7ca4cdc66f136dda83d3de9b09a3e41335b9c5e6cc5396d6e263654","observation_id":"858e86c6-35f4-42e2-9e97-8ecf7f24873e","resolution":{"observed_at":"2026-05-11T17:17:55.937474Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2508.00500","last_updated":"2026-08-03T00:31:29Z","snapshot_observed_at":"2026-08-05T15:21:46.720887Z","submitted_at":"2025-08-01T10:24:47Z","title":"ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction","version":4},"cited_work":{"arxiv_id":"2508.00500","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2508.00500","snapshot_observed_at":"2026-08-04T02:29:49.790599Z","title":"Pro2Guard: Proactive runtime enforcement of LLM agent safety via probabilistic model checking","venue":null,"work_id":"d4c2a48d-ad9b-4f3b-91df-81f61d80ff64","year":2025},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2508.00500","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:b99f0e8f825f75879d853f878d52600a0645c5b5bb4d6ae5bb8c88e655954167","observation_id":"0b998ebc-d827-4ca8-9b3a-77b86360fcf9","resolution":{"observed_at":"2026-08-04T02:29:49.790599Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2402.01586","last_updated":"2024-10-03T22:12:05Z","snapshot_observed_at":"2026-07-06T17:24:24.953352Z","submitted_at":"2024-02-02T17:26:23Z","title":"TrustAgent: Towards Safe and Trustworthy LLM-based Agents","version":4},"cited_work":{"arxiv_id":"2402.01586","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2402.01586","snapshot_observed_at":"2026-07-04T10:59:46.991732Z","title":"TrustAgent: Towards safe and trustworthy LLM-based agents through agent constitution","venue":null,"work_id":"48ac267c-5463-491e-8e7f-1a93448965cb","year":2024},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2402.01586","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:17039aa640ba9e669b1fc7ea7bd90d71c8d7026f46c334b0fc42b8d79068d4b3","observation_id":"ead2d801-e4f1-4a0f-a1f4-8c1b34704c0d","resolution":{"observed_at":"2026-05-10T12:05:23.714931Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2502.11448","last_updated":"2025-02-18T05:37:44Z","snapshot_observed_at":"2026-07-06T20:37:33.041473Z","submitted_at":"2025-02-17T05:12:33Z","title":"AGrail: A Lifelong Agent Guardrail with Effective and Adaptive Safety Detection","version":2},"cited_work":{"arxiv_id":"2502.11448","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2502.11448","snapshot_observed_at":"2026-07-03T10:17:57.955568Z","title":"Agrail: A lifelong agent guardrail with effective and adaptive safety detection","venue":null,"work_id":"69d519ce-d642-4105-a92f-1dc35b27e81e","year":2025},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2502.11448","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:4db9eaccb7d7224464338287cc1bb1e3c1fef7d483c21397fdc22a03f0170d92","observation_id":"8f71e343-edcd-4e3e-bf07-c0b9e3660a60","resolution":{"observed_at":"2026-05-10T12:05:23.720803Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2602.16708","last_updated":"2026-05-08T15:45:27Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2026-02-18T18:57:12Z","title":"Formal Policy Enforcement for Real-World Agentic Systems","version":3},"cited_work":{"arxiv_id":"2602.16708","doi":null,"metadata_source":"pith","pith_arxiv_id":"2602.16708","snapshot_observed_at":"2026-07-11T02:47:51.036183Z","title":"Formal Policy Enforcement for Real-World Agentic Systems","venue":"cs.CR","work_id":"dc0c6fb4-ef13-485c-8109-a5a138684d7e","year":2026},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2602.16708","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:96940ced15c95f4bc5a7d628470d6748439a7412e6fd25d31ffe6b5973c82a80","observation_id":"1b997b60-645d-4916-97af-8a1e208bbe08","resolution":{"observed_at":"2026-05-12T01:43:58.132331Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":"2603.20449","doi":"10.48550/arxiv.2603.20449","metadata_source":"arxiv_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Solver-Aided Verification of Policy Compliance in Tool-Augmented","venue":"arXiv (Cornell University)","work_id":"9a1a1bbd-ecbf-47c3-8866-ff574b794645","year":2026},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:a71815ce08866f811718f7c3c799ec6fccf9ea78a0c58d433eedd587fb24afe5","observation_id":"bd8a9450-48a5-4335-91bf-925f2485d2c4","resolution":{"observed_at":"2026-05-10T12:10:22.213708Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2309.01933","last_updated":"2023-09-05T03:42:46Z","snapshot_observed_at":"2026-07-06T16:14:17.621050Z","submitted_at":"2023-09-05T03:42:46Z","title":"Provably safe systems: the only path to controllable AGI","version":1},"cited_work":{"arxiv_id":"2309.01933","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2309.01933","snapshot_observed_at":"2026-06-29T07:53:14.195027Z","title":"& Omohundro, S","venue":null,"work_id":"0934949c-bd3b-4334-ae27-fa6a5707630f","year":2023},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2309.01933","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:f9d64ca2a4c71f101d9e0d79f45e8115af53f352e3f0ae85217468094183e2a0","observation_id":"ab98cf10-9220-490e-92b6-cf5224ae1d23","resolution":{"observed_at":"2026-05-10T12:05:23.703516Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2503.18666","last_updated":"2025-07-31T04:00:48Z","snapshot_observed_at":"2026-07-06T20:57:47.748881Z","submitted_at":"2025-03-24T13:31:48Z","title":"AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents","version":3},"cited_work":{"arxiv_id":"2503.18666","doi":"10.48550/arxiv.2503.18666","metadata_source":"pith","pith_arxiv_id":"2503.18666","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents","venue":"cs.AI","work_id":"2d265b31-7dcb-4ab3-8c83-e13bd5598435","year":2025},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2503.18666","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:019e705fa65c5e56a7df8caba1986f2c999ca1c32e4f31046541fbe69a4ff2ab","observation_id":"7517a153-a402-40c9-9f2f-4fd30dc46167","resolution":{"observed_at":"2026-05-14T21:24:32.777586Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-03T00:38:11.552641+00:00","source":"crossref_status_cache"},{"observed_at":"2026-08-03T00:38:11.552641+00:00","source":"openalex_status_cache"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2312.14173","last_updated":"2023-12-16T15:24:44Z","snapshot_observed_at":"2026-07-06T17:06:45.522731Z","submitted_at":"2023-12-16T15:24:44Z","title":"On the relation between the three Reidemeister moves and the three gauge groups","version":1},"cited_work":{"arxiv_id":"2312.14173","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2312.14173","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Benchmarking and defending against indirect prompt injection attacks on large language models","venue":null,"work_id":"2f94feae-54a5-43ff-861f-346201eeb4c7","year":null},"citing_paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-05-10T04:39:28.683739Z"},"links":{"cited_paper":"/paper/2312.14173","citing_paper":"/paper/2604.18658"},"observation_digest":"sha256:642266208d4327c95c9bf9ae5d65cb2560bd591814257e1ce032e7fd45052a6b","observation_id":"4f5929c5-f341-42a8-82e0-90264ec1db98","resolution":{"observed_at":"2026-05-10T12:05:23.708880Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-05T06:32:48.257954+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2604.18658","last_updated":"2026-04-20T10:11:26Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-07-06T23:05:26.398712Z","submitted_at":"2026-04-20T10:11:26Z","title":"Owner-Harm: A Missing Threat Model for AI Agent Safety"},"reference_resolution":{"displayed":14,"state_counts":{"malformed_identifier":0,"metadata_mismatch":1,"parse_uncertain":0,"unresolved":0,"verified_exact":11,"verified_fuzzy":2},"total_outbound_references":14},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-05T06:32:48.257954+00:00","source":"crossref"},{"observed_at":"2026-08-05T06:32:44.755628+00:00","source":"retraction_watch"}],"thesis":"As of 5 August 2026, this Paper Citation Record lists 14 of 14 outbound references and 1 inbound Pith citation observation for arXiv:2604.18658."}