Pith. sign in

Paper Citation Record · LEDGER

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation

As of 6 August 2026, this Paper Citation Record lists 57 of 57 outbound references and 1 inbound Pith citation observation for arXiv:2605.06393.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2605.06393 v1

Coverage vector

measured 57 of 57 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-05-08T09:08:30.102711Z

measured 58 of 58 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-06T06:34:29.942622+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-01T16:35:17.406568Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

57 of 57 outbound references displayed

  • verified exact30
  • verified fuzzy16
  • unresolved2
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch9

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation a938718d-cbc8-489d-a4e0-4caf515480f5 · outbound

This paper cites (2026, Feb.) Openclaw vulnerability: Website-to-local agent takeover.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation (2026, Feb.) Openclaw vulnerability: Website-to-local agent takeover

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.773378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:2272e7b535fe1ccc4f978108328e76c04cf6ca3ec1ac61cf5a7cc5fc1e3c01c7

Observation 0b4b4f70-bf74-4bfe-9329-d953a1068b27 · outbound

This paper cites (2026, Jan.) Openclaw/clawdbot has 1-click RCE via authentication token exfiltration from gatewayurl.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation (2026, Jan.) Openclaw/clawdbot has 1-click RCE via authentication token exfiltration from gatewayurl

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.764787Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:e85388e948adf376ea37ad618ce1ad115ac4ba828938b9a4adeaeeab2473f3a1

Observation 5e1b04e0-c29f-4907-bbc3-6dae257b9c8c · outbound

This paper cites an unresolved cited work.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Unresolved cited work

Reference 3

Resolution
unresolved
raw_fallback, observed 2026-05-26T16:27:39.760093Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:a33e33d49d32c653fc54775c739c49aa8804352e9b4d697a5cdeb22964677b2e

Observation 1d00f4a1-38ba-43f1-8026-d190f7616d74 · outbound

This paper cites an unresolved cited work.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Unresolved cited work

Reference 4

Resolution
unresolved
raw_fallback, observed 2026-05-26T16:27:39.769061Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:874cfbdec6a6076704b92c872a9ca99a4ecc0a8991fd436cb4f484c141377809

Observation fad4c65c-8e02-43f5-a36a-5e9154213b04 · outbound

This paper cites OP-TEE (Open Portable Trusted Ex- ecution Environment).

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation OP-TEE (Open Portable Trusted Ex- ecution Environment)

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.750852Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:ae307461a2f6c0beccf9052e9dc2e8a823cbc4fd324e822e5f5ba1467e35bf93

Observation 729c4a5c-21ab-43ec-a6de-fe4de97459fa · outbound

This paper cites OP-TEE Documentation.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation OP-TEE Documentation

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.746149Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:603a7d361c6f005cce6c92caddde80381bb335c3cb7b608bc6497c6c5e181cdd

Observation 1e866452-8f82-480d-9b55-a219e09aaffa · outbound

This paper cites Keystone: An Open Framework for Architecting Trusted Execution Environments.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Keystone: An Open Framework for Architecting Trusted Execution Environments

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.731695Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:c57a58764a9e0f86299943e50453fef4422bcce0076b189c118633e5f0ddae24

Observation b791c4df-827c-42d6-89c3-d94ba8fd38b3 · outbound

This paper cites Keystone Enclave Documentation.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Keystone Enclave Documentation

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.736465Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:4e533cf9203292619d60d0e3a5e06816241bf16acde9159249766988c06997ff

Observation 83fa6f85-a065-4603-9992-8591b9515393 · outbound

This paper cites Enclave Application Cache for RISC-V Keystone.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Enclave Application Cache for RISC-V Keystone

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.741545Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:ba2d490132d42c85d5cf1a56cadd6a27827a50eed7d66e465dc95a5c289d7be6

Observation 680bc1a0-c6e7-4d44-a5ef-231d5167017f · outbound

This paper cites (2026) Openclaw - personal AI assistant.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation (2026) Openclaw - personal AI assistant

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.755621Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:fc386df6a443d4befcde539b0f7fd41a02c7d1f5b64d58cf76982ad475457dc8

Observation e7a12b60-8192-4402-979c-f18fb8387449 · outbound

This paper cites Camels can use computers too: System-level security for computer use agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Camels can use computers too: System-level security for computer use agents

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.777394Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:7514019a38df239aa161eab48ac184fd48e8927b337dd9253c0dee35cdd63da7

Observation 80f11375-14d6-4b59-9f5b-2cbb42f59c25 · outbound

This paper cites CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents

Reference 12

Resolution
metadata mismatch
arxiv_id, observed 2026-06-05T02:16:21.941428Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:c9a76cb5874fab3456132037b365898ac52b16d85b4bdf96098d1ac6d396d4de

Observation 857b32e5-5f7b-45c6-a219-0997fc26a1a6 · outbound

This paper cites Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw

Reference 13

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.296295Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:7c8a68c77a704dabe4476dd36e757e5e2c7a0eaa904c9339abee8dc7f23902e4

Observation 10e9b729-e369-4008-854b-f832dc2c4825 · outbound

This paper cites A systematic security evaluation of openclaw and its variants.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation A systematic security evaluation of openclaw and its variants

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.791050Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:41e3ee584497dbefb286aaebf45403872540def1d57d762f05442f7e74a85a95

Observation e68f8a17-c9fe-47c6-9705-c693cb3197ce · outbound

This paper cites A Systematic Security Evaluation of OpenClaw and Its Variants.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation A Systematic Security Evaluation of OpenClaw and Its Variants

Reference 15

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T20:26:11.278150Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:8128342e0e3e19ac6fdab4b72cc97a03e212caf1255e58607a68fed4e0d71f47

Observation 39f98c1e-b1b9-4aca-87fa-7eb13a3daa37 · outbound

This paper cites Vpi-bench: Visual prompt injection attacks for computer-use agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Vpi-bench: Visual prompt injection attacks for computer-use agents

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.095045Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:051a0782617837955ebd500be6c3ae085245f532a3c469e25a05dfd17c98049b

Observation 45dd7915-755b-42d6-ac93-a71691def5e3 · outbound

This paper cites What Did It Actually Do?: Understanding risk awareness and traceability for computer-use agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation What Did It Actually Do?: Understanding risk awareness and traceability for computer-use agents

Reference 17

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.228751Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:e54585c51e4f6a926f8d100ce04ce075fe71166e8a92d620bf9ae26566e90625

Observation 8e28b5e1-9c8f-4e4f-96f1-bf64c5cc2a3e · outbound

This paper cites Don’t let the claw grip your hand: A security analysis and defense framework for openclaw.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Don’t let the claw grip your hand: A security analysis and defense framework for openclaw

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.781871Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:3fb5d5c44b4d331b6c648dec73c8eecbf52eec9b4b6e717dbe1cc6a6a42a232d

Observation 405030aa-437b-4afd-9d6d-a84e5ecb9e86 · outbound

This paper cites Don’t let the claw grip your hand: A security analysis and defense framework for OpenClaw.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Don’t let the claw grip your hand: A security analysis and defense framework for OpenClaw

Reference 19

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.236477Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:bdcfdedbd5361a4ade056230b824f055a5ad8b1eccf63ae82d6f47268ea62062

Observation f3eea4e2-db26-40ad-9ede-4fb04cf25768 · outbound

This paper cites Uncovering security threats and architecting defenses in autonomous agents: A case study of OpenClaw.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Uncovering security threats and architecting defenses in autonomous agents: A case study of OpenClaw

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.247346Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:1e5f013c34d5435972efafce3bc2506230248ff18fa287b716d1920654a9f760

Observation febdfbe8-d7e8-4c79-bbf1-b6ed5bb54490 · outbound

This paper cites ClawLess: A Security Model of AI Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ClawLess: A Security Model of AI Agents

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.221742Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:6a55a4a82186859291335e189af426f0b15337682ee14a8b5b80ad58a96d89ce

Observation c0e71a4c-64d8-4714-a732-03437511829a · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 22

Resolution
verified exact
arxiv_id, observed 2026-05-13T21:40:06.567267Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:7722d5a32617919f32ab2eab6787798eb7ec48798ddaad7aa81a92b1cbb199b0

Observation 3790cb3c-65a3-4eb4-9d82-9fa95ff9aab5 · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 23

Resolution
verified exact
arxiv_id, observed 2026-05-13T06:35:13.649872Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:b446fe7891b5831045330b66ada5ca71ca3c53d3ee63a131112d4d0a347359d1

Observation 60c9c6e5-77ac-428d-90fa-e0414e5d0b22 · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 24

Resolution
verified exact
arxiv_id, observed 2026-05-12T13:36:57.477107Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:ff25f9b207fabaf4d052c231d5e29312a3871f0fd3247fe88189d82f9bd00eca

Observation aff62ec5-9650-430a-bebc-7d87a21deba8 · outbound

This paper cites Os-harm: A benchmark for measuring safety of computer use agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Os-harm: A benchmark for measuring safety of computer use agents

Reference 25

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.272766Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:91e4dfc00db583481e3349d2f1eda8d6a16282052b162185acff7d8db78c6a0f

Observation b6392458-5895-4aef-bb61-063e44d78daf · outbound

This paper cites WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-15T22:22:05.737978Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:60b2333517ca39966aff6deb7cff508e87b0c18f3867e165e209b7c2bd441eea

Observation 1244999e-f9f3-488d-96d2-2b4c9c8f1b3d · outbound

This paper cites AgentHazard: A Benchmark for Evaluating Harmful Behavior in Computer-Use Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentHazard: A Benchmark for Evaluating Harmful Behavior in Computer-Use Agents

Reference 27

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.179617Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:fe22dd14c4e9e204e3d7496828a8d85349d0b6f02cc1c49ab05d0be136d59200

Observation 6515f193-6b6e-48af-b7ce-2993cb57e9fa · outbound

This paper cites ClawSafety: "Safe" LLMs, Unsafe Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ClawSafety: "Safe" LLMs, Unsafe Agents

Reference 28

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.194653Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:f486e61e6f8ea0dbd97565fea9b583f2a389351073ddee22fbb2bf8d8a4262bd

Observation 124b7586-b60b-41bd-851d-d8c68926a21c · outbound

This paper cites Code agent can be an end-to-end system hacker: Benchmarking real-world threats of computer-use agent.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Code agent can be an end-to-end system hacker: Benchmarking real-world threats of computer-use agent

Reference 29

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.139612Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:828e3b0e39bbfc9e28558fe44f4f2a1239a11392ab7f9b59598be1de64fcfcea

Observation cfbda53c-fe70-4b69-8b8e-569fbd67782f · outbound

This paper cites ICON: Indirect prompt injection defense for agents based on inference-time correction.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ICON: Indirect prompt injection defense for agents based on inference-time correction

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.157152Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:f88a4df9248d5d97efc6e516990282861662ed0db8aa5e4a8d7fd603419b8634

Observation c5432059-af0f-467e-850f-7cddc4d5b4f5 · outbound

This paper cites Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Simple Prompt Injection Attacks Can Leak Personal Data Observed by LLM Agents During Task Execution

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.150157Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:1074be5cf54920e29706c28caeee91007f125e8ba217af8bd8bf7b86e0643cda

Observation 7045ce5a-3719-4e0d-8e90-87a6f6e798dd · outbound

This paper cites arXiv preprint arXiv:2602.10453 , year=.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation arXiv preprint arXiv:2602.10453 , year=

Reference 32

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.164074Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:0b6865132409e9c3227662c3840f272d1809cdf94d021db2a6f198c9ae7f5bc3

Observation 83c79e3c-d9a9-4028-a6be-b095f6633a40 · outbound

This paper cites Memory poisoning attack and defense on memory based LLM-agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Memory poisoning attack and defense on memory based LLM-agents

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.726884Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:49401b6f510379850b58301841a70846e5ef85c50c805bb8a7e7b835f651e963

Observation 07484e74-c5af-4bfb-b66b-1f63318bdd77 · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-05-14T21:24:32.777586Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:61f927558d32b96ca5f0e3a9f003880a327b426da4c37dee9770b21800071c34

Observation 1cf11920-0b88-401c-a02d-1639deeeda9b · outbound

This paper cites Formal Policy Enforcement for Real-World Agentic Systems.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Formal Policy Enforcement for Real-World Agentic Systems

Reference 35

Resolution
verified exact
arxiv_id, observed 2026-05-12T01:43:58.132331Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:737f1029450d0fa44c556f1744b67b9f4a31ed4cc172afe64a4e1de7d9f163b9

Observation 3a65c88d-70c8-4b4d-b8e2-96631ab50289 · outbound

This paper cites Wang, Trisha Singhal, Ameya Kelkar, and Jason Tuo.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Wang, Trisha Singhal, Ameya Kelkar, and Jason Tuo

Reference 36

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.289832Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:7d49851c334f483769bdd14aacbdaef175b9cdf22c6dc4f87ef58780f11c8133

Observation 79808576-a662-47f2-8eb0-7586e30dd6d0 · outbound

This paper cites From Governance Norms to Enforceable Controls: A Layered Translation Method for Runtime Guardrails in Agentic AI.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation From Governance Norms to Enforceable Controls: A Layered Translation Method for Runtime Guardrails in Agentic AI

Reference 37

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.112259Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:3181eda3fa615562d127fd044abf0ebbcce318d701b11c789ce7aa626bca44ab

Observation 9c4d0216-016c-4e0c-b5eb-75b5c00c4ee2 · outbound

This paper cites Kaptein, V.-J.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Kaptein, V.-J

Reference 38

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.033709Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:fea192a11dc493ea76570f22ec6234bbaa20d8f0a34e3ad68dfb72ae4973ac06

Observation 8ecb8f47-41c0-46c7-a2cb-fa8a78897c79 · outbound

This paper cites Uchibeke.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Uchibeke

Reference 39

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:10.998204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:6fe8b21fee955076324b6e7c2073a2dc9bff75b1bea97789ba37400e0e3674f6

Observation 8ae5faa8-34a4-4369-8397-0a37b9e330da · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Progent: Securing AI Agents with Privilege Control

Reference 40

Resolution
verified exact
arxiv_id, observed 2026-05-15T01:43:10.493453Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:be5163236cd73db6fa4bfa9b89c24465b70677b0dae62f22aec3b5b86af8b784

Observation 46bff2a8-8ccb-4bd7-8772-b4def0492778 · outbound

This paper cites ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-08-04T02:29:49.790599Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:0d71fc83ae006377696756f672ac7c2dcf5b8136992224fb0219457c4f76b99e

Observation 8fce22f1-336f-4e23-aa2d-2f2d869a9b99 · outbound

This paper cites Agent Behavioral Contracts: Formal Specification and Runtime Enforcement.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Agent Behavioral Contracts: Formal Specification and Runtime Enforcement

Reference 42

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:10.961108Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:ce8a3c7e6b9cc02d4f9e267fc7eeea82d458fd0266249f101a4a52918e0a4e8d

Observation 00fb860b-50b0-46e9-824e-6493c1c3ed53 · outbound

This paper cites Evaluating Privilege Usage of Agents with Real-World Tools.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Evaluating Privilege Usage of Agents with Real-World Tools

Reference 43

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:10.968405Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:705f3c470e3d4d7248260df85f4ad8e4a513426b82dbafff94029c7009ea743f

Observation 86acbf06-b9b5-4128-b4e8-d914434b1ecf · outbound

This paper cites SafeClaw-R: Risk analysis and runtime enforcement for OpenClaw skills.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation SafeClaw-R: Risk analysis and runtime enforcement for OpenClaw skills

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:10.985007Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:510bfe94f9c057eb9217adb35d5d55919f836a9f9a6051ad9b024f25a54241e3

Observation fbb5e2cf-877a-421f-995f-4aaa38147dd5 · outbound

This paper cites Security Considerations for Artificial Intelligence Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Security Considerations for Artificial Intelligence Agents

Reference 45

Resolution
verified exact
local_arxiv, observed 2026-05-11T20:26:11.020770Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:66e3052eb0dcc705d3588d5007605f2eac60e83007aa741976f51c5ec5ce45f2

Observation 0b7bd804-a764-4f99-b017-a16b441fc0fd · outbound

This paper cites Preventing privilege escala- tion.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Preventing privilege escala- tion

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.795252Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:891d2f699b6447a30316e8ec4bac67e4d3ccef99153d8d2cf8d087a3967a6d43

Observation aaf89c1e-2d1b-40a6-92d3-be094afd834e · outbound

This paper cites Enforceable security policies.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Enforceable security policies

Reference 47

Resolution
verified exact
arxiv_id, observed 2026-05-08T22:24:19.059649Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:aa78b303c457541b2b46d881fb58c7df5a6664743999796f345242be2b00612a

Observation 18ac8001-21ab-4c87-a6d5-5765c533885b · outbound

This paper cites SC-11: Trusted Path.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation SC-11: Trusted Path

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.721928Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:9e9ad33302dc2eb830368d41b27cd9d4044ea4ae94bdb5dc26ab74db7063b954

Observation 2b6a1e22-f50d-4448-ae00-ce754119e139 · outbound

This paper cites Evidence- based audit.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Evidence- based audit

Reference 49

Resolution
verified exact
doi, observed 2026-05-08T22:24:19.064342Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:da2e5db819d613ca01c9061af66bfea9defd487ede78855c79a180e940025361

Observation 37192e4b-2743-420c-b239-cf356377d326 · outbound

This paper cites Systems security foundations for agentic computing.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Systems security foundations for agentic computing

Reference 50

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.044363Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:43097151e8bccc6abb51fbb46f58e99bfe0cb42c293446a692621ed09d00f930

Observation 7e382754-e76c-4c4a-8122-4a3bc07887d8 · outbound

This paper cites Ai agents under threat: A survey of key security challenges and future pathways.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Ai agents under threat: A survey of key security challenges and future pathways

Reference 51

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.067357Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:77a88fd28986ac3976ed918c1841133d59b2198c89b85ea6550939e8db089c55

Observation e01b55d3-0550-41b1-b9e0-7a7aaf50e233 · outbound

This paper cites AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 52

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.054246Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:258cd3c065c79ebf62e65a145092e05a973ce57f9b843644d34af35fdd6ecd2c

Observation feca86c2-699d-439c-862d-c539df9af9d4 · outbound

This paper cites AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 53

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.087888Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:61165cfab5464a49b53e6fed7aefb83ae2c65b0edb755106c635cb8a6f684ee0

Observation 812bbb9c-6812-4222-8e0f-6b0884b22141 · outbound

This paper cites Poison once, exploit forever: Environment-injected memory poisoning attacks on web agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Poison once, exploit forever: Environment-injected memory poisoning attacks on web agents

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.717404Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:e315a7c70e3bd913c8a3ea06e272358ee7234734031c401d323d2188068e801d

Observation ca9a4bb9-9268-419a-bee3-71963bd3fa48 · outbound

This paper cites Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents

Reference 55

Resolution
metadata mismatch
local_arxiv, observed 2026-05-11T20:26:11.122650Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:df7305bc59507c731e152c2e45453639f05b78edf0ad5d90ce67fe652d1d06cd

Observation ed97e1cc-5655-45ed-b989-7a0abf94d55a · outbound

This paper cites Maloyan and D.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation Maloyan and D

Reference 56

Resolution
metadata mismatch
arxiv_id, observed 2026-05-11T20:26:11.009072Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:80bd783b125a1e122c92b38a25c76c57249cf887e47596c4d6b36611d6fdddb7

Observation dd7c609b-319f-4a4d-8f9d-500d6728a290 · outbound

This paper cites His research interests include trusted com- puting, confidential computing, system and network security.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation His research interests include trusted com- puting, confidential computing, system and network security

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-05-26T16:27:39.786529Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-06T06:34:29.942622+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:365049b7d8936cc339fb5187517cc386bf82e3ff6ef6aad03cb1e1a98cfaac5e

Pith citing papers

Observation cdd1d98e-bac1-4a6a-99bc-586b5e77c7e5 · inbound

RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control cites this paper.

RT-SHCUA: Real-Time Self-Hosted Computer-Use Agent for UAV Control Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation

Reference 2026

Resolution
unresolved
no resolver link, observed 2026-08-01T16:35:17.406568Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T16:35:17.406568Z digest=sha256:e183dac721f6c0174dd003bf148c761f443e61c9374b6e317d0d05a500eb2450