Pith. sign in

Paper Citation Record · LEDGER

Intent-Governed Tool Authorization for AI Agents

As of 10 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 2 inbound Pith citation observations for arXiv:2606.22916.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2606.22916 v3

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-02T10:32:34.305658Z

measured 31 of 31 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-10T06:31:04.303077+00:00

measured 2 of 2 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T21:46:23.178867Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-07T21:46:23.228007Z

Reference resolution

29 of 29 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved29
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 35e4b550-9009-4b6e-a0c5-77af0bd29a83 · outbound

This paper cites Mitchell, and Helen Nissenbaum.

Intent-Governed Tool Authorization for AI Agents Mitchell, and Helen Nissenbaum

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.190015Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.190015Z digest=sha256:135071238994999a85405af5e5d9660a09059174c5e8cec440bcbed5e6d3d892

Observation 4ad0b115-7c52-4a14-bf3e-af0d0a81cb75 · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries, 2024.

Intent-Governed Tool Authorization for AI Agents StruQ: Defending Against Prompt Injection with Structured Queries, 2024

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.195425Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.195425Z digest=sha256:4a90f8c5b5507714ad56b95f5f9a61b9419058e96f7a57897930b92c00fba5aa

Observation e6925ba9-b5db-4f60-947d-7fd4af1dd12e · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents, 2024.

Intent-Governed Tool Authorization for AI Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents, 2024

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.200454Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.200454Z digest=sha256:992cd209c7707724485e3efb52fea53da77d682ecd947a0cf1d039298bf6685f

Observation 1d6554e7-29dd-475e-b524-7a9b20ba8dd0 · outbound

This paper cites Ferraiolo and D.

Intent-Governed Tool Authorization for AI Agents Ferraiolo and D

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.204718Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.204718Z digest=sha256:8e69859c6bee00791bb64d72953c95249b42cb4d7d5764068716ba95539df020

Observation d0f6652c-2c24-4d45-a1d0-def0189e696e · outbound

This paper cites Operationalizing Contextual Integrity in Privacy-Conscious Assistants, 2024.

Intent-Governed Tool Authorization for AI Agents Operationalizing Contextual Integrity in Privacy-Conscious Assistants, 2024

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.209047Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.209047Z digest=sha256:bf40ae1cab9d05d47f47ce7729003b702c13fd133f6e59189a5f913a8d7dd424

Observation 5148af58-0ae0-44f1-8027-39fb613b014a · outbound

This paper cites AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations, 2026.

Intent-Governed Tool Authorization for AI Agents AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations, 2026

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.213183Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.213183Z digest=sha256:537ddbedcf3e42d523086c07a8c917a38c4f6d98fee6db1877442ecf6650094c

Observation 95a6121f-b61e-4f21-abb2-81c8b95b9eee · outbound

This paper cites Hu, David Ferraiolo, D.

Intent-Governed Tool Authorization for AI Agents Hu, David Ferraiolo, D

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.217976Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.217976Z digest=sha256:2f681ce38420a354aaea9c6df4516854d4cf5fb5dbfbfd3809d229fb6a5d5bf3

Observation aadee338-8424-4dab-bc4b-2a7b4a7e7a9d · outbound

This paper cites Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning, 2026.

Intent-Governed Tool Authorization for AI Agents Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning, 2026

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.221964Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.221964Z digest=sha256:5665b7710f8fe9e99c13cb1f48c089a1fda1945cfa50d02b7532d287d8b8b774

Observation 155969ce-f6d2-48af-b01b-39ac1b6ec51a · outbound

This paper cites Need to Know: Contextual-Integrity-Grounded Query Rewriting for Privacy-Conscious LLM Delegation, 2026.

Intent-Governed Tool Authorization for AI Agents Need to Know: Contextual-Integrity-Grounded Query Rewriting for Privacy-Conscious LLM Delegation, 2026

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.226055Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.226055Z digest=sha256:0f33a48645960aa38b3c892f02db9f76cc50a001a3f6f030c097febe9a847111

Observation fc683ac0-ffc0-49de-bb82-d0b72c09f240 · outbound

This paper cites Securing the Model Context Protocol: Defending LLMs Against Tool Poisoning and Adversarial Attacks, 2025.

Intent-Governed Tool Authorization for AI Agents Securing the Model Context Protocol: Defending LLMs Against Tool Poisoning and Adversarial Attacks, 2025

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.230584Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.230584Z digest=sha256:9cc5a9a242e50f2ce8fb3190c758e0da77af88f2a4d4d9f2764421564f549745

Observation 04527dff-7c3f-442d-a8ec-6f0de9fb2625 · outbound

This paper cites AgentDyn: A Dynamic Open-Ended Benchmark for Evaluating Prompt Injection Attacks of Real-World Agent Security System, 2026.

Intent-Governed Tool Authorization for AI Agents AgentDyn: A Dynamic Open-Ended Benchmark for Evaluating Prompt Injection Attacks of Real-World Agent Security System, 2026

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.234585Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.234585Z digest=sha256:ff005d0af2a15af23ee423288f9e12a4bab7a5ef7224dbeda52ffd4b864ef5af

Observation 07390d51-9322-4ebd-b180-551a78573fc9 · outbound

This paper cites ToolSandbox: A Stateful, Conversational, Interactive Evaluation Benchmark for LLM Tool Use Capabilities, 2024.

Intent-Governed Tool Authorization for AI Agents ToolSandbox: A Stateful, Conversational, Interactive Evaluation Benchmark for LLM Tool Use Capabilities, 2024

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.238425Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.238425Z digest=sha256:0b00bf16de47190cc915cbc5fefbe683ce90777c62ca9280211f82fff938573a

Observation f1ba5f8d-8550-411d-af00-4b72ce3fe447 · outbound

This paper cites Authorization.

Intent-Governed Tool Authorization for AI Agents Authorization

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.242656Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.242656Z digest=sha256:850d21e854a874bd3973723af127e819f29954304c52ab9c9d2de01b9c4bcd07

Observation ce07bee1-4c59-4d39-846f-8db0deceea91 · outbound

This paper cites an unresolved cited work.

Intent-Governed Tool Authorization for AI Agents Unresolved cited work

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.246480Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.246480Z digest=sha256:6684f3f13ed280753a398927f5f9d0ed4087c0139180ba81a8ba074e5c42d110

Observation 4305c0a2-561c-46c6-a159-87cd8ffc45bb · outbound

This paper cites Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile.

Intent-Governed Tool Authorization for AI Agents Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.250987Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.250987Z digest=sha256:20dd08290860802159ff2a41494438a9f69d581147b4620faded5dbe68e69952

Observation 317a95c7-4542-42b8-965f-5bcff794f96d · outbound

This paper cites Stanford University Press, 2009.

Intent-Governed Tool Authorization for AI Agents Stanford University Press, 2009

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.254698Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.254698Z digest=sha256:070c14df3e912b751079e4ec622e7e10db1798ee08ba7dd7a35cc5ea31d2fe4f

Observation 248fada8-082e-454e-bf66-5b1528e87fe2 · outbound

This paper cites LLM01:2025 Prompt Injection.

Intent-Governed Tool Authorization for AI Agents LLM01:2025 Prompt Injection

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.258538Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.258538Z digest=sha256:db8e40d67c8923c39aba2d2df7d3afd2291caa4a1cbb4d52f599e3009fc47955

Observation ea0dbd09-bbb0-40bd-b484-24a0b327d865 · outbound

This paper cites OW ASP Top 10 for LLM Applications 2025.

Intent-Governed Tool Authorization for AI Agents OW ASP Top 10 for LLM Applications 2025

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.262506Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.262506Z digest=sha256:728488134a3aee9cbf14043830a8bb3c5427049f63a30c96c3ed0c1860b477ef

Observation 12854581-b907-4f19-8917-076c26188621 · outbound

This paper cites Maddison, and Tatsunori Hashimoto.

Intent-Governed Tool Authorization for AI Agents Maddison, and Tatsunori Hashimoto

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.266439Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.266439Z digest=sha256:616a436b240692fcc2b05a09b03505b366785d9fd13e036acfc6fc251dbf1e92

Observation 24193b09-c495-4e28-a941-85aa18df27b7 · outbound

This paper cites Saltzer and Michael D.

Intent-Governed Tool Authorization for AI Agents Saltzer and Michael D

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.270482Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.270482Z digest=sha256:1541d8e26eccf09d8d662a700601f33c2327ab25d4824d964eefb6f6dcff47e9

Observation 18747825-aa31-4fc9-846d-f4d8f8e1e8e5 · outbound

This paper cites MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems, 2026.

Intent-Governed Tool Authorization for AI Agents MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems, 2026

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.274818Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.274818Z digest=sha256:eba80c9dd5ca618e4ade3506c0e09fee02d33bab4bbf40fb2ef1e26f0b97f777

Observation eebae825-626a-4ea0-84ab-2ac6ce20bfb7 · outbound

This paper cites Prompt Injection Attack to Tool Selection in LLM Agents, 2025.

Intent-Governed Tool Authorization for AI Agents Prompt Injection Attack to Tool Selection in LLM Agents, 2025

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.278453Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.278453Z digest=sha256:b3194606207d21339ef7c525209ac678406b1b6cc3873ba4756322933a7e4aa1

Observation 00621fd8-9e55-4b4d-bda7-b74ec9383132 · outbound

This paper cites ToolTweak: An Attack on Tool Selection in LLM-based Agents, 2025.

Intent-Governed Tool Authorization for AI Agents ToolTweak: An Attack on Tool Selection in LLM-based Agents, 2025

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.282521Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.282521Z digest=sha256:ea04535848bfad3285f6c15ed91aa413f1eb8b5e63466b3c6219887657b6f9d4

Observation 98643bf9-498f-43c6-9087-381d3c6661fd · outbound

This paper cites Data Guard: A Fine-grained Purpose-based Access Control System for Large Data Warehouses, 2025.

Intent-Governed Tool Authorization for AI Agents Data Guard: A Fine-grained Purpose-based Access Control System for Large Data Warehouses, 2025

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.286490Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.286490Z digest=sha256:2047708f42b901f95b2e59f333943d7b869c1ca6019477ae05940c8fadd90560

Observation e214b054-0206-4d5e-b16d-f35e9c1af57b · outbound

This paper cites MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers, 2025.

Intent-Governed Tool Authorization for AI Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers, 2025

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.290321Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.290321Z digest=sha256:5890ca09cee417586a40f980ba0b31bafaf16d3a0ebd555338b9fdcef48597e8

Observation 16334e18-31fb-4d43-803b-2114a0d375c8 · outbound

This paper cites Messaging with Purpose Limitation – Privacy-Compliant Publish-Subscribe Systems, 2021.

Intent-Governed Tool Authorization for AI Agents Messaging with Purpose Limitation – Privacy-Compliant Publish-Subscribe Systems, 2021

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.294081Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.294081Z digest=sha256:d04854bbcf304988705bc019215c1760d1869520e565b3ef4fba7c7802e419ba

Observation cf519791-baee-479a-aa36-7bbec0918fb1 · outbound

This paper cites τ-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains, 2024.

Intent-Governed Tool Authorization for AI Agents τ-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains, 2024

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.297969Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.297969Z digest=sha256:c45bde4bc14a876907ce44f0b198346275e6f10cf28f3e5c02728b434448d727

Observation 425f23c7-a4f1-4650-9752-c017d720c82f · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents, 2024.

Intent-Governed Tool Authorization for AI Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents, 2024

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.301794Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.301794Z digest=sha256:0a02c7a9f6fe8f645dbf3464d314d5155c3ec9ed208d17218c02b21058035499

Observation b8d8d1d6-3e6d-47e0-b085-4800c10f72d7 · outbound

This paper cites AgentSentry: Mitigating Indirect Prompt Injection in LLM Agents via Temporal Causal Diagnostics and Context Purification, 2026.

Intent-Governed Tool Authorization for AI Agents AgentSentry: Mitigating Indirect Prompt Injection in LLM Agents via Temporal Causal Diagnostics and Context Purification, 2026

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-02T10:32:34.305658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T10:32:34.305658Z digest=sha256:471286f6d932dc78c7ae94cb37202b7ee27e2525b537b9c20e5b4a994ebee6c9

Pith citing papers

Observation 889e1901-795c-4aed-8869-f65b2837f1dd · inbound

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales cites this paper.

Explanation-Bound Tool Execution for AI Agents: Server-Verified Action Claims Without Trusting Model Rationales Intent-Governed Tool Authorization for AI Agents

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T02:43:24.437055Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T02:43:24.437055Z digest=sha256:d4952794c2ada3e3f0a8dc37f21e245f11fdd0fe13dc79f1182d37bcf7d79691

Observation fdc261ba-1e82-46d5-a9b2-c2aa5dc85c59 · inbound

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents cites this paper.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Intent-Governed Tool Authorization for AI Agents

Reference 40

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.233895Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-10T06:31:04.303077+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.178867Z digest=sha256:9735ee8427c5146aaeb45dd93ac990afb2c3207962a0edd9af571df00bc387aa