Pith. sign in

Paper Citation Record · LEDGER

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents

As of 21 August 2026, this Paper Citation Record lists 33 of 33 outbound references and 0 inbound Pith citation observations for arXiv:2607.23999.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.23999 v2

Coverage vector

measured 33 of 33 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-07-31T23:24:19.584090Z

measured 33 of 33 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-21T06:32:19.484+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

33 of 33 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved33
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation aeac695c-9b02-4acc-84eb-a808e7344957 · outbound

This paper cites LLMail-Inject: A Dataset from a Realistic Adaptive Prompt Injection Challenge.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents LLMail-Inject: A Dataset from a Realistic Adaptive Prompt Injection Challenge

Reference 1

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.497728Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.497728Z digest=sha256:ee9094d59a6739a4d37ffcb41da137ea86513527a666be11bf2ff285d1e848e6

Observation 9ee9772c-52c1-40c9-8507-5291b06a9e54 · outbound

This paper cites Benchmark Early and Red Team Often: A Framework for Assessing and Managing Dual-Use Hazards of AI Foundation Models.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Benchmark Early and Red Team Often: A Framework for Assessing and Managing Dual-Use Hazards of AI Foundation Models

Reference 2

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.501291Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.501291Z digest=sha256:1151ee12d158314722b8303f1bf533114083b29fb2ad149c1d224d01265e5550

Observation 9717f0fd-4b9e-41f1-9000-9311b93b6de6 · outbound

This paper cites Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Ghost in the Agent: Redefining Information Flow Tracking for LLM Agents

Reference 3

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.504351Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.504351Z digest=sha256:681f1067428418e75a219dbbab1d3e852b2959b67a0bbb4a90b27cef3d451cee

Observation c08ec257-4107-4c63-bc5b-6e3e968135b9 · outbound

This paper cites JailbreakBench: An Open Robustness Benchmark for Jailbreaking Large Language Models.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents JailbreakBench: An Open Robustness Benchmark for Jailbreaking Large Language Models

Reference 4

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.507389Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.507389Z digest=sha256:cedf93d062ddb947820eea2102466aac61aff5e6cb1ea762f430c56590277e74

Observation f15623fb-4e63-48a7-a836-0c8851e6a052 · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents StruQ: Defending Against Prompt Injection with Structured Queries

Reference 5

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.510770Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.510770Z digest=sha256:7de2f709c0d6961254082f2744a3e70abc52d592658ae3e22f56067d8f85ee66

Observation 7e004625-42f8-46f4-ada6-d0988f2534ca · outbound

This paper cites SecAlign: Defending Against Prompt Injection with Preference Optimization.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents SecAlign: Defending Against Prompt Injection with Preference Optimization

Reference 6

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.513672Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.513672Z digest=sha256:0f86bb1741c03d3362471d922a7bd2ce81bfaeb586c9528d2ffdbb4ced0c3a5d

Observation 4cd445f0-290a-4c60-b6b6-7af7ddf3b826 · outbound

This paper cites Securing AI Agents with Information-Flow Control.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Securing AI Agents with Information-Flow Control

Reference 7

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.517062Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.517062Z digest=sha256:f48fc3fd133ead1f576368a1414d1e227eac9e73c9d589073417d4bc5d051801

Observation 57c374de-2176-4142-b4ef-4b8e297b7b86 · outbound

This paper cites Defeating Prompt Injections by Design.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Defeating Prompt Injections by Design

Reference 8

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.519727Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.519727Z digest=sha256:4a161b7d04211458bb2c8ad9341f901593c1bfaef2d1ea4d8b294282c42d265f

Observation 03d99116-2a6c-42d7-a133-65f741bf37b5 · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 9

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.522434Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.522434Z digest=sha256:868adde9ebb799f3079eec60512c41410878dc8b32a9a5246cf373a31edeae2f

Observation 40160c12-7f09-4560-81c3-d5c55c8cb5ba · outbound

This paper cites PIArena: A Platform for Prompt Injection Evaluation.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents PIArena: A Platform for Prompt Injection Evaluation

Reference 10

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.525298Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.525298Z digest=sha256:045437e9ec4642cf13d4b5f20ec208213411e4241bd15b3522817c7f1ba73703

Observation 821494c3-93b2-4b8e-bb2f-c9f4f9c18a25 · outbound

This paper cites Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

Reference 11

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.528297Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.528297Z digest=sha256:425354282b87f473c7c18dd61e0bd4723dac831efa38a007f68a343bc51a541f

Observation 3c6d3d66-f670-4597-ba6b-f672b28a96b4 · outbound

This paper cites an unresolved cited work.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work

Reference 12

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.530826Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.530826Z digest=sha256:29d153a624dbc19e915ae475ca38e61058ae967ecf851a8b677bfbcc93403a3b

Observation 9cd601ce-f0bd-4cc9-b8d2-48f47dc6a814 · outbound

This paper cites an unresolved cited work.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work

Reference 13

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.533172Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.533172Z digest=sha256:70567cfb93687ad2a69a756241c40b775a5fcd1d83b9ec81a897800977c29099

Observation 2ee13d19-4e71-44e9-879b-70ece1bc97b3 · outbound

This paper cites AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations

Reference 14

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.535536Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.535536Z digest=sha256:646f551b894500776b67d8f31e0c0ed646d7816702094d9b3a04b5bdf8ebd0c4

Observation 1847c81d-a1bd-4925-8204-fb4336c41cec · outbound

This paper cites The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents

Reference 15

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.538321Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.538321Z digest=sha256:997749efccb4b1f804b9a654c28c831b1d4a082b3d3de72a584808566599c10f

Observation 537025d7-8b68-47e8-bd76-5ffb88b6a598 · outbound

This paper cites an unresolved cited work.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work

Reference 16

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.541489Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.541489Z digest=sha256:7e8d9bd7c9f14211eaea64f2eda586e2a229cd7d0522a4a534ce59341adcda5e

Observation 79dd798b-0af9-4051-ae66-5709aa246531 · outbound

This paper cites an unresolved cited work.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work

Reference 17

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.543798Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.543798Z digest=sha256:8fdd0e32898157ce28bce4f5b6c325e94e73f4f3814893cc7ab9f998b3d7c1f1

Observation eaa2c2ad-ef7c-4974-ae9c-874e66312460 · outbound

This paper cites AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?

Reference 18

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.546238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.546238Z digest=sha256:5b8e16bde903a5390522b474b89d3908b45c4b268b52d8180e9de63f6d2be9ad

Observation 0e5ab8cb-f451-44f9-9b0e-829a48db625a · outbound

This paper cites an unresolved cited work.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work

Reference 19

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.548846Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.548846Z digest=sha256:f80ed7866d77f53a5d7963694f1d72aedc3c921749f08b634bb7a991c99ab3ce

Observation ec202576-c99d-448f-8282-f480d312a74b · outbound

This paper cites an unresolved cited work.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work

Reference 20

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.551189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.551189Z digest=sha256:a351174428e59342193b34c67c023b8fb33cd9fbeb3ce903ac7f151688e4b152

Observation df633017-c20f-4002-931b-59ffa8d091b3 · outbound

This paper cites Hidden in Memory: Sleeper Memory Poisoning in LLM Agents.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Hidden in Memory: Sleeper Memory Poisoning in LLM Agents

Reference 21

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.553643Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.553643Z digest=sha256:1379cbf1f42f662776d9a3d6a46ba006e5624c2925e8867f5b2dc388c8c2d3f0

Observation 9d7b2f26-314f-449a-aa5c-5bad1cab13e5 · outbound

This paper cites On the Security of Research Artifacts.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents On the Security of Research Artifacts

Reference 22

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.556466Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.556466Z digest=sha256:ffd7fddd9dcb376bfa808c45c9320cb15f0063495cc4c2e843a7a9fa6f3b1b1d

Observation a6561c55-5b02-4db0-9230-688998f169c5 · outbound

This paper cites XSTest: A Test Suite for Identifying Exaggerated Safety Behaviours in Large Language Models.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents XSTest: A Test Suite for Identifying Exaggerated Safety Behaviours in Large Language Models

Reference 23

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.559009Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.559009Z digest=sha256:e24fbd4ee138424fb8862960a5b8625c4ce4bd4d36bba56e7e24175d605380ae

Observation 91461674-e372-43c8-b8fd-57db70a1d14f · outbound

This paper cites Model evaluation for extreme risks.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Model evaluation for extreme risks

Reference 24

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.561447Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.561447Z digest=sha256:d7479216aec33d209744c75dcf47143964c133601c1f917b525739af51760af2

Observation 05ea2542-c8a2-4670-b3ae-2a66fa62a11d · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Progent: Securing AI Agents with Privilege Control

Reference 25

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.564377Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.564377Z digest=sha256:5810389e8e7b29c5c1e203bb93facbd73757400a8ea0b824e052f9372a569d25

Observation 93f01eca-e0a2-46bd-b77f-26dffe350b4e · outbound

This paper cites an unresolved cited work.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Unresolved cited work

Reference 26

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.567115Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.567115Z digest=sha256:b9364431c3e0fe30a950ec0cf492f6f89d51e2ba1291aedefe872e78cd7a4c40

Observation f59612fe-e213-458a-ad2b-960d48303897 · outbound

This paper cites A StrongREJECT for Empty Jailbreaks.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents A StrongREJECT for Empty Jailbreaks

Reference 27

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.569415Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.569415Z digest=sha256:8ee27f56bae79cc85967b7391e6cde63f82d179105e48050b02665128d6f1467

Observation 05761911-becf-4f48-8109-c5106db028bc · outbound

This paper cites Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Aligning Provenance with Authorization: A Dual-Graph Defense for LLM Agents

Reference 28

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.571879Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.571879Z digest=sha256:0780c9ceb21d334363b405536cc4c82ef210c311a073dd0b119d7d8757aa19ed

Observation 6461035e-c70b-4983-b037-2ce642539fa6 · outbound

This paper cites AgentWatcher: A Rule-based Prompt Injection Monitor.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents AgentWatcher: A Rule-based Prompt Injection Monitor

Reference 29

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.574454Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.574454Z digest=sha256:9e59a31f59376882ebc9b9f1b800addbf662d556337c9b59156ccfb94c39bb56

Observation db4457de-bbd2-4963-a793-ecef3e38fac2 · outbound

This paper cites Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents Benchmarking and Defending Against Indirect Prompt Injection Attacks on Large Language Models

Reference 30

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.576853Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.576853Z digest=sha256:2022325265829dd1c7934cd19b2ca506fe8b7999b45e40df2ee555c45ce4a651

Observation 518f7e29-b41a-4e0c-9ac4-e543b5e30a0c · outbound

This paper cites PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses

Reference 31

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.579327Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.579327Z digest=sha256:7465f1e1a0a4dabbc3535fc1dcc506675c47dcd8928c7b9c218c2aee86204db1

Observation b9707586-dd10-4ae5-9fcc-3f98054edf33 · outbound

This paper cites InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents

Reference 32

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.581798Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.581798Z digest=sha256:5f71ff2a50d5856a8c7466b76cc4187fe486b5cded0d5fe56b4d579a986b8921

Observation e18f42e5-3596-43bb-acbc-680fa8fce847 · outbound

This paper cites ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection.

ContainmentBench: Trace-Based Evaluation of Post-Injection Containment in Tool-Using LLM Agents ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection

Reference 33

Resolution
unresolved
no resolver link, observed 2026-07-31T23:24:19.584090Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-31T23:24:19.584090Z digest=sha256:579d055eee02133dce497a761dcb5f4236c18edc06be22628aeb5ae6afc40a8e

Pith citing papers

No inbound Pith citation observations are available.