Pith. sign in

Paper Citation Record · LEDGER

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure

As of 13 August 2026, this Paper Citation Record lists 25 of 25 outbound references and 0 inbound Pith citation observations for arXiv:2607.08288.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.08288 v1

Coverage vector

measured 25 of 25 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-07-10T10:00:19.465944Z

measured 25 of 25 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-12T06:34:41.77262+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

25 of 25 outbound references displayed

  • verified exact10
  • verified fuzzy11
  • unresolved0
  • parse uncertain0
  • malformed identifier3
  • metadata mismatch1

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation df37b3eb-ce39-4be2-9471-8fc288a5d032 · outbound

This paper cites Disrupting the First Reported AI- Orchestrated Cyber Espionage Campaign.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Disrupting the First Reported AI- Orchestrated Cyber Espionage Campaign

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.334550Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:c65687ccd7242ceee21d0b8331d1d9a4ffd853d0f1803428698a81a68cdc5ea4

Observation 26f0d3c0-3b9a-4009-84ea-e8c35fa92322 · outbound

This paper cites GPT-4.1 Model.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure GPT-4.1 Model

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.329492Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:6701a3206be28f485e4d124752feead2647e7fbf9a0ca4083d8dac608062e594

Observation 5c741c11-12c6-45fa-8a31-b6510f4eefe6 · outbound

This paper cites A Survey of Cyber- Physical Attacks and Detection Methods in Smart Water Distribution Systems.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure A Survey of Cyber- Physical Attacks and Detection Methods in Smart Water Distribution Systems

Reference 3

Resolution
metadata mismatch
arxiv_id, observed 2026-07-10T10:07:01.009963Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:5c7b017be425c642a28c7190b143cced04553b040efbd795d71c7f91e2dc2dab

Observation fa7228e2-6d23-4f38-83f0-68f034ac62f9 · outbound

This paper cites L333, pp.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure L333, pp

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.315735Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:ad6dc2b33c11ecdff3bad51913ad1b1c50baeb9fea99b80d3704896cbef09b2a

Observation febf772b-be26-49e0-8ded-dba75a62b10f · outbound

This paper cites Stand-der- Technik-Bibliothek.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Stand-der- Technik-Bibliothek

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.332849Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:370a5a58f71782c9148e43845120074ed85690048bfd614b0dcc430962658a5e

Observation b08a8005-4a62-41db-882d-066b98cb3b51 · outbound

This paper cites Model Context Protocol.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Model Context Protocol

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.331175Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:c9f1578d9a6b8af99722b325115063824e1859997d08d11eedd3eb88aa049cbb

Observation 7b126e55-21a9-4bd1-bd22-509c52b7b299 · outbound

This paper cites Towards the Automation of Attack Graph- Based Risk Assessment with OSCAL.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Towards the Automation of Attack Graph- Based Risk Assessment with OSCAL

Reference 7

Resolution
malformed identifier
raw_fallback, observed 2026-07-10T10:07:01.327943Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:25913282b094c3b6a45092cd76f4fde8ea26d8c75a5575a71be6dd2ce3d9535b

Observation 8adcf2a2-d0b5-4e03-8462-013ca9224f09 · outbound

This paper cites Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions

Reference 8

Resolution
malformed identifier
local_arxiv, observed 2026-07-10T10:07:01.026230Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:8d64a55e01c86f6e9f8ec4090833cc2476086a1f642464fdc576362fcf355197

Observation 90a3c1ad-2af0-441e-b20b-d81fffadf249 · outbound

This paper cites Integrated Risk Scoring and Exploit Prediction for Cyber-Physical Power System Vul- nerabilities.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Integrated Risk Scoring and Exploit Prediction for Cyber-Physical Power System Vul- nerabilities

Reference 9

Resolution
verified exact
doi, observed 2026-07-10T10:07:00.828901Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:85a509082e47314d1abd8d05b452335720355e209fa4a517e6fb53547e783c6e

Observation 8da4f9a9-5d24-4d60-8fb0-3347bdf67003 · outbound

This paper cites CISA Stakeholder-Specific Vulnerability Categorization Guide.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure CISA Stakeholder-Specific Vulnerability Categorization Guide

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.324414Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:c6713ddd1937ff1a18d95f914b15ce146d85f5fcb90d5dbdbff7ae2122ab1dfb

Observation c339eb63-7de1-4fe0-b56e-47cfd307deb8 · outbound

This paper cites Common Vulnerability Scoring System Version 4.0: User Guide.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Common Vulnerability Scoring System Version 4.0: User Guide

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.322676Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:8852bdd420a3cbdf75306468d2fd39faa76a2770d3376363f22306724ad40d0d

Observation be5f3483-8945-4a24-929a-ad2c900d4c9b · outbound

This paper cites Towards an open standard for assessing the severity of robot security vulnerabilities, the Robot Vulnerability Scoring System (RVSS).

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Towards an open standard for assessing the severity of robot security vulnerabilities, the Robot Vulnerability Scoring System (RVSS)

Reference 12

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:00.818378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:ef26e61f9a9de091bdf4855238292603a2bdc9ec3e8cd942d13ddbcd7929d76f

Observation 29fe8337-bf3f-40f9-bdeb-a1c05e73ca34 · outbound

This paper cites Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritiza- tion.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritiza- tion

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-07-10T10:07:00.826747Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:ba5f031a4627441e8115a668bb40ae966e4914f60f68ee6c00efb309a8ae6182

Observation 1156a84b-c9dc-4c82-837e-d50a2e668b1c · outbound

This paper cites Dynamic Vulnerability Severity Cal- culator for Industrial Control Systems.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Dynamic Vulnerability Severity Cal- culator for Industrial Control Systems

Reference 14

Resolution
verified exact
doi, observed 2026-07-10T10:07:00.823892Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:55dbf4f34c23732a715747ad760a254df6355a8fa5f701e0887e7dced4fadd28

Observation bf364a0d-31b6-4248-be1c-0edb854a3b54 · outbound

This paper cites A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges

Reference 15

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.023608Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:2880ca96dff5f578cf92ea0be545032590ce2f03029e83a8ba7e950bab7c17ce

Observation 647ce3c4-4ed0-4a20-aa43-aa0fa1f23446 · outbound

This paper cites Exploit Prediction Scoring System (EPSS).

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Exploit Prediction Scoring System (EPSS)

Reference 17

Resolution
verified exact
doi, observed 2026-07-10T10:07:00.817677Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:1bc204f91ee67f45c6b753595cdde30a5a4f67361e7d2c3d639a90a90ab30713

Observation bb56844d-c1bf-4f55-8b45-0a7b549d0254 · outbound

This paper cites MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits

Reference 18

Resolution
malformed identifier
local_arxiv, observed 2026-07-10T10:07:00.827231Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:2af1d080fe8a3ec88a5c3f2235f928edea7f0034851ff6a5c9ce12584a649cbb

Observation ee385496-f361-4292-8678-624262320a64 · outbound

This paper cites AgCyRAG: an Agentic Knowledge Graph based RAG Framework for Automated Secu- rity Analysis.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure AgCyRAG: an Agentic Knowledge Graph based RAG Framework for Automated Secu- rity Analysis

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.319095Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:160b31490ff249833b00dd69df55e7d50ce4ac6c1f40883a821dfb071dd68a5a

Observation 2362171a-444d-4a8e-bfdc-951d4346d8ee · outbound

This paper cites Agentic AI for Autonomous Defense in Software Supply Chain Secu- rity: Beyond Provenance to Vulnerability Mitigation.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Agentic AI for Autonomous Defense in Software Supply Chain Secu- rity: Beyond Provenance to Vulnerability Mitigation

Reference 20

Resolution
verified exact
arxiv_id, observed 2026-07-10T10:07:01.020853Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:97cb77eaf57c5fe64e7fec081375ec715652382240249498fd392f89686493cb

Observation 37c7a9aa-96dd-4d1f-950b-8df909cebb0e · outbound

This paper cites Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.012931Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:58545e3d588196c6ef7249ec550fee432b63c8c3aeeb2a651e59b1069067d16f

Observation f95f48ac-37b7-4c98-9eac-80bdac932ef6 · outbound

This paper cites ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control

Reference 22

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.028882Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:63933f39a879840cf7cf0d6e8697891a22520bdca63d0221b41270cf11281d6e

Observation e362f7aa-c3ab-4325-bdd6-448acfe45ccd · outbound

This paper cites Industrial Cybersecurity.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Industrial Cybersecurity

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.317373Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:842842a82626563f3bfd3d90583f83386f467a57364454a3e1014188f6286085

Observation 9ca6bb2c-5381-4667-8b8c-836317303042 · outbound

This paper cites Using LLMs for Security Advisory Investigations: How Far Are We?.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Using LLMs for Security Advisory Investigations: How Far Are We?

Reference 24

Resolution
verified exact
local_arxiv, observed 2026-07-10T10:07:01.015449Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:af8029753405842328f763558d59138935048368cea200df382d1100e58f8cfc

Observation 65d3bbbb-724f-4d8a-9810-e8586f127e2a · outbound

This paper cites Binding Operational Directive 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Binding Operational Directive 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.320861Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:63c896f39e31a37dcda20cdbb0e3287983fb7f8786654c6d2943a2a7b30f2d97

Observation 4692d70e-0fea-4e64-9e1c-91f062d45c8a · outbound

This paper cites Guide to Industrial Control Systems (ICS) Security.

From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure Guide to Industrial Control Systems (ICS) Security

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-07-10T10:07:01.326063Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-07-10T10:00:19.465944Z digest=sha256:05ffaddc646973e25f255abfc5bd2bf4a92f9afccd387b351166dcccde858bfa

Pith citing papers

No inbound Pith citation observations are available.