Pith. sign in

Paper Citation Record · LEDGER

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance

As of 9 August 2026, this Paper Citation Record lists 55 of 55 outbound references and 0 inbound Pith citation observations for arXiv:2608.01558.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.01558 v1

Coverage vector

measured 55 of 55 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T00:12:27.078558Z

measured 55 of 55 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

55 of 55 outbound references displayed

  • verified exact6
  • verified fuzzy10
  • unresolved39
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation d90b0aef-fc35-4176-9847-d71e7c2998a8 · outbound

This paper cites 2024.System architecture for the 5G System (TS 23.501).

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2024.System architecture for the 5G System (TS 23.501)

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.575025Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:22.866701Z digest=sha256:df25faadfd9635b2197fe21de70ebd2da2cafdd556949edf2794bfe7a96bb418

Observation 508f4b3a-d805-4f3d-8234-47afce6c2e12 · outbound

This paper cites Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:22.935267Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:22.935267Z digest=sha256:edbbc684c195dcc812b2186ef48d75524e2a29cb78218d801461e49c52567e0e

Observation b7dfa417-2d66-441a-9b2b-2fb93ac7d73e · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.018725Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.018725Z digest=sha256:e27b0413bbbbbe682c86abc27fa85d91dd4b8d328d435eaf3034eace05e3c94e

Observation 7655f297-4550-4aee-b806-2a18b97ac2eb · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.119614Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.119614Z digest=sha256:93be4b3a5a8985378874a04e9b273ba487b18e2f8335cbe59bf7eeec7a52c434

Observation c3facac2-0e00-4c0c-aed9-bbd8c38eb557 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 5

Resolution
verified exact
raw_fallback, observed 2026-08-07T00:12:58.790971Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:23.194415Z digest=sha256:3dd5b9fe144ebd7e3cf381c011fda351711aacff56f4da557f6c68f546055086

Observation f332cb43-44ed-47b3-bb15-2d598316e784 · outbound

This paper cites AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.283898Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.283898Z digest=sha256:ccf220a6335fe4e931f51a8dfafd707060dd57766bfc0132d1861285b7d1baba

Observation 345b9450-26d8-49f5-97a3-22b13a5d5372 · outbound

This paper cites 2012.Computer Security Incident Handling Guide (NIST SP 800-61 Rev.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2012.Computer Security Incident Handling Guide (NIST SP 800-61 Rev

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.545974Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:23.368163Z digest=sha256:9d0d4711a18733071171965c07bf2534aa328a5da8c46abf5d82064685061199

Observation 4982389e-3cb7-4eef-841b-8e46e62152cf · outbound

This paper cites 2025.Securing AI Agents with Cisco’s Open-Source A2A Scanner.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Securing AI Agents with Cisco’s Open-Source A2A Scanner

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.531905Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:23.430931Z digest=sha256:926a68d373279ae5445258a17ba63193228a4c3636afb692aff19927c85e5698

Observation 12a6028b-46e2-497f-9099-3e687c51ea92 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 9

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.518070Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:23.482516Z digest=sha256:4454bc1b519a76eb59677a661b4f54e2927d7c4c9836e9c44e1123d017c066c4

Observation a7a7e11a-186f-4033-a1fb-0de4a6ce2a25 · outbound

This paper cites Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.578617Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.578617Z digest=sha256:080a0f93c8f47a1134c99aeaab04f8f85ce7d73cc09b147e82891114ee9ebc55

Observation b560053b-4adf-47e6-85ef-147adec35fd9 · outbound

This paper cites Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.625640Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.625640Z digest=sha256:bd555cc1abb5cfe0d7fc912995f2278f0a535a237bc8c0a9f89a99f3c2522a8f

Observation 752afc91-068b-4e94-8e2c-55e86530c623 · outbound

This paper cites Defeating Prompt Injections by Design.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Defeating Prompt Injections by Design

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.711741Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.711741Z digest=sha256:cad25d7e3de9d7f24b72aace68cd71a673eca0e5c7ff0c7d99aff4eef51d7ad6

Observation 0d707773-6112-4200-91d1-82a20796ddbe · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.784463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.784463Z digest=sha256:15cafd92ac7a99b157b3f7a86244f7270fa93455d2c0a72e36e29a4390448def

Observation 0f5ac053-9f9d-4e43-b4f2-62f43889da4c · outbound

This paper cites A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP).

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:23.867036Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:23.867036Z digest=sha256:28ff94c05c8571360655aa0b11506b3ebf61ac50d3439bb1559114238147341f

Observation ed5b273b-06c8-40a4-81ea-7e1a09c5f7d9 · outbound

This paper cites 2018.MiFID II Articles 17 and 21; RTS 6 Algorithmic Trading.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2018.MiFID II Articles 17 and 21; RTS 6 Algorithmic Trading

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.503952Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:23.980376Z digest=sha256:4196b28b3d51e7de79d0626cc045cd43a9bf2e54eb22e1237c6421402f624466

Observation 76b2a1c9-1e9e-4e20-9bc0-1a529b3408ad · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:24.077540Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:24.077540Z digest=sha256:fd774ff679bd2244fa64ea76a622f485eb34c8a72cdfe8a9a2a96c78f43cee58

Observation a97c45a7-0929-471c-ab3a-90dd132c3903 · outbound

This paper cites 2025.Safeguarding AI Agents: An In-Depth Look at A2A Protocol Risks.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Safeguarding AI Agents: An In-Depth Look at A2A Protocol Risks

Reference 17

Resolution
verified exact
raw_fallback, observed 2026-08-07T00:12:58.569959Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.177719Z digest=sha256:0cfc4a1fa45b0bc1f914f4731c2b2bb26bfc7c4b95ef9390ce3a79ec24b2be95

Observation b4d4b2f8-ca56-4a56-b4a8-c9e594d47e4d · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 18

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.489856Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.249778Z digest=sha256:a1d1f2d6faf80bf816b570a19d03e8da4479062fd74768dc02758224ff76e867

Observation 3fb1543d-b560-4271-9859-6410d51c2893 · outbound

This paper cites 2023.HL7 FHIR Release 5: Workflow Module.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2023.HL7 FHIR Release 5: Workflow Module

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.474737Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.312520Z digest=sha256:ed6c9bf2f7e966ee6c8eaec7ade59949536c1d93f4f4e077a1f6e9f958120a80

Observation 096cf875-d7a9-4935-94c6-3b4e673fa876 · outbound

This paper cites Don't Make Models Guess Security and Safety: Symbolic Guardrails for Domain-Specific AI Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Don't Make Models Guess Security and Safety: Symbolic Guardrails for Domain-Specific AI Agents

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:24.400080Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:24.400080Z digest=sha256:256b7121551c32de0eb6a8d6542e705195510ae7f34a66954e860de46fbe5cfe

Observation 52e314d6-b13d-4526-b304-b05bfdc6b52e · outbound

This paper cites RepetitionCurse: Measuring and Understanding Router Imbalance in Mixture-of-Experts LLMs under DoS Stress.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance RepetitionCurse: Measuring and Understanding Router Imbalance in Mixture-of-Experts LLMs under DoS Stress

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-08-07T00:12:58.362037Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.458193Z digest=sha256:b90bdf3baad63c4a152c69e63039a743b998960e4f0bcf7d46305f7016eb2872

Observation 456f57e7-6c97-4e49-ae3e-09d5ecce964c · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 22

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.459263Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.525702Z digest=sha256:1fe9266bf7d25b72ab1a264db3763fab8084e3ae71bba13517ee4227a546b4d9

Observation e610b514-8243-471d-b14b-65abcb25fd59 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 23

Resolution
verified exact
doi, observed 2026-08-07T00:12:42.649877Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.577229Z digest=sha256:29137a074a892f9800183fd79c71954733b22f6fd7039ffda3c21a408c2cfba1

Observation 663c4715-075b-4a8b-933e-70c67598f1ee · outbound

This paper cites 2025.Potential Attack Surfaces in Agent2Agent (A2A) Protocol.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Potential Attack Surfaces in Agent2Agent (A2A) Protocol

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.442944Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.663366Z digest=sha256:a0b1bacbf06c9a498a6310e8ce62dd5b1f8e729bececaed2d6719c0fc47ccac4

Observation 71f63925-21cb-4534-a09f-99c0f9fa8664 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:24.716939Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:24.716939Z digest=sha256:20dcde5d29e15d5082768f463988c888e2e667ca0799889cc5a60e6a9fd335d5

Observation 78243060-5fa4-4890-ae64-9c6f4248e067 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 26

Resolution
verified exact
doi, observed 2026-08-07T00:12:42.470683Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.780186Z digest=sha256:2ade77882a5ad557ee06bbb1510c44f38b71c9b67de6a099c209703b9fa4ec04

Observation eb452181-ee18-4f62-b1ca-0d1bae3a2c5b · outbound

This paper cites 2025.ACP Joins Forces with A2A Under the Linux Foundation’s LF AI & Data.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.ACP Joins Forces with A2A Under the Linux Foundation’s LF AI & Data

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.427440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.838712Z digest=sha256:ddbdb305817cecb4ce59420d06c2f01335f2ad7e466ead19b23cc07a837834bf

Observation 6fde1e6d-e018-42c1-87af-c49f61f02043 · outbound

This paper cites Life-Cycle Routing Vulnerabilities of LLM Router.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Life-Cycle Routing Vulnerabilities of LLM Router

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:24.911258Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:24.911258Z digest=sha256:ebc77e688eb6bdda187a78b1ce289b4bd9e7747e3d9bc128d220013f56177f75

Observation 77a0b4f7-0765-4890-b4a2-52ac4e864081 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 29

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.411614Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:24.980670Z digest=sha256:1a131369e1cdb922a7fb4dea48224265d23e0c126346948e03ef85763501d602

Observation 87e5d589-ed43-460a-8cb5-72f0bc6e0714 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 30

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.392032Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:25.015079Z digest=sha256:140248f3479d67a1d58de220d9ed1c4ddd5ef22ac548d10e82c675176f155b1e

Observation cf032acd-a091-4d9c-909e-04c7a881af85 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.092502Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.092502Z digest=sha256:7127ceb5549891056dd9cc1a1da4b7b5e0783c4668956c0724473cfb07521673

Observation 60075151-2517-4ac8-ac33-6151af36fca9 · outbound

This paper cites Security Considerations for Multi-agent Systems.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Security Considerations for Multi-agent Systems

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.164426Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.164426Z digest=sha256:2dbb1b687343a96af08d680493f5c0ae0ca559ad72c05a0635c87e6e38ce9128

Observation 7ed7363c-916d-4dcb-9bbd-887ab9a97125 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 33

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.371119Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:25.236137Z digest=sha256:f6aa24c8a0080d45a948ce586bc40a607c5a158ad72df9bb69df29a87ff01b43

Observation 544baad3-4d8c-42f8-a7f7-8094c98cfb95 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 34

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.347754Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:25.300553Z digest=sha256:ad84a0b5d73c1416720cb32eb36ce2837924d81dff9f64946b6d27c77ea8286d

Observation 6c6d1120-29b5-4128-9578-f9c013ce9061 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 35

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.331578Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:25.386968Z digest=sha256:603ef37813978b9bdeadedfd6d2801e31f1d7ebca5b49ef2319567bfa67572b5

Observation 3b43a8ba-78a0-4810-96b4-396a523c4364 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 36

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.307043Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:25.453517Z digest=sha256:0314affc0e873effd849169378737604b247c8cae60fb75a27a8432db17be109

Observation 5c4db43f-afef-4d0f-bc0e-1af3fed63b7b · outbound

This paper cites Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.516024Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.516024Z digest=sha256:50ca9df11226290e81809bc5370636d8299c09166272b7862c722806772123dd

Observation 75121b02-8aed-4888-91cd-87613c0d45a6 · outbound

This paper cites 2026.A2A Protocol Security: Authenticating Agent-to-Agent Communi- cation.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2026.A2A Protocol Security: Authenticating Agent-to-Agent Communi- cation

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:13:00.272211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:25.610975Z digest=sha256:747f43a599d80cdc3f4981b5ebece8149eab136218eeecbb3995c6417c7c1f03

Observation 446a917b-4392-4785-8152-6b8b809c6b60 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 39

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:13:00.036365Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:25.686470Z digest=sha256:6021489af959cb51ef01c8a2b8c2fc6f0c0b8d7c9a8c2fcc8f3a1b5df3ec98ce

Observation 6d5755eb-7184-4249-bc1f-95add8c6fd6c · outbound

This paper cites Prompt Injection Attack to Tool Selection in LLM Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Prompt Injection Attack to Tool Selection in LLM Agents

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.831378Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.831378Z digest=sha256:cd3a1814426d2704d1912a85ad1c012271f4938651a0e879c4f02d8c8dc368cd

Observation 32663088-c234-4639-84e0-42d246b24447 · outbound

This paper cites Progent: Securing AI Agents with Privilege Control.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Progent: Securing AI Agents with Privilege Control

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.895446Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.895446Z digest=sha256:56740a61233c454a8de7eb610fb514d49bc4c20e54f06bc6d428f1eb91d5078c

Observation ed50bcb4-1f05-445a-b2ce-2b59540e69d4 · outbound

This paper cites Route to Rome Attack: Directing LLM Routers to Expensive Models via Adversarial Suffix Optimization.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Route to Rome Attack: Directing LLM Routers to Expensive Models via Adversarial Suffix Optimization

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.015766Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.015766Z digest=sha256:59c70ad874afa79d9435145f67e517f12aabd23c3bf0ae5ae4bb0869b4e7992c

Observation 57a63382-f3dc-43ee-8317-8b52ef0cdab6 · outbound

This paper cites 2025.Linux Foundation Announces the Forma- tion of the Agentic AI Foundation (AAIF).

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Linux Foundation Announces the Forma- tion of the Agentic AI Foundation (AAIF)

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:12:59.835938Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:26.121588Z digest=sha256:fc3acb9adbce4a4710234cea34afe44b31bdf34098a1f439d0ddf28382c596bb

Observation 8679f679-8ad9-410a-8543-f962ff3dd360 · outbound

This paper cites 2025.Linux Foundation Launches the Agent2Agent Protocol Project to Enable Secure, Intelligent Communication Between AI Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance 2025.Linux Foundation Launches the Agent2Agent Protocol Project to Enable Secure, Intelligent Communication Between AI Agents

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T00:12:59.269986Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:26.296684Z digest=sha256:570302d72440cec3da6e214b5f9d7b1a52fc58b4e1069a58af1bbd340d2cfe55

Observation 21ad1643-490a-4954-a7ff-b87eb2d7bfad · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 45

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:12:59.543610Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:26.211036Z digest=sha256:e257a6b0ac130a63e090a142716ac717d4bb6b39d24bc1207e39ee50fa2c94bc

Observation 84c6b314-84ef-488c-8ddd-afc663ba51d0 · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.491944Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.491944Z digest=sha256:fa9495319352094b39ca5b1868f24dc8824a5258996d918895c0c74e0c9a1038

Observation 30284983-2ca0-436a-9563-ea2437dc1589 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 47

Resolution
unresolved
raw_fallback, observed 2026-08-07T00:12:59.017385Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:26.391388Z digest=sha256:860ce0dc236f01e3a3e0e0eed09e97ed59b51a5b1dd3be8a8049cbc69de39db1

Observation 36cfab86-09f9-4d41-beae-26d34d1865e7 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.677481Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.677481Z digest=sha256:74782d4bdff15a62f280e44e35da8690a695d918c1c06bd2c81eb1bbe090414c

Observation 1867f1c6-7164-4a3b-ad41-b75d7b65c53e · outbound

This paper cites ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance ProbGuard: Proactive Runtime Monitoring for LLM Agent Safety via Probabilistic Prediction

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.587196Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.587196Z digest=sha256:fcc7b624617388bfb9de4b7cf4490bf2229edd799ada16932c9dfec47cc39826

Observation b46de631-1721-4aa0-8f88-30252ed74380 · outbound

This paper cites Stealing User Prompts from Mixture of Experts.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Stealing User Prompts from Mixture of Experts

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.839942Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.839942Z digest=sha256:85c7a6f3383849d74a76871c5d6499679024b6661e65b2d290504db1b2255adf

Observation 6b32b77d-b644-4426-be8a-c43df23e9368 · outbound

This paper cites RouteHijack: Routing-Aware Attack on Mixture-of-Experts LLMs.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance RouteHijack: Routing-Aware Attack on Mixture-of-Experts LLMs

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:26.741411Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:26.741411Z digest=sha256:d80d2744e8884939b327c7ecfa306fb91135a0d10b2e6cfe2b5fae9f2b706b0d

Observation 6baedb92-ac0c-4dd5-a071-338cecee1a3b · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:27.004844Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:27.004844Z digest=sha256:9c4ab4832a71abd376c910b67149484e87b29f0b4c3d99aaed52d0db73dda4fd

Observation 364c5f77-8357-4899-aab5-bf48bd693a52 · outbound

This paper cites an unresolved cited work.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Unresolved cited work

Reference 53

Resolution
verified exact
raw_fallback, observed 2026-08-07T00:12:42.992528Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=pdf_text observed=2026-08-07T00:12:26.925470Z digest=sha256:fdb828cfe5153159d960c895c7f33b9432824c2ae94a7a1ca677d47a8a864a4a

Observation b762fbc8-2f22-4c04-afaf-36ca9dbed0c2 · outbound

This paper cites PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:27.078558Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:27.078558Z digest=sha256:acf25cc26ff619743dcfffe2f841227ef2b0781ac3159d3f1f5b219491f31ee1

Observation 08950bca-1daa-4dde-8a86-4f1e282ff083 · outbound

This paper cites Rerouting LLM Routers.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance Rerouting LLM Routers

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:25.735180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:25.735180Z digest=sha256:145cd8d46af8afcf55d29b43d3f9c8e4d7fbad776c3d7bf38a0f7a22d804f6cd

Pith citing papers

No inbound Pith citation observations are available.