Pith. sign in

Paper Citation Record · LEDGER

Imprompter: Tricking LLM Agents into Improper Tool Use

As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 26 inbound Pith citation observations for arXiv:2410.14923.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2410.14923 v2

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 26 of 26 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 26 of 26 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T15:37:51.603999Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

2
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 66e6083f-e437-47c3-874b-88c06a6b83e7 · inbound

Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions cites this paper.

Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 26

Resolution
verified exact
arxiv_id, observed 2026-05-13T09:02:40.411688Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-13T09:02:40.294491Z digest=sha256:9250e08d1e65846ddf333e161e812894ee1750183c0ef6e50e122fa51b4943d3

Observation aab7e631-2d14-4b0c-921c-5c3990c973cf · inbound

Lessons from Defending Gemini Against Indirect Prompt Injections cites this paper.

Lessons from Defending Gemini Against Indirect Prompt Injections Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-07T15:37:51.603999Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:37:51.603999Z digest=sha256:b497d0ba4783517fc0b484f01f30342986d07b839cd63fda3cee6bd310299def

Observation ac2626e6-3ed5-47fa-8f37-4d423204ba59 · inbound

Data-Centric Safety and Ethical Measures for Data and AI Governance cites this paper.

Data-Centric Safety and Ethical Measures for Data and AI Governance Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T04:34:08.000242Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T04:34:08.000242Z digest=sha256:48bdbbe1c0edc69e2227f82c2030c5789e2ff2700c2e6b148457b3aba067ac34

Observation 87ea844c-4b84-4efe-b22f-b0f8cc12c09b · inbound

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems cites this paper.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.507283Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.507283Z digest=sha256:adf322d400f2324ca72ace93cd72577cf5781b81bc6148eaed0efde490c0a8c0

Observation ef7e3098-7e36-4660-b5c1-1aa73879559b · inbound

FaSTA$^*$: Fast-Slow Toolpath Agent with Subroutine Mining for Efficient Multi-turn Image Editing cites this paper.

FaSTA$^*$: Fast-Slow Toolpath Agent with Subroutine Mining for Efficient Multi-turn Image Editing Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 5

Resolution
verified exact
arxiv_id, observed 2026-05-19T08:17:10.746601Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-19T08:17:08.223736Z digest=sha256:0d4edada66a838f19b718a5471023a8e23764919661b40604c38d7adf469c552

Observation b8580e78-b2fc-44d8-ad47-fd96cdb4f583 · inbound

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents cites this paper.

A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 122

Resolution
unresolved
no resolver link, observed 2026-08-06T21:34:45.093922Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T21:34:45.093922Z digest=sha256:11eb3df8dfcf302041cbe99d680b579e45b2fd92252bb545537e8f911ed0cded

Observation 757c4528-ba1f-4594-9e0b-f07bfcbb87e9 · inbound

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree cites this paper.

Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-06T15:52:56.510579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T15:52:56.510579Z digest=sha256:0e5e53d698e307fd6a14c1037b9a6dfc6cf0c158fe8968387b3fffb5a39add1a

Observation 4a7c8dd4-d55a-448e-aa63-0896643f70a5 · inbound

On the Future of Software Reuse in the Era of AI Native Software Engineering cites this paper.

On the Future of Software Reuse in the Era of AI Native Software Engineering Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-05T15:29:05.783421Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T15:29:05.783421Z digest=sha256:bd0034498e2bad0493a60a3eabcdcfdc98827d0241ac0780365af113dac9ab1f

Observation dc60bca4-8180-45eb-ab43-56784df000e4 · inbound

AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents cites this paper.

AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-04T21:44:12.278474Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T21:44:12.278474Z digest=sha256:0442214e58247c27445dce548b70effd8cd9c4bdbd960e35ff04071dcfc0e396

Observation 02c1bb54-0bef-4954-b47c-dde9e019eabb · inbound

AgentBound: Securing Execution Boundaries of AI Agents cites this paper.

AgentBound: Securing Execution Boundaries of AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
metadata mismatch
arxiv_id, observed 2026-05-18T05:15:54.156005Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-18T05:12:23.542793Z digest=sha256:69ff08b9b86c285a4d45a15523410e0b862d0b43a793b143feeb88a176487d97

Observation 8fae375b-c2cf-4058-b1bf-1bed57620730 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 45

Resolution
metadata mismatch
arxiv_id, observed 2026-05-18T03:42:22.516285Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:44c913032f1c62dbd64ed7687ecd1c406ebba4cd488ff011edd3c2cf35be2a4f

Observation 2f4b6a39-39f6-49ec-80b1-3cfe183eaf56 · inbound

GUIGuard-Bench: Toward a General Evaluation for Privacy-Preserving GUI Agents cites this paper.

GUIGuard-Bench: Toward a General Evaluation for Privacy-Preserving GUI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 56

Resolution
metadata mismatch
arxiv_id, observed 2026-05-16T11:32:48.257431Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-16T11:31:16.087579Z digest=sha256:1e4b50e3bb5854c8dfd7e58e4a232d2a6fb0b20192ebc0218bf9589e13c75aa8

Observation 5d05004d-b4bb-4c5f-ad2c-0db093425c95 · inbound

Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP cites this paper.

Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 71

Resolution
verified exact
arxiv_id, observed 2026-05-16T05:07:20.812637Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-16T05:05:16.370606Z digest=sha256:fb6678b2d0ce6912152e7c364aa2d023a4aec21856ed97e11231250e0e3f0070

Observation fe22c24f-fdc2-4fff-94a8-7539659ed8de · inbound

From Storage to Steering: Memory Control Flow Attacks on LLM Agents cites this paper.

From Storage to Steering: Memory Control Flow Attacks on LLM Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 1

Resolution
unresolved
no resolver link, observed 2026-07-14T20:40:43.875392Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-14T20:40:43.875392Z digest=sha256:72a39e044b647b65ccc8e7ff6554f44410e623e2a5ba91f031948d22d78d2401

Observation f631d8a7-2d9a-4229-aa2a-57fef3addcd8 · inbound

How Your Credentials Are Leaked by LLM Agent Skills: An Empirical Study cites this paper.

How Your Credentials Are Leaked by LLM Agent Skills: An Empirical Study Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 18

Resolution
verified exact
arxiv_id, observed 2026-05-13T19:53:11.688398Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-13T19:51:29.230241Z digest=sha256:30d769fca113c28b878f2e311d992e743c4df292fe023bb1c7ce3facad798f16

Observation 1fe5a63e-6a84-41a7-bcfe-92c99bfd40c2 · inbound

HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents? cites this paper.

HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents? Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-05-10T10:34:29.224645Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-10T10:32:37.967401Z digest=sha256:0c9f530f029430131ab40262894fe9762d36862541828dad0cf385ef4d273881

Observation bb9e389e-d419-4939-bb20-1b698435fbbf · inbound

WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections cites this paper.

WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 21

Resolution
metadata mismatch
arxiv_id, observed 2026-07-01T14:45:49.558073Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-30T20:16:13.413064Z digest=sha256:443a8e031c2a560102a5e1229b10fbd3115f3eb40d89cbb56f979e85d17098ba

Observation 432be1f4-7116-4eb1-a1ec-aeef85c35e84 · inbound

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety cites this paper.

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-05-22T05:51:07.946360Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-22T05:50:28.114140Z digest=sha256:acb0b2e0c8213afef4f3ee19c4869160ed5bc134ba8daf20841d10c2a768332d

Observation f4c8e78c-002a-4c01-bf51-b6d2680fb3ee · inbound

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety cites this paper.

Boiling the Frog: A Multi-Turn Benchmark for Agentic Safety Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 30

Resolution
verified exact
arxiv_id, observed 2026-05-25T06:06:43.046681Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-05-25T06:05:27.736494Z digest=sha256:3dc3637e4ff6af3de9058109de049b1e01d7e911667692484130bee1946cf360

Observation a32cd385-442e-4221-ae45-5eeb7ecd29dd · inbound

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents cites this paper.

"I Strongly Suspect This Website Is a Scam": Benchmarking PII Leakage and Detection without Defense in Autonomous Web Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 127

Resolution
verified exact
arxiv_id, observed 2026-06-28T19:42:36.161487Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-06-28T18:53:41.420255Z digest=sha256:b6f8f78dd3d17baba0fd98369f27744a87ffacfc3c060981a0793970bc93deea

Observation 79b665f1-26d8-4d01-bda8-fcab0f5f660b · inbound

Assessing Automated Prompt Injection Attacks in Agentic Environments cites this paper.

Assessing Automated Prompt Injection Attacks in Agentic Environments Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.981522Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:92f1cdaac267c3d800b750480896948e5253db6166a3ee99b99dd66f6e4d301f

Observation 5486ad3f-d5bb-4798-af87-ff92b493f921 · inbound

SAIGuard: Communication-State Simulation for Proactive Defense of LLM Multi-Agent Systems cites this paper.

SAIGuard: Communication-State Simulation for Proactive Defense of LLM Multi-Agent Systems Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 17

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T13:28:18.842251Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=arxiv_source observed=2026-06-27T08:04:15.004591Z digest=sha256:c24431b06c83e72a8605ce0507f88c069956681852f94366979b6dcf4984be55

Observation 8a2bfdbd-ac6d-49fe-a55a-265fd27b1e89 · inbound

AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents cites this paper.

AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 42

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T16:48:40.495135Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-06-27T04:57:54.827932Z digest=sha256:037618332fc4aa692aca71738bd8081eb72b4ddd2f5675af3980b35c3cb3d235

Observation c52f5f5f-d966-4c28-9e05-07c50195f8c3 · inbound

DualView: Preventing Indirect Prompt Injection in Personal AI Agents cites this paper.

DualView: Preventing Indirect Prompt Injection in Personal AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 58

Resolution
unresolved
no resolver link, observed 2026-07-11T23:43:28.649948Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T23:43:28.649948Z digest=sha256:1e5346bf28b1c3533a9b5d695e9c39139f08001f8ca10983b7e7dcdb2b38866b

Observation aa3314d3-c3fa-4027-98e2-0b3b8e754aea · inbound

Agent Data Injection Attacks are Realistic Threats to AI Agents cites this paper.

Agent Data Injection Attacks are Realistic Threats to AI Agents Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 8

Resolution
unresolved
no resolver link, observed 2026-07-11T08:31:36.099368Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-11T08:31:36.099368Z digest=sha256:50436d8b3c883e9dc3ccc49e92798b74501057a0dd2657b717e8ab35e7cca234

Observation 61022b50-8da0-46cb-85f6-ca54b0432b68 · inbound

Agent Security Needs Redefinition through a Holistic Framework cites this paper.

Agent Security Needs Redefinition through a Holistic Framework Imprompter: Tricking LLM Agents into Improper Tool Use

Reference 269

Resolution
unresolved
no resolver link, observed 2026-08-01T06:04:46.607188Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-01T06:04:46.607188Z digest=sha256:d6047d53369914c46c6a65257cb422f17d57006dbe35a191310ff93269e67529