Pith. sign in

Paper Citation Record · LEDGER

AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

As of 13 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 18 inbound Pith citation observations for arXiv:2505.05849.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.05849 v4

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 18 of 18 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-13T06:32:02.005865+00:00

measured 18 of 18 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-07T14:34:34.867377Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-04T10:09:45.177863Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation 1b69edd8-c974-46b4-8663-438abb005067 · inbound

Progent: Securing AI Agents with Privilege Control cites this paper.

Progent: Securing AI Agents with Privilege Control AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 64

Resolution
verified exact
arxiv_id, observed 2026-05-22T21:12:08.484176Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-22T21:09:51.782808Z digest=sha256:209457182c095c0f8e6b9abf9e4bd2c03abe303d7bb4110c47172bda5304ce25

Observation 36d40690-2b23-4e58-aca1-4e32eff4c2b1 · inbound

Invisible Tokens, Visible Bills: The Urgent Need to Audit Hidden Operations in Opaque LLM Services cites this paper.

Invisible Tokens, Visible Bills: The Urgent Need to Audit Hidden Operations in Opaque LLM Services AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T14:34:34.867377Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:34:34.867377Z digest=sha256:542d6fb1434418277347433284e8ffc7bc33ff7d1d581b301f92d0d6bbc1ca38

Observation 60f33eb7-2813-4eeb-88e6-64af5737e63e · inbound

A Red Teaming Roadmap Towards System-Level Safety cites this paper.

A Red Teaming Roadmap Towards System-Level Safety AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 90

Resolution
unresolved
no resolver link, observed 2026-08-07T12:11:24.967328Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T12:11:24.967328Z digest=sha256:6e5fd7c7be7619da46458f19b1f49d2cf5961725c78451b4c5235395d694597d

Observation 3f6dbd46-137c-4c4a-b0c3-bd62c8ba26ba · inbound

PromptArmor: Simple yet Effective Prompt Injection Defenses cites this paper.

PromptArmor: Simple yet Effective Prompt Injection Defenses AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-06T15:42:01.058771Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T15:42:01.058771Z digest=sha256:8a0671ccb8c9fa079d56cd1456d1eb0f082dcf87823f8ce4c489874a455b53b1

Observation 59e59dd2-a947-4309-b9b2-8a72a1bf3145 · inbound

Agentic Web: Weaving the Next Web with AI Agents cites this paper.

Agentic Web: Weaving the Next Web with AI Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 224

Resolution
unresolved
no resolver link, observed 2026-08-06T13:05:40.367994Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T13:05:40.367994Z digest=sha256:15d126d05e6bb7e6aeb175c07f151e28074d457c4161a64683778d3412cf9253

Observation e01b55d3-0550-41b1-b9e0-7a7aaf50e233 · inbound

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation cites this paper.

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 52

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:26:11.054246Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-08T09:08:30.102711Z digest=sha256:ce39aa78e25d8742dd0fb9d10fabadb9935a8e51b2e602adc597fbc66c601c8c

Observation 3ef61d7f-ae1b-4ee4-92bc-5f80b0238b63 · inbound

Agent Security is a Systems Problem cites this paper.

Agent Security is a Systems Problem AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 75

Resolution
verified exact
arxiv_id, observed 2026-05-20T09:03:09.842181Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-20T09:02:59.719090Z digest=sha256:b7bf51e06076f9bbb644aa8e2eeadea42a2490d28c2239b4f7a4e0b7f8f89c54

Observation f3353e1c-a6ab-42ad-94a8-a09152700dd7 · inbound

Agent Security is a Systems Problem cites this paper.

Agent Security is a Systems Problem AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 75

Resolution
verified exact
arxiv_id, observed 2026-05-21T07:44:02.914269Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-05-21T07:43:14.250188Z digest=sha256:8a4fac70b90650b099cece041bef02075fc12581937da20a9bbcf18364cde4e5

Observation 403464f2-3a56-4ea4-ac84-709e17e2fe54 · inbound

Hallucination as Exploit: Evidence-Carrying Multimodal Agents cites this paper.

Hallucination as Exploit: Evidence-Carrying Multimodal Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-20T09:48:11.589903Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=arxiv_source observed=2026-05-20T09:46:42.413501Z digest=sha256:a6a9bff7e15d9a042565026764fa6aa9fba8f188094947da7180c6bd094a8cc3

Observation d44f66e0-cfef-4cdc-b84b-b769a5bd773c · inbound

Hallucination as Exploit: Evidence-Carrying Multimodal Agents cites this paper.

Hallucination as Exploit: Evidence-Carrying Multimodal Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 13

Resolution
verified exact
arxiv_id, observed 2026-05-22T09:01:19.894756Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=arxiv_source observed=2026-05-22T08:57:29.491043Z digest=sha256:5e50f9f550ba6229882a7f515b8c668405608af237317f56f1478f23f86737a1

Observation eb3ef02b-eb9b-4acb-8c6b-1a6272bf5342 · inbound

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models cites this paper.

Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 21

Resolution
metadata mismatch
arxiv_id, observed 2026-06-28T19:22:34.394638Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=arxiv_source observed=2026-06-28T19:19:17.673497Z digest=sha256:abc92f7d406c24ff5298d7ee618894d6e79500f5e850b8fa0149b63d1603316b

Observation 412cde2d-a5bb-4fc3-bbf5-52bb12fd7d8a · inbound

Assessing Automated Prompt Injection Attacks in Agentic Environments cites this paper.

Assessing Automated Prompt Injection Attacks in Agentic Environments AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-07-03T06:17:41.945423Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-27T12:47:09.467463Z digest=sha256:c5bc8759c72a1fc15b755bbc77886f96309a6c832b020d118fa3dd8b157ed7df

Observation d3594358-41db-416a-ba7e-17f323c11cce · inbound

PI-Hunter: Automated Red-Teaming for Exposing and Localizing Prompt Injections cites this paper.

PI-Hunter: Automated Red-Teaming for Exposing and Localizing Prompt Injections AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 28

Resolution
metadata mismatch
arxiv_id, observed 2026-07-03T12:38:07.269748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=arxiv_source observed=2026-06-27T08:56:12.882653Z digest=sha256:1a67da61b6dac6ef405688b2e197abcf90f4b0ee31e554b459f5cf18c5937e37

Observation f47fff1d-8f9a-4b0b-a561-ff066adb7b40 · inbound

Same-Origin Policy for Agentic Browsers cites this paper.

Same-Origin Policy for Agentic Browsers AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-07-01T07:35:29.017390Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-07-01T07:29:08.355105Z digest=sha256:bcab9eb41a819cdb52d75c6cdaec00b749dae9dd86a39d0602054b7400520621

Observation 92e8edb9-0134-4a58-9b27-8bcfe956fd8a · inbound

When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents cites this paper.

When AUC 0.998 Is Not Enough: A Candidate Evaluation Protocol for Hidden-State Probes of Indirect Prompt Injection in Multimodal Computer-Use Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-07-04T10:09:45.179850Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-06-26T09:05:22.096955Z digest=sha256:36b76bb77ae91c35c0288c51de4b2fbbe7f81104801e883a82f28b33dfa25829

Observation fc937447-2d5a-4b84-b05b-49bdfdbedfc9 · inbound

CONTRA: Red-Teaming Configurations of Personalizable Agents cites this paper.

CONTRA: Red-Teaming Configurations of Personalizable Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 13

Resolution
unresolved
no resolver link, observed 2026-07-12T04:03:40.067404Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-07-12T04:03:40.067404Z digest=sha256:5aa57e9cccd91763e051489d9623d86c314155f94551c16dde6b092293465698

Observation 1b17e9f1-3daf-4a2b-ae26-da210751b368 · inbound

Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents cites this paper.

Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T11:38:19.674889Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T11:38:19.674889Z digest=sha256:335a34c77858b2e9cdf8c2bf27eab3c5c81e3a1b3e7e58cb2a657838026321e7

Observation c76f5e9b-e5d3-4311-b3ff-1e806e38fac5 · inbound

GPT-Red: Automated Red Teaming via Self-Play at Scale cites this paper.

GPT-Red: Automated Red Teaming via Self-Play at Scale AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T01:12:44.169745Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T01:12:44.169745Z digest=sha256:9695191ae9e25f7d2ee8c25642993449be63e7d199f3d8b0497968afcacb33e2