Pith. sign in

Paper Citation Record · LEDGER

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents

As of 10 August 2026, this Paper Citation Record lists 32 of 32 outbound references and 0 inbound Pith citation observations for arXiv:2608.05884.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2608.05884 v1

Coverage vector

measured 32 of 32 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T21:46:23.185376Z

measured 32 of 32 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

32 of 32 outbound references displayed

  • verified exact0
  • verified fuzzy15
  • unresolved11
  • parse uncertain2
  • malformed identifier0
  • metadata mismatch4

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 5415756e-7ed2-4c3c-9b3b-729ecdec0aea · outbound

This paper cites Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.737672Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.031735Z digest=sha256:153ed8757726d2c9696e2b64e2b9ee1a7bf7465476e5da4c7678684717ebfd7b

Observation 1c2e7a2d-8b3d-499c-aed1-a17b73d9d6bd · outbound

This paper cites Accelerating the adoption of software and artificial intelligence agent identity and authorization.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Accelerating the adoption of software and artificial intelligence agent identity and authorization

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.726853Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.037423Z digest=sha256:4103e5f48428b7804166c16b597678decc5773ca4e5b7414a4abd10cdccb82b7

Observation 64eb9206-c389-450c-bcd7-87fe3c47336f · outbound

This paper cites CVE program glossary.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents CVE program glossary

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.716191Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.046348Z digest=sha256:6d3e528464bf3ab0e260633d1d73b3dedb5d29212380812b8cbe4b9b8986abbc

Observation 930953cb-2ee5-4d72-bb2e-5c977f8edd12 · outbound

This paper cites Agent baseline: Six security outcomes for safely building, deploying and operating AI agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Agent baseline: Six security outcomes for safely building, deploying and operating AI agents

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.705198Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.050508Z digest=sha256:571dff1369c8578c38111b474ea3cd8ddcba0e4fe88630c6ed987f92c25f5651

Observation 1f5feeca-7050-4879-8650-638a5c4ffaa4 · outbound

This paper cites Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.693093Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.054324Z digest=sha256:d2b984747cb2188d4071666408ba39dc8021b08f53579aa8754e7dcb898e2bd6

Observation abecf350-9b96-4983-9a10-a0ac1664572d · outbound

This paper cites LLM06:2025 Excessive Agency.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents LLM06:2025 Excessive Agency

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.681955Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.066092Z digest=sha256:7e4fc19875ab3b55da5832e430b99b1bcac6cf942ee7443a7404f53f91c3f6b0

Observation 42e2e241-18c1-4abd-a900-e0060a5efa35 · outbound

This paper cites Complete Dictionary Learning via $\ell_p$-norm Maximization.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Complete Dictionary Learning via $\ell_p$-norm Maximization

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.078142Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.078142Z digest=sha256:e594f53c52cc799d7927212ac36e8c9f33d15f8bef724f87acb4e20ecc042049

Observation 932b6529-685a-418a-9d9c-4184cb5f23aa · outbound

This paper cites Guide to enterprise patch management planning: Preventive maintenance for technology.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Guide to enterprise patch management planning: Preventive maintenance for technology

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.671347Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.082061Z digest=sha256:894f8bd39856a27c01b64047fdbb8a1785f663b00b31d96d51709fb555591fa6

Observation 75c001a0-a75b-47d6-a6e3-251beac83376 · outbound

This paper cites AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents AgentSpec: Customizable Runtime Enforcement for Safe and Reliable LLM Agents

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.092713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.092713Z digest=sha256:dfe7fa7728eed9cf3099ba1da00abc8f8ab08e6c39dfd5f6f915ac188ceb21bd

Observation 96f6e19c-3e4f-4f76-b2e7-3adf4810215a · outbound

This paper cites Cyber defense matrix.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Cyber defense matrix

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.660898Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.104328Z digest=sha256:9b498bf2a917eab5ffa0e46ecd247cd2509033ed9ca1ccbfc691cbabffa2dc56

Observation cb7c2515-45dd-4fd0-ac2c-e99a6953accf · outbound

This paper cites AI agent remote code execution.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents AI agent remote code execution

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.650229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.107898Z digest=sha256:f5681f336418834ffe5d3121d4aaedd18c7a05167569cad6418ef5dcfbdd791e

Observation 3276b1c2-7c82-4d44-9fcf-66944c7e54c9 · outbound

This paper cites , howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents , howpublished =

Reference 22

Resolution
parse uncertain
no resolver link, observed 2026-08-07T21:46:23.115180Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.115180Z digest=sha256:de07ee1c48dec1cc6ecc0d6344b58a67398e2e6cb7eb7ec464473b3e89589c2d

Observation b5cd30f9-2f84-4298-b025-caca076eeb17 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 23

Resolution
parse uncertain
no resolver link, observed 2026-08-07T21:46:23.118904Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.118904Z digest=sha256:571be70f94b71c4c4996234880280a8430c49d4d0605f6037249f27dc635ba25

Observation ebee3091-c85d-4e25-95d4-22842858a8b5 · outbound

This paper cites 2026 , month = jul, howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2026 , month = jul, howpublished =

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.624209Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.122223Z digest=sha256:5e78ad99de5f757b7cbe6abbf43bf52dc322ebc981e30b0ba393e49ccc3e454a

Observation 739dbcfe-6dbf-4919-ab1a-3ffa606b8483 · outbound

This paper cites 2025 , month = aug, howpublished =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2025 , month = aug, howpublished =

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.613044Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.125718Z digest=sha256:cdaecf0153f94c8d1b267fff669bf87c3268e04002e9658ac492363cda070519

Observation 7fb36911-593c-41d2-a412-80ee9afb4ae5 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.129671Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.129671Z digest=sha256:7aa097415dbb088e912ee734bec68b92110962d0803112891e70d029bea4d7ce

Observation 18313a73-227c-434a-906c-35357144d502 · outbound

This paper cites 2022 , month = apr, doi =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2022 , month = apr, doi =

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.594302Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.133320Z digest=sha256:4b8d3ace544f4b11f2a7a62bc812a944a0e7d46b7295ce1ec47405d501f92b8e

Observation bdc2018d-2675-4b72-bef5-1e09df9862da · outbound

This paper cites Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.136931Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.136931Z digest=sha256:449379bdcade5535a9cc12a849f2d4f0bfffad5dfb43cb9d786c803f741ef560

Observation 1f2dd371-a2fd-47a6-afc7-f937b711a170 · outbound

This paper cites Haines and Somesh Jha and Richard P.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Haines and Somesh Jha and Richard P

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.583226Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.140659Z digest=sha256:46124b0b222b8c08dcb47defba71a70e7b2b2de26361557bacfafb47a4ec7387

Observation 217393ac-46d8-491c-b418-cec6ad2f4f7c · outbound

This paper cites 2026 , month = feb, type =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents 2026 , month = feb, type =

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.571886Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.144245Z digest=sha256:9495976396f46ab386807b7b4da965c39351ce87b327a84fec584918ec3dc6f0

Observation 74dc51d4-9edb-4f76-955e-d8249283dfd3 · outbound

This paper cites Authenticated Delegation and Authorized AI Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Authenticated Delegation and Authorized AI Agents

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.147775Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.147775Z digest=sha256:5a0872b2970e69347e30907322728b69ff5b877d7a9d8000a005c8ad4feddce9

Observation 512a8847-7ec1-4824-8100-9a21d45e4ff9 · outbound

This paper cites Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.151426Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.151426Z digest=sha256:45c90bfb28bf3d1c441aa7185c09967b7af0bb8d1b395ac54f989721dc753995

Observation 1ff63302-8548-4a26-bae3-05156959092a · outbound

This paper cites The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents

Reference 33

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.263208Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.154924Z digest=sha256:7130147959bbf08b3ee7f96f9057fc81824f4904058f478b18456249b0240439

Observation d11472dd-044d-4900-b953-607a114f83cf · outbound

This paper cites Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.158456Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.158456Z digest=sha256:a45c7c60ece7a989ddd7cfaecfb95d23bf37844a058e680fd431e529718785e2

Observation b8763d81-1b0f-432a-8070-936b747ebbee · outbound

This paper cites Do Coding Agents Understand Least-Privilege Authorization?.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Do Coding Agents Understand Least-Privilege Authorization?

Reference 35

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.249319Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.161803Z digest=sha256:d46db6ae8726672a1fdf0a034a94b0db8a3933117af3cf6de2e37983b1437e52

Observation afc2c480-0158-4566-a2af-738301c2cfc6 · outbound

This paper cites Poskitt and Jun Sun , title =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Poskitt and Jun Sun , title =

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T21:46:23.560382Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.165381Z digest=sha256:dbbdc6d4c02747748cb0c43a4b569432c3644d7a9155ba38574154e9ba0b1242

Observation 9507c2c8-4bcb-4209-9305-bc8766478b75 · outbound

This paper cites arXiv preprint arXiv:2603.20953 , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents arXiv preprint arXiv:2603.20953 , year =

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.168974Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.168974Z digest=sha256:f2b9c88e1b15fc51b6b43626ffc6f5b0dbaedb9264580353f234f2fcc788d606

Observation 488b57ee-d62f-4920-9e3f-555d9d1be740 · outbound

This paper cites Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.172245Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.172245Z digest=sha256:f43a00ae6bd7dbeb6d963aa94147f62c968ed259d8762a86e1e72ed43790c0df

Observation 64c2d950-463b-454b-99b2-7d8d55e974cd · outbound

This paper cites arXiv preprint arXiv:2603.16586 , year =.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents arXiv preprint arXiv:2603.16586 , year =

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T21:46:23.175452Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T21:46:23.175452Z digest=sha256:ba4cfc060cc42f5f308f9c9432f37c7cfee3b49fbdcf3e2a92a56793f2ba6277

Observation fdc261ba-1e82-46d5-a9b2-c2aa5dc85c59 · outbound

This paper cites Intent-Governed Tool Authorization for AI Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Intent-Governed Tool Authorization for AI Agents

Reference 40

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.233895Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.178867Z digest=sha256:d213bb9a4a026a6bab5d57f7a5126f6421b556530c53ae501e28e364f98c8448

Observation b3f1c257-8c23-4208-ad9e-4c2310f8b43e · outbound

This paper cites When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents

Reference 41

Resolution
metadata mismatch
local_arxiv, observed 2026-08-07T21:46:23.447632Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.182040Z digest=sha256:1e6dda684ff3921c1da01a8c270520a5332bf2fcfd01a77f42709812ce606978

Observation 1217cedd-1aae-45d6-8cb5-7b32995a9e36 · outbound

This paper cites an unresolved cited work.

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents Unresolved cited work

Reference 42

Resolution
unresolved
raw_fallback, observed 2026-08-07T21:46:23.549537Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.

source=arxiv_source observed=2026-08-07T21:46:23.185376Z digest=sha256:79422fe6cd920bc592baed6908bc855c41bce6ca578263cb644a0fc1ae6ab8a3

Pith citing papers

No inbound Pith citation observations are available.