{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:UCBG77Z6NKB23OARDC3FZWNA3J","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"598d6f809545f7f0b0a7e74bee3210a7765c8a51f06c0b044f6d9482a8eb2db8","cross_cats_sorted":["cs.AI","cs.CL"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-06T02:10:03Z","title_canon_sha256":"e69b7a8d4ed39059e428917ef67acee12ff88c81cfaa0d4d9d4557952b054af8"},"schema_version":"1.0","source":{"id":"2606.07943","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.07943","created_at":"2026-06-09T01:04:56Z"},{"alias_kind":"arxiv_version","alias_value":"2606.07943v1","created_at":"2026-06-09T01:04:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.07943","created_at":"2026-06-09T01:04:56Z"},{"alias_kind":"pith_short_12","alias_value":"UCBG77Z6NKB2","created_at":"2026-06-09T01:04:56Z"},{"alias_kind":"pith_short_16","alias_value":"UCBG77Z6NKB23OAR","created_at":"2026-06-09T01:04:56Z"},{"alias_kind":"pith_short_8","alias_value":"UCBG77Z6","created_at":"2026-06-09T01:04:56Z"}],"graph_snapshots":[{"event_id":"sha256:f22a890550cd05ea3e615e41b9935418a38373bd16b7ec86a573fbcfce83af6d","target":"graph","created_at":"2026-06-09T01:04:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.07943/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Agent skills provide a lightweight mechanism for extending general-purpose agents, but their open format exposes them to skill-poisoning attacks. A practically dangerous injection must stay invisible: if executing the payload derails the user's legitimate task, the resulting failure signal invites inspection of the skill. We therefore evaluate attacks by Attack Success Rate, which requires the injected payload to execute and the user's task to still pass its verifier in the same trial. Prior skill-poisoning attacks face a reliability-stealth trade-off under this lens: YAML-header injections ar","authors_text":"Dehai Min, Haochang Hao, Lu Cheng, Miao Xu, Yingqiang Ge, Yunbei Zhang, Zhifang Zhang","cross_cats":["cs.AI","cs.CL"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-06T02:10:03Z","title":"POISE: Position-Aware Undetectable Skill Injection on LLM Agents"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.07943","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2fd9f860a2f9e1bb61b6301ea13c827bab965d7099e20684b9ad862766358ca0","target":"record","created_at":"2026-06-09T01:04:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"598d6f809545f7f0b0a7e74bee3210a7765c8a51f06c0b044f6d9482a8eb2db8","cross_cats_sorted":["cs.AI","cs.CL"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-06T02:10:03Z","title_canon_sha256":"e69b7a8d4ed39059e428917ef67acee12ff88c81cfaa0d4d9d4557952b054af8"},"schema_version":"1.0","source":{"id":"2606.07943","kind":"arxiv","version":1}},"canonical_sha256":"a0826fff3e6a83adb81118b65cd9a0da402f46491907cbf0cc61bb2f3ae33101","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a0826fff3e6a83adb81118b65cd9a0da402f46491907cbf0cc61bb2f3ae33101","first_computed_at":"2026-06-09T01:04:56.073012Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-09T01:04:56.073012Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"KFuZmJ1q5KQKu3PKXqG68geWVlc1EjRpLq18Rg1amTbCPL1xIq/UoYu7GSyDk6lZtd7PpD5U2FGiOmDoz8MvBg==","signature_status":"signed_v1","signed_at":"2026-06-09T01:04:56.073432Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.07943","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2fd9f860a2f9e1bb61b6301ea13c827bab965d7099e20684b9ad862766358ca0","sha256:f22a890550cd05ea3e615e41b9935418a38373bd16b7ec86a573fbcfce83af6d"],"state_sha256":"aec46a6ce9e39f4878b4b4da93b6e3621fef8ce2aabed01f7bb831de118fc4a7"}