Research discovery wing · kingdom.research-observatory-publication/0.1

The
Observatory

A bounded conversion membrane between public research metadata and human attention. It preserves sources, exact identifiers, updates, contradictions, and reasons to look—without pretending that discovery is truth or permission.

This is a bounded capture, not a claim of complete global coverage.The snapshot preserves imported metadata returned by explicit allowlisted polls through 2026-08-20T18:10:14Z. Source lag, index gaps, English-only watch terms, and missed later updates remain visible limits. Importing and page rendering make no network request; the earlier harvest did.

9source contracts
3reviewed watchlists
36inert observations
34exact-ID works
53reasons to look

The membrane has four gates

  1. 1 · DiscoveryObserved here; metadata only.
  2. 2 · EvaluationNot performed; separately owned.
  3. 3 · AdoptionNot recorded; explicit choice required.
  4. 4 · Bounded useNot authorized; capability and expiry required.

A later module would be KINGDOM-owned code. A later guest would stay source-owned under a narrow, revocable contract. Neither path is proposed by an attention signal, and this snapshot creates neither.

What this first lens watches

English terms · multilingual expansion absent

Secure information flow and agent security

Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

agent securitycapability securityconfused deputydata exfiltrationindirect prompt injectioninformation flow controlprompt injectionsandbox escapetool poisoning

English terms · multilingual expansion absent

Interpretable reasoning and J-space

Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.

activation steeringcausal tracingcircuit tracinginterpretable reasoningJ-spaceJacobian lensmechanistic interpretabilityrepresentation engineeringsparse autoencoder

English terms · multilingual expansion absent

Natural-language programming and agent interoperability

Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

agent interoperabilityagent protocollanguage-oriented programmingmodel context protocolnatural-language programmingsemantic interfacetool interoperabilitytool protocol

The terms are intentionally visible and incomplete. No translation is guessed, no prestige factor is used, and no scalar “high value” score hides the judgment.

Observed research objects

Cards are ordered by latest source observation, then stable work ID—not by scientific value. Titles, author names, identifiers, and links below are inert source data. A match orders possible human attention; it is not an endorsement, safety finding, truth verdict, or instruction.

preprint · active Observed — not evaluated

Registry Descriptions Go Stale Unevenly: An 89-Day Measurement of Model Context Protocol Drift, and Why Drift-Ranked Re-Auditing Under-Covers It

Gautam BhartiPublished: Observed:

arxiv:2608.00997

Why this surfaced

  • Registry Descriptions Go Stale Unevenly: An 89-Day Measurement of Model Context Protocol Drift, and Why Drift-Ranked Re-Auditing Under-Covers It matches Natural-language programming and agent interoperability

    Matched reviewed English terms: model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

No source change relation in this snapshot.

Evidence vector

  • mediumsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: arxiv
  • unknownrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: item-level licence absent

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: model context protocol
  • highfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2026-08-02
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

software · active Observed — not evaluated

ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol

Arnold, JaretPublished: Observed:

doi:10.5281/zenodo.21729883

Why this surfaced

  • ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol matches Natural-language programming and agent interoperability

    Matched reviewed English terms: model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

2 factual source-change assertions also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

  • Explicit is-version-of relation to 10.5281/zenodo.21713452

    The source relation creates an edge; it does not silently merge the records.

  • Explicit is-supplement-to relation to datacite:https://github.com/musharna/ldraw-mcp

    The source relation creates an edge; it does not silently merge the records.

Evidence vector

  • highsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: datacite
  • unknownrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: uninterpreted item licence:mit

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: model context protocol
  • highfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2026-08-01
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Semantic Zero-Trust for Model Context Protocol

David A. Flynn, Flynn, David C.Published: Observed:

doi:10.5281/zenodo.21731418 openalex:W7172128171

Why this surfaced

  • Semantic Zero-Trust for Model Context Protocol matches Natural-language programming and agent interoperability

    Matched reviewed English terms: model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

3 factual source-change assertions also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

  • Explicit is-version-of relation to 10.5281/zenodo.21731417

    The source relation creates an edge; it does not silently merge the records.

  • 2 sources report exact identifiers for this work

    Exact shared identifiers connect the observations; this does not independently verify the research claim.

  • 2 source observations or versions are preserved

    The observations remain separate even when exact identifiers resolve to one work.

Evidence vector

  • highsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: datacite · openalex
  • mediumrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:cc-by · reported item licence:cc-by-4.0

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: model context protocol
  • highfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2026-08-01
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

software · active Observed — not evaluated

ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol

Arnold, JaretPublished: Observed:

doi:10.5281/zenodo.21736124

Why this surfaced

  • ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol matches Natural-language programming and agent interoperability

    Matched reviewed English terms: model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

2 factual source-change assertions also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

  • Explicit is-version-of relation to 10.5281/zenodo.21713452

    The source relation creates an edge; it does not silently merge the records.

  • Explicit is-supplement-to relation to datacite:https://github.com/musharna/ldraw-mcp

    The source relation creates an edge; it does not silently merge the records.

Evidence vector

  • highsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: datacite
  • unknownrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: uninterpreted item licence:mit

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: model context protocol
  • highfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2026-08-01
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Semantic Zero-Trust for Model Context Protocol

David A. Flynn, Flynn, David C.Published: Observed:

doi:10.5281/zenodo.21731417 openalex:W7172123867

Why this surfaced

  • Semantic Zero-Trust for Model Context Protocol matches Natural-language programming and agent interoperability

    Matched reviewed English terms: model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

4 factual source-change assertions also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

  • Explicit is-version-of relation to 10.5281/zenodo.21731417

    The source relation creates an edge; it does not silently merge the records.

    2 source assertions represented
  • 2 sources report exact identifiers for this work

    Exact shared identifiers connect the observations; this does not independently verify the research claim.

  • 2 source observations or versions are preserved

    The observations remain separate even when exact identifiers resolve to one work.

Evidence vector

  • highsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: datacite · openalex
  • mediumrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:cc-by · reported item licence:cc-by-4.0

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: model context protocol
  • highfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2026-08-01
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Enterprise Agentic AI: A Reference Architecture for Natural Language to SQL, Model Context Protocol (MCP), Retrieval-Augmented Generation (RAG), Multi-Agent Systems, and Production AI

Bothraj PPublished: Observed:

doi:10.5281/zenodo.21740544

Why this surfaced

  • Enterprise Agentic AI: A Reference Architecture for Natural Language to SQL, Model Context Protocol (MCP), Retrieval-Augmented Generation (RAG), Multi-Agent Systems, and Production AI matches Natural-language programming and agent interoperability

    Matched reviewed English terms: model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

1 factual source-change assertion also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

  • Explicit is-version-of relation to 10.5281/zenodo.21740544

    The source relation creates an edge; it does not silently merge the records.

Evidence vector

  • highsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: datacite
  • mediumrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:cc-by-4.0

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: model context protocol
  • highfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2026-08-01
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training

J. MeltonPublished: Observed:

doi:10.5281/zenodo.21906711 openalex:W7202247495

Why this surfaced

  • Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training matches Interpretable reasoning and J-space

    Matched reviewed English terms: mechanistic interpretability, sparse autoencoder.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Interpretable reasoning and J-space

    Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowreview state

    Distinguish preprint, peer-reviewed, and unknown review states.

    Evidence: preprint
  • unknownintegrity

    Surface correction, withdrawal, and retraction evidence without averaging it away.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed term that matched the named need.

    Evidence: mechanistic interpretability · sparse autoencoder
  • highfreshness

    Show source and update dates without treating recency as validity.

    Evidence: 2026-08-12
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training

J. MeltonPublished: Observed:

doi:10.5281/zenodo.21906710 openalex:W7202273798

Why this surfaced

  • Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training matches Interpretable reasoning and J-space

    Matched reviewed English terms: mechanistic interpretability, sparse autoencoder.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Interpretable reasoning and J-space

    Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowreview state

    Distinguish preprint, peer-reviewed, and unknown review states.

    Evidence: preprint
  • unknownintegrity

    Surface correction, withdrawal, and retraction evidence without averaging it away.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed term that matched the named need.

    Evidence: mechanistic interpretability · sparse autoencoder
  • highfreshness

    Show source and update dates without treating recency as validity.

    Evidence: 2026-08-14
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Thinking vs. NoThinking: Towards Interpreting Reasoning Mechanisms of Large Language Models via Sparse Autoencoders

Bo Cheng, Qiaolin Lu, Yi Chang, Yuan WuPublished: Observed:

doi:10.48550/arxiv.2608.08168 openalex:W7202210108

Why this surfaced

  • Thinking vs. NoThinking: Towards Interpreting Reasoning Mechanisms of Large Language Models via Sparse Autoencoders matches Interpretable reasoning and J-space

    Matched reviewed English terms: sparse autoencoder.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Interpretable reasoning and J-space

    Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowreview state

    Distinguish preprint, peer-reviewed, and unknown review states.

    Evidence: preprint
  • unknownintegrity

    Surface correction, withdrawal, and retraction evidence without averaging it away.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed term that matched the named need.

    Evidence: sparse autoencoder
  • highfreshness

    Show source and update dates without treating recency as validity.

    Evidence: 2026-08-08
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Measuring Indirect Prompt Injection in Autonomous Web Agents

Sahir MaharajPublished: Observed:

doi:10.2139/ssrn.7276838

Why this surfaced

  • Measuring Indirect Prompt Injection in Autonomous Web Agents matches Secure information flow and agent security

    Matched reviewed English terms: indirect prompt injection, prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: crossref
  • lowreview state

    Security claims need visible review and replication status.

    Evidence: preprint
  • mediumrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:https://creativecommons.org/licenses/by/4.0/
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: indirect prompt injection · prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Balancing Security and Performance in LLM Agents: Spotlight-Guard, a Layered Defense Against Indirect Prompt Injection

Doygun Demirol, Murat AydoganPublished: Observed:

doi:10.3390/app16157662

Why this surfaced

  • Balancing Security and Performance in LLM Agents: Spotlight-Guard, a Layered Defense Against Indirect Prompt Injection matches Secure information flow and agent security

    Matched reviewed English terms: indirect prompt injection, prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: crossref
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • mediumrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:https://creativecommons.org/licenses/by/4.0/
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: indirect prompt injection · prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

DT-GenShield: A Digital Twin-Driven Runtime Security Architecture for Protecting Large Language Models Against Indirect Prompt Injection

Alaa Alnemari, Mashael M. AlsulamiPublished: Observed:

doi:10.3390/electronics15163640

Why this surfaced

  • DT-GenShield: A Digital Twin-Driven Runtime Security Architecture for Protecting Large Language Models Against Indirect Prompt Injection matches Secure information flow and agent security

    Matched reviewed English terms: indirect prompt injection, prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: crossref
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • mediumrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:https://creativecommons.org/licenses/by/4.0/
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: indirect prompt injection · prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks

Aaron Grattafiori, Arman Zharmagambetov, Chuan Guo, Ivan Evtimov, Kamalika ChaudhuriPublished: Observed:

doi:10.52202/085713-0666

Why this surfaced

  • WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks matches Secure information flow and agent security

    Matched reviewed English terms: agent security, prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: crossref
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • unknownrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: item-level licence absent
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: agent security · prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Secure MCP-Based Tool-Augmented RAG for Industrial IoT Diagnostics Under Indirect Prompt Injection, Retrieval Poisoning, and Modality Outages

Mustafa Erşahin, Pınar ErsoyPublished: Observed:

doi:10.1109/icecet65726.2026.11632629

Why this surfaced

  • Secure MCP-Based Tool-Augmented RAG for Industrial IoT Diagnostics Under Indirect Prompt Injection, Retrieval Poisoning, and Modality Outages matches Secure information flow and agent security

    Matched reviewed English terms: indirect prompt injection, prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: crossref
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • unknownrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: uninterpreted item licence:https://ieeexplore.ieee.org/Xplorehelp/downloads/license-information/IEEE.html
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: indirect prompt injection · prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Securing Federated Model Context Protocol (MCP) and Multi-Agent Supply Chains

Ashish VishwakarmaPublished: Observed:

doi:10.2139/ssrn.7184619

Why this surfaced

  • Securing Federated Model Context Protocol (MCP) and Multi-Agent Supply Chains matches Natural-language programming and agent interoperability

    Matched reviewed English terms: model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

No source change relation in this snapshot.

Evidence vector

  • highsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: crossref
  • unknownrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: uninterpreted item licence:https://www.uspto.gov/ip-policy/copyright-policy/copyright-basics

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: model context protocol
  • lowfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2026-01-01
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

A Toolset-First Paradigm Based on Large Language Model and Agent via Model Context Protocol for Intelligent Computation

Authorship not suppliedPublished: Observed:

doi:10.1021/acs.jpclett.6c02004.s001

Why this surfaced

  • A Toolset-First Paradigm Based on Large Language Model and Agent via Model Context Protocol for Intelligent Computation matches Natural-language programming and agent interoperability

    Matched reviewed English terms: model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

No source change relation in this snapshot.

Evidence vector

  • highsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: crossref
  • unknownrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: item-level licence absent

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: model context protocol
  • highfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2026-08-20
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Towards secure agentic workflows: a MAESTRO-based assessment framework for Model Context Protocol and Agent-to-Agent Protocol

Bhuvan Sai Teja GabbitaPublished: Observed:

doi:10.62791/20494

Why this surfaced

  • Towards secure agentic workflows: a MAESTRO-based assessment framework for Model Context Protocol and Agent-to-Agent Protocol matches Natural-language programming and agent interoperability

    Matched reviewed English terms: agent protocol, model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

No source change relation in this snapshot.

Evidence vector

  • highsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: crossref
  • unknownrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: uninterpreted item licence:http://creativecommons.org/licenses/by-nc-nd/4.0/

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: agent protocol · model context protocol
  • lowfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2025-11-12
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Application of Sparse Autoencoders to Enhance Mechanistic Interpretability of Large Language Models in Medicine.

Karabacak M, Margetis K., Metzger A, Patil S, Sugarmann LRPublished: Observed:

doi:10.2196/81134 pmid:42201744 pmcid:PMC13215048 source:europe-pmc:MED:42201744

Why this surfaced

  • Application of Sparse Autoencoders to Enhance Mechanistic Interpretability of Large Language Models in Medicine. matches Interpretable reasoning and J-space

    Matched reviewed English terms: mechanistic interpretability, sparse autoencoder.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Interpretable reasoning and J-space

    Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.

What changed

No source change relation in this snapshot.

Evidence vector

  • unknownreview state

    Distinguish preprint, peer-reviewed, and unknown review states.

    Evidence: unknown
  • unknownintegrity

    Surface correction, withdrawal, and retraction evidence without averaging it away.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed term that matched the named need.

    Evidence: mechanistic interpretability · sparse autoencoder
  • mediumfreshness

    Show source and update dates without treating recency as validity.

    Evidence: 2026-05-27
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Mechanistic interpretability of reinforcement learning in Medicaid care coordination.

Basu S, Batniji R., Elamaran N, Kinra A, Muralidharan B, Patel S, Sheth PPublished: Observed:

doi:10.1136/bmjhci-2025-101935 pmid:41667212 pmcid:PMC12911724 source:europe-pmc:MED:41667212

Why this surfaced

  • Mechanistic interpretability of reinforcement learning in Medicaid care coordination. matches Interpretable reasoning and J-space

    Matched reviewed English terms: mechanistic interpretability.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Interpretable reasoning and J-space

    Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.

What changed

No source change relation in this snapshot.

Evidence vector

  • unknownreview state

    Distinguish preprint, peer-reviewed, and unknown review states.

    Evidence: unknown
  • unknownintegrity

    Surface correction, withdrawal, and retraction evidence without averaging it away.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed term that matched the named need.

    Evidence: mechanistic interpretability
  • lowfreshness

    Show source and update dates without treating recency as validity.

    Evidence: 2026-02-10
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Mechanistic Interpretability-Guided Selective Fine-Tuning of Vision-Language Models for Centimeter-Level Flood Depth Estimation

Dongxiao Zhu, Nafis Fuad, Xiaodong QianPublished: Observed:

arxiv:2608.07562

Why this surfaced

  • Mechanistic Interpretability-Guided Selective Fine-Tuning of Vision-Language Models for Centimeter-Level Flood Depth Estimation matches Interpretable reasoning and J-space

    Matched reviewed English terms: mechanistic interpretability.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Interpretable reasoning and J-space

    Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowreview state

    Distinguish preprint, peer-reviewed, and unknown review states.

    Evidence: preprint
  • unknownintegrity

    Surface correction, withdrawal, and retraction evidence without averaging it away.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed term that matched the named need.

    Evidence: mechanistic interpretability
  • highfreshness

    Show source and update dates without treating recency as validity.

    Evidence: 2026-08-02
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem

Dilip Thakur, Saroj Mishra, Shiva Gaire, Srijan Gyawali, Suman Niroula, Umesh YadavPublished: Observed:

doi:10.1007/978-3-032-32726-0_29 openalex:W7114797566

Why this surfaced

  • Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem matches Natural-language programming and agent interoperability

    Matched reviewed English terms: model context protocol.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Natural-language programming and agent interoperability

    Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowsource authority

    Registry metadata and graph-derived relations carry different evidentiary weight.

    Evidence: openalex
  • unknownrights clarity

    A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: item-level licence absent

Priority vector

  • highnamed need fit

    Expose which protocol or language-interface phrase matched.

    Evidence: model context protocol
  • highfreshness

    Protocol work changes quickly, so dates matter without becoming a quality score.

    Evidence: 2026-08-13
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Prompt injection attacks on vision-language models for surgical decision support.

Carstens M, Clusmann J, Kather JN, Kolbinger FR., Loiselle MS, Martinus FM, Mroczkowski MK, Qadir MI, Zhang EH, Zhang ZPublished: Observed:

doi:10.1038/s44484-026-00014-6 pmid:42523678 source:europe-pmc:MED:42523678

Why this surfaced

  • Prompt injection attacks on vision-language models for surgical decision support. matches Secure information flow and agent security

    Matched reviewed English terms: prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: europe-pmc
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • unknownrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: item-level licence absent
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Labelled-Metadata Channels and Declarative Payload Phrasing in Hidden Prompt Injection: A Cross-Format Measurement Study

Rashidi M.Published: Observed:

doi:10.21203/rs.3.rs-10646218/v1 source:europe-pmc:PPR:PPR1296126

Why this surfaced

  • Labelled-Metadata Channels and Declarative Payload Phrasing in Hidden Prompt Injection: A Cross-Format Measurement Study matches Secure information flow and agent security

    Matched reviewed English terms: prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: europe-pmc
  • lowreview state

    Security claims need visible review and replication status.

    Evidence: preprint
  • unknownrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: item-level licence absent
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Prompt injection compromises large language model-based peer review: evidence from randomised controlled trial abstracts from anaesthesia journals.

Boscolo A, De Cassai A, Dost B, Navalesi P., Pistollato E, Zarantonello FPublished: Observed:

doi:10.1016/j.bja.2026.06.041 pmid:42580931 source:europe-pmc:MED:42580931

Why this surfaced

  • Prompt injection compromises large language model-based peer review: evidence from randomised controlled trial abstracts from anaesthesia journals. matches Secure information flow and agent security

    Matched reviewed English terms: prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: europe-pmc
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • unknownrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: item-level licence absent
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

Amisha Bagari, Hayretdin Bahsi, Neha NagarajaPublished: Observed:

arxiv:2608.00747

Why this surfaced

  • When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems matches Secure information flow and agent security

    Matched reviewed English terms: prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • mediumsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: arxiv
  • lowreview state

    Security claims need visible review and replication status.

    Evidence: preprint
  • unknownrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: item-level licence absent
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Role-Styled Prompt Injection: An Activation and KV-State Probe in a Compact Language Model

Taureka, WellingtonPublished: Observed:

doi:10.5281/zenodo.21757178

Why this surfaced

  • Role-Styled Prompt Injection: An Activation and KV-State Probe in a Compact Language Model matches Secure information flow and agent security

    Matched reviewed English terms: prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

2 factual source-change assertions also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

  • Explicit is-supplement-to relation to 10.5281/zenodo.21739163

    The source relation creates an edge; it does not silently merge the records.

  • Explicit is-version-of relation to 10.5281/zenodo.21757178

    The source relation creates an edge; it does not silently merge the records.

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: datacite
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • mediumrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:cc-by-4.0
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty

Cidade, Irlan de AlvarengaPublished: Observed:

doi:10.5281/zenodo.21731493

Why this surfaced

  • The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty matches Secure information flow and agent security

    Matched reviewed English terms: agent security.

    The match orders attention only; it is not evaluation, adoption, or use authority.

2 factual source-change assertions also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

  • Explicit is-version-of relation to 10.5281/zenodo.21731493

    The source relation creates an edge; it does not silently merge the records.

    2 source assertions represented

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: datacite
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • mediumrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:cc-by-4.0
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: agent security
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Measuring Indirect Prompt Injection in Autonomous Web Agents

Sahir MaharajPublished: Observed:

doi:10.5281/zenodo.21855133 openalex:W7201980560

Why this surfaced

  • Measuring Indirect Prompt Injection in Autonomous Web Agents matches Secure information flow and agent security

    Matched reviewed English terms: indirect prompt injection, prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: openalex
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • mediumrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:cc-by
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: indirect prompt injection · prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty

Cidade, Irlan de AlvarengaPublished: Observed:

doi:10.5281/zenodo.21731494

Why this surfaced

  • The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty matches Secure information flow and agent security

    Matched reviewed English terms: agent security.

    The match orders attention only; it is not evaluation, adoption, or use authority.

1 factual source-change assertion also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

  • Explicit is-version-of relation to 10.5281/zenodo.21731493

    The source relation creates an edge; it does not silently merge the records.

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: datacite
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • mediumrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:cc-by-4.0
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: agent security
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection

Pulastya, PrateekPublished: Observed:

doi:10.5281/zenodo.21746423

Why this surfaced

  • Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection matches Secure information flow and agent security

    Matched reviewed English terms: prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

3 factual source-change assertions also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

  • Explicit is-version-of relation to 10.5281/zenodo.21746423

    The source relation creates an edge; it does not silently merge the records.

    2 source assertions represented
  • Explicit is-supplemented-by relation to datacite:https://github.com/Prateek-Pulastya/Guardrail-As-A-Service-V2

    The source relation creates an edge; it does not silently merge the records.

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: datacite
  • lowreview state

    Security claims need visible review and replication status.

    Evidence: preprint
  • mediumrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:cc-by-4.0
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection

Pulastya, PrateekPublished: Observed:

doi:10.5281/zenodo.21746424

Why this surfaced

  • Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection matches Secure information flow and agent security

    Matched reviewed English terms: prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

2 factual source-change assertions also surfaced this work; the source text appears under What changed.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

  • Explicit is-version-of relation to 10.5281/zenodo.21746423

    The source relation creates an edge; it does not silently merge the records.

  • Explicit is-supplemented-by relation to datacite:https://github.com/Prateek-Pulastya/Guardrail-As-A-Service-V2

    The source relation creates an edge; it does not silently merge the records.

Evidence vector

  • highsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: datacite
  • lowreview state

    Security claims need visible review and replication status.

    Evidence: preprint
  • mediumrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: reported item licence:cc-by-4.0
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

Prompt Injection Attacks on LLM Generated Reviews of Scientific Publications

Janis KeuperPublished: Observed:

doi:10.1007/978-3-032-31335-5_9 openalex:W4415090291

Why this surfaced

  • Prompt Injection Attacks on LLM Generated Reviews of Scientific Publications matches Secure information flow and agent security

    Matched reviewed English terms: prompt injection.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Secure information flow and agent security

    Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowsource authority

    Keep canonical registry evidence separate from aggregator enrichment.

    Evidence: openalex
  • unknownreview state

    Security claims need visible review and replication status.

    Evidence: unknown
  • unknownrights clarity

    A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object.

    Evidence: item-level licence absent
  • unknownintegrity

    Corrections or withdrawals can change the safe interpretation of a result.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed security term that matched.

    Evidence: prompt injection
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

publication · active Observed — not evaluated

The Non-Linear Representation Dilemma: Is Causal Abstraction Enough for Mechanistic Interpretability?

Denis Sutter, Julian Minder, Thomas Hofmann, Tiago PimentelPublished: Observed:

doi:10.52202/085713-5000

Why this surfaced

  • The Non-Linear Representation Dilemma: Is Causal Abstraction Enough for Mechanistic Interpretability? matches Interpretable reasoning and J-space

    Matched reviewed English terms: mechanistic interpretability.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Interpretable reasoning and J-space

    Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.

What changed

No source change relation in this snapshot.

Evidence vector

  • unknownreview state

    Distinguish preprint, peer-reviewed, and unknown review states.

    Evidence: unknown
  • unknownintegrity

    Surface correction, withdrawal, and retraction evidence without averaging it away.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed term that matched the named need.

    Evidence: mechanistic interpretability
  • lowfreshness

    Show source and update dates without treating recency as validity.

    Evidence: 2025-01-01
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

preprint · active Observed — not evaluated

Causal Intervention Framework for Variational Auto Encoder Mechanistic Interpretability

Dip RoyPublished: Observed:

doi:10.21203/rs.3.rs-6599791/v1

Why this surfaced

  • Causal Intervention Framework for Variational Auto Encoder Mechanistic Interpretability matches Interpretable reasoning and J-space

    Matched reviewed English terms: mechanistic interpretability.

    The match orders attention only; it is not evaluation, adoption, or use authority.

Possible KINGDOM fit

  • Interpretable reasoning and J-space

    Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.

What changed

No source change relation in this snapshot.

Evidence vector

  • lowreview state

    Distinguish preprint, peer-reviewed, and unknown review states.

    Evidence: preprint
  • unknownintegrity

    Surface correction, withdrawal, and retraction evidence without averaging it away.

    Evidence: active

Priority vector

  • highnamed need fit

    Expose the exact reviewed term that matched the named need.

    Evidence: mechanistic interpretability
  • lowfreshness

    Show source and update dates without treating recency as validity.

    Evidence: 2025-05-07
Discovery observedEvaluation not performedAdoption not recordedUse not authorized

Coverage and source boundaries

9 source contracts is not a poll or coverage count. Each card states whether its reviewed access lane is enabled or held. Even “live poll enabled” does not prove a successful poll or complete record coverage in this snapshot.

core · preprint-repository

arXiv

Access lane: live poll enabled

Global submissions with strongest coverage in physics, mathematics, computer science, and adjacent fields.

Observed:
Expected lag: Best-effort new-submission discovery only. Offset cursors over a changing result set are not a complete or stable update/deletion feed; consumers must overlap and restart rather than claim lossless sync.

Metadata rights claim: Descriptive API metadata is offered as CC0; item content remains under its submitted licence or copyright.

core · preprint-repository

bioRxiv and medRxiv

Access lane: fixture-only / policy hold

Global submissions in biology, health sciences, and medicine.

Observed:
Expected lag: Published-journal links can appear after publication and should be treated as later observations.

Metadata rights claim: Metadata API access is public; each manuscript has an author-selected content licence.

core · trial-registry

ClinicalTrials.gov

Access lane: fixture-only / policy hold

International study registrations submitted to the United States registry.

Observed:
Expected lag: Registry processing and sponsor updates can lag real-world study events.

Metadata rights claim: Registry data is publicly available with required attribution/currentness practices and third-party caveats.

core · pid-registry

Crossref

Access lane: live poll enabled

Global member-deposited scholarly metadata.

Observed:
Expected lag: Deposits and later corrections arrive on publisher schedules; polling must overlap and deduplicate.

Metadata rights claim: Most bibliographic fields are factual and openly retrievable; abstracts and some deposited fields may remain copyrighted.

integrity · integrity-feed

Crossref updates and Retraction Watch

Access lane: live poll enabled

Global Crossref update relations plus Retraction Watch records distributed through Crossref.

Observed:
Expected lag: Notices can lag the underlying event and coverage is not complete.

Metadata rights claim: The Retraction Watch database distributed by Crossref is CC0; Crossref requests citation when it is used in published work.

core · pid-registry

DataCite

Access lane: live poll enabled

Global repository-deposited research objects.

Observed:
Expected lag: Created-record discovery can miss later metadata updates; updates depend on repository deposits and their metadata practices.

Metadata rights claim: DataCite DOI metadata is released under CC0.

enrichment · domain-index

Europe PMC

Access lane: live poll enabled

Global life-science literature, preprints, grants, citations, data links, and text-mined annotations.

Observed:
Expected lag: Aggregation, citation, text-mining, and publication-link updates can trail primary registries.

Metadata rights claim: EMBL-EBI imposes no additional restriction on supplied data beyond rights held by original data owners; public queryability is not itself a reuse grant.

enrichment · research-graph

OpenAlex

Access lane: live poll enabled

Broad global graph spanning works, authors, institutions, sources, topics, publishers, and funders.

Observed:
Expected lag: The MVP uses free from_publication_date discovery, not paid update synchronization; later metadata changes can therefore be missed unless another source reports them.

Metadata rights claim: OpenAlex metadata is released under CC0.

core · domain-index

PubMed and PubMed Central

Access lane: fixture-only / policy hold

Global biomedical and life-science citations; PMC adds an archive of participating full-text works.

Observed:
Expected lag: Publisher deposits, MeSH indexing, and linked corrections may arrive after first citation publication.

Metadata rights claim: NLM database records are downloadable under NLM terms; source-supplied material can retain separate rights.

What did not happen

Inspect the complete snapshot, its closed schema, and the human protocol.