{
  "asOf": "2026-08-20T18:10:14Z",
  "boundaries": {
    "adoptionRecorded": false,
    "artifactExecution": false,
    "buildNetworkUsed": false,
    "captureProvenance": "imported-live-captures",
    "evaluationPerformed": false,
    "fullTextIncluded": false,
    "guestAdmitted": false,
    "liveHarvestNetworkObserved": true,
    "moduleCreated": false,
    "useAuthorized": false
  },
  "generatedFrom": {
    "captureProjection": {
      "availableObservations": 36,
      "policy": "latest-and-latest-nonempty-per-lane-plus-30-day-integrity-v0.1",
      "projectionReceipt": "sha256:bb254dc70f58e162da4f77904bbc910394394ba3beb791f7f41a04b18c70befe",
      "publishedObservations": 36,
      "retainedCaptureFiles": 16,
      "selectedCaptureFiles": 16,
      "truncatedObservations": 0
    },
    "captureSetReceipt": "sha256:68a69dc390aa34133cadc8807ed33ddd1fae72e7e99706cf714d72698d071f7f",
    "fixtureSetReceipt": null,
    "pipelineVersion": "0.1.0",
    "sourceManifestReceipt": "sha256:4944c8de28f40c4a7d769c964bb5ff0fdddbd845d214a2a97e3d1014bc7d0dfe",
    "watchlistManifestReceipt": "sha256:fa9cbff182d6e1df38938b51161e2638b1383d281ca0fa9d5bfb718830332b2e"
  },
  "metadataOnly": true,
  "mode": "captured-live-observatory",
  "observations": [
    {
      "authors": [
        {
          "name": "Neha Nagaraja",
          "orcid": null
        },
        {
          "name": "Amisha Bagari",
          "orcid": null
        },
        {
          "name": "Hayretdin Bahsi",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://arxiv.org/abs/2608.00747",
      "id": "observation:arxiv:28c2c5fcfeca666e",
      "identifiers": [
        {
          "scheme": "arxiv",
          "value": "2608.00747"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": "en",
      "observedAt": "2026-08-20T18:07:21Z",
      "payloadBytes": 13536,
      "payloadReceipt": "sha256:aca634242cab8069907af4a1c5c77d06eb2b86354a44d976663d385d604709cd",
      "publishedOn": "2026-08-01",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "arxiv",
      "sourceRecordId": "2608.00747",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "cs.AI",
        "cs.CR",
        "cs.MA",
        "cs.RO"
      ],
      "synthetic": false,
      "title": "When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems",
      "upstreamCreatedAt": "2026-08-01T16:31:00Z",
      "upstreamUpdatedAt": "2026-08-04T16:20:03Z",
      "version": "v2"
    },
    {
      "authors": [
        {
          "name": "Nafis Fuad",
          "orcid": null
        },
        {
          "name": "Xiaodong Qian",
          "orcid": null
        },
        {
          "name": "Dongxiao Zhu",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://arxiv.org/abs/2608.07562",
      "id": "observation:arxiv:bb59396c7fe27bb3",
      "identifiers": [
        {
          "scheme": "arxiv",
          "value": "2608.07562"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": "en",
      "observedAt": "2026-08-20T18:07:49Z",
      "payloadBytes": 13737,
      "payloadReceipt": "sha256:11415b7c6b2e81f3092c10402772a78b7eceeca1064c817ed3c8992bce35328a",
      "publishedOn": "2026-08-02",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "arxiv",
      "sourceRecordId": "2608.07562",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "cs.CV",
        "cs.LG"
      ],
      "synthetic": false,
      "title": "Mechanistic Interpretability-Guided Selective Fine-Tuning of Vision-Language Models for Centimeter-Level Flood Depth Estimation",
      "upstreamCreatedAt": "2026-08-02T22:38:25Z",
      "upstreamUpdatedAt": "2026-08-02T22:38:25Z",
      "version": "v1"
    },
    {
      "authors": [
        {
          "name": "Gautam Bharti",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://arxiv.org/abs/2608.00997",
      "id": "observation:arxiv:e6f88ec1494225ed",
      "identifiers": [
        {
          "scheme": "arxiv",
          "value": "2608.00997"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": "en",
      "observedAt": "2026-08-20T18:10:14Z",
      "payloadBytes": 15034,
      "payloadReceipt": "sha256:2ee0413c8600110b459d631b27cb368754f5e44af15334c449ec8a839887849f",
      "publishedOn": "2026-08-02",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "arxiv",
      "sourceRecordId": "2608.00997",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "cs.CR",
        "cs.SE"
      ],
      "synthetic": false,
      "title": "Registry Descriptions Go Stale Unevenly: An 89-Day Measurement of Model Context Protocol Drift, and Why Drift-Ranked Re-Auditing Under-Covers It",
      "upstreamCreatedAt": "2026-08-02T04:54:06Z",
      "upstreamUpdatedAt": "2026-08-04T23:19:10Z",
      "version": "v2"
    },
    {
      "authors": [
        {
          "name": "Alaa Alnemari",
          "orcid": null
        },
        {
          "name": "Mashael M. Alsulami",
          "orcid": "https://orcid.org/0000-0003-2298-8278"
        }
      ],
      "canonicalUrl": "https://doi.org/10.3390/electronics15163640",
      "id": "observation:crossref:2388068f3e413d55",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.3390/electronics15163640"
        }
      ],
      "inert": true,
      "itemLicense": "https://creativecommons.org/licenses/by/4.0/",
      "language": null,
      "observedAt": "2026-08-20T18:09:16Z",
      "payloadBytes": 8038,
      "payloadReceipt": "sha256:0f7f1055ed2943d2ef0e04bbd76df988e76fd528b97524d18e51de403f8f9292",
      "publishedOn": "2026-08-15",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.3390/electronics15163640",
      "sourceStatus": "journal-article",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "DT-GenShield: A Digital Twin-Driven Runtime Security Architecture for Protecting Large Language Models Against Indirect Prompt Injection",
      "upstreamCreatedAt": "2026-08-17T11:00:05Z",
      "upstreamUpdatedAt": "2026-08-17T12:25:08Z",
      "version": "journal-article"
    },
    {
      "authors": [
        {
          "name": "Denis Sutter",
          "orcid": null
        },
        {
          "name": "Julian Minder",
          "orcid": null
        },
        {
          "name": "Thomas Hofmann",
          "orcid": null
        },
        {
          "name": "Tiago Pimentel",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.52202/085713-5000",
      "id": "observation:crossref:3c987dfc1571681f",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.52202/085713-5000"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": null,
      "observedAt": "2026-08-20T18:06:56Z",
      "payloadBytes": 8333,
      "payloadReceipt": "sha256:b265b9235163d22837fedcd7237669160bc7f02b5709546b1f7812840611a7cb",
      "publishedOn": "2025-01-01",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.52202/085713-5000",
      "sourceStatus": "proceedings-article",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "The Non-Linear Representation Dilemma: Is Causal Abstraction Enough for Mechanistic Interpretability?",
      "upstreamCreatedAt": "2026-08-06T14:44:29Z",
      "upstreamUpdatedAt": "2026-08-06T17:12:23Z",
      "version": "proceedings-article"
    },
    {
      "authors": [
        {
          "name": "Doygun Demirol",
          "orcid": "https://orcid.org/0000-0002-3272-1078"
        },
        {
          "name": "Murat Aydogan",
          "orcid": "https://orcid.org/0000-0002-6876-6454"
        }
      ],
      "canonicalUrl": "https://doi.org/10.3390/app16157662",
      "id": "observation:crossref:6febc941c6477298",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.3390/app16157662"
        }
      ],
      "inert": true,
      "itemLicense": "https://creativecommons.org/licenses/by/4.0/",
      "language": null,
      "observedAt": "2026-08-20T18:09:16Z",
      "payloadBytes": 8038,
      "payloadReceipt": "sha256:0f7f1055ed2943d2ef0e04bbd76df988e76fd528b97524d18e51de403f8f9292",
      "publishedOn": "2026-08-02",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.3390/app16157662",
      "sourceStatus": "journal-article",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "Balancing Security and Performance in LLM Agents: Spotlight-Guard, a Layered Defense Against Indirect Prompt Injection",
      "upstreamCreatedAt": "2026-08-03T14:16:27Z",
      "upstreamUpdatedAt": "2026-08-03T15:18:28Z",
      "version": "journal-article"
    },
    {
      "authors": [
        {
          "name": "Pınar Ersoy",
          "orcid": null
        },
        {
          "name": "Mustafa Erşahin",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.1109/icecet65726.2026.11632629",
      "id": "observation:crossref:792b9edd45cc7292",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1109/icecet65726.2026.11632629"
        }
      ],
      "inert": true,
      "itemLicense": "https://ieeexplore.ieee.org/Xplorehelp/downloads/license-information/IEEE.html",
      "language": null,
      "observedAt": "2026-08-20T18:09:16Z",
      "payloadBytes": 8038,
      "payloadReceipt": "sha256:0f7f1055ed2943d2ef0e04bbd76df988e76fd528b97524d18e51de403f8f9292",
      "publishedOn": "2026-07-01",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.1109/icecet65726.2026.11632629",
      "sourceStatus": "proceedings-article",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "Secure MCP-Based Tool-Augmented RAG for Industrial IoT Diagnostics Under Indirect Prompt Injection, Retrieval Poisoning, and Modality Outages",
      "upstreamCreatedAt": "2026-08-12T19:13:33Z",
      "upstreamUpdatedAt": "2026-08-13T06:28:09Z",
      "version": "proceedings-article"
    },
    {
      "authors": [
        {
          "name": "Dip Roy",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.21203/rs.3.rs-6599791/v1",
      "id": "observation:crossref:9d9767af45efe7de",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.21203/rs.3.rs-6599791/v1"
        }
      ],
      "inert": true,
      "itemLicense": "https://creativecommons.org/licenses/by/4.0/",
      "language": null,
      "observedAt": "2026-08-20T18:06:56Z",
      "payloadBytes": 8333,
      "payloadReceipt": "sha256:b265b9235163d22837fedcd7237669160bc7f02b5709546b1f7812840611a7cb",
      "publishedOn": "2025-05-07",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.21203/rs.3.rs-6599791/v1",
      "sourceStatus": "posted-content",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "Causal Intervention Framework for Variational Auto Encoder Mechanistic Interpretability",
      "upstreamCreatedAt": "2025-05-07T10:29:27Z",
      "upstreamUpdatedAt": "2026-08-01T17:00:56Z",
      "version": "posted-content"
    },
    {
      "authors": [
        {
          "name": "Ivan Evtimov",
          "orcid": null
        },
        {
          "name": "Arman Zharmagambetov",
          "orcid": null
        },
        {
          "name": "Aaron Grattafiori",
          "orcid": null
        },
        {
          "name": "Chuan Guo",
          "orcid": null
        },
        {
          "name": "Kamalika Chaudhuri",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.52202/085713-0666",
      "id": "observation:crossref:ab21ffe4074b8d82",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.52202/085713-0666"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": null,
      "observedAt": "2026-08-20T18:09:16Z",
      "payloadBytes": 8038,
      "payloadReceipt": "sha256:0f7f1055ed2943d2ef0e04bbd76df988e76fd528b97524d18e51de403f8f9292",
      "publishedOn": "2025-01-01",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.52202/085713-0666",
      "sourceStatus": "proceedings-article",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks",
      "upstreamCreatedAt": "2026-08-06T14:44:29Z",
      "upstreamUpdatedAt": "2026-08-06T16:47:15Z",
      "version": "proceedings-article"
    },
    {
      "authors": [],
      "canonicalUrl": "https://doi.org/10.1021/acs.jpclett.6c02004.s001",
      "id": "observation:crossref:d67a1b4ed7547770",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1021/acs.jpclett.6c02004.s001"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": null,
      "observedAt": "2026-08-20T18:09:14Z",
      "payloadBytes": 5268,
      "payloadReceipt": "sha256:25ea32ccc1ff0248af53cb4a4e7eb7855f8dc2815dbcc8103a6dbca689d3f027",
      "publishedOn": "2026-08-20",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.1021/acs.jpclett.6c02004.s001",
      "sourceStatus": "component",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "A Toolset-First Paradigm Based on Large Language Model and Agent via Model Context Protocol for Intelligent Computation",
      "upstreamCreatedAt": "2026-08-20T12:35:42Z",
      "upstreamUpdatedAt": "2026-08-20T13:25:42Z",
      "version": "component"
    },
    {
      "authors": [
        {
          "name": "Ashish Vishwakarma",
          "orcid": "https://orcid.org/0009-0001-6860-7357"
        }
      ],
      "canonicalUrl": "https://doi.org/10.2139/ssrn.7184619",
      "id": "observation:crossref:d6920254ad639948",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.2139/ssrn.7184619"
        }
      ],
      "inert": true,
      "itemLicense": "https://www.uspto.gov/ip-policy/copyright-policy/copyright-basics",
      "language": null,
      "observedAt": "2026-08-20T18:09:14Z",
      "payloadBytes": 5268,
      "payloadReceipt": "sha256:25ea32ccc1ff0248af53cb4a4e7eb7855f8dc2815dbcc8103a6dbca689d3f027",
      "publishedOn": "2026-01-01",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.2139/ssrn.7184619",
      "sourceStatus": "posted-content",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "Securing Federated Model Context Protocol (MCP) and Multi-Agent Supply Chains",
      "upstreamCreatedAt": "2026-08-06T04:20:34Z",
      "upstreamUpdatedAt": "2026-08-06T04:47:30Z",
      "version": "posted-content"
    },
    {
      "authors": [
        {
          "name": "Sahir Maharaj",
          "orcid": "https://orcid.org/0009-0008-7878-0138"
        }
      ],
      "canonicalUrl": "https://doi.org/10.2139/ssrn.7276838",
      "id": "observation:crossref:d6ca8526a1b03056",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.2139/ssrn.7276838"
        }
      ],
      "inert": true,
      "itemLicense": "https://creativecommons.org/licenses/by/4.0/",
      "language": null,
      "observedAt": "2026-08-20T18:09:16Z",
      "payloadBytes": 8038,
      "payloadReceipt": "sha256:0f7f1055ed2943d2ef0e04bbd76df988e76fd528b97524d18e51de403f8f9292",
      "publishedOn": "2026-01-01",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.2139/ssrn.7276838",
      "sourceStatus": "posted-content",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "Measuring Indirect Prompt Injection in Autonomous Web Agents",
      "upstreamCreatedAt": "2026-08-17T04:16:26Z",
      "upstreamUpdatedAt": "2026-08-17T04:26:11Z",
      "version": "posted-content"
    },
    {
      "authors": [
        {
          "name": "Bhuvan Sai Teja Gabbita",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.62791/20494",
      "id": "observation:crossref:ecced040bec1000c",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.62791/20494"
        }
      ],
      "inert": true,
      "itemLicense": "http://creativecommons.org/licenses/by-nc-nd/4.0/",
      "language": null,
      "observedAt": "2026-08-20T18:09:14Z",
      "payloadBytes": 5268,
      "payloadReceipt": "sha256:25ea32ccc1ff0248af53cb4a4e7eb7855f8dc2815dbcc8103a6dbca689d3f027",
      "publishedOn": "2025-11-12",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "crossref",
      "sourceRecordId": "10.62791/20494",
      "sourceStatus": "dissertation",
      "status": "active",
      "subjects": [],
      "synthetic": false,
      "title": "Towards secure agentic workflows: a MAESTRO-based assessment framework for Model Context Protocol and Agent-to-Agent Protocol",
      "upstreamCreatedAt": "2025-11-12T21:28:26Z",
      "upstreamUpdatedAt": "2026-08-18T05:59:20Z",
      "version": "dissertation"
    },
    {
      "authors": [
        {
          "name": "Pulastya, Prateek",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21746424",
      "id": "observation:datacite:00f0afac1c7665c2",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21746424"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by-4.0",
      "language": "en",
      "observedAt": "2026-08-20T18:07:20Z",
      "payloadBytes": 19032,
      "payloadReceipt": "sha256:c4aa57a024ce29f52fb92ef62fb1f74687553b6ef91b8591639693f6d171f061",
      "publishedOn": "2026-08-01",
      "recordType": "preprint",
      "relations": [
        {
          "assertedAt": "2026-08-01T20:21:58Z",
          "identifier": {
            "scheme": "source",
            "value": "datacite:https://github.com/Prateek-Pulastya/Guardrail-As-A-Service-V2"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplemented-by"
        },
        {
          "assertedAt": "2026-08-01T20:21:58Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21746423"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21746424",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "Aho-Corasick",
        "DeBERTa",
        "Evaluation Technology",
        "Guardrails",
        "LLM Security",
        "Over-defense",
        "Trust boundaries",
        "prompt injection"
      ],
      "synthetic": false,
      "title": "Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection",
      "upstreamCreatedAt": "2026-08-01T20:21:58Z",
      "upstreamUpdatedAt": "2026-08-01T20:21:58Z",
      "version": "1.0.0"
    },
    {
      "authors": [
        {
          "name": "Cidade, Irlan de Alvarenga",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21731494",
      "id": "observation:datacite:0716c674df8147ca",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731494"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by-4.0",
      "language": "en",
      "observedAt": "2026-08-20T18:07:20Z",
      "payloadBytes": 19032,
      "payloadReceipt": "sha256:c4aa57a024ce29f52fb92ef62fb1f74687553b6ef91b8591639693f6d171f061",
      "publishedOn": "2026-08-01",
      "recordType": "publication",
      "relations": [
        {
          "assertedAt": "2026-08-01T03:05:44Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21731493"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21731494",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "Knowledge Augmented Generation",
        "agentic security",
        "bounded autonomy",
        "bug bounty",
        "evidence-grounded assessments",
        "multi-agent systems",
        "security quality assurance"
      ],
      "synthetic": false,
      "title": "The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty",
      "upstreamCreatedAt": "2026-08-01T03:05:43Z",
      "upstreamUpdatedAt": "2026-08-01T03:05:44Z",
      "version": "1.0"
    },
    {
      "authors": [
        {
          "name": "Flynn, David C.",
          "orcid": "https://orcid.org/0000-0002-2768-6650"
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21731418",
      "id": "observation:datacite:1916afceb5a82955",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731418"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by-4.0",
      "language": null,
      "observedAt": "2026-08-20T18:09:58Z",
      "payloadBytes": 19000,
      "payloadReceipt": "sha256:8073fb244311355bd71e6becb29d38ae72bce726c186ffb315c586e6ae74bba5",
      "publishedOn": "2026-08-01",
      "recordType": "preprint",
      "relations": [
        {
          "assertedAt": "2026-08-01T03:05:08Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21731417"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21731418",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "30B Semantic Risk Evaluator",
        "Compositional Tool‑Use Threats",
        "Intent Tree",
        "Model Context Protocol",
        "Semantic Zero‑Trust",
        "Signed Intent Manifest",
        "Trusted Context Assembly"
      ],
      "synthetic": false,
      "title": "Semantic Zero-Trust for Model Context Protocol",
      "upstreamCreatedAt": "2026-08-01T03:05:08Z",
      "upstreamUpdatedAt": "2026-08-01T03:05:08Z",
      "version": "V1"
    },
    {
      "authors": [
        {
          "name": "Taureka, Wellington",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21757178",
      "id": "observation:datacite:6119662c70f05464",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21757178"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by-4.0",
      "language": "en",
      "observedAt": "2026-08-20T18:07:20Z",
      "payloadBytes": 19032,
      "payloadReceipt": "sha256:c4aa57a024ce29f52fb92ef62fb1f74687553b6ef91b8591639693f6d171f061",
      "publishedOn": "2026-08-02",
      "recordType": "publication",
      "relations": [
        {
          "assertedAt": "2026-08-02T09:19:48Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21739163"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplement-to"
        },
        {
          "assertedAt": "2026-08-02T09:19:48Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21757178"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21757178",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "KV cache",
        "PSCS",
        "Pakheta relational conduction",
        "activation probe",
        "prompt injection",
        "role confusion",
        "semantic security",
        "source isolation"
      ],
      "synthetic": false,
      "title": "Role-Styled Prompt Injection: An Activation and KV-State Probe in a Compact Language Model",
      "upstreamCreatedAt": "2026-08-02T09:19:47Z",
      "upstreamUpdatedAt": "2026-08-02T09:19:48Z",
      "version": "1.0"
    },
    {
      "authors": [
        {
          "name": "Arnold, Jaret",
          "orcid": "https://orcid.org/0009-0003-4055-5238"
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21736124",
      "id": "observation:datacite:67eab70b87c630d0",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21736124"
        }
      ],
      "inert": true,
      "itemLicense": "mit",
      "language": null,
      "observedAt": "2026-08-20T18:09:58Z",
      "payloadBytes": 19000,
      "payloadReceipt": "sha256:8073fb244311355bd71e6becb29d38ae72bce726c186ffb315c586e6ae74bba5",
      "publishedOn": "2026-08-01",
      "recordType": "software",
      "relations": [
        {
          "assertedAt": "2026-08-01T07:11:35Z",
          "identifier": {
            "scheme": "source",
            "value": "datacite:https://github.com/musharna/ldraw-mcp"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplement-to"
        },
        {
          "assertedAt": "2026-08-01T07:11:35Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21713452"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "software",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21736124",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "3d-rendering",
        "blender",
        "ldraw",
        "lego",
        "mcp",
        "model-context-protocol"
      ],
      "synthetic": false,
      "title": "ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol",
      "upstreamCreatedAt": "2026-08-01T07:11:35Z",
      "upstreamUpdatedAt": "2026-08-01T07:11:35Z",
      "version": "v0.2.2"
    },
    {
      "authors": [
        {
          "name": "Bothraj P",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21740544",
      "id": "observation:datacite:6e71c79f4f0f367c",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21740544"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by-4.0",
      "language": null,
      "observedAt": "2026-08-20T18:09:58Z",
      "payloadBytes": 19000,
      "payloadReceipt": "sha256:8073fb244311355bd71e6becb29d38ae72bce726c186ffb315c586e6ae74bba5",
      "publishedOn": "2026-08-01",
      "recordType": "preprint",
      "relations": [
        {
          "assertedAt": "2026-08-01T14:22:02Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21740544"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21740544",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "AI Agents",
        "Agentci AI",
        "Artificial Intelligence",
        "Large Language Models",
        "Model Context Protocol",
        "Natural Language to SQL",
        "Retrieval-Augmented Generation"
      ],
      "synthetic": false,
      "title": "Enterprise Agentic AI: A Reference Architecture for Natural Language to SQL, Model Context Protocol (MCP), Retrieval-Augmented Generation (RAG), Multi-Agent Systems, and Production AI",
      "upstreamCreatedAt": "2026-08-01T14:22:02Z",
      "upstreamUpdatedAt": "2026-08-01T14:22:02Z",
      "version": "v1.0"
    },
    {
      "authors": [
        {
          "name": "Pulastya, Prateek",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21746423",
      "id": "observation:datacite:6ec8c4115f9af5e7",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21746423"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by-4.0",
      "language": "en",
      "observedAt": "2026-08-20T18:07:20Z",
      "payloadBytes": 19032,
      "payloadReceipt": "sha256:c4aa57a024ce29f52fb92ef62fb1f74687553b6ef91b8591639693f6d171f061",
      "publishedOn": "2026-08-01",
      "recordType": "preprint",
      "relations": [
        {
          "assertedAt": "2026-08-01T20:21:59Z",
          "identifier": {
            "scheme": "source",
            "value": "datacite:https://github.com/Prateek-Pulastya/Guardrail-As-A-Service-V2"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplemented-by"
        },
        {
          "assertedAt": "2026-08-01T20:21:59Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21746423"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21746423",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "Aho-Corasick",
        "DeBERTa",
        "Evaluation Technology",
        "Guardrails",
        "LLM Security",
        "Over-defense",
        "Trust boundaries",
        "prompt injection"
      ],
      "synthetic": false,
      "title": "Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection",
      "upstreamCreatedAt": "2026-08-01T20:21:59Z",
      "upstreamUpdatedAt": "2026-08-01T20:21:59Z",
      "version": "1.0.0"
    },
    {
      "authors": [
        {
          "name": "Arnold, Jaret",
          "orcid": "https://orcid.org/0009-0003-4055-5238"
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21729883",
      "id": "observation:datacite:799f792243ed9d07",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21729883"
        }
      ],
      "inert": true,
      "itemLicense": "mit",
      "language": null,
      "observedAt": "2026-08-20T18:09:58Z",
      "payloadBytes": 19000,
      "payloadReceipt": "sha256:8073fb244311355bd71e6becb29d38ae72bce726c186ffb315c586e6ae74bba5",
      "publishedOn": "2026-08-01",
      "recordType": "software",
      "relations": [
        {
          "assertedAt": "2026-08-01T00:07:33Z",
          "identifier": {
            "scheme": "source",
            "value": "datacite:https://github.com/musharna/ldraw-mcp"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplement-to"
        },
        {
          "assertedAt": "2026-08-01T00:07:33Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21713452"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "software",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21729883",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "3d-rendering",
        "blender",
        "ldraw",
        "lego",
        "mcp",
        "model-context-protocol"
      ],
      "synthetic": false,
      "title": "ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol",
      "upstreamCreatedAt": "2026-08-01T00:07:32Z",
      "upstreamUpdatedAt": "2026-08-01T00:07:33Z",
      "version": "v0.2.1"
    },
    {
      "authors": [
        {
          "name": "Flynn, David C.",
          "orcid": "https://orcid.org/0000-0002-2768-6650"
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21731417",
      "id": "observation:datacite:b19e4c97f9b23d62",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731417"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by-4.0",
      "language": null,
      "observedAt": "2026-08-20T18:09:58Z",
      "payloadBytes": 19000,
      "payloadReceipt": "sha256:8073fb244311355bd71e6becb29d38ae72bce726c186ffb315c586e6ae74bba5",
      "publishedOn": "2026-08-01",
      "recordType": "preprint",
      "relations": [
        {
          "assertedAt": "2026-08-01T03:05:09Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21731417"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21731417",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "30B Semantic Risk Evaluator",
        "Compositional Tool‑Use Threats",
        "Intent Tree",
        "Model Context Protocol",
        "Semantic Zero‑Trust",
        "Signed Intent Manifest",
        "Trusted Context Assembly"
      ],
      "synthetic": false,
      "title": "Semantic Zero-Trust for Model Context Protocol",
      "upstreamCreatedAt": "2026-08-01T03:05:08Z",
      "upstreamUpdatedAt": "2026-08-01T03:05:09Z",
      "version": "V1"
    },
    {
      "authors": [
        {
          "name": "Cidade, Irlan de Alvarenga",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://zenodo.org/doi/10.5281/zenodo.21731493",
      "id": "observation:datacite:da51e63e259cf7cf",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731493"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by-4.0",
      "language": "en",
      "observedAt": "2026-08-20T18:07:20Z",
      "payloadBytes": 19032,
      "payloadReceipt": "sha256:c4aa57a024ce29f52fb92ef62fb1f74687553b6ef91b8591639693f6d171f061",
      "publishedOn": "2026-08-01",
      "recordType": "publication",
      "relations": [
        {
          "assertedAt": "2026-08-01T03:05:44Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21731493"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "datacite",
      "sourceRecordId": "10.5281/zenodo.21731493",
      "sourceStatus": "findable",
      "status": "active",
      "subjects": [
        "Knowledge Augmented Generation",
        "agentic security",
        "bounded autonomy",
        "bug bounty",
        "evidence-grounded assessments",
        "multi-agent systems",
        "security quality assurance"
      ],
      "synthetic": false,
      "title": "The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty",
      "upstreamCreatedAt": "2026-08-01T03:05:44Z",
      "upstreamUpdatedAt": "2026-08-01T03:05:44Z",
      "version": "1.0"
    },
    {
      "authors": [
        {
          "name": "Basu S",
          "orcid": null
        },
        {
          "name": "Patel S",
          "orcid": null
        },
        {
          "name": "Sheth P",
          "orcid": null
        },
        {
          "name": "Muralidharan B",
          "orcid": null
        },
        {
          "name": "Elamaran N",
          "orcid": null
        },
        {
          "name": "Kinra A",
          "orcid": null
        },
        {
          "name": "Batniji R.",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.1136/bmjhci-2025-101935",
      "id": "observation:europe-pmc:37fb2684bcb2e0fc",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1136/bmjhci-2025-101935"
        },
        {
          "scheme": "pmcid",
          "value": "PMC12911724"
        },
        {
          "scheme": "pmid",
          "value": "41667212"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:MED:41667212"
        }
      ],
      "inert": true,
      "itemLicense": "cc by-nc",
      "language": "en",
      "observedAt": "2026-08-20T18:07:53Z",
      "payloadBytes": 24642,
      "payloadReceipt": "sha256:3248fcdfdb2729a9441d00fc499fa4ce4357adec154e3b68bddd65555c2d4842",
      "publishedOn": "2026-02-10",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "europe-pmc",
      "sourceRecordId": "MED:41667212",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Journal Article",
        "research-article"
      ],
      "synthetic": false,
      "title": "Mechanistic interpretability of reinforcement learning in Medicaid care coordination.",
      "upstreamCreatedAt": "2026-02-10T00:00:00Z",
      "upstreamUpdatedAt": "2026-08-13T00:00:00Z",
      "version": "indexed-publication"
    },
    {
      "authors": [
        {
          "name": "De Cassai A",
          "orcid": null
        },
        {
          "name": "Dost B",
          "orcid": null
        },
        {
          "name": "Pistollato E",
          "orcid": null
        },
        {
          "name": "Zarantonello F",
          "orcid": null
        },
        {
          "name": "Boscolo A",
          "orcid": null
        },
        {
          "name": "Navalesi P.",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.1016/j.bja.2026.06.041",
      "id": "observation:europe-pmc:52129ee39ae1f6a0",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1016/j.bja.2026.06.041"
        },
        {
          "scheme": "pmid",
          "value": "42580931"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:MED:42580931"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": "en",
      "observedAt": "2026-08-20T18:07:27Z",
      "payloadBytes": 20133,
      "payloadReceipt": "sha256:8740a9f1c5ebb5454061d64bec1bfbf168db9f27e50fa0e14a35667364217919",
      "publishedOn": "2026-08-11",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "europe-pmc",
      "sourceRecordId": "MED:42580931",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Letter"
      ],
      "synthetic": false,
      "title": "Prompt injection compromises large language model-based peer review: evidence from randomised controlled trial abstracts from anaesthesia journals.",
      "upstreamCreatedAt": "2026-08-11T00:00:00Z",
      "upstreamUpdatedAt": "2026-08-11T00:00:00Z",
      "version": "indexed-publication"
    },
    {
      "authors": [
        {
          "name": "Metzger A",
          "orcid": null
        },
        {
          "name": "Patil S",
          "orcid": null
        },
        {
          "name": "Sugarmann LR",
          "orcid": null
        },
        {
          "name": "Karabacak M",
          "orcid": null
        },
        {
          "name": "Margetis K.",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.2196/81134",
      "id": "observation:europe-pmc:5e5fc3bb812281c3",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.2196/81134"
        },
        {
          "scheme": "pmcid",
          "value": "PMC13215048"
        },
        {
          "scheme": "pmid",
          "value": "42201744"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:MED:42201744"
        }
      ],
      "inert": true,
      "itemLicense": "cc by",
      "language": "en",
      "observedAt": "2026-08-20T18:07:53Z",
      "payloadBytes": 24642,
      "payloadReceipt": "sha256:3248fcdfdb2729a9441d00fc499fa4ce4357adec154e3b68bddd65555c2d4842",
      "publishedOn": "2026-05-27",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "europe-pmc",
      "sourceRecordId": "MED:42201744",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Journal Article",
        "research-article"
      ],
      "synthetic": false,
      "title": "Application of Sparse Autoencoders to Enhance Mechanistic Interpretability of Large Language Models in Medicine.",
      "upstreamCreatedAt": "2026-05-27T00:00:00Z",
      "upstreamUpdatedAt": "2026-08-13T00:00:00Z",
      "version": "indexed-publication"
    },
    {
      "authors": [
        {
          "name": "Rashidi M.",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.21203/rs.3.rs-10646218/v1",
      "id": "observation:europe-pmc:a25ee238b7d86ca6",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.21203/rs.3.rs-10646218/v1"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:PPR:PPR1296126"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": null,
      "observedAt": "2026-08-20T18:07:27Z",
      "payloadBytes": 20133,
      "payloadReceipt": "sha256:8740a9f1c5ebb5454061d64bec1bfbf168db9f27e50fa0e14a35667364217919",
      "publishedOn": "2026-08-11",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "europe-pmc",
      "sourceRecordId": "PPR:PPR1296126",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Preprint"
      ],
      "synthetic": false,
      "title": "Labelled-Metadata Channels and Declarative Payload Phrasing in Hidden Prompt Injection: A Cross-Format Measurement Study",
      "upstreamCreatedAt": "2026-08-12T00:00:00Z",
      "upstreamUpdatedAt": "2026-08-12T00:00:00Z",
      "version": "preprint"
    },
    {
      "authors": [
        {
          "name": "Zhang Z",
          "orcid": null
        },
        {
          "name": "Qadir MI",
          "orcid": null
        },
        {
          "name": "Carstens M",
          "orcid": null
        },
        {
          "name": "Zhang EH",
          "orcid": null
        },
        {
          "name": "Loiselle MS",
          "orcid": null
        },
        {
          "name": "Martinus FM",
          "orcid": null
        },
        {
          "name": "Mroczkowski MK",
          "orcid": null
        },
        {
          "name": "Clusmann J",
          "orcid": null
        },
        {
          "name": "Kather JN",
          "orcid": null
        },
        {
          "name": "Kolbinger FR.",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.1038/s44484-026-00014-6",
      "id": "observation:europe-pmc:d630ceb350736a88",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1038/s44484-026-00014-6"
        },
        {
          "scheme": "pmid",
          "value": "42523678"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:MED:42523678"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": "en",
      "observedAt": "2026-08-20T18:07:27Z",
      "payloadBytes": 20133,
      "payloadReceipt": "sha256:8740a9f1c5ebb5454061d64bec1bfbf168db9f27e50fa0e14a35667364217919",
      "publishedOn": "2026-07-27",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "europe-pmc",
      "sourceRecordId": "MED:42523678",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Journal Article"
      ],
      "synthetic": false,
      "title": "Prompt injection attacks on vision-language models for surgical decision support.",
      "upstreamCreatedAt": "2026-07-29T00:00:00Z",
      "upstreamUpdatedAt": "2026-08-13T00:00:00Z",
      "version": "indexed-publication"
    },
    {
      "authors": [
        {
          "name": "Bo Cheng",
          "orcid": null
        },
        {
          "name": "Qiaolin Lu",
          "orcid": null
        },
        {
          "name": "Yi Chang",
          "orcid": null
        },
        {
          "name": "Yuan Wu",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://arxiv.org/abs/2608.08168",
      "id": "observation:openalex:1b8e64b22e3dadc2",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.48550/arxiv.2608.08168"
        },
        {
          "scheme": "openalex",
          "value": "W7202210108"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": null,
      "observedAt": "2026-08-20T18:09:27Z",
      "payloadBytes": 16846,
      "payloadReceipt": "sha256:f189312453977c068eecb917cf38e84d9187f70c207d22dc52c021a7b531dafa",
      "publishedOn": "2026-08-08",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "openalex",
      "sourceRecordId": "W7202210108",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Multimodal Machine Learning Applications",
        "Text Readability and Simplification",
        "Topic Modeling"
      ],
      "synthetic": false,
      "title": "Thinking vs. NoThinking: Towards Interpreting Reasoning Mechanisms of Large Language Models via Sparse Autoencoders",
      "upstreamCreatedAt": "2026-08-12T07:00:00Z",
      "upstreamUpdatedAt": "2026-08-14T14:06:38Z",
      "version": "preprint"
    },
    {
      "authors": [
        {
          "name": "J. Melton",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.5281/zenodo.21906711",
      "id": "observation:openalex:3639582f7362b788",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21906711"
        },
        {
          "scheme": "openalex",
          "value": "W7202247495"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by",
      "language": "en",
      "observedAt": "2026-08-20T18:09:27Z",
      "payloadBytes": 16846,
      "payloadReceipt": "sha256:f189312453977c068eecb917cf38e84d9187f70c207d22dc52c021a7b531dafa",
      "publishedOn": "2026-08-12",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "openalex",
      "sourceRecordId": "W7202247495",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Adversarial Robustness in Machine Learning",
        "Domain Adaptation and Few-Shot Learning",
        "Explainable Artificial Intelligence (XAI)"
      ],
      "synthetic": false,
      "title": "Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training",
      "upstreamCreatedAt": "2026-08-13T07:00:00Z",
      "upstreamUpdatedAt": "2026-08-15T14:11:24Z",
      "version": "preprint"
    },
    {
      "authors": [
        {
          "name": "Sahir Maharaj",
          "orcid": "https://orcid.org/0009-0008-7878-0138"
        }
      ],
      "canonicalUrl": "https://doi.org/10.5281/zenodo.21855133",
      "id": "observation:openalex:440266aaaac7e3cb",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21855133"
        },
        {
          "scheme": "openalex",
          "value": "W7201980560"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by",
      "language": null,
      "observedAt": "2026-08-20T18:07:20Z",
      "payloadBytes": 18085,
      "payloadReceipt": "sha256:bcd46ae33edd77f07725cfeeffab8764c470be20ce34f846c2c501956c1be836",
      "publishedOn": "2026-08-01",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "openalex",
      "sourceRecordId": "W7201980560",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Security and Verification in Computing",
        "Spam and Phishing Detection",
        "Web Application Security Vulnerabilities"
      ],
      "synthetic": false,
      "title": "Measuring Indirect Prompt Injection in Autonomous Web Agents",
      "upstreamCreatedAt": "2026-08-09T07:00:00Z",
      "upstreamUpdatedAt": "2026-08-09T14:27:16Z",
      "version": "article"
    },
    {
      "authors": [
        {
          "name": "David A. Flynn",
          "orcid": "https://orcid.org/0000-0002-2768-6650"
        }
      ],
      "canonicalUrl": "https://doi.org/10.5281/zenodo.21731417",
      "id": "observation:openalex:5df0413b4f705f15",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731417"
        },
        {
          "scheme": "openalex",
          "value": "W7172123867"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by",
      "language": null,
      "observedAt": "2026-08-20T18:07:48Z",
      "payloadBytes": 35754,
      "payloadReceipt": "sha256:2b632e0415b541f7fd58e14d4cd2c88a7a9fe8360a62fc12a7588a2196b4c637",
      "publishedOn": "2026-08-01",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "openalex",
      "sourceRecordId": "W7172123867",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Access Control and Trust",
        "Advanced Authentication Protocols Security",
        "Security and Verification in Computing"
      ],
      "synthetic": false,
      "title": "Semantic Zero-Trust for Model Context Protocol",
      "upstreamCreatedAt": "2026-08-02T07:00:00Z",
      "upstreamUpdatedAt": "2026-08-02T21:50:37Z",
      "version": "preprint"
    },
    {
      "authors": [
        {
          "name": "J. Melton",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.5281/zenodo.21906710",
      "id": "observation:openalex:73435497545114aa",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21906710"
        },
        {
          "scheme": "openalex",
          "value": "W7202273798"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by",
      "language": "en",
      "observedAt": "2026-08-20T18:09:27Z",
      "payloadBytes": 16846,
      "payloadReceipt": "sha256:f189312453977c068eecb917cf38e84d9187f70c207d22dc52c021a7b531dafa",
      "publishedOn": "2026-08-14",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "openalex",
      "sourceRecordId": "W7202273798",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Adversarial Robustness in Machine Learning",
        "Domain Adaptation and Few-Shot Learning",
        "Explainable Artificial Intelligence (XAI)"
      ],
      "synthetic": false,
      "title": "Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training",
      "upstreamCreatedAt": "2026-08-13T07:00:00Z",
      "upstreamUpdatedAt": "2026-08-15T14:11:24Z",
      "version": "preprint"
    },
    {
      "authors": [
        {
          "name": "David A. Flynn",
          "orcid": "https://orcid.org/0000-0002-2768-6650"
        }
      ],
      "canonicalUrl": "https://doi.org/10.5281/zenodo.21731418",
      "id": "observation:openalex:b3101fd2b0bad721",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731418"
        },
        {
          "scheme": "openalex",
          "value": "W7172128171"
        }
      ],
      "inert": true,
      "itemLicense": "cc-by",
      "language": null,
      "observedAt": "2026-08-20T18:07:48Z",
      "payloadBytes": 35754,
      "payloadReceipt": "sha256:2b632e0415b541f7fd58e14d4cd2c88a7a9fe8360a62fc12a7588a2196b4c637",
      "publishedOn": "2026-08-01",
      "recordType": "preprint",
      "relations": [],
      "reviewState": "preprint",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "openalex",
      "sourceRecordId": "W7172128171",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Access Control and Trust",
        "Advanced Authentication Protocols Security",
        "Security and Verification in Computing"
      ],
      "synthetic": false,
      "title": "Semantic Zero-Trust for Model Context Protocol",
      "upstreamCreatedAt": "2026-08-02T07:00:00Z",
      "upstreamUpdatedAt": "2026-08-02T21:50:37Z",
      "version": "preprint"
    },
    {
      "authors": [
        {
          "name": "Shiva Gaire",
          "orcid": null
        },
        {
          "name": "Srijan Gyawali",
          "orcid": null
        },
        {
          "name": "Saroj Mishra",
          "orcid": null
        },
        {
          "name": "Suman Niroula",
          "orcid": null
        },
        {
          "name": "Dilip Thakur",
          "orcid": null
        },
        {
          "name": "Umesh Yadav",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.1007/978-3-032-32726-0_29",
      "id": "observation:openalex:b67d730c87cfc5af",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1007/978-3-032-32726-0_29"
        },
        {
          "scheme": "openalex",
          "value": "W7114797566"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": "en",
      "observedAt": "2026-08-20T18:07:48Z",
      "payloadBytes": 35754,
      "payloadReceipt": "sha256:2b632e0415b541f7fd58e14d4cd2c88a7a9fe8360a62fc12a7588a2196b4c637",
      "publishedOn": "2026-08-13",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "openalex",
      "sourceRecordId": "W7114797566",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Adversarial Robustness in Machine Learning",
        "Blockchain Technology Applications and Security",
        "Machine Learning and Algorithms"
      ],
      "synthetic": false,
      "title": "Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem",
      "upstreamCreatedAt": "2025-12-11T08:00:00Z",
      "upstreamUpdatedAt": "2026-08-14T14:06:38Z",
      "version": "conference-paper"
    },
    {
      "authors": [
        {
          "name": "Janis Keuper",
          "orcid": null
        }
      ],
      "canonicalUrl": "https://doi.org/10.1007/978-3-032-31335-5_9",
      "id": "observation:openalex:c05cc5aedbbe1943",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1007/978-3-032-31335-5_9"
        },
        {
          "scheme": "openalex",
          "value": "W4415090291"
        }
      ],
      "inert": true,
      "itemLicense": null,
      "language": "en",
      "observedAt": "2026-08-20T18:07:20Z",
      "payloadBytes": 18085,
      "payloadReceipt": "sha256:bcd46ae33edd77f07725cfeeffab8764c470be20ce34f846c2c501956c1be836",
      "publishedOn": "2026-08-03",
      "recordType": "publication",
      "relations": [],
      "reviewState": "unknown",
      "schema": "kingdom.research-observation/0.1",
      "sourceId": "openalex",
      "sourceRecordId": "W4415090291",
      "sourceStatus": null,
      "status": "active",
      "subjects": [
        "Digital and Cyber Forensics",
        "Security and Verification in Computing",
        "Web Application Security Vulnerabilities"
      ],
      "synthetic": false,
      "title": "Prompt Injection Attacks on LLM Generated Reviews of Scientific Publications",
      "upstreamCreatedAt": "2025-10-12T07:00:00Z",
      "upstreamUpdatedAt": "2026-08-05T14:39:15Z",
      "version": "conference-paper"
    }
  ],
  "schema": "kingdom.research-public-snapshot/0.1",
  "signals": [
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-supplement-to relation to 10.5281/zenodo.21739163",
      "id": "signal:publication-link:1953589b522a8813",
      "observedAt": "2026-08-02T09:19:48Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:6119662c70f05464"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:001b6af0d2b1fc7f3ac0"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21731493",
      "id": "signal:publication-link:2efdc8314bb5d185",
      "observedAt": "2026-08-01T03:05:44Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:da51e63e259cf7cf"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:7aff5c16654194dfc16c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21713452",
      "id": "signal:publication-link:5542694eeaf873c9",
      "observedAt": "2026-08-01T07:11:35Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:67eab70b87c630d0"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:b6c0a71544ea079ea9f6"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21713452",
      "id": "signal:publication-link:61b92fa5952225f1",
      "observedAt": "2026-08-01T00:07:33Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:799f792243ed9d07"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:60f16fceed98c0791277"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21731417",
      "id": "signal:publication-link:6f42c3e3435c2904",
      "observedAt": "2026-08-01T03:05:08Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:1916afceb5a82955",
        "observation:openalex:b3101fd2b0bad721"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:60f291220d74592bbe4c",
        "work:c6624953de841194cf4c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21746423",
      "id": "signal:publication-link:91b0febbb457bf37",
      "observedAt": "2026-08-01T20:21:58Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:00f0afac1c7665c2"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:ad2d4e22fd3b2d0ba43b",
        "work:b717b7c2eb569e85ac53"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21746423",
      "id": "signal:publication-link:92974e22a74ceaa8",
      "observedAt": "2026-08-01T20:21:59Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:6ec8c4115f9af5e7"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:ad2d4e22fd3b2d0ba43b"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-supplemented-by relation to datacite:https://github.com/Prateek-Pulastya/Guardrail-As-A-Service-V2",
      "id": "signal:publication-link:9cb79a774355c8ec",
      "observedAt": "2026-08-01T20:21:59Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:6ec8c4115f9af5e7"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:ad2d4e22fd3b2d0ba43b"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21740544",
      "id": "signal:publication-link:a02845453818d731",
      "observedAt": "2026-08-01T14:22:02Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:6e71c79f4f0f367c"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:df3a3e7ebd80342f9c6f"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21757178",
      "id": "signal:publication-link:a83f4b77907675be",
      "observedAt": "2026-08-02T09:19:48Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:6119662c70f05464"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:001b6af0d2b1fc7f3ac0"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-supplement-to relation to datacite:https://github.com/musharna/ldraw-mcp",
      "id": "signal:publication-link:b438e6a07dd899bb",
      "observedAt": "2026-08-01T07:11:35Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:67eab70b87c630d0"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:b6c0a71544ea079ea9f6"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21731493",
      "id": "signal:publication-link:d659fc1c6a1da121",
      "observedAt": "2026-08-01T03:05:44Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:0716c674df8147ca"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:7aff5c16654194dfc16c",
        "work:866c714320a9dcac2337"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-version-of relation to 10.5281/zenodo.21731417",
      "id": "signal:publication-link:d8a04364523d5595",
      "observedAt": "2026-08-01T03:05:09Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:b19e4c97f9b23d62",
        "observation:openalex:5df0413b4f705f15"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:c6624953de841194cf4c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-supplemented-by relation to datacite:https://github.com/Prateek-Pulastya/Guardrail-As-A-Service-V2",
      "id": "signal:publication-link:e83bed97caf51e6d",
      "observedAt": "2026-08-01T20:21:58Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:00f0afac1c7665c2"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:b717b7c2eb569e85ac53"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "Explicit is-supplement-to relation to datacite:https://github.com/musharna/ldraw-mcp",
      "id": "signal:publication-link:f715ef9ff3ffa812",
      "observedAt": "2026-08-01T00:07:33Z",
      "reasons": [
        "The source relation creates an edge; it does not silently merge the records."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:799f792243ed9d07"
      ],
      "type": "publication-link",
      "watchlistId": null,
      "workIds": [
        "work:60f16fceed98c0791277"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "2 sources report exact identifiers for this work",
      "id": "signal:source-corroboration:b18a3d633157d76f",
      "observedAt": "2026-08-20T18:09:58Z",
      "reasons": [
        "Exact shared identifiers connect the observations; this does not independently verify the research claim."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:1916afceb5a82955",
        "observation:openalex:b3101fd2b0bad721"
      ],
      "type": "source-corroboration",
      "watchlistId": null,
      "workIds": [
        "work:60f291220d74592bbe4c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "2 sources report exact identifiers for this work",
      "id": "signal:source-corroboration:c4bbbdf0b87359af",
      "observedAt": "2026-08-20T18:09:58Z",
      "reasons": [
        "Exact shared identifiers connect the observations; this does not independently verify the research claim."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "info",
      "sourceObservationIds": [
        "observation:datacite:b19e4c97f9b23d62",
        "observation:openalex:5df0413b4f705f15"
      ],
      "type": "source-corroboration",
      "watchlistId": null,
      "workIds": [
        "work:c6624953de841194cf4c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "2 source observations or versions are preserved",
      "id": "signal:version-activity:1d84606fbe27c21d",
      "observedAt": "2026-08-20T18:09:58Z",
      "reasons": [
        "The observations remain separate even when exact identifiers resolve to one work."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "watch",
      "sourceObservationIds": [
        "observation:datacite:1916afceb5a82955",
        "observation:openalex:b3101fd2b0bad721"
      ],
      "type": "version-activity",
      "watchlistId": null,
      "workIds": [
        "work:60f291220d74592bbe4c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [],
      "headline": "2 source observations or versions are preserved",
      "id": "signal:version-activity:c11cde1868602e92",
      "observedAt": "2026-08-20T18:09:58Z",
      "reasons": [
        "The observations remain separate even when exact identifiers resolve to one work."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "watch",
      "sourceObservationIds": [
        "observation:datacite:b19e4c97f9b23d62",
        "observation:openalex:5df0413b4f705f15"
      ],
      "type": "version-activity",
      "watchlistId": null,
      "workIds": [
        "work:c6624953de841194cf4c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2026-08-20"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "crossref"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "item-level licence absent"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "A Toolset-First Paradigm Based on Large Language Model and Agent via Model Context Protocol for Intelligent Computation matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:027e6c6744e7c989",
      "observedAt": "2026-08-20T18:09:14Z",
      "reasons": [
        "Matched reviewed English terms: model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:d67a1b4ed7547770"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:387b73d3d989fd9ab4fb"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "indirect prompt injection",
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "openalex"
          ],
          "factor": "source-authority",
          "level": "low",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "reported item licence:cc-by"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Measuring Indirect Prompt Injection in Autonomous Web Agents matches Secure information flow and agent security",
      "id": "signal:watchlist-match:07920da1ebd0f5e1",
      "observedAt": "2026-08-20T18:07:20Z",
      "reasons": [
        "Matched reviewed English terms: indirect prompt injection, prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:openalex:440266aaaac7e3cb"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:82888d501426cfc4b2bf"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "europe-pmc"
          ],
          "factor": "source-authority",
          "level": "low",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "item-level licence absent"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Prompt injection attacks on vision-language models for surgical decision support. matches Secure information flow and agent security",
      "id": "signal:watchlist-match:0859075a28467d7e",
      "observedAt": "2026-08-20T18:07:27Z",
      "reasons": [
        "Matched reviewed English terms: prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:europe-pmc:d630ceb350736a88"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:92ea0c7c6a02d587904a"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "datacite"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "reported item licence:cc-by-4.0"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Role-Styled Prompt Injection: An Activation and KV-State Probe in a Compact Language Model matches Secure information flow and agent security",
      "id": "signal:watchlist-match:0e5818f2beb21d20",
      "observedAt": "2026-08-20T18:07:20Z",
      "reasons": [
        "Matched reviewed English terms: prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:6119662c70f05464"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:001b6af0d2b1fc7f3ac0"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "datacite"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "reported item licence:cc-by-4.0"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection matches Secure information flow and agent security",
      "id": "signal:watchlist-match:1d349b375ad5e88a",
      "observedAt": "2026-08-20T18:07:20Z",
      "reasons": [
        "Matched reviewed English terms: prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:6ec8c4115f9af5e7"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:ad2d4e22fd3b2d0ba43b"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2026-08-01"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "datacite"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "uninterpreted item licence:mit"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:1d99ca5c12b76ab1",
      "observedAt": "2026-08-20T18:09:58Z",
      "reasons": [
        "Matched reviewed English terms: model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:799f792243ed9d07"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:60f16fceed98c0791277"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2026-01-01"
          ],
          "factor": "freshness",
          "level": "low",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "crossref"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "uninterpreted item licence:https://www.uspto.gov/ip-policy/copyright-policy/copyright-basics"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "Securing Federated Model Context Protocol (MCP) and Multi-Agent Supply Chains matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:285d7ebf97a90cf5",
      "observedAt": "2026-08-20T18:09:14Z",
      "reasons": [
        "Matched reviewed English terms: model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:d6920254ad639948"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:1f38a749dcc6a37c9b2c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "agent security"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "datacite"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "reported item licence:cc-by-4.0"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty matches Secure information flow and agent security",
      "id": "signal:watchlist-match:2b902437c40a7bdd",
      "observedAt": "2026-08-20T18:07:20Z",
      "reasons": [
        "Matched reviewed English terms: agent security.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:da51e63e259cf7cf"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:7aff5c16654194dfc16c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2026-08-01"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "datacite"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "reported item licence:cc-by-4.0"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "Enterprise Agentic AI: A Reference Architecture for Natural Language to SQL, Model Context Protocol (MCP), Retrieval-Augmented Generation (RAG), Multi-Agent Systems, and Production AI matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:3095f163afba8fbb",
      "observedAt": "2026-08-20T18:09:58Z",
      "reasons": [
        "Matched reviewed English terms: model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:6e71c79f4f0f367c"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:df3a3e7ebd80342f9c6f"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "sparse autoencoder"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed term that matched the named need."
        },
        {
          "evidence": [
            "2026-08-08"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Show source and update dates without treating recency as validity."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Distinguish preprint, peer-reviewed, and unknown review states."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Surface correction, withdrawal, and retraction evidence without averaging it away."
        }
      ],
      "headline": "Thinking vs. NoThinking: Towards Interpreting Reasoning Mechanisms of Large Language Models via Sparse Autoencoders matches Interpretable reasoning and J-space",
      "id": "signal:watchlist-match:3620a05a1d18abb5",
      "observedAt": "2026-08-20T18:09:27Z",
      "reasons": [
        "Matched reviewed English terms: sparse autoencoder.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:openalex:1b8e64b22e3dadc2"
      ],
      "type": "watchlist-match",
      "watchlistId": "interpretable-reasoning",
      "workIds": [
        "work:f0afa9fe8652ed9ab84d"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "europe-pmc"
          ],
          "factor": "source-authority",
          "level": "low",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "item-level licence absent"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Prompt injection compromises large language model-based peer review: evidence from randomised controlled trial abstracts from anaesthesia journals. matches Secure information flow and agent security",
      "id": "signal:watchlist-match:4cd0ca30054563ed",
      "observedAt": "2026-08-20T18:07:27Z",
      "reasons": [
        "Matched reviewed English terms: prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:europe-pmc:52129ee39ae1f6a0"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:fab03dbb7fc3c02d82d8"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "openalex"
          ],
          "factor": "source-authority",
          "level": "low",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "item-level licence absent"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Prompt Injection Attacks on LLM Generated Reviews of Scientific Publications matches Secure information flow and agent security",
      "id": "signal:watchlist-match:4cd96daf353cf6ec",
      "observedAt": "2026-08-20T18:07:20Z",
      "reasons": [
        "Matched reviewed English terms: prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:openalex:c05cc5aedbbe1943"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:e4dd5c51eb6b1b9ea2b0"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "europe-pmc"
          ],
          "factor": "source-authority",
          "level": "low",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "item-level licence absent"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Labelled-Metadata Channels and Declarative Payload Phrasing in Hidden Prompt Injection: A Cross-Format Measurement Study matches Secure information flow and agent security",
      "id": "signal:watchlist-match:5a9f969c366cdf8e",
      "observedAt": "2026-08-20T18:07:27Z",
      "reasons": [
        "Matched reviewed English terms: prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:europe-pmc:a25ee238b7d86ca6"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:f96d771f15df8add52e7"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "mechanistic interpretability",
            "sparse autoencoder"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed term that matched the named need."
        },
        {
          "evidence": [
            "2026-08-14"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Show source and update dates without treating recency as validity."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Distinguish preprint, peer-reviewed, and unknown review states."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Surface correction, withdrawal, and retraction evidence without averaging it away."
        }
      ],
      "headline": "Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training matches Interpretable reasoning and J-space",
      "id": "signal:watchlist-match:65a88cfff3ce6539",
      "observedAt": "2026-08-20T18:09:27Z",
      "reasons": [
        "Matched reviewed English terms: mechanistic interpretability, sparse autoencoder.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:openalex:73435497545114aa"
      ],
      "type": "watchlist-match",
      "watchlistId": "interpretable-reasoning",
      "workIds": [
        "work:e40090ba1132c62ea71c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2026-08-01"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "datacite",
            "openalex"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "reported item licence:cc-by",
            "reported item licence:cc-by-4.0"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "Semantic Zero-Trust for Model Context Protocol matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:6d8caa8562d3bcec",
      "observedAt": "2026-08-20T18:09:58Z",
      "reasons": [
        "Matched reviewed English terms: model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:b19e4c97f9b23d62",
        "observation:openalex:5df0413b4f705f15"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:c6624953de841194cf4c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2026-08-01"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "datacite"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "uninterpreted item licence:mit"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:7541f32fcd11ee19",
      "observedAt": "2026-08-20T18:09:58Z",
      "reasons": [
        "Matched reviewed English terms: model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:67eab70b87c630d0"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:b6c0a71544ea079ea9f6"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "indirect prompt injection",
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "crossref"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "reported item licence:https://creativecommons.org/licenses/by/4.0/"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Balancing Security and Performance in LLM Agents: Spotlight-Guard, a Layered Defense Against Indirect Prompt Injection matches Secure information flow and agent security",
      "id": "signal:watchlist-match:8cbbd65d635ccf25",
      "observedAt": "2026-08-20T18:09:16Z",
      "reasons": [
        "Matched reviewed English terms: indirect prompt injection, prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:6febc941c6477298"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:52568adfe1b21f70b343"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "arxiv"
          ],
          "factor": "source-authority",
          "level": "medium",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "item-level licence absent"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems matches Secure information flow and agent security",
      "id": "signal:watchlist-match:a4992f90bafa1be2",
      "observedAt": "2026-08-20T18:07:21Z",
      "reasons": [
        "Matched reviewed English terms: prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:arxiv:28c2c5fcfeca666e"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:df6d1e5df83d5ccd8e6b"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2026-08-02"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "arxiv"
          ],
          "factor": "source-authority",
          "level": "medium",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "item-level licence absent"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "Registry Descriptions Go Stale Unevenly: An 89-Day Measurement of Model Context Protocol Drift, and Why Drift-Ranked Re-Auditing Under-Covers It matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:a9480de36dfaf813",
      "observedAt": "2026-08-20T18:10:14Z",
      "reasons": [
        "Matched reviewed English terms: model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:arxiv:e6f88ec1494225ed"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:59218754c0e3e56078b7"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "mechanistic interpretability"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed term that matched the named need."
        },
        {
          "evidence": [
            "2026-08-02"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Show source and update dates without treating recency as validity."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Distinguish preprint, peer-reviewed, and unknown review states."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Surface correction, withdrawal, and retraction evidence without averaging it away."
        }
      ],
      "headline": "Mechanistic Interpretability-Guided Selective Fine-Tuning of Vision-Language Models for Centimeter-Level Flood Depth Estimation matches Interpretable reasoning and J-space",
      "id": "signal:watchlist-match:abf302bafa9dbad3",
      "observedAt": "2026-08-20T18:07:49Z",
      "reasons": [
        "Matched reviewed English terms: mechanistic interpretability.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:arxiv:bb59396c7fe27bb3"
      ],
      "type": "watchlist-match",
      "watchlistId": "interpretable-reasoning",
      "workIds": [
        "work:e380067170267187adf4"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "indirect prompt injection",
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "crossref"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "uninterpreted item licence:https://ieeexplore.ieee.org/Xplorehelp/downloads/license-information/IEEE.html"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Secure MCP-Based Tool-Augmented RAG for Industrial IoT Diagnostics Under Indirect Prompt Injection, Retrieval Poisoning, and Modality Outages matches Secure information flow and agent security",
      "id": "signal:watchlist-match:acdf42c0967ad1ae",
      "observedAt": "2026-08-20T18:09:16Z",
      "reasons": [
        "Matched reviewed English terms: indirect prompt injection, prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:792b9edd45cc7292"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:ee6800fe825dd1f14f79"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "mechanistic interpretability"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed term that matched the named need."
        },
        {
          "evidence": [
            "2025-05-07"
          ],
          "factor": "freshness",
          "level": "low",
          "reason": "Show source and update dates without treating recency as validity."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Distinguish preprint, peer-reviewed, and unknown review states."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Surface correction, withdrawal, and retraction evidence without averaging it away."
        }
      ],
      "headline": "Causal Intervention Framework for Variational Auto Encoder Mechanistic Interpretability matches Interpretable reasoning and J-space",
      "id": "signal:watchlist-match:b89405740df853bb",
      "observedAt": "2026-08-20T18:06:56Z",
      "reasons": [
        "Matched reviewed English terms: mechanistic interpretability.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:9d9767af45efe7de"
      ],
      "type": "watchlist-match",
      "watchlistId": "interpretable-reasoning",
      "workIds": [
        "work:d98e745cd4ee2938266d"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "mechanistic interpretability",
            "sparse autoencoder"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed term that matched the named need."
        },
        {
          "evidence": [
            "2026-05-27"
          ],
          "factor": "freshness",
          "level": "medium",
          "reason": "Show source and update dates without treating recency as validity."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Distinguish preprint, peer-reviewed, and unknown review states."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Surface correction, withdrawal, and retraction evidence without averaging it away."
        }
      ],
      "headline": "Application of Sparse Autoencoders to Enhance Mechanistic Interpretability of Large Language Models in Medicine. matches Interpretable reasoning and J-space",
      "id": "signal:watchlist-match:bc696cc829714069",
      "observedAt": "2026-08-20T18:07:53Z",
      "reasons": [
        "Matched reviewed English terms: mechanistic interpretability, sparse autoencoder.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:europe-pmc:5e5fc3bb812281c3"
      ],
      "type": "watchlist-match",
      "watchlistId": "interpretable-reasoning",
      "workIds": [
        "work:781ee43b5d35cbdbc27c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2026-08-13"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "openalex"
          ],
          "factor": "source-authority",
          "level": "low",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "item-level licence absent"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:c23500affad15cd8",
      "observedAt": "2026-08-20T18:07:48Z",
      "reasons": [
        "Matched reviewed English terms: model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:openalex:b67d730c87cfc5af"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:ada943d2a88ffb34e416"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "agent security"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "datacite"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "reported item licence:cc-by-4.0"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty matches Secure information flow and agent security",
      "id": "signal:watchlist-match:c9b7a994ab493036",
      "observedAt": "2026-08-20T18:07:20Z",
      "reasons": [
        "Matched reviewed English terms: agent security.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:0716c674df8147ca"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:866c714320a9dcac2337"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "indirect prompt injection",
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "crossref"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "reported item licence:https://creativecommons.org/licenses/by/4.0/"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Measuring Indirect Prompt Injection in Autonomous Web Agents matches Secure information flow and agent security",
      "id": "signal:watchlist-match:d8a0f51e354bab61",
      "observedAt": "2026-08-20T18:09:16Z",
      "reasons": [
        "Matched reviewed English terms: indirect prompt injection, prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:d6ca8526a1b03056"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:1a4c94016ebdc224b7ac"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "datacite"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "reported item licence:cc-by-4.0"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection matches Secure information flow and agent security",
      "id": "signal:watchlist-match:d932c608e73e5596",
      "observedAt": "2026-08-20T18:07:20Z",
      "reasons": [
        "Matched reviewed English terms: prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:00f0afac1c7665c2"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:b717b7c2eb569e85ac53"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "mechanistic interpretability",
            "sparse autoencoder"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed term that matched the named need."
        },
        {
          "evidence": [
            "2026-08-12"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Show source and update dates without treating recency as validity."
        },
        {
          "evidence": [
            "preprint"
          ],
          "factor": "review-state",
          "level": "low",
          "reason": "Distinguish preprint, peer-reviewed, and unknown review states."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Surface correction, withdrawal, and retraction evidence without averaging it away."
        }
      ],
      "headline": "Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training matches Interpretable reasoning and J-space",
      "id": "signal:watchlist-match:e12f7e3150485aab",
      "observedAt": "2026-08-20T18:09:27Z",
      "reasons": [
        "Matched reviewed English terms: mechanistic interpretability, sparse autoencoder.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:openalex:3639582f7362b788"
      ],
      "type": "watchlist-match",
      "watchlistId": "interpretable-reasoning",
      "workIds": [
        "work:4ba9625856afd44e1e1b"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "mechanistic interpretability"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed term that matched the named need."
        },
        {
          "evidence": [
            "2025-01-01"
          ],
          "factor": "freshness",
          "level": "low",
          "reason": "Show source and update dates without treating recency as validity."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Distinguish preprint, peer-reviewed, and unknown review states."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Surface correction, withdrawal, and retraction evidence without averaging it away."
        }
      ],
      "headline": "The Non-Linear Representation Dilemma: Is Causal Abstraction Enough for Mechanistic Interpretability? matches Interpretable reasoning and J-space",
      "id": "signal:watchlist-match:e4c7435a33981a86",
      "observedAt": "2026-08-20T18:06:56Z",
      "reasons": [
        "Matched reviewed English terms: mechanistic interpretability.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:3c987dfc1571681f"
      ],
      "type": "watchlist-match",
      "watchlistId": "interpretable-reasoning",
      "workIds": [
        "work:33ab84eae181cfcbf5de"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2026-08-01"
          ],
          "factor": "freshness",
          "level": "high",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "datacite",
            "openalex"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "reported item licence:cc-by",
            "reported item licence:cc-by-4.0"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "Semantic Zero-Trust for Model Context Protocol matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:e6fa8160dbdf4705",
      "observedAt": "2026-08-20T18:09:58Z",
      "reasons": [
        "Matched reviewed English terms: model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:datacite:1916afceb5a82955",
        "observation:openalex:b3101fd2b0bad721"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:60f291220d74592bbe4c"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "indirect prompt injection",
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "crossref"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "reported item licence:https://creativecommons.org/licenses/by/4.0/"
          ],
          "factor": "rights-clarity",
          "level": "medium",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "DT-GenShield: A Digital Twin-Driven Runtime Security Architecture for Protecting Large Language Models Against Indirect Prompt Injection matches Secure information flow and agent security",
      "id": "signal:watchlist-match:eccf4f6d1249e35f",
      "observedAt": "2026-08-20T18:09:16Z",
      "reasons": [
        "Matched reviewed English terms: indirect prompt injection, prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:2388068f3e413d55"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:5f8c19452e9c33eecee4"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "agent security",
            "prompt injection"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "evidence": [
            "crossref"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "evidence": [
            "item-level licence absent"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "headline": "WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks matches Secure information flow and agent security",
      "id": "signal:watchlist-match:efa3fb29100ceb89",
      "observedAt": "2026-08-20T18:09:16Z",
      "reasons": [
        "Matched reviewed English terms: agent security, prompt injection.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:ab21ffe4074b8d82"
      ],
      "type": "watchlist-match",
      "watchlistId": "agent-security",
      "workIds": [
        "work:e3076bbde42e9e0457ef"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "mechanistic interpretability"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose the exact reviewed term that matched the named need."
        },
        {
          "evidence": [
            "2026-02-10"
          ],
          "factor": "freshness",
          "level": "low",
          "reason": "Show source and update dates without treating recency as validity."
        },
        {
          "evidence": [
            "unknown"
          ],
          "factor": "review-state",
          "level": "unknown",
          "reason": "Distinguish preprint, peer-reviewed, and unknown review states."
        },
        {
          "evidence": [
            "active"
          ],
          "factor": "integrity",
          "level": "unknown",
          "reason": "Surface correction, withdrawal, and retraction evidence without averaging it away."
        }
      ],
      "headline": "Mechanistic interpretability of reinforcement learning in Medicaid care coordination. matches Interpretable reasoning and J-space",
      "id": "signal:watchlist-match:f576fa09a3c6fafd",
      "observedAt": "2026-08-20T18:07:53Z",
      "reasons": [
        "Matched reviewed English terms: mechanistic interpretability.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:europe-pmc:37fb2684bcb2e0fc"
      ],
      "type": "watchlist-match",
      "watchlistId": "interpretable-reasoning",
      "workIds": [
        "work:fbbda07538a116c22ad3"
      ]
    },
    {
      "authorizesAction": false,
      "factors": [
        {
          "evidence": [
            "agent protocol",
            "model context protocol"
          ],
          "factor": "named-need-fit",
          "level": "high",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "evidence": [
            "2025-11-12"
          ],
          "factor": "freshness",
          "level": "low",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "evidence": [
            "crossref"
          ],
          "factor": "source-authority",
          "level": "high",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "evidence": [
            "uninterpreted item licence:http://creativecommons.org/licenses/by-nc-nd/4.0/"
          ],
          "factor": "rights-clarity",
          "level": "unknown",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable. Source-metadata reuse terms are tracked separately and do not grant rights to the linked object."
        }
      ],
      "headline": "Towards secure agentic workflows: a MAESTRO-based assessment framework for Model Context Protocol and Agent-to-Agent Protocol matches Natural-language programming and agent interoperability",
      "id": "signal:watchlist-match:fed004d3c2eec90e",
      "observedAt": "2026-08-20T18:09:14Z",
      "reasons": [
        "Matched reviewed English terms: agent protocol, model context protocol.",
        "The match orders attention only; it is not evaluation, adoption, or use authority."
      ],
      "schema": "kingdom.research-signal/0.1",
      "severity": "attention",
      "sourceObservationIds": [
        "observation:crossref:ecced040bec1000c"
      ],
      "type": "watchlist-match",
      "watchlistId": "language-agent-interoperability",
      "workIds": [
        "work:e819919fe3140aac1ef6"
      ]
    }
  ],
  "sources": [
    {
      "access": {
        "authentication": "none",
        "documentationUrl": "https://info.arxiv.org/help/api/index.html",
        "incremental": "cursor",
        "interfaces": [
          "rest",
          "oai-pmh",
          "bulk-snapshot"
        ],
        "mvpMode": "fixture-and-explicit-poll",
        "rateLimit": "Legacy API, RSS, and OAI clients should make no more than one request every three seconds.",
        "webhook": false
      },
      "authority": {
        "canonicalFor": [
          "arXiv identifier",
          "arXiv submission version and withdrawal metadata"
        ],
        "kind": "authoritative-domain"
      },
      "coverage": {
        "disciplines": [
          "computer science",
          "economics",
          "electrical engineering",
          "mathematics",
          "physics",
          "quantitative biology",
          "statistics"
        ],
        "geography": "Global submissions with strongest coverage in physics, mathematics, computer science, and adjacent fields.",
        "recordTypes": [
          "preprint"
        ]
      },
      "freshness": {
        "expectedLag": "Best-effort new-submission discovery only. Offset cursors over a changing result set are not a complete or stable update/deletion feed; consumers must overlap and restart rather than claim lossless sync.",
        "observedOn": "2026-08-20",
        "upstreamCadence": "The bounded legacy API exposes announced submissions and is queried by reviewed terms and submitted date; OAI remains the authoritative bulk metadata path but its provider-sized pages exceed this MVP's limits."
      },
      "id": "arxiv",
      "identifiers": [
        "arXiv ID",
        "DOI when supplied"
      ],
      "name": "arXiv",
      "officialUrls": [
        "https://info.arxiv.org/help/api/index.html",
        "https://info.arxiv.org/help/oa/index.html",
        "https://info.arxiv.org/help/api/tou.html",
        "https://info.arxiv.org/help/bulk_data/index.html"
      ],
      "rights": {
        "commercialReview": "recommended",
        "evidenceUrl": "https://info.arxiv.org/help/api/tou.html",
        "fullTextPolicy": "not-ingested",
        "metadataClaim": "Descriptive API metadata is offered as CC0; item content remains under its submitted licence or copyright.",
        "redistribution": "This module republishes normalized metadata and links only; it does not copy article content. Product displays should include: Thank you to arXiv for use of its open access interoperability."
      },
      "risks": [
        "Preprints are not peer reviewed.",
        "The bounded live adapter is best-effort submission discovery and may miss later versions or withdrawals.",
        "Most full text cannot be redistributed without checking the item licence."
      ],
      "role": "preprint-repository",
      "schema": "kingdom.research-source/0.1",
      "tier": "core"
    },
    {
      "access": {
        "authentication": "none",
        "documentationUrl": "https://api.biorxiv.org/details/medrxiv/help",
        "incremental": "cursor",
        "interfaces": [
          "rest",
          "bulk-snapshot"
        ],
        "mvpMode": "fixture-only-policy-hold",
        "rateLimit": "Public API is paged in groups of 100; clients should remain bounded and courteous.",
        "webhook": false
      },
      "authority": {
        "canonicalFor": [
          "bioRxiv and medRxiv posting metadata",
          "preprint version and published-article link"
        ],
        "kind": "authoritative-domain"
      },
      "coverage": {
        "disciplines": [
          "biology",
          "health sciences",
          "medicine"
        ],
        "geography": "Global submissions in biology, health sciences, and medicine.",
        "recordTypes": [
          "preprint"
        ]
      },
      "freshness": {
        "expectedLag": "Published-journal links can appear after publication and should be treated as later observations.",
        "observedOn": "2026-08-20",
        "upstreamCadence": "Date-range and recent-item API views expose posted records and versions."
      },
      "id": "biorxiv-medrxiv",
      "identifiers": [
        "DOI",
        "bioRxiv or medRxiv version"
      ],
      "name": "bioRxiv and medRxiv",
      "officialUrls": [
        "https://api.biorxiv.org/details/medrxiv/help",
        "https://www.biorxiv.org/tdm",
        "https://www.biorxiv.org/about-biorxiv"
      ],
      "rights": {
        "commercialReview": "required",
        "evidenceUrl": "https://www.biorxiv.org/tdm",
        "fullTextPolicy": "not-ingested",
        "metadataClaim": "Metadata API access is public; each manuscript has an author-selected content licence.",
        "redistribution": "Metadata may be indexed with attribution; rehosting full text is outside this module and requires item-specific review."
      },
      "risks": [
        "Screening is not peer review.",
        "Content licences vary by item.",
        "Published-article relations may lag or remain absent."
      ],
      "role": "preprint-repository",
      "schema": "kingdom.research-source/0.1",
      "tier": "core"
    },
    {
      "access": {
        "authentication": "none",
        "documentationUrl": "https://clinicaltrials.gov/data-api/api",
        "incremental": "cursor",
        "interfaces": [
          "rest",
          "bulk-snapshot"
        ],
        "mvpMode": "fixture-only-policy-hold",
        "rateLimit": "Public API v2; this module caps one explicit poll at three pages and 300 metadata records.",
        "webhook": false
      },
      "authority": {
        "canonicalFor": [
          "NCT identifier",
          "submitted ClinicalTrials.gov registration and results metadata"
        ],
        "kind": "canonical"
      },
      "coverage": {
        "disciplines": [
          "clinical research",
          "health sciences",
          "medicine"
        ],
        "geography": "International study registrations submitted to the United States registry.",
        "recordTypes": [
          "trial"
        ]
      },
      "freshness": {
        "expectedLag": "Registry processing and sponsor updates can lag real-world study events.",
        "observedOn": "2026-08-20",
        "upstreamCadence": "Data generally refreshes Monday through Friday around 09:00 US Eastern time."
      },
      "id": "clinicaltrials-gov",
      "identifiers": [
        "NCT ID",
        "secondary trial registry IDs",
        "DOI when supplied"
      ],
      "name": "ClinicalTrials.gov",
      "officialUrls": [
        "https://clinicaltrials.gov/data-api/api",
        "https://clinicaltrials.gov/data-api/about-api/api-migration",
        "https://clinicaltrials.gov/about-site/terms-conditions"
      ],
      "rights": {
        "commercialReview": "recommended",
        "evidenceUrl": "https://clinicaltrials.gov/about-site/terms-conditions",
        "fullTextPolicy": "not-ingested",
        "metadataClaim": "Registry data is publicly available with required attribution/currentness practices and third-party caveats.",
        "redistribution": "Derived metadata must identify ClinicalTrials.gov, processing date, and modifications; third-party material may have separate rights."
      },
      "risks": [
        "Live polling is disabled in 0.1 until the zone-less source processing timestamp and modification disclosure are modeled without inventing UTC.",
        "Sponsor or investigator submission is not a quality endorsement.",
        "A registration is not a positive result.",
        "Duplicate registrations across registries need explicit identifier links."
      ],
      "role": "trial-registry",
      "schema": "kingdom.research-source/0.1",
      "tier": "core"
    },
    {
      "access": {
        "authentication": "none",
        "documentationUrl": "https://www.crossref.org/documentation/retrieve-metadata/rest-api/",
        "incremental": "date-filter",
        "interfaces": [
          "rest",
          "bulk-snapshot"
        ],
        "mvpMode": "fixture-and-explicit-poll",
        "rateLimit": "The current Crossref polite list pool reports three requests per second, aggregated by identified email; follow returned headers because limits can change.",
        "webhook": false
      },
      "authority": {
        "canonicalFor": [
          "Crossref DOI registration metadata",
          "member-deposited work relations and updates"
        ],
        "kind": "canonical"
      },
      "coverage": {
        "disciplines": [
          "multidisciplinary"
        ],
        "geography": "Global member-deposited scholarly metadata.",
        "recordTypes": [
          "publication",
          "preprint",
          "dataset",
          "software"
        ]
      },
      "freshness": {
        "expectedLag": "Deposits and later corrections arrive on publisher schedules; polling must overlap and deduplicate.",
        "observedOn": "2026-08-20",
        "upstreamCadence": "REST index-date filters support fine-grained incremental polling; the public full file is annual and paid snapshots are monthly."
      },
      "id": "crossref",
      "identifiers": [
        "DOI",
        "ORCID",
        "ROR",
        "funder ID",
        "award number"
      ],
      "name": "Crossref",
      "officialUrls": [
        "https://www.crossref.org/documentation/retrieve-metadata/rest-api/",
        "https://www.crossref.org/documentation/retrieve-metadata/bulk-downloads/",
        "https://www.crossref.org/documentation/retrieve-metadata/rest-api/access-and-authentication/"
      ],
      "rights": {
        "commercialReview": "recommended",
        "evidenceUrl": "https://www.crossref.org/documentation/retrieve-metadata/rest-api/",
        "fullTextPolicy": "not-ingested",
        "metadataClaim": "Most bibliographic fields are factual and openly retrievable; abstracts and some deposited fields may remain copyrighted.",
        "redistribution": "Republish normalized facts with attribution and retain field provenance; do not assume abstracts are reusable."
      },
      "risks": [
        "Metadata completeness depends on member deposits.",
        "Abstract, reference, affiliation, funding, and relation coverage is uneven.",
        "There is no webhook; incremental clients need overlap and replay."
      ],
      "role": "pid-registry",
      "schema": "kingdom.research-source/0.1",
      "tier": "core"
    },
    {
      "access": {
        "authentication": "none",
        "documentationUrl": "https://www.crossref.org/documentation/retrieve-metadata/retraction-watch/",
        "incremental": "date-filter",
        "interfaces": [
          "rest",
          "daily-files"
        ],
        "mvpMode": "fixture-and-explicit-poll",
        "rateLimit": "The current Crossref polite list pool reports three requests per second, aggregated by identified email; follow returned headers because limits can change.",
        "webhook": false
      },
      "authority": {
        "canonicalFor": [
          "Crossref-deposited update relation",
          "Retraction Watch status record as distributed by Crossref"
        ],
        "kind": "derived-integrity"
      },
      "coverage": {
        "disciplines": [
          "multidisciplinary"
        ],
        "geography": "Global Crossref update relations plus Retraction Watch records distributed through Crossref.",
        "recordTypes": [
          "status-update"
        ]
      },
      "freshness": {
        "expectedLag": "Notices can lag the underlying event and coverage is not complete.",
        "observedOn": "2026-08-20",
        "upstreamCadence": "Retraction Watch data is updated each working day; publisher-deposited Crossmark updates arrive on publisher schedules."
      },
      "id": "crossref-integrity",
      "identifiers": [
        "DOI",
        "Crossref update type",
        "Retraction Watch record relation"
      ],
      "name": "Crossref updates and Retraction Watch",
      "officialUrls": [
        "https://www.crossref.org/documentation/retrieve-metadata/retraction-watch/",
        "https://www.crossref.org/services/crossmark/",
        "https://www.crossref.org/documentation/crossmark/participating-in-crossmark/"
      ],
      "rights": {
        "commercialReview": "recommended",
        "evidenceUrl": "https://www.crossref.org/documentation/retrieve-metadata/retraction-watch/",
        "fullTextPolicy": "not-ingested",
        "metadataClaim": "The Retraction Watch database distributed by Crossref is CC0; Crossref requests citation when it is used in published work.",
        "redistribution": "Freely reusable as CC0; preserve notice type, date, target, source, record ID, and requested citation. Linked content rights remain separate."
      },
      "risks": [
        "Correction and retraction coverage remains incomplete.",
        "The same assertion may appear from publisher and retraction-watch sources and must not be silently collapsed.",
        "Status must be modeled as sourced, dated evidence rather than a permanent boolean verdict."
      ],
      "role": "integrity-feed",
      "schema": "kingdom.research-source/0.1",
      "tier": "integrity"
    },
    {
      "access": {
        "authentication": "none",
        "documentationUrl": "https://support.datacite.org/docs/harvesting-datacite-doi-metadata",
        "incremental": "cursor",
        "interfaces": [
          "rest",
          "oai-pmh",
          "bulk-snapshot"
        ],
        "mvpMode": "fixture-and-explicit-poll",
        "rateLimit": "Anonymous REST clients receive 500 requests per five minutes; identified and authenticated tiers are higher.",
        "webhook": false
      },
      "authority": {
        "canonicalFor": [
          "DataCite DOI registration metadata",
          "related research object identifiers"
        ],
        "kind": "canonical"
      },
      "coverage": {
        "disciplines": [
          "multidisciplinary"
        ],
        "geography": "Global repository-deposited research objects.",
        "recordTypes": [
          "publication",
          "preprint",
          "dataset",
          "software"
        ]
      },
      "freshness": {
        "expectedLag": "Created-record discovery can miss later metadata updates; updates depend on repository deposits and their metadata practices.",
        "observedOn": "2026-08-20",
        "upstreamCadence": "REST and OAI-PMH expose current metadata; the public full dump is annual and member snapshots are monthly. This MVP's bounded live query selects records by created time only."
      },
      "id": "datacite",
      "identifiers": [
        "DOI",
        "ORCID",
        "ROR",
        "funder ID",
        "award ID",
        "related identifier"
      ],
      "name": "DataCite",
      "officialUrls": [
        "https://support.datacite.org/docs/rest-api",
        "https://support.datacite.org/docs/datacite-oai-pmh",
        "https://support.datacite.org/docs/datacite-public-data-file",
        "https://support.datacite.org/docs/datacite-data-file-use-policy",
        "https://support.datacite.org/docs/rate-limit"
      ],
      "rights": {
        "commercialReview": "not-required",
        "evidenceUrl": "https://support.datacite.org/docs/datacite-data-file-use-policy",
        "fullTextPolicy": "not-ingested",
        "metadataClaim": "DataCite DOI metadata is released under CC0.",
        "redistribution": "Metadata can be redistributed; each linked dataset, software object, or document retains its own rights."
      },
      "risks": [
        "Depositor metadata quality and resource types vary.",
        "Duplicate and version relations require explicit handling.",
        "Metadata CC0 does not grant rights to the identified object."
      ],
      "role": "pid-registry",
      "schema": "kingdom.research-source/0.1",
      "tier": "core"
    },
    {
      "access": {
        "authentication": "none",
        "documentationUrl": "https://europepmc.org/RestfulWebService",
        "incremental": "cursor",
        "interfaces": [
          "rest",
          "oai-pmh",
          "bulk-snapshot"
        ],
        "mvpMode": "fixture-and-explicit-poll",
        "rateLimit": "Public REST is cursor-paged; this module caps explicit polls below the service page maximum.",
        "webhook": false
      },
      "authority": {
        "canonicalFor": [
          "Europe PMC record identifier and aggregation state"
        ],
        "kind": "aggregated"
      },
      "coverage": {
        "disciplines": [
          "biology",
          "health sciences",
          "medicine"
        ],
        "geography": "Global life-science literature, preprints, grants, citations, data links, and text-mined annotations.",
        "recordTypes": [
          "publication",
          "preprint"
        ]
      },
      "freshness": {
        "expectedLag": "Aggregation, citation, text-mining, and publication-link updates can trail primary registries.",
        "observedOn": "2026-08-20",
        "upstreamCadence": "Search APIs expose current indexed records; selected metadata and open-content bulk files update weekly."
      },
      "id": "europe-pmc",
      "identifiers": [
        "PMID",
        "PMCID",
        "DOI",
        "Europe PMC source identifier",
        "grant ID"
      ],
      "name": "Europe PMC",
      "officialUrls": [
        "https://europepmc.org/RestfulWebService",
        "https://europepmc.org/developers",
        "https://www.ebi.ac.uk/about/terms-of-use/"
      ],
      "rights": {
        "commercialReview": "recommended",
        "evidenceUrl": "https://www.ebi.ac.uk/about/terms-of-use/",
        "fullTextPolicy": "not-ingested",
        "metadataClaim": "EMBL-EBI imposes no additional restriction on supplied data beyond rights held by original data owners; public queryability is not itself a reuse grant.",
        "redistribution": "Attribute Europe PMC and EMBL-EBI, comply with original-owner rights, and accept responsibility for third-party permissions. This module republishes selected normalized metadata only and no full text."
      },
      "risks": [
        "Coverage is concentrated in life sciences.",
        "Aggregation and derived citation/entity links can lag.",
        "Full-text rights differ by record."
      ],
      "role": "domain-index",
      "schema": "kingdom.research-source/0.1",
      "tier": "enrichment"
    },
    {
      "access": {
        "authentication": "optional-free-api-key",
        "documentationUrl": "https://help.openalex.org/api/authentication",
        "incremental": "cursor",
        "interfaces": [
          "rest",
          "bulk-snapshot"
        ],
        "mvpMode": "fixture-and-explicit-poll",
        "rateLimit": "Casual basic queries may be keyless; a free key raises the daily budget. List calls have a hard per_page maximum of 100 and cursor paging uses meta.next_cursor.",
        "webhook": false
      },
      "authority": {
        "canonicalFor": [
          "OpenAlex entity identifier and graph assertions"
        ],
        "kind": "aggregated"
      },
      "coverage": {
        "disciplines": [
          "multidisciplinary"
        ],
        "geography": "Broad global graph spanning works, authors, institutions, sources, topics, publishers, and funders.",
        "recordTypes": [
          "publication",
          "preprint",
          "dataset",
          "software"
        ]
      },
      "freshness": {
        "expectedLag": "The MVP uses free from_publication_date discovery, not paid update synchronization; later metadata changes can therefore be missed unless another source reports them.",
        "observedOn": "2026-08-20",
        "upstreamCadence": "The public API supports bounded discovery queries. True from_updated_date/from_created_date synchronization filters and daily changefiles require paid access."
      },
      "id": "openalex",
      "identifiers": [
        "OpenAlex ID",
        "DOI",
        "PMID",
        "PMCID",
        "arXiv ID",
        "ORCID",
        "ROR"
      ],
      "name": "OpenAlex",
      "officialUrls": [
        "https://help.openalex.org/api",
        "https://help.openalex.org/api/authentication",
        "https://help.openalex.org/api/paging"
      ],
      "rights": {
        "commercialReview": "not-required",
        "evidenceUrl": "https://help.openalex.org/api",
        "fullTextPolicy": "not-ingested",
        "metadataClaim": "OpenAlex metadata is released under CC0.",
        "redistribution": "Graph metadata can be redistributed; linked abstracts and content may carry upstream rights and are not ingested here."
      },
      "risks": [
        "Author, topic, citation, and deduplication assertions are algorithmic rather than canonical.",
        "Free publication-date polling is discovery, not a complete update feed.",
        "Do not send a free key with paid-only synchronization filters or describe it as a paid entitlement."
      ],
      "role": "research-graph",
      "schema": "kingdom.research-source/0.1",
      "tier": "enrichment"
    },
    {
      "access": {
        "authentication": "none",
        "documentationUrl": "https://pubmed.ncbi.nlm.nih.gov/download/",
        "incremental": "daily-files",
        "interfaces": [
          "rest",
          "oai-pmh",
          "daily-files",
          "bulk-snapshot"
        ],
        "mvpMode": "fixture-only-policy-hold",
        "rateLimit": "E-utilities permits about three requests per second without a key and ten with a key; bulk daily update files are preferred for complete deltas.",
        "webhook": false
      },
      "authority": {
        "canonicalFor": [
          "PMID",
          "PMCID",
          "NLM-linked correction and retraction status"
        ],
        "kind": "authoritative-domain"
      },
      "coverage": {
        "disciplines": [
          "biology",
          "health sciences",
          "medicine"
        ],
        "geography": "Global biomedical and life-science citations; PMC adds an archive of participating full-text works.",
        "recordTypes": [
          "publication",
          "preprint",
          "status-update"
        ]
      },
      "freshness": {
        "expectedLag": "Publisher deposits, MeSH indexing, and linked corrections may arrive after first citation publication.",
        "observedOn": "2026-08-20",
        "upstreamCadence": "PubMed publishes an annual XML baseline and daily new, revised, and deleted citation files."
      },
      "id": "pubmed-pmc",
      "identifiers": [
        "PMID",
        "PMCID",
        "DOI",
        "ORCID",
        "grant ID",
        "data accession"
      ],
      "name": "PubMed and PubMed Central",
      "officialUrls": [
        "https://pubmed.ncbi.nlm.nih.gov/download/",
        "https://pmc.ncbi.nlm.nih.gov/tools/oai/",
        "https://www.ncbi.nlm.nih.gov/home/develop/api/",
        "https://www.nlm.nih.gov/bsd/policy/errata.html"
      ],
      "rights": {
        "commercialReview": "recommended",
        "evidenceUrl": "https://www.nlm.nih.gov/databases/download/terms_and_conditions.html",
        "fullTextPolicy": "not-ingested",
        "metadataClaim": "NLM database records are downloadable under NLM terms; source-supplied material can retain separate rights.",
        "redistribution": "Attribute NLM, preserve update dates, and label stale or modified data; PMC full text is outside this MVP."
      },
      "risks": [
        "Coverage is biomedical rather than all-discipline.",
        "Indexing and publisher corrections can lag.",
        "Full-text reuse rights are separate from citation metadata."
      ],
      "role": "domain-index",
      "schema": "kingdom.research-source/0.1",
      "tier": "core"
    }
  ],
  "watchlists": [
    {
      "id": "agent-security",
      "keywords": [
        "agent security",
        "capability security",
        "confused deputy",
        "data exfiltration",
        "indirect prompt injection",
        "information flow control",
        "prompt injection",
        "sandbox escape",
        "tool poisoning"
      ],
      "languageScope": {
        "multilingualExpansion": {
          "reason": "No reviewed multilingual term set has been supplied; translations must not be guessed.",
          "state": "absent"
        },
        "queryLanguage": "en"
      },
      "name": "Secure information flow and agent security",
      "need": "Reduce prompt-injection, confused-deputy, data-exfiltration, and capability-escalation risk in agent systems.",
      "priorityFactors": [
        {
          "factor": "named-need-fit",
          "reason": "Expose the exact reviewed security term that matched."
        },
        {
          "factor": "source-authority",
          "reason": "Keep canonical registry evidence separate from aggregator enrichment."
        },
        {
          "factor": "review-state",
          "reason": "Security claims need visible review and replication status."
        },
        {
          "factor": "rights-clarity",
          "reason": "A useful benchmark or implementation still needs explicit reuse rights."
        },
        {
          "factor": "integrity",
          "reason": "Corrections or withdrawals can change the safe interpretation of a result."
        }
      ],
      "schema": "kingdom.research-watchlist/0.1"
    },
    {
      "id": "interpretable-reasoning",
      "keywords": [
        "activation steering",
        "causal tracing",
        "circuit tracing",
        "interpretable reasoning",
        "J-space",
        "Jacobian lens",
        "mechanistic interpretability",
        "representation engineering",
        "sparse autoencoder"
      ],
      "languageScope": {
        "multilingualExpansion": {
          "reason": "No reviewed multilingual term set has been supplied; translations must not be guessed.",
          "state": "absent"
        },
        "queryLanguage": "en"
      },
      "name": "Interpretable reasoning and J-space",
      "need": "Understand, inspect, and test internal reasoning representations without treating a probe or explanation as ground truth.",
      "priorityFactors": [
        {
          "factor": "named-need-fit",
          "reason": "Expose the exact reviewed term that matched the named need."
        },
        {
          "factor": "freshness",
          "reason": "Show source and update dates without treating recency as validity."
        },
        {
          "factor": "review-state",
          "reason": "Distinguish preprint, peer-reviewed, and unknown review states."
        },
        {
          "factor": "integrity",
          "reason": "Surface correction, withdrawal, and retraction evidence without averaging it away."
        }
      ],
      "schema": "kingdom.research-watchlist/0.1"
    },
    {
      "id": "language-agent-interoperability",
      "keywords": [
        "agent interoperability",
        "agent protocol",
        "language-oriented programming",
        "model context protocol",
        "natural-language programming",
        "semantic interface",
        "tool interoperability",
        "tool protocol"
      ],
      "languageScope": {
        "multilingualExpansion": {
          "reason": "No reviewed multilingual term set has been supplied; translations must not be guessed.",
          "state": "absent"
        },
        "queryLanguage": "en"
      },
      "name": "Natural-language programming and agent interoperability",
      "need": "Develop inspectable natural-language software interfaces and interoperable agent protocols with bounded authority.",
      "priorityFactors": [
        {
          "factor": "named-need-fit",
          "reason": "Expose which protocol or language-interface phrase matched."
        },
        {
          "factor": "freshness",
          "reason": "Protocol work changes quickly, so dates matter without becoming a quality score."
        },
        {
          "factor": "source-authority",
          "reason": "Registry metadata and graph-derived relations carry different evidentiary weight."
        },
        {
          "factor": "rights-clarity",
          "reason": "A paper can be visible even when its linked protocol implementation is not reusable."
        }
      ],
      "schema": "kingdom.research-watchlist/0.1"
    }
  ],
  "works": [
    {
      "authors": [
        "Taureka, Wellington"
      ],
      "firstPublishedOn": "2026-08-02",
      "id": "work:001b6af0d2b1fc7f3ac0",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21757178"
        }
      ],
      "itemLicenses": [
        "cc-by-4.0"
      ],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:20Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:6119662c70f05464"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21757178"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-02T09:19:48Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21739163"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplement-to"
        },
        {
          "assertedAt": "2026-08-02T09:19:48Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21757178"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite"
      ],
      "status": "active",
      "subjects": [
        "KV cache",
        "PSCS",
        "Pakheta relational conduction",
        "activation probe",
        "prompt injection",
        "role confusion",
        "semantic security",
        "source isolation"
      ],
      "title": "Role-Styled Prompt Injection: An Activation and KV-State Probe in a Compact Language Model",
      "versions": [
        {
          "label": "1.0",
          "observationId": "observation:datacite:6119662c70f05464",
          "observedAt": "2026-08-20T18:07:20Z",
          "publishedOn": "2026-08-02",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Sahir Maharaj"
      ],
      "firstPublishedOn": "2026-01-01",
      "id": "work:1a4c94016ebdc224b7ac",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.2139/ssrn.7276838"
        }
      ],
      "itemLicenses": [
        "https://creativecommons.org/licenses/by/4.0/"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:16Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:d6ca8526a1b03056"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.2139/ssrn.7276838"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "Measuring Indirect Prompt Injection in Autonomous Web Agents",
      "versions": [
        {
          "label": "posted-content",
          "observationId": "observation:crossref:d6ca8526a1b03056",
          "observedAt": "2026-08-20T18:09:16Z",
          "publishedOn": "2026-01-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Ashish Vishwakarma"
      ],
      "firstPublishedOn": "2026-01-01",
      "id": "work:1f38a749dcc6a37c9b2c",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.2139/ssrn.7184619"
        }
      ],
      "itemLicenses": [
        "https://www.uspto.gov/ip-policy/copyright-policy/copyright-basics"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:14Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:d6920254ad639948"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.2139/ssrn.7184619"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "Securing Federated Model Context Protocol (MCP) and Multi-Agent Supply Chains",
      "versions": [
        {
          "label": "posted-content",
          "observationId": "observation:crossref:d6920254ad639948",
          "observedAt": "2026-08-20T18:09:14Z",
          "publishedOn": "2026-01-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Denis Sutter",
        "Julian Minder",
        "Thomas Hofmann",
        "Tiago Pimentel"
      ],
      "firstPublishedOn": "2025-01-01",
      "id": "work:33ab84eae181cfcbf5de",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.52202/085713-5000"
        }
      ],
      "itemLicenses": [],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:06:56Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:3c987dfc1571681f"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.52202/085713-5000"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "The Non-Linear Representation Dilemma: Is Causal Abstraction Enough for Mechanistic Interpretability?",
      "versions": [
        {
          "label": "proceedings-article",
          "observationId": "observation:crossref:3c987dfc1571681f",
          "observedAt": "2026-08-20T18:06:56Z",
          "publishedOn": "2025-01-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [],
      "firstPublishedOn": "2026-08-20",
      "id": "work:387b73d3d989fd9ab4fb",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1021/acs.jpclett.6c02004.s001"
        }
      ],
      "itemLicenses": [],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:14Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:d67a1b4ed7547770"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.1021/acs.jpclett.6c02004.s001"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "A Toolset-First Paradigm Based on Large Language Model and Agent via Model Context Protocol for Intelligent Computation",
      "versions": [
        {
          "label": "component",
          "observationId": "observation:crossref:d67a1b4ed7547770",
          "observedAt": "2026-08-20T18:09:14Z",
          "publishedOn": "2026-08-20",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "J. Melton"
      ],
      "firstPublishedOn": "2026-08-12",
      "id": "work:4ba9625856afd44e1e1b",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21906711"
        },
        {
          "scheme": "openalex",
          "value": "W7202247495"
        }
      ],
      "itemLicenses": [
        "cc-by"
      ],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:09:27Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:openalex:3639582f7362b788"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21906711"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "openalex"
      ],
      "status": "active",
      "subjects": [
        "Adversarial Robustness in Machine Learning",
        "Domain Adaptation and Few-Shot Learning",
        "Explainable Artificial Intelligence (XAI)"
      ],
      "title": "Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training",
      "versions": [
        {
          "label": "preprint",
          "observationId": "observation:openalex:3639582f7362b788",
          "observedAt": "2026-08-20T18:09:27Z",
          "publishedOn": "2026-08-12",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Doygun Demirol",
        "Murat Aydogan"
      ],
      "firstPublishedOn": "2026-08-02",
      "id": "work:52568adfe1b21f70b343",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.3390/app16157662"
        }
      ],
      "itemLicenses": [
        "https://creativecommons.org/licenses/by/4.0/"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:16Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:6febc941c6477298"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.3390/app16157662"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "Balancing Security and Performance in LLM Agents: Spotlight-Guard, a Layered Defense Against Indirect Prompt Injection",
      "versions": [
        {
          "label": "journal-article",
          "observationId": "observation:crossref:6febc941c6477298",
          "observedAt": "2026-08-20T18:09:16Z",
          "publishedOn": "2026-08-02",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Gautam Bharti"
      ],
      "firstPublishedOn": "2026-08-02",
      "id": "work:59218754c0e3e56078b7",
      "identifiers": [
        {
          "scheme": "arxiv",
          "value": "2608.00997"
        }
      ],
      "itemLicenses": [],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:10:14Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:arxiv:e6f88ec1494225ed"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "arxiv",
        "value": "2608.00997"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "arxiv"
      ],
      "status": "active",
      "subjects": [
        "cs.CR",
        "cs.SE"
      ],
      "title": "Registry Descriptions Go Stale Unevenly: An 89-Day Measurement of Model Context Protocol Drift, and Why Drift-Ranked Re-Auditing Under-Covers It",
      "versions": [
        {
          "label": "v2",
          "observationId": "observation:arxiv:e6f88ec1494225ed",
          "observedAt": "2026-08-20T18:10:14Z",
          "publishedOn": "2026-08-02",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Alaa Alnemari",
        "Mashael M. Alsulami"
      ],
      "firstPublishedOn": "2026-08-15",
      "id": "work:5f8c19452e9c33eecee4",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.3390/electronics15163640"
        }
      ],
      "itemLicenses": [
        "https://creativecommons.org/licenses/by/4.0/"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:16Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:2388068f3e413d55"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.3390/electronics15163640"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "DT-GenShield: A Digital Twin-Driven Runtime Security Architecture for Protecting Large Language Models Against Indirect Prompt Injection",
      "versions": [
        {
          "label": "journal-article",
          "observationId": "observation:crossref:2388068f3e413d55",
          "observedAt": "2026-08-20T18:09:16Z",
          "publishedOn": "2026-08-15",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Arnold, Jaret"
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:60f16fceed98c0791277",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21729883"
        }
      ],
      "itemLicenses": [
        "mit"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:58Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:799f792243ed9d07"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21729883"
      },
      "recordTypes": [
        "software"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-01T00:07:33Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21713452"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        },
        {
          "assertedAt": "2026-08-01T00:07:33Z",
          "identifier": {
            "scheme": "source",
            "value": "datacite:https://github.com/musharna/ldraw-mcp"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplement-to"
        }
      ],
      "reviewStates": [
        "software"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite"
      ],
      "status": "active",
      "subjects": [
        "3d-rendering",
        "blender",
        "ldraw",
        "lego",
        "mcp",
        "model-context-protocol"
      ],
      "title": "ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol",
      "versions": [
        {
          "label": "v0.2.1",
          "observationId": "observation:datacite:799f792243ed9d07",
          "observedAt": "2026-08-20T18:09:58Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "David A. Flynn",
        "Flynn, David C."
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:60f291220d74592bbe4c",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731418"
        },
        {
          "scheme": "openalex",
          "value": "W7172128171"
        }
      ],
      "itemLicenses": [
        "cc-by",
        "cc-by-4.0"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:58Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:1916afceb5a82955",
        "observation:openalex:b3101fd2b0bad721"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21731418"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-01T03:05:08Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21731417"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite",
        "openalex"
      ],
      "status": "active",
      "subjects": [
        "30B Semantic Risk Evaluator",
        "Access Control and Trust",
        "Advanced Authentication Protocols Security",
        "Compositional Tool‑Use Threats",
        "Intent Tree",
        "Model Context Protocol",
        "Security and Verification in Computing",
        "Semantic Zero‑Trust",
        "Signed Intent Manifest",
        "Trusted Context Assembly"
      ],
      "title": "Semantic Zero-Trust for Model Context Protocol",
      "versions": [
        {
          "label": "preprint",
          "observationId": "observation:openalex:b3101fd2b0bad721",
          "observedAt": "2026-08-20T18:07:48Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        },
        {
          "label": "V1",
          "observationId": "observation:datacite:1916afceb5a82955",
          "observedAt": "2026-08-20T18:09:58Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Karabacak M",
        "Margetis K.",
        "Metzger A",
        "Patil S",
        "Sugarmann LR"
      ],
      "firstPublishedOn": "2026-05-27",
      "id": "work:781ee43b5d35cbdbc27c",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.2196/81134"
        },
        {
          "scheme": "pmid",
          "value": "42201744"
        },
        {
          "scheme": "pmcid",
          "value": "PMC13215048"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:MED:42201744"
        }
      ],
      "itemLicenses": [
        "cc by"
      ],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:53Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:europe-pmc:5e5fc3bb812281c3"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.2196/81134"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "europe-pmc"
      ],
      "status": "active",
      "subjects": [
        "Journal Article",
        "research-article"
      ],
      "title": "Application of Sparse Autoencoders to Enhance Mechanistic Interpretability of Large Language Models in Medicine.",
      "versions": [
        {
          "label": "indexed-publication",
          "observationId": "observation:europe-pmc:5e5fc3bb812281c3",
          "observedAt": "2026-08-20T18:07:53Z",
          "publishedOn": "2026-05-27",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Cidade, Irlan de Alvarenga"
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:7aff5c16654194dfc16c",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731493"
        }
      ],
      "itemLicenses": [
        "cc-by-4.0"
      ],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:20Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:da51e63e259cf7cf"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21731493"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-01T03:05:44Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21731493"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite"
      ],
      "status": "active",
      "subjects": [
        "Knowledge Augmented Generation",
        "agentic security",
        "bounded autonomy",
        "bug bounty",
        "evidence-grounded assessments",
        "multi-agent systems",
        "security quality assurance"
      ],
      "title": "The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty",
      "versions": [
        {
          "label": "1.0",
          "observationId": "observation:datacite:da51e63e259cf7cf",
          "observedAt": "2026-08-20T18:07:20Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Sahir Maharaj"
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:82888d501426cfc4b2bf",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21855133"
        },
        {
          "scheme": "openalex",
          "value": "W7201980560"
        }
      ],
      "itemLicenses": [
        "cc-by"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:07:20Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:openalex:440266aaaac7e3cb"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21855133"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "openalex"
      ],
      "status": "active",
      "subjects": [
        "Security and Verification in Computing",
        "Spam and Phishing Detection",
        "Web Application Security Vulnerabilities"
      ],
      "title": "Measuring Indirect Prompt Injection in Autonomous Web Agents",
      "versions": [
        {
          "label": "article",
          "observationId": "observation:openalex:440266aaaac7e3cb",
          "observedAt": "2026-08-20T18:07:20Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Cidade, Irlan de Alvarenga"
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:866c714320a9dcac2337",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731494"
        }
      ],
      "itemLicenses": [
        "cc-by-4.0"
      ],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:20Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:0716c674df8147ca"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21731494"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-01T03:05:44Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21731493"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite"
      ],
      "status": "active",
      "subjects": [
        "Knowledge Augmented Generation",
        "agentic security",
        "bounded autonomy",
        "bug bounty",
        "evidence-grounded assessments",
        "multi-agent systems",
        "security quality assurance"
      ],
      "title": "The Evidence Closure Loop: Engineering a Bounded-Autonomous, Multi-Agent Security Staff for Evidence-Grounded Assessments and Bug Bounty",
      "versions": [
        {
          "label": "1.0",
          "observationId": "observation:datacite:0716c674df8147ca",
          "observedAt": "2026-08-20T18:07:20Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Carstens M",
        "Clusmann J",
        "Kather JN",
        "Kolbinger FR.",
        "Loiselle MS",
        "Martinus FM",
        "Mroczkowski MK",
        "Qadir MI",
        "Zhang EH",
        "Zhang Z"
      ],
      "firstPublishedOn": "2026-07-27",
      "id": "work:92ea0c7c6a02d587904a",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1038/s44484-026-00014-6"
        },
        {
          "scheme": "pmid",
          "value": "42523678"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:MED:42523678"
        }
      ],
      "itemLicenses": [],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:27Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:europe-pmc:d630ceb350736a88"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.1038/s44484-026-00014-6"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "europe-pmc"
      ],
      "status": "active",
      "subjects": [
        "Journal Article"
      ],
      "title": "Prompt injection attacks on vision-language models for surgical decision support.",
      "versions": [
        {
          "label": "indexed-publication",
          "observationId": "observation:europe-pmc:d630ceb350736a88",
          "observedAt": "2026-08-20T18:07:27Z",
          "publishedOn": "2026-07-27",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Pulastya, Prateek"
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:ad2d4e22fd3b2d0ba43b",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21746423"
        }
      ],
      "itemLicenses": [
        "cc-by-4.0"
      ],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:20Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:6ec8c4115f9af5e7"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21746423"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-01T20:21:59Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21746423"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        },
        {
          "assertedAt": "2026-08-01T20:21:59Z",
          "identifier": {
            "scheme": "source",
            "value": "datacite:https://github.com/Prateek-Pulastya/Guardrail-As-A-Service-V2"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplemented-by"
        }
      ],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite"
      ],
      "status": "active",
      "subjects": [
        "Aho-Corasick",
        "DeBERTa",
        "Evaluation Technology",
        "Guardrails",
        "LLM Security",
        "Over-defense",
        "Trust boundaries",
        "prompt injection"
      ],
      "title": "Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection",
      "versions": [
        {
          "label": "1.0.0",
          "observationId": "observation:datacite:6ec8c4115f9af5e7",
          "observedAt": "2026-08-20T18:07:20Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Dilip Thakur",
        "Saroj Mishra",
        "Shiva Gaire",
        "Srijan Gyawali",
        "Suman Niroula",
        "Umesh Yadav"
      ],
      "firstPublishedOn": "2026-08-13",
      "id": "work:ada943d2a88ffb34e416",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1007/978-3-032-32726-0_29"
        },
        {
          "scheme": "openalex",
          "value": "W7114797566"
        }
      ],
      "itemLicenses": [],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:48Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:openalex:b67d730c87cfc5af"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.1007/978-3-032-32726-0_29"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "openalex"
      ],
      "status": "active",
      "subjects": [
        "Adversarial Robustness in Machine Learning",
        "Blockchain Technology Applications and Security",
        "Machine Learning and Algorithms"
      ],
      "title": "Systematization of Knowledge: Security and Safety in the Model Context Protocol Ecosystem",
      "versions": [
        {
          "label": "conference-paper",
          "observationId": "observation:openalex:b67d730c87cfc5af",
          "observedAt": "2026-08-20T18:07:48Z",
          "publishedOn": "2026-08-13",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Arnold, Jaret"
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:b6c0a71544ea079ea9f6",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21736124"
        }
      ],
      "itemLicenses": [
        "mit"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:58Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:67eab70b87c630d0"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21736124"
      },
      "recordTypes": [
        "software"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-01T07:11:35Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21713452"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        },
        {
          "assertedAt": "2026-08-01T07:11:35Z",
          "identifier": {
            "scheme": "source",
            "value": "datacite:https://github.com/musharna/ldraw-mcp"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplement-to"
        }
      ],
      "reviewStates": [
        "software"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite"
      ],
      "status": "active",
      "subjects": [
        "3d-rendering",
        "blender",
        "ldraw",
        "lego",
        "mcp",
        "model-context-protocol"
      ],
      "title": "ldraw-mcp: real-geometry LDraw/LEGO rendering for vision-capable models over the Model Context Protocol",
      "versions": [
        {
          "label": "v0.2.2",
          "observationId": "observation:datacite:67eab70b87c630d0",
          "observedAt": "2026-08-20T18:09:58Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Pulastya, Prateek"
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:b717b7c2eb569e85ac53",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21746424"
        }
      ],
      "itemLicenses": [
        "cc-by-4.0"
      ],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:20Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:00f0afac1c7665c2"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21746424"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-01T20:21:58Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21746423"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        },
        {
          "assertedAt": "2026-08-01T20:21:58Z",
          "identifier": {
            "scheme": "source",
            "value": "datacite:https://github.com/Prateek-Pulastya/Guardrail-As-A-Service-V2"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-supplemented-by"
        }
      ],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite"
      ],
      "status": "active",
      "subjects": [
        "Aho-Corasick",
        "DeBERTa",
        "Evaluation Technology",
        "Guardrails",
        "LLM Security",
        "Over-defense",
        "Trust boundaries",
        "prompt injection"
      ],
      "title": "Trust Boundaries and the Limits of Pattern-Based Prompt Injection Detection",
      "versions": [
        {
          "label": "1.0.0",
          "observationId": "observation:datacite:00f0afac1c7665c2",
          "observedAt": "2026-08-20T18:07:20Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "David A. Flynn",
        "Flynn, David C."
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:c6624953de841194cf4c",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21731417"
        },
        {
          "scheme": "openalex",
          "value": "W7172123867"
        }
      ],
      "itemLicenses": [
        "cc-by",
        "cc-by-4.0"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:58Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:b19e4c97f9b23d62",
        "observation:openalex:5df0413b4f705f15"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21731417"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-01T03:05:09Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21731417"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite",
        "openalex"
      ],
      "status": "active",
      "subjects": [
        "30B Semantic Risk Evaluator",
        "Access Control and Trust",
        "Advanced Authentication Protocols Security",
        "Compositional Tool‑Use Threats",
        "Intent Tree",
        "Model Context Protocol",
        "Security and Verification in Computing",
        "Semantic Zero‑Trust",
        "Signed Intent Manifest",
        "Trusted Context Assembly"
      ],
      "title": "Semantic Zero-Trust for Model Context Protocol",
      "versions": [
        {
          "label": "preprint",
          "observationId": "observation:openalex:5df0413b4f705f15",
          "observedAt": "2026-08-20T18:07:48Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        },
        {
          "label": "V1",
          "observationId": "observation:datacite:b19e4c97f9b23d62",
          "observedAt": "2026-08-20T18:09:58Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Dip Roy"
      ],
      "firstPublishedOn": "2025-05-07",
      "id": "work:d98e745cd4ee2938266d",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.21203/rs.3.rs-6599791/v1"
        }
      ],
      "itemLicenses": [
        "https://creativecommons.org/licenses/by/4.0/"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:06:56Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:9d9767af45efe7de"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.21203/rs.3.rs-6599791/v1"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "Causal Intervention Framework for Variational Auto Encoder Mechanistic Interpretability",
      "versions": [
        {
          "label": "posted-content",
          "observationId": "observation:crossref:9d9767af45efe7de",
          "observedAt": "2026-08-20T18:06:56Z",
          "publishedOn": "2025-05-07",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Bothraj P"
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:df3a3e7ebd80342f9c6f",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21740544"
        }
      ],
      "itemLicenses": [
        "cc-by-4.0"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:58Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:datacite:6e71c79f4f0f367c"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21740544"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [
        {
          "assertedAt": "2026-08-01T14:22:02Z",
          "identifier": {
            "scheme": "doi",
            "value": "10.5281/zenodo.21740544"
          },
          "recordId": null,
          "source": "datacite-deposit",
          "type": "is-version-of"
        }
      ],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "datacite"
      ],
      "status": "active",
      "subjects": [
        "AI Agents",
        "Agentci AI",
        "Artificial Intelligence",
        "Large Language Models",
        "Model Context Protocol",
        "Natural Language to SQL",
        "Retrieval-Augmented Generation"
      ],
      "title": "Enterprise Agentic AI: A Reference Architecture for Natural Language to SQL, Model Context Protocol (MCP), Retrieval-Augmented Generation (RAG), Multi-Agent Systems, and Production AI",
      "versions": [
        {
          "label": "v1.0",
          "observationId": "observation:datacite:6e71c79f4f0f367c",
          "observedAt": "2026-08-20T18:09:58Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Amisha Bagari",
        "Hayretdin Bahsi",
        "Neha Nagaraja"
      ],
      "firstPublishedOn": "2026-08-01",
      "id": "work:df6d1e5df83d5ccd8e6b",
      "identifiers": [
        {
          "scheme": "arxiv",
          "value": "2608.00747"
        }
      ],
      "itemLicenses": [],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:21Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:arxiv:28c2c5fcfeca666e"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "arxiv",
        "value": "2608.00747"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "arxiv"
      ],
      "status": "active",
      "subjects": [
        "cs.AI",
        "cs.CR",
        "cs.MA",
        "cs.RO"
      ],
      "title": "When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems",
      "versions": [
        {
          "label": "v2",
          "observationId": "observation:arxiv:28c2c5fcfeca666e",
          "observedAt": "2026-08-20T18:07:21Z",
          "publishedOn": "2026-08-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Aaron Grattafiori",
        "Arman Zharmagambetov",
        "Chuan Guo",
        "Ivan Evtimov",
        "Kamalika Chaudhuri"
      ],
      "firstPublishedOn": "2025-01-01",
      "id": "work:e3076bbde42e9e0457ef",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.52202/085713-0666"
        }
      ],
      "itemLicenses": [],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:16Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:ab21ffe4074b8d82"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.52202/085713-0666"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "WASP: Benchmarking Web Agent Security Against Prompt Injection Attacks",
      "versions": [
        {
          "label": "proceedings-article",
          "observationId": "observation:crossref:ab21ffe4074b8d82",
          "observedAt": "2026-08-20T18:09:16Z",
          "publishedOn": "2025-01-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Dongxiao Zhu",
        "Nafis Fuad",
        "Xiaodong Qian"
      ],
      "firstPublishedOn": "2026-08-02",
      "id": "work:e380067170267187adf4",
      "identifiers": [
        {
          "scheme": "arxiv",
          "value": "2608.07562"
        }
      ],
      "itemLicenses": [],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:49Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:arxiv:bb59396c7fe27bb3"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "arxiv",
        "value": "2608.07562"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "arxiv"
      ],
      "status": "active",
      "subjects": [
        "cs.CV",
        "cs.LG"
      ],
      "title": "Mechanistic Interpretability-Guided Selective Fine-Tuning of Vision-Language Models for Centimeter-Level Flood Depth Estimation",
      "versions": [
        {
          "label": "v1",
          "observationId": "observation:arxiv:bb59396c7fe27bb3",
          "observedAt": "2026-08-20T18:07:49Z",
          "publishedOn": "2026-08-02",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "J. Melton"
      ],
      "firstPublishedOn": "2026-08-14",
      "id": "work:e40090ba1132c62ea71c",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.5281/zenodo.21906710"
        },
        {
          "scheme": "openalex",
          "value": "W7202273798"
        }
      ],
      "itemLicenses": [
        "cc-by"
      ],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:09:27Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:openalex:73435497545114aa"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.5281/zenodo.21906710"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "openalex"
      ],
      "status": "active",
      "subjects": [
        "Adversarial Robustness in Machine Learning",
        "Domain Adaptation and Few-Shot Learning",
        "Explainable Artificial Intelligence (XAI)"
      ],
      "title": "Distributed Mechanistic Interpretability at Scale: Activation Streaming, Split-Layer Inference, and Distributed Sparse Autoencoder Training",
      "versions": [
        {
          "label": "preprint",
          "observationId": "observation:openalex:73435497545114aa",
          "observedAt": "2026-08-20T18:09:27Z",
          "publishedOn": "2026-08-14",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Janis Keuper"
      ],
      "firstPublishedOn": "2026-08-03",
      "id": "work:e4dd5c51eb6b1b9ea2b0",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1007/978-3-032-31335-5_9"
        },
        {
          "scheme": "openalex",
          "value": "W4415090291"
        }
      ],
      "itemLicenses": [],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:20Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:openalex:c05cc5aedbbe1943"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.1007/978-3-032-31335-5_9"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "openalex"
      ],
      "status": "active",
      "subjects": [
        "Digital and Cyber Forensics",
        "Security and Verification in Computing",
        "Web Application Security Vulnerabilities"
      ],
      "title": "Prompt Injection Attacks on LLM Generated Reviews of Scientific Publications",
      "versions": [
        {
          "label": "conference-paper",
          "observationId": "observation:openalex:c05cc5aedbbe1943",
          "observedAt": "2026-08-20T18:07:20Z",
          "publishedOn": "2026-08-03",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Bhuvan Sai Teja Gabbita"
      ],
      "firstPublishedOn": "2025-11-12",
      "id": "work:e819919fe3140aac1ef6",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.62791/20494"
        }
      ],
      "itemLicenses": [
        "http://creativecommons.org/licenses/by-nc-nd/4.0/"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:14Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:ecced040bec1000c"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.62791/20494"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "Towards secure agentic workflows: a MAESTRO-based assessment framework for Model Context Protocol and Agent-to-Agent Protocol",
      "versions": [
        {
          "label": "dissertation",
          "observationId": "observation:crossref:ecced040bec1000c",
          "observedAt": "2026-08-20T18:09:14Z",
          "publishedOn": "2025-11-12",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Mustafa Erşahin",
        "Pınar Ersoy"
      ],
      "firstPublishedOn": "2026-07-01",
      "id": "work:ee6800fe825dd1f14f79",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1109/icecet65726.2026.11632629"
        }
      ],
      "itemLicenses": [
        "https://ieeexplore.ieee.org/Xplorehelp/downloads/license-information/IEEE.html"
      ],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:16Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:crossref:792b9edd45cc7292"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.1109/icecet65726.2026.11632629"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "crossref"
      ],
      "status": "active",
      "subjects": [],
      "title": "Secure MCP-Based Tool-Augmented RAG for Industrial IoT Diagnostics Under Indirect Prompt Injection, Retrieval Poisoning, and Modality Outages",
      "versions": [
        {
          "label": "proceedings-article",
          "observationId": "observation:crossref:792b9edd45cc7292",
          "observedAt": "2026-08-20T18:09:16Z",
          "publishedOn": "2026-07-01",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Bo Cheng",
        "Qiaolin Lu",
        "Yi Chang",
        "Yuan Wu"
      ],
      "firstPublishedOn": "2026-08-08",
      "id": "work:f0afa9fe8652ed9ab84d",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.48550/arxiv.2608.08168"
        },
        {
          "scheme": "openalex",
          "value": "W7202210108"
        }
      ],
      "itemLicenses": [],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:09:27Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:openalex:1b8e64b22e3dadc2"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.48550/arxiv.2608.08168"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "openalex"
      ],
      "status": "active",
      "subjects": [
        "Multimodal Machine Learning Applications",
        "Text Readability and Simplification",
        "Topic Modeling"
      ],
      "title": "Thinking vs. NoThinking: Towards Interpreting Reasoning Mechanisms of Large Language Models via Sparse Autoencoders",
      "versions": [
        {
          "label": "preprint",
          "observationId": "observation:openalex:1b8e64b22e3dadc2",
          "observedAt": "2026-08-20T18:09:27Z",
          "publishedOn": "2026-08-08",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Rashidi M."
      ],
      "firstPublishedOn": "2026-08-11",
      "id": "work:f96d771f15df8add52e7",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.21203/rs.3.rs-10646218/v1"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:PPR:PPR1296126"
        }
      ],
      "itemLicenses": [],
      "languages": [],
      "latestObservedAt": "2026-08-20T18:07:27Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:europe-pmc:a25ee238b7d86ca6"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.21203/rs.3.rs-10646218/v1"
      },
      "recordTypes": [
        "preprint"
      ],
      "relations": [],
      "reviewStates": [
        "preprint"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "europe-pmc"
      ],
      "status": "active",
      "subjects": [
        "Preprint"
      ],
      "title": "Labelled-Metadata Channels and Declarative Payload Phrasing in Hidden Prompt Injection: A Cross-Format Measurement Study",
      "versions": [
        {
          "label": "preprint",
          "observationId": "observation:europe-pmc:a25ee238b7d86ca6",
          "observedAt": "2026-08-20T18:07:27Z",
          "publishedOn": "2026-08-11",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Boscolo A",
        "De Cassai A",
        "Dost B",
        "Navalesi P.",
        "Pistollato E",
        "Zarantonello F"
      ],
      "firstPublishedOn": "2026-08-11",
      "id": "work:fab03dbb7fc3c02d82d8",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1016/j.bja.2026.06.041"
        },
        {
          "scheme": "pmid",
          "value": "42580931"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:MED:42580931"
        }
      ],
      "itemLicenses": [],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:27Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:europe-pmc:52129ee39ae1f6a0"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.1016/j.bja.2026.06.041"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "europe-pmc"
      ],
      "status": "active",
      "subjects": [
        "Letter"
      ],
      "title": "Prompt injection compromises large language model-based peer review: evidence from randomised controlled trial abstracts from anaesthesia journals.",
      "versions": [
        {
          "label": "indexed-publication",
          "observationId": "observation:europe-pmc:52129ee39ae1f6a0",
          "observedAt": "2026-08-20T18:07:27Z",
          "publishedOn": "2026-08-11",
          "status": "active"
        }
      ]
    },
    {
      "authors": [
        "Basu S",
        "Batniji R.",
        "Elamaran N",
        "Kinra A",
        "Muralidharan B",
        "Patel S",
        "Sheth P"
      ],
      "firstPublishedOn": "2026-02-10",
      "id": "work:fbbda07538a116c22ad3",
      "identifiers": [
        {
          "scheme": "doi",
          "value": "10.1136/bmjhci-2025-101935"
        },
        {
          "scheme": "pmid",
          "value": "41667212"
        },
        {
          "scheme": "pmcid",
          "value": "PMC12911724"
        },
        {
          "scheme": "source",
          "value": "europe-pmc:MED:41667212"
        }
      ],
      "itemLicenses": [
        "cc by-nc"
      ],
      "languages": [
        "en"
      ],
      "latestObservedAt": "2026-08-20T18:07:53Z",
      "lifecycle": {
        "adoption": "not-recorded",
        "discovery": "observed",
        "evaluation": "not-performed",
        "use": "not-authorized"
      },
      "observationIds": [
        "observation:europe-pmc:37fb2684bcb2e0fc"
      ],
      "paths": {
        "guest": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        },
        "module": {
          "requiresSeparateAdoption": true,
          "requiresSeparateEvaluation": true,
          "requiresSeparateUseAuthority": true,
          "state": "not-proposed"
        }
      },
      "primaryIdentifier": {
        "scheme": "doi",
        "value": "10.1136/bmjhci-2025-101935"
      },
      "recordTypes": [
        "publication"
      ],
      "relations": [],
      "reviewStates": [
        "unknown"
      ],
      "schema": "kingdom.research-work/0.1",
      "sourceIds": [
        "europe-pmc"
      ],
      "status": "active",
      "subjects": [
        "Journal Article",
        "research-article"
      ],
      "title": "Mechanistic interpretability of reinforcement learning in Medicaid care coordination.",
      "versions": [
        {
          "label": "indexed-publication",
          "observationId": "observation:europe-pmc:37fb2684bcb2e0fc",
          "observedAt": "2026-08-20T18:07:53Z",
          "publishedOn": "2026-02-10",
          "status": "active"
        }
      ]
    }
  ]
}
