{
  "schema": "camden.source_review.v1",
  "at": "2026-09-23T06:08:34.765689+00:00",
  "sources": [
    {
      "source_id": "EFFECT26",
      "url": "https://arxiv.org/html/2609.15397v1",
      "accessed_at": "2026-09-23T05:00:34.055487+00:00",
      "http_status": 200,
      "body_sha256": "a57906aa9b60ef71e288bb3fed0105990259ff58b639f9c73c284b1ea14363c6",
      "retrieval_truncated": false,
      "observed_title": "When Tool Calls Succeed but Workflows Fail:Anomalies at the Agent–Tool Boundary",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "RAJ26",
      "url": "https://arxiv.org/html/2607.28802v1",
      "accessed_at": "2026-09-23T05:00:34.056651+00:00",
      "http_status": 200,
      "body_sha256": "2add8abb06b799b8eac6857f03be2c6da848fe9c78ab4c3e7745a0a4f1f30555",
      "retrieval_truncated": false,
      "observed_title": "Model or Harness? An Interaction-Centric Taxonomy forLocalizing Agent Failures",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "MCPFAULT26",
      "url": "https://arxiv.org/html/2603.05637v1",
      "accessed_at": "2026-09-23T05:00:34.056651+00:00",
      "http_status": 200,
      "body_sha256": "0f06fa547dbafba60a5491163b4494e314b759f70216390bcc06c7ac6e0d95e3",
      "retrieval_truncated": false,
      "observed_title": "Real Faults in Model Context Protocol (MCP) Software: a Comprehensive Taxonomy",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "AGFAULT26",
      "url": "https://arxiv.org/html/2603.06847v1",
      "accessed_at": "2026-09-23T05:00:34.057826+00:00",
      "http_status": 200,
      "body_sha256": "a092be8ef6c1d706a918195ec2de09545c586398ad390efc9338216430406d4b",
      "retrieval_truncated": false,
      "observed_title": "Characterizing Faults in Agentic AI: A Taxonomy of Types, Symptoms, and Root Causes",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "MAST25",
      "url": "https://arxiv.org/html/2503.13657v3",
      "accessed_at": "2026-09-23T05:00:34.340785+00:00",
      "http_status": 200,
      "body_sha256": "ace1d2ed4facba29148639274ec57d8c1ff698ac272ae50ba227a3d8692976f1",
      "retrieval_truncated": false,
      "observed_title": "Why Do Multi-Agent LLM Systems Fail?",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "TOOLSCAN25",
      "url": "https://arxiv.org/html/2411.13547v2",
      "accessed_at": "2026-09-23T05:00:34.409340+00:00",
      "http_status": 200,
      "body_sha256": "19072ceeae67d95420047a8392efd44850ff74966336fe7cf4feda6d55b8416c",
      "retrieval_truncated": false,
      "observed_title": "ToolScan: A Benchmark for Characterizing Errors in Tool-Use LLMs",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "TOOLBENCHX26",
      "url": "https://arxiv.org/html/2606.25819v1",
      "accessed_at": "2026-09-23T05:00:34.439172+00:00",
      "http_status": 200,
      "body_sha256": "f6f9d35cb3ffd0f240f9198f844b501aab2009f7521b917109b3796d278bfe4d",
      "retrieval_truncated": false,
      "observed_title": "Beyond Function Calling: Benchmarking Tool-Using Agents under Tool-Environment Unreliability",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "CHAOS26",
      "url": "https://arxiv.org/html/2608.14680v1",
      "accessed_at": "2026-09-23T05:00:34.459305+00:00",
      "http_status": 200,
      "body_sha256": "8cf14573453a3c4139541aef4cbd011851803b9833428bc5fb3036834b09464b",
      "retrieval_truncated": false,
      "observed_title": "When Agentic Executions Fail: Detecting and Localizing Runtime Faults from Telemetry",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "MEMFAIL26",
      "url": "https://arxiv.org/html/2605.26667v1",
      "accessed_at": "2026-09-23T05:00:34.578690+00:00",
      "http_status": 200,
      "body_sha256": "373351843152ce0de82690707df5039acdb8ae85dc7c2cb9decc130681a5f926",
      "retrieval_truncated": true,
      "observed_title": "MemFail: Stress-Testing Failure Modes of LLM Memory Systems",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "MEMDRIFT26",
      "url": "https://arxiv.org/html/2605.24941v1",
      "accessed_at": "2026-09-23T05:00:34.590884+00:00",
      "http_status": 200,
      "body_sha256": "c4f939188e1bb8c74a3405ca86ec6d0ee18f9796c0656174dabdc7fd7e61f932",
      "retrieval_truncated": true,
      "observed_title": "Memory-Induced Tool-Drift in LLM Agents",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "MINJA25",
      "url": "https://arxiv.org/html/2503.03704v4",
      "accessed_at": "2026-09-23T05:00:34.633919+00:00",
      "http_status": 200,
      "body_sha256": "be900a875f110570cdbae9d51ecf0156f73dfe8a4c69162d34636000e436e2d9",
      "retrieval_truncated": false,
      "observed_title": "Memory Injection Attacks on LLM Agents via Query-Only Interaction",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "MEMRISK26",
      "url": "https://arxiv.org/abs/2605.17830",
      "accessed_at": "2026-09-23T05:00:34.636981+00:00",
      "http_status": 200,
      "body_sha256": "74d78c325380f58a7fed9466cf276b1974e0c9d6d9dc54b0dcd658bd9df8e6be",
      "retrieval_truncated": false,
      "observed_title": "[2605.17830] Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "PLAUSIBLE26",
      "url": "https://arxiv.org/html/2606.14589v1",
      "accessed_at": "2026-09-23T05:00:34.781767+00:00",
      "http_status": 200,
      "body_sha256": "619c6bfd41b65b46d99fc0760341169aadf16d441d2e2cfd34572b13293d253d",
      "retrieval_truncated": false,
      "observed_title": "When Errors Become Narratives: A Longitudinal Taxonomy of Silent Failures in a Production LLM Agent Runtime",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "TOCTOU25",
      "url": "https://arxiv.org/abs/2508.17155",
      "accessed_at": "2026-09-23T05:00:34.864523+00:00",
      "http_status": 200,
      "body_sha256": "61b35f8ac774f174d9d671fbbb1e9789f0f29e34561eb6afad981149bc6795f4",
      "retrieval_truncated": false,
      "observed_title": "[2508.17155] Mind the Gap: Time-of-Check to Time-of-Use Vulnerabilities in LLM-Enabled Agents",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "PROGRESS26",
      "url": "https://arxiv.org/abs/2609.18849",
      "accessed_at": "2026-09-23T05:00:34.890611+00:00",
      "http_status": 200,
      "body_sha256": "5e9685cbe60af7340f0e4826b56e0af9fe3b4a2e5813b903746c4cf5e38e8ed4",
      "retrieval_truncated": false,
      "observed_title": "[2609.18849] Ask the Tool, Don&#39;t Guess: Agent Tool Calls Hold Their Progress, and the Serving System Should Read It",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "AGENTLEAK26",
      "url": "https://arxiv.org/html/2602.11510v1",
      "accessed_at": "2026-09-23T05:00:35.006856+00:00",
      "http_status": 200,
      "body_sha256": "d743053774158cc209c1d780d4db14bd22d4074fceceab6056e150ed0374f5c7",
      "retrieval_truncated": false,
      "observed_title": "AgentLeak: A Full-Stack Benchmark for Privacy Leakage in Multi-Agent LLM Systems",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "AGENTRX26",
      "url": "https://arxiv.org/html/2602.02475v1",
      "accessed_at": "2026-09-23T05:00:35.026708+00:00",
      "http_status": 200,
      "body_sha256": "0af76c9cb51da5ad16fdb4b0da68bd4227d8a667591221105fff68c70c0b6b4d",
      "retrieval_truncated": false,
      "observed_title": "AgentRx: Diagnosing AI Agent Failures from Execution Trajectories",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "AGENTEVAL26",
      "url": "https://arxiv.org/html/2604.23581v1",
      "accessed_at": "2026-09-23T05:00:35.042062+00:00",
      "http_status": 200,
      "body_sha256": "c0aee642fe100b945173781cc50fdf8843245e78dc99b3068bb8ef59e98e21d7",
      "retrieval_truncated": false,
      "observed_title": "AgentEval: DAG-Structured Step-Level Evaluationfor Agentic Workflows with Error Propagation Tracking",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "AIRT26",
      "url": "https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/bade/documents/products-and-services/en-us/security/Taxonomy-of-Failure-Modes-in-Agentic-AI-Systems-v2-0.pdf",
      "accessed_at": "2026-09-23T05:00:35.091358+00:00",
      "http_status": 200,
      "body_sha256": "6ca740d5762e10b8160d0313477862738e58dbd2f06128653215412b7e916b5c",
      "retrieval_truncated": false,
      "observed_title": null,
      "review_scope": "SELECTED_RENDERED_PAGES_REVIEWED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "OWASP26",
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "accessed_at": "2026-09-23T05:00:35.232329+00:00",
      "http_status": 200,
      "body_sha256": "be7c3d0c8346201c765253f49ea1f3f9710989a543dd12500015aeacc2744df2",
      "retrieval_truncated": false,
      "observed_title": "OWASP Top 10 for Agentic Applications for 2026 - OWASP Gen AI Security Project",
      "review_scope": "LANDING_PAGE_ONLY_TAXONOMY_SUPPORT_UNVERIFIED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Retained body identifies the 2026 project landing page, but the searched taxonomy passages were not exposed. Individual mappings retain the supplied basis and are not independently certified here."
    },
    {
      "source_id": "HARNESSES25",
      "url": "https://www.anthropic.com/engineering/effective-harnesses-for-long-running-agents",
      "accessed_at": "2026-09-23T05:00:35.276423+00:00",
      "http_status": 200,
      "body_sha256": "cbfaf177749282e812f71511537f3021456c17d8c09614d476f012afa2f0acff",
      "retrieval_truncated": false,
      "observed_title": "Effective harnesses for long-running agents \\ Anthropic",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected progress/testing and future-work paragraphs describe one web-development harness. Generalization and single versus multiple agent performance remain open; this is not authority to spawn agents."
    },
    {
      "source_id": "AWSID",
      "url": "https://aws.amazon.com/builders-library/making-retries-safe-with-idempotent-APIs/",
      "accessed_at": "2026-09-23T05:00:35.293330+00:00",
      "http_status": 200,
      "body_sha256": "562c4f98a19242d266665aca0d83521267ceb30b1cb4c76c3287996877e0d8d1",
      "retrieval_truncated": false,
      "observed_title": "references-details-empty",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Body contains the client request identity and parameter-mismatch discussion despite the extracted references-details-empty title. At-most-once commitments are scoped to particular API contracts, with implementation cost and complexity."
    },
    {
      "source_id": "STRIPEID",
      "url": "https://docs.stripe.com/api/idempotent_requests",
      "accessed_at": "2026-09-23T05:00:35.487217+00:00",
      "http_status": 200,
      "body_sha256": "77b006f18c1c9ec43be18177d89a7345b2bd1b20eed97943b4cc1172a15663aa",
      "retrieval_truncated": false,
      "observed_title": "Idempotent requests | Stripe API Reference",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "The retained v1 page describes pruning after at least 24 hours, new requests after pruning, parameter comparison and results retained only after execution begins. Do not generalize this to all Stripe APIs."
    },
    {
      "source_id": "STRIPEV2",
      "url": "https://docs.stripe.com/api-v2-overview",
      "accessed_at": "2026-09-23T05:00:35.539047+00:00",
      "http_status": 200,
      "body_sha256": "ff82d331be45d52d55f12a67158aaa119ce554c1b75596eb09dd39f574706827",
      "retrieval_truncated": false,
      "observed_title": "API v2 overview | Stripe Documentation",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Retained v2 page distinguishes same API/account or sandbox within 30 days, POST and DELETE, and retries that may provide updated responses. Its scope differs from v1."
    },
    {
      "source_id": "OUTBOX",
      "url": "https://docs.aws.amazon.com/prescriptive-guidance/latest/cloud-design-patterns/transactional-outbox.html",
      "accessed_at": "2026-09-23T05:00:35.567627+00:00",
      "http_status": 200,
      "body_sha256": "8444f45302b4af60a33ae465c2fac9a48190a915a5c2b1f893692799b6546d7f",
      "retrieval_truncated": false,
      "observed_title": "Transactional outbox pattern - AWS Prescriptive Guidance",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected issues describe duplicate messages, consumer deduplication, ordering, rollback and multi-service transaction concerns. Outbox alone is not exactly-once business completion."
    },
    {
      "source_id": "SAGA",
      "url": "https://learn.microsoft.com/en-us/azure/architecture/patterns/compensating-transaction",
      "accessed_at": "2026-09-23T05:00:35.577959+00:00",
      "http_status": 200,
      "body_sha256": "410758fd7a2643bbd181418068241d21227ef157bc1271767cfea1ca6a5c6bdb",
      "retrieval_truncated": false,
      "observed_title": "Compensating Transaction Pattern - Azure Architecture Center | Microsoft Learn",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected text requires compensation to account for concurrent application changes. Restoring an old snapshot can overwrite those changes. No generic inverse guarantee inferred."
    },
    {
      "source_id": "PGISO",
      "url": "https://www.postgresql.org/docs/18/transaction-iso.html",
      "accessed_at": "2026-09-23T05:00:35.823439+00:00",
      "http_status": 200,
      "body_sha256": "beef1cd1c5f512e3934fd049454730e3cc9d459e69db8e938bf941125387cefc",
      "retrieval_truncated": false,
      "observed_title": "PostgreSQL: Documentation: 18: 13.2. Transaction Isolation",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected Serializable discussion requires applications to handle serialization failures and retry the whole transaction. No remote external-effect atomicity inferred."
    },
    {
      "source_id": "PGPITR",
      "url": "https://www.postgresql.org/docs/18/continuous-archiving.html",
      "accessed_at": "2026-09-23T05:00:35.932696+00:00",
      "http_status": 200,
      "body_sha256": "fa69a344ad55a482760d069b6dfa0d94d80b5058d88b171148d94e168ae78346",
      "retrieval_truncated": false,
      "observed_title": "PostgreSQL: Documentation: 18: 25.3. Continuous Archiving and Point-in-Time Recovery (PITR)",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected continuous-archiving caveats describe template/database and absolute tablespace-path recovery limits. Database recovery is not reversal of external effects; full backup procedure not qualified here."
    },
    {
      "source_id": "SQLITE",
      "url": "https://sqlite.org/howtocorrupt.html",
      "accessed_at": "2026-09-23T05:00:36.049080+00:00",
      "http_status": 200,
      "body_sha256": "e00709e3f37e95332d8e6df243510665e9cab1d7938d4fd85cbf5f47648a50bf",
      "retrieval_truncated": false,
      "observed_title": "How To Corrupt An SQLite Database File",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected live-copy guidance names the backup API, VACUUM INTO and journal preservation. Copying only the live database file is not established as a consistent backup."
    },
    {
      "source_id": "TEMPORAL",
      "url": "https://docs.temporal.io/workflow-definition",
      "accessed_at": "2026-09-23T05:00:36.107017+00:00",
      "http_status": 200,
      "body_sha256": "d4f7b1032326a99c4d127d3d01813a2cd9b8354536d88428e3eaf7f77fdec26d",
      "retrieval_truncated": false,
      "observed_title": "Temporal Workflow Definition | Temporal Documentation",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Retained workflow definition distinguishes replay constraints, command-generating APIs and Activities. Documentation comparison is not execution or a proof of connector effect semantics."
    },
    {
      "source_id": "FENCES",
      "url": "https://martin.kleppmann.com/2016/02/08/how-to-do-distributed-locking.html",
      "accessed_at": "2026-09-23T05:00:36.309621+00:00",
      "http_status": 200,
      "body_sha256": "1545a172a17efa5f1804076a7b3e9e74a3ff3452467511f35eb217c712a5b592",
      "retrieval_truncated": false,
      "observed_title": "How to do distributed locking &mdash; Martin Kleppmann&rsquo;s blog",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected discussion requires fencing checks at protected resource accesses. Merely generating a token or holding a client-side lock does not stop a delayed writer."
    },
    {
      "source_id": "FLP85",
      "url": "https://groups.csail.mit.edu/tds/papers/Lynch/jacm85.pdf",
      "accessed_at": "2026-09-23T05:00:36.364934+00:00",
      "http_status": 200,
      "body_sha256": "80e1c33be45362d6ce0eeaba0259939df16eaff592cd612d42d783e4686c82b7",
      "retrieval_truncated": false,
      "observed_title": null,
      "review_scope": "SELECTED_RENDERED_PAGES_REVIEWED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "RIFL15",
      "url": "https://sigops.org/s/conferences/sosp/2015/current/2015-Monterey/126-lee-online.pdf",
      "accessed_at": "2026-09-23T05:00:36.396144+00:00",
      "http_status": 200,
      "body_sha256": "29bc02629cb5ab7b6364866ed78799e9d31639d6e4101a67f1f90294191517fc",
      "retrieval_truncated": false,
      "observed_title": null,
      "review_scope": "SELECTED_RENDERED_PAGES_REVIEWED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "RFC9110",
      "url": "https://www.rfc-editor.org/rfc/rfc9110.html",
      "accessed_at": "2026-09-23T05:00:36.492300+00:00",
      "http_status": 200,
      "body_sha256": "d431760660ea44e130f6e919dab216df2d0b3a490567a98089267523368fe1e5",
      "retrieval_truncated": false,
      "observed_title": "RFC 9110: HTTP Semantics",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Section 15.3.3 describes HTTP 202 as noncommittal acceptance for asynchronous processing. It is not proof that processing completed."
    },
    {
      "source_id": "RFC9700",
      "url": "https://www.rfc-editor.org/rfc/rfc9700.html",
      "accessed_at": "2026-09-23T05:00:36.516318+00:00",
      "http_status": 200,
      "body_sha256": "c00e2234fcd79581bc29669c60d693afaa42f67d9205bddee848f757ae975419",
      "retrieval_truncated": false,
      "observed_title": "RFC 9700: Best Current Practice for OAuth 2.0 Security",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected audience-restriction discussion scopes access tokens to resource servers and notes functional/privacy consequences. It does not authenticate a local transcript or grant release authority."
    },
    {
      "source_id": "RFC8785",
      "url": "https://www.rfc-editor.org/rfc/rfc8785.html",
      "accessed_at": "2026-09-23T05:00:36.761551+00:00",
      "http_status": 200,
      "body_sha256": "a644657e1e1fc460aa4958fb93c111cacf945a6b9f5999c854c60641c858b832",
      "retrieval_truncated": false,
      "observed_title": "RFC 8785: JSON Canonicalization Scheme (JCS)",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected canonicalization discussion concerns a serialization filter for cryptographic schemes. No semantic truth or business-effect correctness follows from canonical bytes."
    },
    {
      "source_id": "RFC3339",
      "url": "https://www.rfc-editor.org/rfc/rfc3339.html",
      "accessed_at": "2026-09-23T05:00:36.827362+00:00",
      "http_status": 200,
      "body_sha256": "c53b2d121b9f284e2cb28e2989c907470ae26a9db441bcd8a3236c6004a60bee",
      "retrieval_truncated": false,
      "observed_title": null,
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Section 4.3 distinguishes unknown local offset -00:00 from Z or +00:00. Timestamp syntax alone does not synchronize clocks or establish event ordering."
    },
    {
      "source_id": "K8SAPI",
      "url": "https://kubernetes.io/docs/reference/using-api/api-concepts/",
      "accessed_at": "2026-09-23T05:00:36.894725+00:00",
      "http_status": 200,
      "body_sha256": "555c9c8ca5f31884cf48138032e8c110bc7853ef5c163297782251bca6ee4c40",
      "retrieval_truncated": false,
      "observed_title": "Kubernetes API Concepts | Kubernetes",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected unavailable-resource-version text permits timeout/Retry-After responses and distinguishes expired versions. A failed observer does not by itself prove object absence."
    },
    {
      "source_id": "K8SGC",
      "url": "https://kubernetes.io/docs/concepts/architecture/garbage-collection/",
      "accessed_at": "2026-09-23T05:00:36.922529+00:00",
      "http_status": 200,
      "body_sha256": "43f3d3f507421c5551e89e15d37bd9487f4773e8002d6297e14b474ca070ea79",
      "retrieval_truncated": false,
      "observed_title": "Garbage Collection | Kubernetes",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected deletion text distinguishes background deletion, foreground deletion and orphaned dependents. A deletion request is not a receipt that every dependent effect has vanished."
    },
    {
      "source_id": "K8SCTRL",
      "url": "https://kubernetes.io/docs/concepts/architecture/controller/",
      "accessed_at": "2026-09-23T05:00:37.007788+00:00",
      "http_status": 200,
      "body_sha256": "ca5018ccc3ef70ccbe88b65674ff8fd8c2184c582c50d0922feba38a85a531bb",
      "retrieval_truncated": false,
      "observed_title": "Controllers | Kubernetes",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected controller discussion separates desired resources, control loops and linked managed resources; controllers themselves may fail. A stored desired state is not observed convergence."
    },
    {
      "source_id": "SRELOAD",
      "url": "https://sre.google/sre-book/handling-overload/",
      "accessed_at": "2026-09-23T05:00:37.027760+00:00",
      "http_status": 200,
      "body_sha256": "8ca912a82390e7f61e8bbae7baab3a74489f5068d71dee1ff24aed99375e0373",
      "retrieval_truncated": false,
      "observed_title": "Google SRE: Load Balancing with Client Side Throttling",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected retry discussion scopes retries to the immediate failing layer and uses budgets to avoid multiplied retries. This is not authorization to reset a spent budget."
    },
    {
      "source_id": "SRECASCADE",
      "url": "https://sre.google/sre-book/addressing-cascading-failures/",
      "accessed_at": "2026-09-23T05:00:37.309893+00:00",
      "http_status": 200,
      "body_sha256": "f16f9a582bab016af83c9393e56d7571ba91b49e371bd6b55e7a482c041dddb3",
      "retrieval_truncated": false,
      "observed_title": "Google SRE - Cascading Failures: Reducing System Outage",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Opening definition describes failures amplified by positive feedback and increased load on remaining replicas. No production load experiment was run."
    },
    {
      "source_id": "MCPSEC",
      "url": "https://modelcontextprotocol.io/docs/2025-11-25/tutorials/security/security_best_practices",
      "accessed_at": "2026-09-23T05:00:37.316584+00:00",
      "http_status": 200,
      "body_sha256": "4b4880225d9ad9bf13e457b5e22009d06a3f379c198730ac25a6daabeca78093",
      "retrieval_truncated": false,
      "observed_title": "Security Best Practices - Model Context Protocol",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected security guidance forbids token passthrough without correct audience validation. The released local read-only stdio slice is not a remote OAuth implementation."
    },
    {
      "source_id": "A2A",
      "url": "https://a2a-protocol.org/latest/specification/",
      "accessed_at": "2026-09-23T05:00:37.341571+00:00",
      "http_status": 200,
      "body_sha256": "4805254c10d8cbde59a82f6767598c37b051d7c3cdf9d5ce636dba287cd6ab2b",
      "retrieval_truncated": false,
      "observed_title": "Overview - A2A Protocol",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected specification discusses asynchronous tasks and requires per-request caller authorization and scoped resources. No A2A endpoint is implemented by this candidate."
    },
    {
      "source_id": "GHSEC",
      "url": "https://docs.github.com/en/actions/reference/security/secure-use",
      "accessed_at": "2026-09-23T05:00:37.393448+00:00",
      "http_status": 200,
      "body_sha256": "9c38373744d95e748f08f64e57bff1a7ff3967961ed29d6b47bea319f291fbf3",
      "retrieval_truncated": false,
      "observed_title": "Secure use reference - GitHub Docs",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected guidance recommends full commit SHA pinning, checking repository origin and auditing action handling of source/secrets. Pinning does not make arbitrary action code safe."
    },
    {
      "source_id": "SLSA",
      "url": "https://slsa.dev/spec/v1.1/threats-overview",
      "accessed_at": "2026-09-23T05:00:37.509357+00:00",
      "http_status": 200,
      "body_sha256": "6808c3d4770f17951478ac7c080961b1a1e2c10c63c9e1801914bd97dee9ca9e",
      "retrieval_truncated": false,
      "observed_title": "SLSA • Supply chain threats",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected threat table explicitly excludes some malicious-producer, default-credential and dependency-availability threats. Provenance does not certify intent or availability."
    },
    {
      "source_id": "CWE78",
      "url": "https://cwe.mitre.org/data/definitions/78.html",
      "accessed_at": "2026-09-23T05:00:37.686463+00:00",
      "http_status": 200,
      "body_sha256": "ca94d1a2a3342d33e6b979495e3e3aead978bd003cdf8895267800b270d5d9e1",
      "retrieval_truncated": false,
      "observed_title": "CWE - CWE-78: Improper Neutralization of Special Elements used in an OS Command (&#39;OS Command Injection&#39;) (4.20)",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Definition concerns externally influenced OS commands with insufficient control/data separation. The category is not a claim of a discovered vulnerability in this candidate."
    },
    {
      "source_id": "CWE918",
      "url": "https://cwe.mitre.org/data/definitions/918.html",
      "accessed_at": "2026-09-23T05:00:37.690376+00:00",
      "http_status": 200,
      "body_sha256": "ab26aa0d013931389c57bad67cb62407c4b4b94e50004a342fe0d16848a76d66",
      "retrieval_truncated": false,
      "observed_title": "CWE - CWE-918: Server-Side Request Forgery (SSRF) (4.20)",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Definition concerns server-side requests without sufficient destination assurance. No arbitrary network target is exposed by the candidate MCP tools."
    },
    {
      "source_id": "CWE400",
      "url": "https://cwe.mitre.org/data/definitions/400.html",
      "accessed_at": "2026-09-23T05:00:38.016491+00:00",
      "http_status": 200,
      "body_sha256": "4a81e70ea642db7c361deccb236a2d5a12d06cbb92b4d6a15b01188811f969ed",
      "retrieval_truncated": false,
      "observed_title": "CWE - CWE-400: Uncontrolled Resource Consumption (4.20)",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Definition concerns uncontrolled limited-resource allocation and maintenance. Candidate bounds cover named paths, not a universal denial-of-service guarantee."
    },
    {
      "source_id": "TLA",
      "url": "https://lamport.azurewebsites.net/tla/book.html",
      "accessed_at": "2026-09-23T05:00:38.220020+00:00",
      "http_status": 200,
      "body_sha256": "1f24c5a6977818b747b944964fd2e28180866a678e275d87609fd5323906bd1a",
      "retrieval_truncated": false,
      "observed_title": "Specifying Systems",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Retrieved landing page identifies Specifying Systems and the book redistribution restriction. The book was not read or redistributed; no formal specification/model-checking result is claimed."
    },
    {
      "source_id": "DELTABOX",
      "url": "https://arxiv.org/abs/2605.22781",
      "accessed_at": "2026-09-23T05:00:38.257103+00:00",
      "http_status": 200,
      "body_sha256": "af40631f4e4efa409fa028884390e7bef4f7d7b3afaa0b45c88b8d8a1ae65820",
      "retrieval_truncated": false,
      "observed_title": "[2605.22781] DeltaBox: Scaling Stateful AI Agents with Millisecond-Level Sandbox Checkpoint/Rollback",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "CONSENSUS26",
      "url": "https://arxiv.org/abs/2606.21666",
      "accessed_at": "2026-09-23T05:00:38.317816+00:00",
      "http_status": 200,
      "body_sha256": "7f8f04fcacc59840e0b3f59279c9fb1271259b2567b29be052f4be4a34b33356",
      "retrieval_truncated": false,
      "observed_title": "[2606.21666] Hallucination as Context Drift: Synchronization Protocols for Multi-Agent LLM Systems",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "AGENTDOJO24",
      "url": "https://arxiv.org/abs/2406.13352",
      "accessed_at": "2026-09-23T05:00:38.398925+00:00",
      "http_status": 200,
      "body_sha256": "142602756ade99b34922167e3be4c95eeaeea5252bd7b24a41776edcd70ec58c",
      "retrieval_truncated": false,
      "observed_title": "[2406.13352] AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "VERIFIED26",
      "url": "https://arxiv.org/abs/2608.02645",
      "accessed_at": "2026-09-23T05:00:38.438820+00:00",
      "http_status": 200,
      "body_sha256": "81e7f52ee2f8df422ab0b9e97931d2ee1fb0e1d5bceed09f0745cef5fc2219b1",
      "retrieval_truncated": false,
      "observed_title": "[2608.02645] Verified Tool Calls Improve LLM Agent Reliability Under Non-Atomic Failures",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "SYNTHESIS26",
      "url": "https://arxiv.org/abs/2607.05775",
      "accessed_at": "2026-09-23T05:00:38.482537+00:00",
      "http_status": 200,
      "body_sha256": "63968ac30dc7144f147b9d82531ccb33c816180e1f37802c8453bf95d8064d75",
      "retrieval_truncated": false,
      "observed_title": "[2607.05775] Beyond the Leaderboard: A Synthesis of Tool-Use, Planning, and Reasoning Failures in Large Language Model Agents",
      "review_scope": "ABSTRACT_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism."
    },
    {
      "source_id": "RFC6973",
      "url": "https://www.rfc-editor.org/rfc/rfc6973.html",
      "accessed_at": "2026-09-23T05:00:38.553104+00:00",
      "http_status": 200,
      "body_sha256": "b9920c94a78d6ef63f005300574b4b2b5e4655a46d85e2c07d32f083cffaeb96",
      "retrieval_truncated": false,
      "observed_title": null,
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected section 7.1 asks which identifiers/data can be omitted or made less identifying. Documentation review is not a privacy certification."
    },
    {
      "source_id": "NASAVV",
      "url": "https://www.nasa.gov/reference/appendix-i-verification-and-validation-plan-outline/",
      "accessed_at": "2026-09-23T05:00:38.561439+00:00",
      "http_status": 200,
      "body_sha256": "2272c07751f90a646c76c43b2c8d8e01ff91e0f4d72bffe0c83e4782d298c789",
      "retrieval_truncated": false,
      "observed_title": "Appendix I: Verification and Validation Plan Outline - NASA",
      "review_scope": "SELECTED_PRIMARY_PASSAGES_REVIEWED_NOT_REPLICATED",
      "runtime_replication": false,
      "full_text_review_claimed": false,
      "limitation": "The original research source record and its qualification remain unchanged. Retrieval does not certify every mapped mechanism.",
      "finding": "Selected purpose text distinguishes compliance with requirements from meeting customer expectations, and calls for defined responsibility/change authority. This candidate is not NASA-certified."
    }
  ],
  "errata": [
    {
      "id": "REVIEW-001",
      "source_id": "AGENTEVAL26",
      "scope": "Table 8, PDF page 11",
      "finding": "Caption and abstract say 21 subcategories; visible Level 3 rows total 20. No missing row inferred."
    },
    {
      "id": "REVIEW-002",
      "source_id": "RIFL15",
      "scope": "Current body at supplied PDF URL",
      "finding": "The retrieved artifact is a research paper, not a slide presentation. Its first page includes abstract, authors and SOSP15 copyright notice."
    }
  ],
  "still_required": "Full claim-by-claim support for all 283 mappings is not independently established. Abstract-only, selected-page, landing-page and truncated-source limitations remain explicit; no source is a runtime prevention certificate"
}
