Multiverse Computing Introduces ProvenanceGuard for MCP Agents on Hugging Face

29 Sep 2026

Released by Multiverse Computing

MediaRelease.co Summary

Multiverse Computing published ProvenanceGuard, a source-aware factuality check for LLM agents that use the Model Context Protocol, on the Hugging Face blog. The method targets cross-source conflation, where a claim is true in pooled evidence but attributed to the wrong MCP tool output. Unlike source-blind checkers such as RAGAS faithfulness, ProvenanceGuard asks whether each claim is supported by the specific source the answer names; the paper is available on Hugging Face and arXiv.

Original release

Tool-using LLM agents no longer read from a single retrieved passage. Through the Model Context Protocol (MCP), an agent can call a search tool, inspect a structured patient or account record, query a database, and pull metadata, then weave all of it into one answer. That makes the usual question of factuality more subtle than it looks. Most of the systems built to check LLM answers, from RAGAS faithfulness to fine-grained checkers like MiniCheck, AlignScore, and SummaC, ask whether a claim is supported by the available evidence once that evidence has been pooled together. In their usual form, they do not tell us which MCP tool output supports each claim, or whether that is the source the answer names.

Our latest paper, ProvenanceGuard: Source-Aware Factuality Verification for MCP-Based LLM Agents (available on Hugging Face and on arXiv), targets that gap. The failure mode we care about is one we call cross-source conflation: a claim that is true somewhere in the evidence, but attributed to the wrong source. A source-blind verifier may pass it, because the fact does exist in the pool. A source-aware verifier should not.

The problem: supported somewhere is not the same as supported by the right source

Consider a customer support agent that answers, "According to the account record, this plan includes a 30-day refund window." The refund window may be perfectly real, but stated in a policy document, not in the account record the answer points to. Pool the two together and the claim looks supported. Keep them separate and the attribution is wrong, and in a data-sensitive setting a wrong attribution can be as damaging as a wrong fact.

A claim can be supported by one MCP source while the answer attributes it to another. Source-blind scoring sees support in the pooled evidence and passes it; ProvenanceGuard separately checks whether the supporting source matches the one the answer states or implies.

This is why faithfulness scores, useful as they are, are not enough for MCP agents. An answer carries provenance, sometimes explicitly ("according to the account record") and sometimes implicitly. ProvenanceGuard keeps that connection between claim and source available for inspection.

What ProvenanceGuard does

ProvenanceGuard is a post-generation verification layer that sits on top of a black-box MCP agent. It runs after an agent produces an answer, and never collapses the evidence into one anonymous context. Instead it carries the source identity all the way through the pipeline. It reads the captured MCP trace, including the tool outputs and their source IDs, without retraining the agent. Then it does five things in sequence: it breaks the answer into specific claims, finds the source most relevant to each one, checks whether that source actually supports it, compares the source with the one the answer names or implies, and finally emits both a per-claim source verdict and a global, answer-level allow or block decision.

Source identity is preserved through decomposition, routing, support scoring, attribution checking, and repair, rather than being pooled. Blocked answers can go through a repair step that corrects attribution or withholds unsupported claims.

The paper and related materials were published on the Hugging Face blog by Multiverse Computing researchers Antonio Tiene, Ander Alvarez Sanz, and Oliver Wirjadi on September 29, 2026.

Key details

Author/spokesperson
Multiverse Computing
Published
29 Sep 2026
Publisher country
United States
Subject country/region
United States
Topics
AI

Source: https://huggingface.co/blog/MultiverseComputingCAI/getting-the-source-right-not-just-the-fact-source

MediaRelease.co ID: mr01090 · Markdown

← Back to AI overview