Agent skill

Verify Watermark Removal

by davepoon in davepoon/buildwithclaude

Verify that a watermark-removal or "humanizer" step actually removed a statistical text watermark, by measuring a sample whose key the user holds.

MITAuto-check passedWriting & Content

Install Verify Watermark Removal

skills CLI
$ npx skills add davepoon/buildwithclaude --skill verify-watermark-removal -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davepoon/buildwithclaude verify-watermark-removal --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/all-skills/skills/verify-watermark-removal .claude/skills/verify-watermark-removal && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-watermark-removal
GitHub stars
3.6k
Token cost
~2.6k tokens
SKILL.md length
1,487 words
Files
1
Skills in repo
247
Repo updated
First seen
Licence
MIT

At a glance

Verify that a watermark-removal or "humanizer" step actually removed a statistical text watermark, by measuring a sample whose key the user holds.

  • Works in 5 steps: Plants a known mark: generates text… → Scores what came back: runs the keyed… → Measures the cost: meaning similarity,… → …
  • Asks whether such a tool works
  • SKILL.md covers When to Use This Skill, What This Skill Does, How to Use and Example, plus 3 more sections
  • Calls git and pip; reaches github.com and download.pytorch.org; needs UNMARK_CHECKER_KEY

What it does

Verify Watermark Removal is an agent skill from davepoon/buildwithclaude. Verify that a watermark-removal or "humanizer" step actually removed a statistical text watermark, by measuring a sample whose key the user holds. Use after any tool, script or service claims to have cleaned a text, or when the user asks whether such a tool works, which one to trust, or how to test one. Reports a detector score against fixed thresholds plus what the run cost in meaning, facts, verbatim overlap and length. This skill only measures and never removes a mark.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Writing & Content, covering Humanizing AI text. The repository describes itself as: A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw. The licence is MIT.

When your agent uses it

  • Asks whether such a tool works
  • Which one to trust
  • How to test one

Example prompts

  • “humanizer”
  • “/verify-watermark-removal”

Requirements

  • Python 3
  • A credential in UNMARK_CHECKER_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Plants a known mark: generates text carrying a statistical watermark of the SynthID-Text class under a key the user chooses, and scores…
  2. Scores what came back: runs the keyed detector on the returned text and places the score against thresholds that were fixed before any…
  3. Measures the cost: meaning similarity, facts kept, longest verbatim run, share of words changed, length ratio.
  4. Builds a comparison table: turns several recorded runs into one matrix, so tools are ranked on the same measurements instead of on their…
  5. Keeps the answer honest: reports the grey zone as an outcome of its own and never turns a passing run into "this text is now undetectable".

What it can do on your machine

Read from SKILL.md and the folder at commit 616deb5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • download.pytorch.org

    Also links to:

    • unmarkclaude.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • UNMARK_CHECKER_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify Watermark Removal loads about 2.6k tokens when it runs. Until then it costs about 125 tokens; SKILL.md has 1,487 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~125
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davepoon/buildwithclaude at commit 616deb5, republished under its MIT licence (© davepoon). 1,487 words, ~2,565 tokens.

Download SKILL.mdSave it as .claude/skills/verify-watermark-removal/SKILL.md (or your agent's skills folder).
name
verify-watermark-removal
description
Verify that a watermark-removal or "humanizer" step actually removed a statistical text watermark, by measuring a sample whose key the user holds. Use after any tool, script or service claims to have cleaned a text, or when the user asks whether such a tool works, which one to trust, or how to test one. Reports a detector score against fixed thresholds plus what the run cost in meaning, facts, verbatim overlap and length. This skill only measures and never removes a mark.
category
testing-qa
license
MIT

Verify Watermark Removal

A tool says it removed a watermark from a text. This skill checks whether it did, by measuring rather than by trusting the tool's own report.

The check works because the mark is planted first, with a key the user holds. A detector that knows the key is the strongest detector that can exist for that text, so its score is a ceiling rather than a guess. What the key buys is a scale of the user's own; what keeps a tool from recognising the sample is something else, namely that a freshly generated private sample is a text nobody has seen before. The samples shipped with the tool are published together with their key, so those can be recognised, and the repository says so in samples/README.md. The skill also reports what the rewrite cost the text, because a mark that disappeared together with half the meaning is not a result anyone wants.

This skill measures. It never removes a mark, and it never claims anything about a specific vendor's watermark.

When to Use This Skill

  • A "watermark remover", "AI humanizer" or "detector bypass" tool claims it cleaned a text, and the claim needs checking before anyone repeats it.
  • Someone is about to pay for such a tool and wants evidence instead of a landing page.
  • Several such tools have to be compared on one ruler, with numbers another person can reproduce.
  • A rewriting step sits inside a pipeline, and someone needs to know what it costs in meaning, facts and length.
  • The user asks how these tools can be tested at all, or why a "99% undetectable" promise cannot be verified from outside.

What This Skill Does

  1. Plants a known mark: generates text carrying a statistical watermark of the SynthID-Text class under a key the user chooses, and scores every sample as it writes it, so a text where the mark did not plant is named before anything is handed to a tool.
  2. Scores what came back: runs the keyed detector on the returned text and places the score against thresholds that were fixed before any run, giving one of four outcomes.
  3. Measures the cost: meaning similarity, facts kept, longest verbatim run, share of words changed, length ratio.
  4. Builds a comparison table: turns several recorded runs into one matrix, so tools are ranked on the same measurements instead of on their own claims.
  5. Keeps the answer honest: reports the grey zone as an outcome of its own and never turns a passing run into "this text is now undetectable".

How to Use

Basic Usage

Install once. A CPU is enough, Python 3.10 or newer:

bash
git clone https://github.com/Yurakonoplya/unmark-checker && cd unmark-checker
git checkout v0.1.5              # the revision this page describes
pip install --index-url https://download.pytorch.org/whl/cpu torch
pip install -e .                 # no PyPI package: install from the clone
read -rs UNMARK_CHECKER_KEY && export UNMARK_CHECKER_KEY

The checkout pins exactly the revision described here: main moves, and a command that behaves differently from this page is worse than no page.

The key is typed at the read prompt, which echoes nothing and writes nothing to the shell history. Keep it in the environment, never in a file and never in a command that gets logged. The key is the whole basis of the check.

If the tool under test runs on the same machine, start it with env -u UNMARK_CHECKER_KEY <tool> ...: a process that inherits the key could score the sample itself and shape its output to it, which is exactly what the measurement is meant to rule out.

Then four steps.

1. Get a marked sample. The repository ships ready samples in samples/, with their key printed in samples/README.md. That is the fast path. For a test no tool can anticipate, generate your own (about two minutes each on a CPU with the small model):

bash
unmark-checker generate --num 2 --words 100 --scheme shallow \
    --model sshleifer/tiny-gpt2 --out my-samples

Use --model gpt2 instead when the sample has to read as English, for example when it is going into a web form that rejects nonsense.

Every sample is scored as it is written, and the manifest next to the texts records the outcome of that scoring. Hand a tool only the samples the manifest records as mark_present. The command does not do this filtering for you: if the mark planted in none of the samples it says so and exits with code 2, but if it planted in some of them it warns, lists the ones it did not plant in and exits with code 0, leaving every file on disk. check behaves the same way: given such a sample it prints a warning and measures it anyway, and that measurement means nothing, because a mark that was never there cannot be removed.

2. Run the tool under test on the sample, and save exactly what came back, unedited, to a file.

3. Measure, one command:

bash
unmark-checker check --sample my-samples/UM-1A2B3C.txt --returned cleaned.txt

4. Report what the run says, and only that. The outcome is one of four:

OutcomeWhat it means
mark_presentscore at or above 4.0; the tool did not take this mark out
uncertainscore between 2.0 and 4.0, the grey zone; do not round it to a yes or a no
mark_gonescore below 2.0; on this sample, on this run, the mark did not survive
not_our_textfewer than half the content words of the returned text come from the sample, so it is not recognisably the sample and no score is reported

Always report the cost numbers next to the outcome: meaning kept, facts kept, longest verbatim run, share of words changed, length ratio. They exist for the three scored outcomes only (mark_present, uncertain, mark_gone). A not_our_text run stops before they are computed and reports four things instead: the outcome, the share of content words that came from the sample, and the word counts of both texts. Do not ask for a meaning or facts number there, and do not report one as zero: it was never measured.

Show full SKILL.md (538 more words)Show less
Advanced Usage

Add --json when the numbers are going into a table or a report:

bash
unmark-checker check --sample my-samples/UM-1A2B3C.txt --returned cleaned.txt --json

One run on one sample is one measurement, not a verdict on a product. For a claim worth repeating, run several samples at several lengths and across the three scheme presets (shallow, default, deep).

Record each run as a service file and build one table out of the folder:

bash
unmark-checker matrix --dir my-runs --out my-runs/matrix.md

The service file format is described in docs/service-file.md in the repository. Runs measured this way and published in the same format are collected at https://unmarkclaude.io/check/services, so a table built locally can be set against one built by someone else.

When installing anything is not an option, the same check runs in a browser at https://unmarkclaude.io/check, on a sample whose key that site holds. Use this skill instead when the text must not leave the machine, or when the key has to be the user's own.

Example

User: "I ran this paragraph through a humanizer that promises to strip AI watermarks. Did it work?"

Output:

The mark is still there. Detector score 6.41, at or above 4.0. Under the null
case a clean text scores that high about three times in a hundred thousand, so
this is not a coin flip: the tool did not take this mark out.
Meaning kept: 0.94 of 1.00. Facts kept: 7 of 7.
Longest verbatim run: 38 words. Words changed: 11%. Length: 0.97x (100 words
in, 97 out).

Read back to the user: the mark this tool was asked to remove is still in place, and the text came back almost unchanged. On this sample, on this run, the tool did not do what it promised. This says nothing about any vendor's own watermark.

What the Check Proves, and What It Does Not

  • A tool that leaves this mark in place is unlikely to remove a vendor's mark either: this is an inference from where both marks live (word choice), not a measurement; the measurement covers one key, one scheme, one model and one sample.
  • A tool that removes this mark has not been shown to remove anyone else's. Different key, different scheme parameters, different model. Say so, and do not let a passing run turn into "the text is now undetectable".
  • uncertain is an answer, not a rounding error. Collapsing the grey zone into a yes or a no is a lie in one direction or the other.

Tips

  • Use the user's own key whenever the result has to be strict. The shipped samples are convenient, and their published key is also their one weakness: a tool could recognise those exact texts and treat them specially.
  • Save what the tool returned byte for byte. Trimming a heading or a stray line moves the score and the verbatim run, and the numbers stop being comparable.
  • Report the cost numbers every time, not only when they look bad. They are what separates "removed the mark" from "rewrote the text into something else".
  • Longer samples give a steadier score. Below roughly 80 words the detector has little to work with, and uncertain becomes the normal answer.
  • Never tune the thresholds to a result. They were fixed before any run, and moving them after seeing one invalidates every number produced with this code.
  • Apply this only to text the user owns or is authorised to process.

Common Use Cases

  • Checking a paid "humanizer" before the subscription renews.
  • Comparing several removal services on one ruler and publishing the table.
  • Testing a rewriting step inside an internal pipeline for what it costs in facts and meaning.
  • Answering "is this text still watermarked" with a measurement and a stated limit, instead of a guess.

© davepoon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/all-skills/skills/verify-watermark-removal of davepoon/buildwithclaude.

Open the folder on GitHubat commit 616deb5

Compare with similar skills

Verify Watermark Removal next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Watermark Removal compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Watermark Removal this skilldavepoon/buildwithclaude3.6k—~2.6kAutomated safety check: PassMIT
HumanizerAzure-Samples/interview-coach-agent-framework17338 repos~5.8kAutomated safety check: PassMIT
Avoid AI Writingconorbronsdon/avoid-ai-writing4.9k3 repos~8.1kAutomated safety check: PassMIT
User-Facing Text Cleanupguillaumemeyer/watermarks-remover24k—~3.5kAutomated safety check: PassMIT
Install Anti Sloptrycompai/crm11k1 repos~881Automated safety check: PassMIT
Stop SlopXe/site7328 repos~423Automated safety check: PassMIT

Similar skills

  • Humanizer

    Azure-Samples/interview-coach-agent-framework

    Official

    Remove signs of AI-generated writing from text. An agent skill from Azure-Samples/interview-coach-agent-framework.

    173 GitHub starsUsed in 38 repos~5.8k tokens
    Writing & ContentAuto-check passed
  • Avoid AI Writing

    conorbronsdon/avoid-ai-writing

    Audit and rewrite content to remove AI writing patterns ("AI-isms").

    4.9k GitHub starsUsed in 3 repos~8.1k tokens
    Writing & ContentAuto-check passed
  • User-Facing Text Cleanup

    guillaumemeyer/watermarks-remover

    Audits prose for invisible Unicode characters and rewrites it while keeping facts, citations, code and required disclosures unchanged and the writer's voice intact.

    24k GitHub stars~3.5k tokensUpdated yesterday
    Writing & ContentAuto-check passed
  • Install Anti Slop

    trycompai/crm

    Install and configure the anti-slop Oxlint plugin in a local TypeScript or JavaScript repository.

    11k GitHub starsUsed in 1 repo~881 tokens
    Writing & ContentAuto-check passed
  • Stop Slop

    Xe/site

    Remove AI writing patterns from prose. An agent skill from Xe/site.

    732 GitHub starsUsed in 8 repos~423 tokens
    Writing & ContentAuto-check passed
  • Chinese Text Humanizer

    op7418/Humanizer-zh

    Edits Chinese articles, comments and documents to remove filler, repetition and template phrasing while keeping the facts, the level of certainty and the author's voice.

    19k GitHub stars~2k tokensUpdated 17 days ago
    Writing & ContentAuto-check passed

More from davepoon/buildwithclaude

All 247 skills in this repo
  • iOS Hig Design Guide

    davepoon/buildwithclaude

    Build, update, and apply iOS design specifications using Apple Human Interface Guidelines (HIG) source data.

    3.6k GitHub stars~735 tokensUpdated yesterday
    Auto-check passed
  • Video Downloader

    davepoon/buildwithclaude

    Download YouTube videos with customizable quality and format options.

    3.6k GitHub starsUsed in 1 repo~871 tokens
    Auto-check passed
  • Qwen Vision

    davepoon/buildwithclaude

    A skill your agent uses when the user asks to "analyze video", "watch this video", "what happens in this video", "describe this clip", "review this footage", "classify these videos", "compare…

    3.6k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Atlas Cloud Media

    davepoon/buildwithclaude

    Discover Atlas Cloud image and video models, inspect their live schemas, and submit one confirmed media generation request with bounded GET polling.

    3.6k GitHub stars~852 tokensUpdated yesterday
    Auto-check passed
  • Browser Extension Launch

    davepoon/buildwithclaude

    面向没有编程经验的用户,把想法做成可试用的浏览器插件,并完成检查、商店材料、审核提交和上线验证;也用于继续已有插件、排错和发布新版。用户说“帮我做个插件”“把插件上架”“继续我的插件”时使用。普通网站开发、仅查询插件知识不触发。

    3.6k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Slack Gif Creator

    davepoon/buildwithclaude

    Toolkit for creating animated GIFs optimized for Slack, with validators for size constraints and composable animation primitives.

    3.6k GitHub starsUsed in 12 repos~4.3k tokens
    Auto-check passed

Questions about Verify Watermark Removal

What does Verify Watermark Removal do?

Verify that a watermark-removal or "humanizer" step actually removed a statistical text watermark, by measuring a sample whose key the user holds. Verify Watermark Removal is an agent skill from davepoon/buildwithclaude. Verify that a watermark-removal or "humanizer" step actually removed a statistical text watermark, by measuring a sample whose key the user holds.

When should I use Verify Watermark Removal?

Verify Watermark Removal fits situations like: asks whether such a tool works; which one to trust; how to test one.

How do I install Verify Watermark Removal in Claude Code?

Run `npx skills add davepoon/buildwithclaude --skill verify-watermark-removal -a claude-code`. Or copy the skill folder (plugins/all-skills/skills/verify-watermark-removal in davepoon/buildwithclaude) into .claude/skills/verify-watermark-removal in your project. Claude Code loads it when a task matches its description.

How do I install Verify Watermark Removal in Codex?

Run `npx skills add davepoon/buildwithclaude --skill verify-watermark-removal -a codex`. Or copy the skill folder (plugins/all-skills/skills/verify-watermark-removal in davepoon/buildwithclaude) into .agents/skills/verify-watermark-removal in your project. Codex loads it when a task matches its description.

Can I use Verify Watermark Removal in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davepoon/buildwithclaude --skill verify-watermark-removal -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-watermark-removal, .gemini/skills/verify-watermark-removal, .github/skills/verify-watermark-removal and .opencode/skills/verify-watermark-removal in your project.

What does Verify Watermark Removal need to run?

Going by SKILL.md and its folder, Verify Watermark Removal needs the command-line tools its instructions call (git and pip) and credentials named UNMARK_CHECKER_KEY. Our summary lists: Python 3; A credential in UNMARK_CHECKER_KEY.

Does Verify Watermark Removal access the network?

SKILL.md names 3 domains. In commands or code: github.com and download.pytorch.org; the agent is likely to contact these when it follows the instructions. As links in the text: unmarkclaude.io. This is read from the text; nothing was executed.

Is Verify Watermark Removal safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Watermark Removal use?

Verify Watermark Removal is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Watermark Removal use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify Watermark Removal?

Skills that share tags, products or a category with Verify Watermark Removal: Humanizer (Azure-Samples/interview-coach-agent-framework, 173 stars), Avoid AI Writing (conorbronsdon/avoid-ai-writing, 4.9k stars), User-Facing Text Cleanup (guillaumemeyer/watermarks-remover, 24k stars) and Install Anti Slop (trycompai/crm, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Watermark Removal?

davepoon (a GitHub user) maintains it in davepoon/buildwithclaude, which has 3,610 GitHub stars. The repository holds 247 skills in this directory. The repository was last updated on October 9, 2026.

Source: davepoon/buildwithclaude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.