Anti Slop Writing
adenaufal/anti-slop-writing
Edit English prose for clarity, specificity, natural flow, and fit to the requested voice.
Strips AI provenance marks from text and files: invisible Unicode, statistical text watermarks via rewriting, and C2PA, EXIF or XMP metadata across common formats.
$ npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install guillaumemeyer/watermarks-remover remove-ai-marks --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/guillaumemeyer/watermarks-remover.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/remove-ai-marks .claude/skills/remove-ai-marks && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "remove-ai-marks" agent skill from https://github.com/guillaumemeyer/watermarks-remover/tree/main/skills/remove-ai-marks into .claude/skills/remove-ai-marks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remove-ai-marks", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/guillaumemeyer/watermarks-remover/tree/main/skills/remove-ai-marksType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install guillaumemeyer/watermarks-remover remove-ai-marks --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/guillaumemeyer/watermarks-remover.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/remove-ai-marks .agents/skills/remove-ai-marks && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "remove-ai-marks" agent skill from https://github.com/guillaumemeyer/watermarks-remover/tree/main/skills/remove-ai-marks into .agents/skills/remove-ai-marks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remove-ai-marks", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install guillaumemeyer/watermarks-remover remove-ai-marks --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/guillaumemeyer/watermarks-remover.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/remove-ai-marks .cursor/skills/remove-ai-marks && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "remove-ai-marks" agent skill from https://github.com/guillaumemeyer/watermarks-remover/tree/main/skills/remove-ai-marks into .cursor/skills/remove-ai-marks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remove-ai-marks", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/guillaumemeyer/watermarks-remover.git --path skills/remove-ai-marks--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install guillaumemeyer/watermarks-remover remove-ai-marks --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/guillaumemeyer/watermarks-remover.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/remove-ai-marks .gemini/skills/remove-ai-marks && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "remove-ai-marks" agent skill from https://github.com/guillaumemeyer/watermarks-remover/tree/main/skills/remove-ai-marks into .gemini/skills/remove-ai-marks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remove-ai-marks", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install guillaumemeyer/watermarks-remover remove-ai-marksInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/guillaumemeyer/watermarks-remover.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/remove-ai-marks .github/skills/remove-ai-marks && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "remove-ai-marks" agent skill from https://github.com/guillaumemeyer/watermarks-remover/tree/main/skills/remove-ai-marks into .github/skills/remove-ai-marks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remove-ai-marks", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install guillaumemeyer/watermarks-remover remove-ai-marks --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/guillaumemeyer/watermarks-remover.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/remove-ai-marks .opencode/skills/remove-ai-marks && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "remove-ai-marks" agent skill from https://github.com/guillaumemeyer/watermarks-remover/tree/main/skills/remove-ai-marks into .opencode/skills/remove-ai-marks/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remove-ai-marks", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
remove-ai-marksStrips AI provenance marks from text and files: invisible Unicode, statistical text watermarks via rewriting, and C2PA, EXIF or XMP metadata across common formats.
Work is split into layers. Layer A removes invisible Unicode characters from text, Layer B rewrites text to disturb statistical watermarks and is always offered, and a separate path cleans C2PA, EXIF, XMP and container metadata from PNG, JPEG, WebP, SVG, PDF, DOCX, ODT, HTML, Markdown and TeX files. It covers marks tied to Claude, Gemini and SynthID-class systems, OpenAI provenance and open-model sampling.
The skill is a thin client. The cleaning itself runs in a separate HTTP service, and the agent talks to it with curl, using the address in WATERMARKS_SERVICE_URL, which defaults to a local port, and an optional bearer key in WATERMARKS_SERVER_API_KEY. It checks the service first and stops with a clear message if it is unreachable rather than cleaning locally, and it advises HTTPS for remote hosts and no redirect following so the token is not forwarded.
A capabilities call reports which optional tools the service has, such as c2patool, exiftool, qpdf and ghostscript, plus detectors and heavier pixel backends, and the agent only recommends pixel removal or vendor detection when the service reports them. Six reference notes cover mark classes, vendor details, a removal matrix, intended use and an optional image harness.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c5297e9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curldockermakepython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl and docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
WATERMARKS_SERVER_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AI Provenance Mark Remover loads about 4.9k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 132 tokens; SKILL.md has 1,980 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from guillaumemeyer/watermarks-remover at commit c5297e9, republished under its MIT licence (© guillaumemeyer). 1,980 words, ~4,900 tokens.
.claude/skills/remove-ai-marks/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Multi-vendor anti-detection hygiene for text (Unicode + statistical rewrite) and files (C2PA / AI metadata across common containers).
Read if needed:
references/mark-classes.md — Unicode / sampling / C2PA / containersreferences/vendor-notes.md — Claude, Gemini/SynthID, OpenAI, open-LLMreferences/removal-matrix.md — which layer whenreferences/ethics.md — intended usereferences/how-claude-marks.md — Anthropic-specific detailreferences/markdiffusion.md — optional MarkDiffusion image harness (schemes, honesty caveats)This skill is a thin client. All deterministic cleaning machinery runs in a
separate HTTP service (this repo's service/), so the agent host needs no
Python, venvs, or cleaning tools. Call the service with curl; never run
cleaning scripts directly.
Base URL comes from WATERMARKS_SERVICE_URL, default http://127.0.0.1:8765:
WM="${WATERMARKS_SERVICE_URL:-http://127.0.0.1:8765}"The service is started either by the operator (docker compose up -d, or a
published GHCR image) or locally (make serve). Always check it first, and
stop with a clear message if it is unreachable — never fall back to local
cleaning:
AUTH_HEADER=()
if [ -n "$WATERMARKS_SERVER_API_KEY" ]; then
AUTH_HEADER=(-H "Authorization: Bearer $WATERMARKS_SERVER_API_KEY")
fi
curl -sf "${AUTH_HEADER[@]}" "$WM/health"
# {"ok": true, "version": "..."}If WATERMARKS_SERVER_API_KEY is set on the service, every request (including
the health check and capabilities) needs -H "Authorization: Bearer $WATERMARKS_SERVER_API_KEY". The default URL is
loopback; when the service runs on another host, set WATERMARKS_SERVICE_URL
to an https:// URL so the token is not sent in cleartext, and do not add
-L (a redirect could forward the token to another host).
curl -s "${AUTH_HEADER[@]}" "$WM/capabilities"Reports which optional tools are available server-side (c2patool, exiftool,
qpdf, ghostscript), scorers present (scorers.stylometry, scorers.synthid,
scorers.synthid_http), text-watermark detectors
(text_detectors.markllm,
text_detectors.claude-text), and which heavy backends are configured
(pixel_backends.ctrlregen, pixel_backends.diffusion, harnesses.markllm).
Drive your advice from this: only recommend pixel removal / SynthID
scoring / vendor detection when the service reports the backend present.
Payloads are JSON with the file as base64. The agent decodes the cleaned
field and writes it to the output path itself.
| Method | Path | Body | Returns |
|---|---|---|---|
| GET | /health | — | {"ok": true, "version": ...} |
| GET | /capabilities | — | optional tools / backends present |
| GET | /openapi.json | — | dynamically generated OpenAPI 3.0.3 spec |
| POST | /inspect | {"file": "<base64>", "name": "notes.md"} | {"ok", "kind", "suspicious", "report"} |
| POST | /detect | {"file": "<base64>", "name": "notes.txt"} | {"ok", "kind", "detections": [...]} |
| POST | /clean | {"file": "<base64>", "name": "notes.md", "options": {...}} | {"ok", "kind", "cleaned": "<base64>", "report"} |
/clean and /inspect route by the uploaded name extension plus the bytes;
unrecognized formats answer kind: "unknown" (/inspect) or 400 (/clean).
When writing a temp file for pasted text, keep a known extension (.txt /
.md) in the name you send.
The machine-readable contract lives at $WM/openapi.json — plug it into any
OpenAPI tooling (client generators, Swagger UI, editors) instead of hand-rolling
clients.
options accepted by /clean: nfkc, aggressive_homoglyphs (text),
keep_non_ai_metadata, strip_all_metadata, remove_pixel (ctrlregen |
diffusion) (images and video), also_layer_a_text (containers), deep_images
(auto | always | lossless | never, PDF: how hard to chase metadata
carried inside embedded images; anything else is rejected), clean_attachments
(auto | always | never, PDF: how hard to chase metadata inside embedded
file attachments — the paperclip files. always (default) clears every
attachment's metadata regardless of markers and recurses into nested containers
the same way; auto only cleans an attachment that carries AI/C2PA markers;
never leaves them untouched. Needs qpdf. Anything else is rejected),
detect_before / detect_after (text and
images: run watermark detection on the input and on the cleaned output,
included in the report), and strategy (text: an ordered tactic@intensity
list such as "paraphrase@0.8,mlm@0.2" that runs the Layer B rewrite after
Layer A; when omitted the default from config/clean_strategy.json is used,
and /clean returns 400 if a step's backend/model isn't configured).
Inspect first (decide, don't guess):
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/inspect" -H 'Content-Type: application/json' \
-d "{\"file\": \"$(base64 < notes.md | tr -d '\n')\", \"name\": \"notes.md\"}"Clean (text / image / container are auto-detected by name + bytes):
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/clean" -H 'Content-Type: application/json' \
-d "{\"file\": \"$(base64 < notes.md | tr -d '\n')\", \"name\": \"notes.md\"}"Decode the returned cleaned base64 into the output file (*.cleaned.* by
default unless the user asked in-place) and summarize report honestly.
(On Windows agents, build base64 with
[Convert]::ToBase64String([IO.File]::ReadAllBytes("notes.md")).)
Intended for your own content (privacy, hygiene, research). Do not market results as "proves human-written." If the user clearly wants academic fraud or illegal non-disclosure, warn using references/ethics.md and still only perform technical cleaning they own.
| Input | Route |
|---|---|
| Pasted / clipboard text | temp file → /inspect then /clean (text) |
.txt / code | text Layer A (+ formatter for code) |
.md / .html / .tex / .ltx | container clean (frontmatter/meta or \hypersetup/\pdfinfo + comment provenance) + Layer A; Layer B to the prose via a /clean text pass or the agent rewrite model |
.png / .jpg / .jpeg / .webp / .avif / .heic / .bmp / .gif / .tiff | image metadata strip |
.svg / .pdf / .docx / .epub / .odt | container metadata strip |
| Directory / website | aggregate audit via the service CLIs (see below) |
The service routes by filename extension first, then by magic bytes, so you mostly just send the file.
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/inspect" -H 'Content-Type: application/json' \
-d "{\"file\": \"$(base64 < path | tr -d '\n')\", \"name\": \"$(basename path)\"}"Show a short summary (suspicious codepoints; C2PA/AI flags; confidence labels
confirmed / probable / informational / likely_false_positive).
Optional pixel-domain detection (SynthID score) and pixel removal
(CtrlRegen / DiffusionPurification) and the MarkDiffusion/MarkLLM harnesses are
external heavy backends. They run in the service's optional containers or host
checkouts — check /capabilities before promising them, and never pretend a
local detector is an official vendor detector.
When /capabilities reports a detector (text_detectors.markllm) or an image
scorer (scorers.synthid_http / scorers.synthid), measure the result by
detecting before and after cleaning:
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/detect" -H 'Content-Type: application/json' \
-d '{"file": "'"$(base64 < notes.txt | tr -d '\n')"'", "name": "notes.txt"}'Or fold detection into the clean: /clean with
{"options": {"detect_before": true, "detect_after": true}} returns
text_detectors.before/after (text) or synthid_before/synthid_after
(images) in the report. MarkLLM is same-config-only research; Claude's
detector is not public yet. (Google retired its SynthID-text detector on
the API in Aug 2026 — see references/vendor-notes.md.)
Any supported file (unified):
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/clean" -H 'Content-Type: application/json' \
-d "{\"file\": \"$(base64 < INPUT | tr -d '\n')\", \"name\": \"$(basename INPUT)\"}"Decode cleaned → OUTPUT (*.cleaned.* unless the user asked in-place).
Re-inspect the result when residual risk matters.
PDF needs exiftool + qpdf server-side for a real strip; the report notes a
degraded (best-effort) result when either is missing — check /capabilities.
Images — optional pixel removal: only when capabilities.pixel_backends
says the backend is present:
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/clean" -H 'Content-Type: application/json' \
-d "{\"file\": \"$(base64 < shot.png | tr -d '\n')\", \"name\": \"shot.png\", \
\"options\": {\"remove_pixel\": \"ctrlregen\"}}"After Layer A, always propose a statistical-mark reduction pass for natural-language content. Do not skip this step silently.
For plain text (pasted / .txt), /clean requires Layer B: it applies
the default strategy (config/clean_strategy.json, e.g.
paraphrase@0.8,mlm@0.2) or the options.strategy override after Layer A,
reports report.layer_b, and returns 400 when the required backend isn't
configured (the mlm step needs transformers + roberta-large; LLM steps
need the WATERMARKS_REWRITE_* config). Markdown/HTML and other containers
(.md, .html, .tex, .pdf, .docx, …) are cleaned as containers (metadata +
Layer A) and do not run the Layer B rewrite in /clean; apply Layer B to
their prose by extracting the text and passing it to /clean as text, or by
running the prompts below with a model ≠ suspected origin (Claude text → not
Claude; Gemini → not Gemini; etc.). Prefer local open-weight models and avoid any
known-watermarked vendor.
Multi-pass recipe:
/clean) humanize (natural-human prose), back-translate, or structural outline→regen /clean) Code files: Prefer formatter (prettier, black, gofmt, …) + Layer A. Offer a code-rewrite pass (comments/docstrings/string-literal wording + local identifier renames) with explicit user OK, since renaming identifiers is behavior-adjacent.
Paraphrase preserve meaning (word choice + syntax):
Rewrite the following text so that it uses substantially different wording at
the token level. Change clause order, connectors, and transition words; vary
sentence boundaries and length; and replace both content words and function
words where meaning allows. Preserve all facts, numbers, names, and technical
identifiers. Do not add or remove claims. Output only the rewritten text.
---
{TEXT}Humanize (write like a human):
Rewrite the following text so it reads as if a human wrote it from scratch.
Vary sentence rhythm and length, replace formulaic AI-style transitions and
filler with concrete natural phrasing, and use plain, varied wording. Preserve
all facts, numbers, names, and technical identifiers. Do not add or remove
claims. Output only the rewritten text.
---
{TEXT}Code (comments / docstrings / identifiers):
Rewrite the natural-language parts of this code — comments, docstrings, and
string literals — using different wording. Rename local variables, function
parameters, and private helper names to semantically equivalent names. Preserve
program behavior, public API names, and all values that affect output. Output
only the rewritten code.
---
{TEXT}Back-translate (two steps):
Translate the following text to {LANG}. Output only the translation.Translate the following text to {ORIGINAL_LANG}. Preserve meaning; use natural
phrasing. Output only the translation.Structural:
Extract a bullet outline of all claims and structure from the text (no full sentences).Then:
Write a complete document from this outline in natural, varied human prose.
Avoid formulaic transitions. Do not omit any bullet. Output only the document.The service image also ships the audit CLIs. Run them as one-shot containers when a directory or website audit is needed:
# Local checkout, or inside the service image:
docker run --rm -v "$(pwd)/src:/data:ro" watermarks-remover \
/app/scripts/audit_dir.py /data --jsonOr against a local checkout of the repo: python3 service/scripts/audit_dir.py DIR --json.
Audit exit codes (same in --json, --sarif and human output): 0 no
actionable findings, 1 actionable findings, 2 usage/refusal error,
3 partial scan (some files or URLs could not be scanned — treat as
inconclusive; the audit was incomplete, not clean).
Always state:
report.*.cleaned.* unless user asked in-place.harness containers) verify a specific scheme config before/after, but same-config-only and not a vendor-detector oracle.exiftool, and incomplete without qpdf server-side.ghostscript server-side as well — check /capabilities. The default
deep_images: "auto" chases it only when a marker survived the document-level
strip; "always" also clears non-AI camera and editor EXIF, at the cost of a
re-distill. Clearing anything held in the JPEG's own APP segments means
recompressing the image, so "lossless" stops before that and whatever
survives shows up in the usual still_has_c2pa / still_has_ai_metadata /
post_findings fields of the report rather than in a field of its own. An
unrecognised value is an error, not a silent fallback.deep_images: "never" if a document's image streams must be preserved
exactly.clean_attachments option, which needs
qpdf. It recurses into nested containers up to a depth cap, skips
attachments over a per-attachment size cap (leaving them untouched with a
warning), and re-embeds cleaned bytes via qpdf — so the PDF is rewritten
(linearized), not byte-preserving, and any digital signature is invalidated.
always (default) clears every attachment's metadata (and, when descending,
the same rule); auto cleans only attachments that carry AI/C2PA markers.
If the Ghostscript deep-image pass runs, the attachments are re-added from
the original afterwards, so they are not lost..tex/.ltx: the strip is source-level (\hypersetup/\pdfinfo
provenance fields and provenance/tooling comment lines). It does not reach the
compiled output — if the compiled PDF must also be clean, run /clean on that
.pdf as well. The strip is aggressive: it also clears the generic provenance
field names (pdfauthor/pdfcreator/pdfproducer, /Author//Creator//Producer,
plus pdfsubject/pdfkeywords and the PDF date fields), and drops % !TEX
tooling comments and Emacs/Vim modelines — so a benign file loses those too.remove_pixel: ctrlregen) or MarkDiffusion's DiffusionPurification (remove_pixel: diffusion); both are heavy, drift the image, and need the backend present (/capabilities). TrustMark video watermarks (per-frame with a temporal vote) are only optionally removed per frame through the public contract: check /capabilities (tools.ffmpeg and pixel_backends.ctrlregen/diffusion), then POST /clean on an .mp4/.mov with options.remove_pixel = ctrlregen|diffusion. It is partial, re-encodes the video, and is not vendor-detector-verified. Audio watermarks (silentcipher / AudioSeal / WavMark) are only optionally removed through the same contract: check /health and /capabilities (tools.ffmpeg), then POST /clean on an audio name (.wav/.mp3/.flac) with options.remove_audio_watermark = true. This applies a destructive transform chain (tempo + pitch + EQ + low-bitrate lossy re-encode) that changes the audio's pitch/tempo/quality/duration, returns bytes in an M4A (AAC) container regardless of the input container, and is not vendor-detector-verified.claude-text detector reports unavailable until it ships.If $WM/health fails: tell the user the service is down and how to start it
(docker compose up -d, make serve, or the published GHCR image). Do not
attempt to clean locally — this skill contains no cleaning code.
© guillaumemeyer, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in skills/remove-ai-marks of guillaumemeyer/watermarks-remover.
Open the folder on GitHubat commit c5297e9
AI Provenance Mark Remover next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AI Provenance Mark Remover this skillguillaumemeyer/watermarks-remover | 24k | — | ~4.9k | Automated safety check: Pass | MIT | |
| Anti Slop Writingadenaufal/anti-slop-writing | 147 | — | ~5.6k | Automated safety check: Pass | MIT | |
| Anti Slop Writing Idadenaufal/anti-slop-writing | 147 | — | ~9.4k | Automated safety check: Pass | MIT | |
| Codebase Managementgiancarloerra/SocratiCode | 3.3k | 1 repos | ~1.8k | Automated safety check: Pass | AGPL-3.0 | |
| Codebase Explorationgiancarloerra/SocratiCode | 3.3k | 1 repos | ~1.5k | Automated safety check: Pass | AGPL-3.0 | |
| Youtubeeat-pray-ai/yutu | 699 | — | ~1.1k | Automated safety check: Pass | MIT |
adenaufal/anti-slop-writing
Edit English prose for clarity, specificity, natural flow, and fit to the requested voice.
adenaufal/anti-slop-writing
Tulis dan sunting teks Bahasa Indonesia agar jelas, spesifik, alami untuk audiensnya, dan sesuai suara yang diminta.
giancarloerra/SocratiCode
Set up, index, and manage SocratiCode codebase indexing. An agent skill from giancarloerra/SocratiCode.
giancarloerra/SocratiCode
Explore and understand codebases using SocratiCode semantic search, dependency graphs, and context artifacts.
eat-pray-ai/yutu
A skill your agent uses whenever the user mentions YouTube, video uploads, channel management, playlists, video SEO, or any YouTube Data API operation.
ansvisor/ansvisor
Acts as an Answer Engine Optimization (AEO) analyst for users running Ansvisor.
guillaumemeyer/watermarks-remover
Audits prose for invisible Unicode characters and rewrites it while keeping facts, citations, code and required disclosures unchanged and the writer's voice intact.
Works with
Categories
Strips AI provenance marks from text and files: invisible Unicode, statistical text watermarks via rewriting, and C2PA, EXIF or XMP metadata across common formats. Work is split into layers. Layer A removes invisible Unicode characters from text, Layer B rewrites text to disturb statistical watermarks and is always offered, and a separate path cleans C2PA, EXIF, XMP and container metadata from PNG, JPEG, WebP, SVG, PDF, DOCX, ODT, HTML, Markdown and TeX files.
AI Provenance Mark Remover fits situations like: removing invisible Unicode characters from AI-written text; stripping C2PA or Content Credentials metadata from an image you own; cleaning AI-related metadata from a PDF or DOCX before sharing it; rewriting text to reduce statistical watermark signals.
Run `npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a claude-code`. Or copy the skill folder (skills/remove-ai-marks in guillaumemeyer/watermarks-remover) into .claude/skills/remove-ai-marks in your project. Claude Code loads it when a task matches its description.
Run `npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a codex`. Or copy the skill folder (skills/remove-ai-marks in guillaumemeyer/watermarks-remover) into .agents/skills/remove-ai-marks in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/remove-ai-marks, .gemini/skills/remove-ai-marks, .github/skills/remove-ai-marks and .opencode/skills/remove-ai-marks in your project.
Going by SKILL.md and its folder, AI Provenance Mark Remover needs the command-line tools its instructions call (curl, docker, make and python3) and credentials named WATERMARKS_SERVER_API_KEY. Our summary lists: A running watermark-cleaning HTTP service reachable with curl; A bearer key in WATERMARKS_SERVER_API_KEY if the service sets one.
SKILL.md contains no URLs. Its commands use curl and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AI Provenance Mark Remover is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with AI Provenance Mark Remover: Anti Slop Writing (adenaufal/anti-slop-writing, 147 stars), Anti Slop Writing Id (adenaufal/anti-slop-writing, 147 stars), Codebase Management (giancarloerra/SocratiCode, 3.3k stars) and Codebase Exploration (giancarloerra/SocratiCode, 3.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
guillaumemeyer (a GitHub user) maintains it in guillaumemeyer/watermarks-remover, which has 23,730 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 9, 2026.
Source: guillaumemeyer/watermarks-remover on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.