Agent skill

AI Provenance Mark Remover

by guillaumemeyer in guillaumemeyer/watermarks-remover

Strips AI provenance marks from text and files: invisible Unicode, statistical text watermarks via rewriting, and C2PA, EXIF or XMP metadata across common formats.

MITAuto-check passedDocuments & Office

Install AI Provenance Mark Remover

skills CLI
$ npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install guillaumemeyer/watermarks-remover remove-ai-marks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/guillaumemeyer/watermarks-remover.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/remove-ai-marks .claude/skills/remove-ai-marks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
remove-ai-marks
GitHub stars
24k
Token cost
~4.9k tokens
SKILL.md length
1,980 words
Files
7 (incl. references)
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Strips AI provenance marks from text and files: invisible Unicode, statistical text watermarks via rewriting, and C2PA, EXIF or XMP metadata across common formats.

  • Works in 5 steps: Classify input → Inspect first → Deterministic clean (always for matching… → …
  • Removing invisible Unicode characters from AI-written text
  • SKILL.md covers Service access, HTTP API (curl), Ethics and Workflow, plus 2 more sections
  • Calls curl, docker and make; needs WATERMARKS_SERVER_API_KEY

What it does

Work is split into layers. Layer A removes invisible Unicode characters from text, Layer B rewrites text to disturb statistical watermarks and is always offered, and a separate path cleans C2PA, EXIF, XMP and container metadata from PNG, JPEG, WebP, SVG, PDF, DOCX, ODT, HTML, Markdown and TeX files. It covers marks tied to Claude, Gemini and SynthID-class systems, OpenAI provenance and open-model sampling.

The skill is a thin client. The cleaning itself runs in a separate HTTP service, and the agent talks to it with curl, using the address in WATERMARKS_SERVICE_URL, which defaults to a local port, and an optional bearer key in WATERMARKS_SERVER_API_KEY. It checks the service first and stops with a clear message if it is unreachable rather than cleaning locally, and it advises HTTPS for remote hosts and no redirect following so the token is not forwarded.

A capabilities call reports which optional tools the service has, such as c2patool, exiftool, qpdf and ghostscript, plus detectors and heavier pixel backends, and the agent only recommends pixel removal or vendor detection when the service reports them. Six reference notes cover mark classes, vendor details, a removal matrix, intended use and an optional image harness.

When your agent uses it

  • Removing invisible Unicode characters from AI-written text
  • Stripping C2PA or Content Credentials metadata from an image you own
  • Cleaning AI-related metadata from a PDF or DOCX before sharing it
  • Rewriting text to reduce statistical watermark signals

Example prompts

  • “Remove the invisible Unicode characters from draft.md and show me what changed.”
  • “Strip the C2PA metadata from banner.png and check that nothing remains.”
  • “Run /remove-ai-marks on report.docx and tell me which layers applied.”

Requirements

  • A running watermark-cleaning HTTP service reachable with curl
  • A bearer key in WATERMARKS_SERVER_API_KEY if the service sets one

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Classify input
  2. Inspect first
  3. Deterministic clean (always for matching inputs)
  4. Layer B — always offer rewrite (prose)
  5. Report

What it can do on your machine

Read from SKILL.md and the folder at commit c5297e9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • docker
    • make
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • WATERMARKS_SERVER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Provenance Mark Remover loads about 4.9k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 132 tokens; SKILL.md has 1,980 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~132
When it runs · the whole SKILL.md, loaded when a task matches
~4.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from guillaumemeyer/watermarks-remover at commit c5297e9, republished under its MIT licence (© guillaumemeyer). 1,980 words, ~4,900 tokens.

Download SKILL.mdSave it as .claude/skills/remove-ai-marks/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
remove-ai-marks
description
Remove multi-vendor AI provenance marks: invisible Unicode (Layer A), statistical text watermarks via rewrite (Layer B, always offer), and C2PA/EXIF/XMP/container metadata on PNG/JPEG/WebP/SVG/PDF/DOCX/ODT/HTML/MD/TEX. Covers Claude, Gemini/SynthID-class, OpenAI provenance, and open-LLM sampling marks. Use when the user asks to strip watermarks, remove C2PA/Content Credentials, clean AI metadata, remove invisible Unicode, anti-detect clean AI output, or runs /remove-ai-marks (aliases: /remove-claude-marks).

Remove AI marks

Multi-vendor anti-detection hygiene for text (Unicode + statistical rewrite) and files (C2PA / AI metadata across common containers).

Read if needed:

  • references/mark-classes.md — Unicode / sampling / C2PA / containers
  • references/vendor-notes.md — Claude, Gemini/SynthID, OpenAI, open-LLM
  • references/removal-matrix.md — which layer when
  • references/ethics.md — intended use
  • references/how-claude-marks.md — Anthropic-specific detail
  • references/markdiffusion.md — optional MarkDiffusion image harness (schemes, honesty caveats)

This skill is a thin client. All deterministic cleaning machinery runs in a separate HTTP service (this repo's service/), so the agent host needs no Python, venvs, or cleaning tools. Call the service with curl; never run cleaning scripts directly.

Service access

Base URL comes from WATERMARKS_SERVICE_URL, default http://127.0.0.1:8765:

bash
WM="${WATERMARKS_SERVICE_URL:-http://127.0.0.1:8765}"

The service is started either by the operator (docker compose up -d, or a published GHCR image) or locally (make serve). Always check it first, and stop with a clear message if it is unreachable — never fall back to local cleaning:

bash
AUTH_HEADER=()
if [ -n "$WATERMARKS_SERVER_API_KEY" ]; then
  AUTH_HEADER=(-H "Authorization: Bearer $WATERMARKS_SERVER_API_KEY")
fi
curl -sf "${AUTH_HEADER[@]}" "$WM/health"
# {"ok": true, "version": "..."}

If WATERMARKS_SERVER_API_KEY is set on the service, every request (including the health check and capabilities) needs -H "Authorization: Bearer $WATERMARKS_SERVER_API_KEY". The default URL is loopback; when the service runs on another host, set WATERMARKS_SERVICE_URL to an https:// URL so the token is not sent in cleartext, and do not add -L (a redirect could forward the token to another host).

Capabilities
bash
curl -s "${AUTH_HEADER[@]}" "$WM/capabilities"

Reports which optional tools are available server-side (c2patool, exiftool, qpdf, ghostscript), scorers present (scorers.stylometry, scorers.synthid, scorers.synthid_http), text-watermark detectors (text_detectors.markllm, text_detectors.claude-text), and which heavy backends are configured (pixel_backends.ctrlregen, pixel_backends.diffusion, harnesses.markllm). Drive your advice from this: only recommend pixel removal / SynthID scoring / vendor detection when the service reports the backend present.

HTTP API (curl)

Payloads are JSON with the file as base64. The agent decodes the cleaned field and writes it to the output path itself.

MethodPathBodyReturns
GET/health—{"ok": true, "version": ...}
GET/capabilities—optional tools / backends present
GET/openapi.json—dynamically generated OpenAPI 3.0.3 spec
POST/inspect{"file": "<base64>", "name": "notes.md"}{"ok", "kind", "suspicious", "report"}
POST/detect{"file": "<base64>", "name": "notes.txt"}{"ok", "kind", "detections": [...]}
POST/clean{"file": "<base64>", "name": "notes.md", "options": {...}}{"ok", "kind", "cleaned": "<base64>", "report"}

/clean and /inspect route by the uploaded name extension plus the bytes; unrecognized formats answer kind: "unknown" (/inspect) or 400 (/clean). When writing a temp file for pasted text, keep a known extension (.txt / .md) in the name you send.

The machine-readable contract lives at $WM/openapi.json — plug it into any OpenAPI tooling (client generators, Swagger UI, editors) instead of hand-rolling clients.

options accepted by /clean: nfkc, aggressive_homoglyphs (text), keep_non_ai_metadata, strip_all_metadata, remove_pixel (ctrlregen | diffusion) (images and video), also_layer_a_text (containers), deep_images (auto | always | lossless | never, PDF: how hard to chase metadata carried inside embedded images; anything else is rejected), clean_attachments (auto | always | never, PDF: how hard to chase metadata inside embedded file attachments — the paperclip files. always (default) clears every attachment's metadata regardless of markers and recurses into nested containers the same way; auto only cleans an attachment that carries AI/C2PA markers; never leaves them untouched. Needs qpdf. Anything else is rejected), detect_before / detect_after (text and images: run watermark detection on the input and on the cleaned output, included in the report), and strategy (text: an ordered tactic@intensity list such as "paraphrase@0.8,mlm@0.2" that runs the Layer B rewrite after Layer A; when omitted the default from config/clean_strategy.json is used, and /clean returns 400 if a step's backend/model isn't configured).

Inspect first (decide, don't guess):

bash
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/inspect" -H 'Content-Type: application/json' \
  -d "{\"file\": \"$(base64 < notes.md | tr -d '\n')\", \"name\": \"notes.md\"}"

Clean (text / image / container are auto-detected by name + bytes):

bash
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/clean" -H 'Content-Type: application/json' \
  -d "{\"file\": \"$(base64 < notes.md | tr -d '\n')\", \"name\": \"notes.md\"}"

Decode the returned cleaned base64 into the output file (*.cleaned.* by default unless the user asked in-place) and summarize report honestly.

(On Windows agents, build base64 with [Convert]::ToBase64String([IO.File]::ReadAllBytes("notes.md")).)

Ethics

Intended for your own content (privacy, hygiene, research). Do not market results as "proves human-written." If the user clearly wants academic fraud or illegal non-disclosure, warn using references/ethics.md and still only perform technical cleaning they own.

Workflow

1. Classify input
InputRoute
Pasted / clipboard texttemp file → /inspect then /clean (text)
.txt / codetext Layer A (+ formatter for code)
.md / .html / .tex / .ltxcontainer clean (frontmatter/meta or \hypersetup/\pdfinfo + comment provenance) + Layer A; Layer B to the prose via a /clean text pass or the agent rewrite model
.png / .jpg / .jpeg / .webp / .avif / .heic / .bmp / .gif / .tiffimage metadata strip
.svg / .pdf / .docx / .epub / .odtcontainer metadata strip
Directory / websiteaggregate audit via the service CLIs (see below)

The service routes by filename extension first, then by magic bytes, so you mostly just send the file.

2. Inspect first
bash
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/inspect" -H 'Content-Type: application/json' \
  -d "{\"file\": \"$(base64 < path | tr -d '\n')\", \"name\": \"$(basename path)\"}"

Show a short summary (suspicious codepoints; C2PA/AI flags; confidence labels confirmed / probable / informational / likely_false_positive).

Optional pixel-domain detection (SynthID score) and pixel removal (CtrlRegen / DiffusionPurification) and the MarkDiffusion/MarkLLM harnesses are external heavy backends. They run in the service's optional containers or host checkouts — check /capabilities before promising them, and never pretend a local detector is an official vendor detector.

2b. Watermark detection before/after (when configured)

When /capabilities reports a detector (text_detectors.markllm) or an image scorer (scorers.synthid_http / scorers.synthid), measure the result by detecting before and after cleaning:

bash
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/detect" -H 'Content-Type: application/json' \
  -d '{"file": "'"$(base64 < notes.txt | tr -d '\n')"'", "name": "notes.txt"}'

Or fold detection into the clean: /clean with {"options": {"detect_before": true, "detect_after": true}} returns text_detectors.before/after (text) or synthid_before/synthid_after (images) in the report. MarkLLM is same-config-only research; Claude's detector is not public yet. (Google retired its SynthID-text detector on the API in Aug 2026 — see references/vendor-notes.md.)

3. Deterministic clean (always for matching inputs)

Any supported file (unified):

bash
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/clean" -H 'Content-Type: application/json' \
  -d "{\"file\": \"$(base64 < INPUT | tr -d '\n')\", \"name\": \"$(basename INPUT)\"}"

Decode cleaned → OUTPUT (*.cleaned.* unless the user asked in-place). Re-inspect the result when residual risk matters.

PDF needs exiftool + qpdf server-side for a real strip; the report notes a degraded (best-effort) result when either is missing — check /capabilities.

Images — optional pixel removal: only when capabilities.pixel_backends says the backend is present:

bash
curl -s -X POST "${AUTH_HEADER[@]}" "$WM/clean" -H 'Content-Type: application/json' \
  -d "{\"file\": \"$(base64 < shot.png | tr -d '\n')\", \"name\": \"shot.png\", \
       \"options\": {\"remove_pixel\": \"ctrlregen\"}}"
4. Layer B — always offer rewrite (prose)

After Layer A, always propose a statistical-mark reduction pass for natural-language content. Do not skip this step silently.

For plain text (pasted / .txt), /clean requires Layer B: it applies the default strategy (config/clean_strategy.json, e.g. paraphrase@0.8,mlm@0.2) or the options.strategy override after Layer A, reports report.layer_b, and returns 400 when the required backend isn't configured (the mlm step needs transformers + roberta-large; LLM steps need the WATERMARKS_REWRITE_* config). Markdown/HTML and other containers (.md, .html, .tex, .pdf, .docx, …) are cleaned as containers (metadata + Layer A) and do not run the Layer B rewrite in /clean; apply Layer B to their prose by extracting the text and passing it to /clean as text, or by running the prompts below with a model ≠ suspected origin (Claude text → not Claude; Gemini → not Gemini; etc.). Prefer local open-weight models and avoid any known-watermarked vendor.

Multi-pass recipe:

  1. Layer A clean (via /clean)
  2. Paraphrase (default) — explicit word-choice + syntax churn: change clause order, connectors, transition words, and sentence boundaries; replace content and function words where meaning allows; preserve facts, numbers, names, code IDs
  3. Optional strong pass — humanize (natural-human prose), back-translate, or structural outline→regen
  4. Layer A again on the result (/clean)
  5. Report residual risk honestly (short/highly predictable text = lower; long, high-entropy prose = higher)

Code files: Prefer formatter (prettier, black, gofmt, …) + Layer A. Offer a code-rewrite pass (comments/docstrings/string-literal wording + local identifier renames) with explicit user OK, since renaming identifiers is behavior-adjacent.

Rewrite prompts (use as-is)

Paraphrase preserve meaning (word choice + syntax):

Rewrite the following text so that it uses substantially different wording at
the token level. Change clause order, connectors, and transition words; vary
sentence boundaries and length; and replace both content words and function
words where meaning allows. Preserve all facts, numbers, names, and technical
identifiers. Do not add or remove claims. Output only the rewritten text.

---
{TEXT}

Humanize (write like a human):

Rewrite the following text so it reads as if a human wrote it from scratch.
Vary sentence rhythm and length, replace formulaic AI-style transitions and
filler with concrete natural phrasing, and use plain, varied wording. Preserve
all facts, numbers, names, and technical identifiers. Do not add or remove
claims. Output only the rewritten text.

---
{TEXT}

Code (comments / docstrings / identifiers):

Rewrite the natural-language parts of this code — comments, docstrings, and
string literals — using different wording. Rename local variables, function
parameters, and private helper names to semantically equivalent names. Preserve
program behavior, public API names, and all values that affect output. Output
only the rewritten code.

---
{TEXT}

Back-translate (two steps):

Translate the following text to {LANG}. Output only the translation.
Translate the following text to {ORIGINAL_LANG}. Preserve meaning; use natural
phrasing. Output only the translation.

Structural:

Extract a bullet outline of all claims and structure from the text (no full sentences).

Then:

Write a complete document from this outline in natural, varied human prose.
Avoid formulaic transitions. Do not omit any bullet. Output only the document.
Show full SKILL.md (809 more words)Show less
Aggregate audits (directories / websites)

The service image also ships the audit CLIs. Run them as one-shot containers when a directory or website audit is needed:

bash
# Local checkout, or inside the service image:
docker run --rm -v "$(pwd)/src:/data:ro" watermarks-remover \
  /app/scripts/audit_dir.py /data --json

Or against a local checkout of the repo: python3 service/scripts/audit_dir.py DIR --json.

Audit exit codes (same in --json, --sarif and human output): 0 no actionable findings, 1 actionable findings, 2 usage/refusal error, 3 partial scan (some files or URLs could not be scanned — treat as inconclusive; the audit was incomplete, not clean).

5. Report

Always state:

  • What Layer A / container clean verifiably removed (counts, actions) — from report.
  • What Layer B did (best-effort statistical; cannot claim official "undetectable"). Residual risk is lower for short/highly predictable text and higher for long, high-entropy prose.
  • Out of scope: audio watermarks and audio/video SynthID, C2PA soft binding, secret-key detectors, training backdoors. Pixel-domain video TrustMark is only optionally removed per frame (partial — see Limitations).
  • Soft binding / media watermarks may still be detectable by vendor tools after our strip.
  • Prefer writing *.cleaned.* unless user asked in-place.
  • Ethics one-liner: own content / no compliance theater.

Limitations

  • Layer A does not remove token-sampling watermarks.
  • Layer B cannot be gold-verified without vendor detectors / keys. Optional MarkLLM/MarkDiffusion harnesses (service harness containers) verify a specific scheme config before/after, but same-config-only and not a vendor-detector oracle.
  • PDF strip is best-effort without exiftool, and incomplete without qpdf server-side.
  • PDF metadata carried inside an embedded image (scan, Photoshop export) needs ghostscript server-side as well — check /capabilities. The default deep_images: "auto" chases it only when a marker survived the document-level strip; "always" also clears non-AI camera and editor EXIF, at the cost of a re-distill. Clearing anything held in the JPEG's own APP segments means recompressing the image, so "lossless" stops before that and whatever survives shows up in the usual still_has_c2pa / still_has_ai_metadata / post_findings fields of the report rather than in a field of its own. An unrecognised value is an error, not a silent fallback.
  • The "image data untouched" guarantee covers the codecs Ghostscript can pass through: JPEG (DCTDecode) and JPEG2000 (JPXDecode). Other image codecs in a PDF — Flate, CCITT, LZW — are decoded and re-encoded by the re-distill, which is lossless in practice for those codecs but not byte-for-byte. Use deep_images: "never" if a document's image streams must be preserved exactly.
  • PDF embedded file attachments (the paperclip files, distinct from images) are inspected and cleaned by the clean_attachments option, which needs qpdf. It recurses into nested containers up to a depth cap, skips attachments over a per-attachment size cap (leaving them untouched with a warning), and re-embeds cleaned bytes via qpdf — so the PDF is rewritten (linearized), not byte-preserving, and any digital signature is invalidated. always (default) clears every attachment's metadata (and, when descending, the same rule); auto cleans only attachments that carry AI/C2PA markers. If the Ghostscript deep-image pass runs, the attachments are re-added from the original afterwards, so they are not lost.
  • .tex/.ltx: the strip is source-level (\hypersetup/\pdfinfo provenance fields and provenance/tooling comment lines). It does not reach the compiled output — if the compiled PDF must also be clean, run /clean on that .pdf as well. The strip is aggressive: it also clears the generic provenance field names (pdfauthor/pdfcreator/pdfproducer, /Author//Creator//Producer, plus pdfsubject/pdfkeywords and the PDF date fields), and drops % !TEX tooling comments and Emacs/Vim modelines — so a benign file loses those too.
  • Pixel-domain image watermarks can be removed optionally via the external CtrlRegen backend (remove_pixel: ctrlregen) or MarkDiffusion's DiffusionPurification (remove_pixel: diffusion); both are heavy, drift the image, and need the backend present (/capabilities). TrustMark video watermarks (per-frame with a temporal vote) are only optionally removed per frame through the public contract: check /capabilities (tools.ffmpeg and pixel_backends.ctrlregen/diffusion), then POST /clean on an .mp4/.mov with options.remove_pixel = ctrlregen|diffusion. It is partial, re-encodes the video, and is not vendor-detector-verified. Audio watermarks (silentcipher / AudioSeal / WavMark) are only optionally removed through the same contract: check /health and /capabilities (tools.ffmpeg), then POST /clean on an audio name (.wav/.mp3/.flac) with options.remove_audio_watermark = true. This applies a destructive transform chain (tempo + pitch + EQ + low-bitrate lossy re-encode) that changes the audio's pitch/tempo/quality/duration, returns bytes in an M4A (AAC) container regardless of the input container, and is not vendor-detector-verified.
  • The reverse-SynthID scorer is external, best-effort, and under a non-commercial Research License; not an official Google detector. Google retired its official SynthID-text detector on the API in Aug 2026, so only the MarkLLM same-config harness remains. Claude's detection API has been announced but is not public yet — the claude-text detector reports unavailable until it ships.
  • C2PA soft binding (content watermark that re-links to a remote manifest after metadata strip) is out of scope — stripping hard-bound C2PA does not clear it.
  • Data-driven / backdoor model marks (trigger phrases) are out of scope.

Service not reachable?

If $WM/health fails: tell the user the service is down and how to start it (docker compose up -d, make serve, or the published GHCR image). Do not attempt to clean locally — this skill contains no cleaning code.

© guillaumemeyer, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/remove-ai-marks of guillaumemeyer/watermarks-remover.

  • SKILL.md
  • references/ethics.md
  • references/how-claude-marks.md
  • references/mark-classes.md
  • references/markdiffusion.md
  • references/removal-matrix.md
  • references/vendor-notes.md

Open the folder on GitHubat commit c5297e9

Compare with similar skills

AI Provenance Mark Remover next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Provenance Mark Remover compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Provenance Mark Remover this skillguillaumemeyer/watermarks-remover24k—~4.9kAutomated safety check: PassMIT
Anti Slop Writingadenaufal/anti-slop-writing147—~5.6kAutomated safety check: PassMIT
Anti Slop Writing Idadenaufal/anti-slop-writing147—~9.4kAutomated safety check: PassMIT
Codebase Managementgiancarloerra/SocratiCode3.3k1 repos~1.8kAutomated safety check: PassAGPL-3.0
Codebase Explorationgiancarloerra/SocratiCode3.3k1 repos~1.5kAutomated safety check: PassAGPL-3.0
Youtubeeat-pray-ai/yutu699—~1.1kAutomated safety check: PassMIT

Similar skills

  • Anti Slop Writing

    adenaufal/anti-slop-writing

    Edit English prose for clarity, specificity, natural flow, and fit to the requested voice.

    147 GitHub stars~5.6k tokensUpdated 14 days ago
    Writing & ContentAuto-check passed
  • Anti Slop Writing Id

    adenaufal/anti-slop-writing

    Tulis dan sunting teks Bahasa Indonesia agar jelas, spesifik, alami untuk audiensnya, dan sesuai suara yang diminta.

    147 GitHub stars~9.4k tokensUpdated 14 days ago
    Writing & ContentAuto-check passed
  • Codebase Management

    giancarloerra/SocratiCode

    Set up, index, and manage SocratiCode codebase indexing. An agent skill from giancarloerra/SocratiCode.

    3.3k GitHub starsUsed in 1 repo~1.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Codebase Exploration

    giancarloerra/SocratiCode

    Explore and understand codebases using SocratiCode semantic search, dependency graphs, and context artifacts.

    3.3k GitHub starsUsed in 1 repo~1.5k tokens
    DatabasesAuto-check passed
  • Youtube

    eat-pray-ai/yutu

    A skill your agent uses whenever the user mentions YouTube, video uploads, channel management, playlists, video SEO, or any YouTube Data API operation.

    699 GitHub stars~1.1k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Ansvisor Aeo Coach

    ansvisor/ansvisor

    Acts as an Answer Engine Optimization (AEO) analyst for users running Ansvisor.

    134 GitHub stars~2.6k tokensUpdated yesterday
    Marketing & SEOAuto-check passed

More from guillaumemeyer/watermarks-remover

  • User-Facing Text Cleanup

    guillaumemeyer/watermarks-remover

    Audits prose for invisible Unicode characters and rewrites it while keeping facts, citations, code and required disclosures unchanged and the writer's voice intact.

    24k GitHub stars~3.5k tokensUpdated 2 days ago
    Auto-check passed

Questions about AI Provenance Mark Remover

What does AI Provenance Mark Remover do?

Strips AI provenance marks from text and files: invisible Unicode, statistical text watermarks via rewriting, and C2PA, EXIF or XMP metadata across common formats. Work is split into layers. Layer A removes invisible Unicode characters from text, Layer B rewrites text to disturb statistical watermarks and is always offered, and a separate path cleans C2PA, EXIF, XMP and container metadata from PNG, JPEG, WebP, SVG, PDF, DOCX, ODT, HTML, Markdown and TeX files.

When should I use AI Provenance Mark Remover?

AI Provenance Mark Remover fits situations like: removing invisible Unicode characters from AI-written text; stripping C2PA or Content Credentials metadata from an image you own; cleaning AI-related metadata from a PDF or DOCX before sharing it; rewriting text to reduce statistical watermark signals.

How do I install AI Provenance Mark Remover in Claude Code?

Run `npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a claude-code`. Or copy the skill folder (skills/remove-ai-marks in guillaumemeyer/watermarks-remover) into .claude/skills/remove-ai-marks in your project. Claude Code loads it when a task matches its description.

How do I install AI Provenance Mark Remover in Codex?

Run `npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a codex`. Or copy the skill folder (skills/remove-ai-marks in guillaumemeyer/watermarks-remover) into .agents/skills/remove-ai-marks in your project. Codex loads it when a task matches its description.

Can I use AI Provenance Mark Remover in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add guillaumemeyer/watermarks-remover --skill remove-ai-marks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/remove-ai-marks, .gemini/skills/remove-ai-marks, .github/skills/remove-ai-marks and .opencode/skills/remove-ai-marks in your project.

What does AI Provenance Mark Remover need to run?

Going by SKILL.md and its folder, AI Provenance Mark Remover needs the command-line tools its instructions call (curl, docker, make and python3) and credentials named WATERMARKS_SERVER_API_KEY. Our summary lists: A running watermark-cleaning HTTP service reachable with curl; A bearer key in WATERMARKS_SERVER_API_KEY if the service sets one.

Does AI Provenance Mark Remover access the network?

SKILL.md contains no URLs. Its commands use curl and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is AI Provenance Mark Remover safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Provenance Mark Remover use?

AI Provenance Mark Remover is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Provenance Mark Remover use?

About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.2k tokens, read only when the agent opens those files.

What are the alternatives to AI Provenance Mark Remover?

Skills that share tags, products or a category with AI Provenance Mark Remover: Anti Slop Writing (adenaufal/anti-slop-writing, 147 stars), Anti Slop Writing Id (adenaufal/anti-slop-writing, 147 stars), Codebase Management (giancarloerra/SocratiCode, 3.3k stars) and Codebase Exploration (giancarloerra/SocratiCode, 3.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Provenance Mark Remover?

guillaumemeyer (a GitHub user) maintains it in guillaumemeyer/watermarks-remover, which has 23,730 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 9, 2026.

Source: guillaumemeyer/watermarks-remover on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.