Embed C2PA provenance in AI-generated images, video or PDF by script.

MITAuto-check passedDocuments & Office

Install C2pa Metadata

skills CLI
$ npx skills add indranilbanerjee/digital-marketing-pro --skill c2pa-metadata -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install indranilbanerjee/digital-marketing-pro c2pa-metadata --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/indranilbanerjee/digital-marketing-pro.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/c2pa-metadata .claude/skills/c2pa-metadata && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
c2pa-metadata
GitHub stars
862
Used in
1 other repo
Token cost
~2.5k tokens
SKILL.md length
874 words
Files
1
Skills in repo
162
Repo updated
First seen
Licence
MIT

At a glance

Embed C2PA provenance in AI-generated images, video or PDF by script.

  • Works in 3 steps: Obtain a C2PA-compatible signing… → Store the cert + key securely (do NOT… → Pass --signing-cert and --signing-key on…
  • Documents & Office work in your project
  • SKILL.md covers Purpose, When to invoke, Quick examples and AI claim values (IPTC digital…, plus 6 more sections
  • Calls python; reaches contentcredentials.org and timestamp.digicert.com

What it does

C2pa Metadata is an agent skill from indranilbanerjee/digital-marketing-pro. Embed C2PA provenance in AI-generated images, video or PDF by script. "add content credentials to this asset"

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office. The repository describes itself as: An open-source AI marketing operating system for strategy, SEO, AEO/GEO, paid media, content, CRM, and analytics - grounded in brand context, human approval, and verifiable… The licence is MIT.

When your agent uses it

  • Documents & Office work in your project

Example prompts

  • “add content credentials to this asset”
  • “/c2pa-metadata”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Obtain a C2PA-compatible signing certificate from a CAI-recognized authority (Adobe, Truepic, Numbers Protocol, Microsoft Azure…
  2. Store the cert + key securely (do NOT commit to git; use an environment-variable path or secret store).
  3. Pass --signing-cert and --signing-key on every production invocation.

What it can do on your machine

Read from SKILL.md and the folder at commit 9e949f3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • contentcredentials.org
    • timestamp.digicert.com

    Also links to:

    • c2pa.org
    • spec.c2pa.org
    • opensource.contentauthenticity.org
    • contentauthenticity.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

C2pa Metadata loads about 2.5k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 874 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from indranilbanerjee/digital-marketing-pro at commit 9e949f3, republished under its MIT licence (© indranilbanerjee). 874 words, ~2,467 tokens.

Download SKILL.mdSave it as .claude/skills/c2pa-metadata/SKILL.md (or your agent's skills folder).
name
c2pa-metadata
description
Embed C2PA provenance in AI-generated images, video or PDF by script. "add content credentials to this asset"

/digital-marketing-pro:c2pa-metadata — Embed Content Authenticity Provenance

Purpose

Wraps scripts/embed-c2pa.py to add a C2PA (Coalition for Content Provenance and Authenticity) manifest to any AI-generated marketing asset. The manifest carries a machine-readable provenance trail (who generated it, what generator was used, what prompt produced it, when it was reviewed) plus a visible AI-generation claim in the IPTC digital-source-type vocabulary.

This is the technical mechanism brands use to comply with:

  • EU AI Act Article 50 (applicable 2 August 2026) — generative-AI marketing content must be marked in a machine-readable format using open, interoperable standards. C2PA is the emerging backbone. Penalty for non-compliance: up to €15 million or 3% global annual turnover.
  • NY synthetic-performer disclosure law (effective June 2026) — $1K–$5K per violation, $10K repeat; applies to synthetic influencers and AI-generated endorsements.
  • FTC May 2026 endorsement guidance — covers AI testimonials and synthetic creator content.
  • Australia Online Safety Act / UK Online Safety Act — emerging deepfake disclosure requirements.

The resulting asset can be inspected by any C2PA-aware viewer (Adobe Photoshop, Lightroom, Truepic, contentcredentials.org/verify).

C2PA spec versions to be aware of (June 2026)
  • Content Credentials 2.3 (released 9 February 2026 — launch post) added format support for: live video (broadcast/streaming), plain text documents, OGG Vorbis audio, large AVI video files, and EXIF Original Preservation Images. If a brand is signing live-stream video or text-based assets for the first time, 2.3 is the floor version to target.
  • C2PA Spec 2.4 (April 2026 — spec.c2pa.org/specifications/specifications/2.4) introduces the AI Disclosure Assertion (c2pa.ai-disclosure) for machine-readable AI transparency info — this is the assertion the EU AI Act Article 50 deployer pathway will rely on. The final Code of Practice on Transparency of AI-Generated Content (published 10 June 2026) references C2PA-style assertions as the canonical machine-readable marking mechanism for both providers and deployers. See skills/context-engine/eu-code-of-practice.md for the full Article 50 context.
  • The C2PA Trust List is now handled via the public C2PA Conformance Program (any CA meeting the Certificate Policy can join). Production signing certificates should come from a Conformance-Program-listed CA, not an ad-hoc cert.

For DMP outputs: embed-c2pa.py now supports --ai-disclosure. Pass it to embed the C2PA 2.4 c2pa.ai-disclosure assertion alongside the existing IPTC digital-source-type claim. The combination gives you both human-readable (IPTC) and machine-readable (c2pa.ai-disclosure) EU AI Act Article 50 signaling — this is the deployer-side machine-readable pathway the final Code of Practice (10 June 2026) points to as the canonical marking mechanism. See skills/context-engine/eu-code-of-practice.md for the full Article 50 context.

When to invoke

  • Right after any AI image / video / audio generation step in the engagement workflow (Part 11 — AI Creative Instructions output)
  • Before handing a generated asset to the design team for review
  • As a pre-publish gate in /digital-marketing-pro:check for EU-targeted assets
  • Bulk-applying to a backlog of AI-generated assets before EU AI Act enforcement on 2 Aug 2026

Quick examples

bash
# Single asset — image generated by Vertex AI / Nano Banana Pro
/digital-marketing-pro:c2pa-metadata \
    --input assets/q3-launch-hero.png \
    --output assets/signed/q3-launch-hero.png \
    --brand "Acme Corp" \
    --generator "Vertex AI / Nano Banana Pro" \
    --ai-claim ai-generated-content \
    --prompt "minimalist product hero shot, soft natural lighting"

# Video with human review tracked
/digital-marketing-pro:c2pa-metadata \
    --input campaigns/launch-video-v3.mp4 \
    --output campaigns/signed/launch-video-v3.mp4 \
    --brand "Acme Corp" \
    --generator "Runway Gen-4" \
    --ai-claim ai-generated-content \
    --reviewer "Jane Smith"

# EU-targeted asset — add the machine-readable Article 50 AI-disclosure assertion (C2PA 2.4)
/digital-marketing-pro:c2pa-metadata \
    --input assets/q3-launch-hero.png \
    --output assets/signed/q3-launch-hero.png \
    --brand "Acme Corp" \
    --generator "Vertex AI / Nano Banana Pro" \
    --ai-claim ai-generated-content \
    --ai-disclosure \
    --prompt "minimalist product hero shot, soft natural lighting"

# Human-created image with AI-assisted edits
/digital-marketing-pro:c2pa-metadata \
    --input assets/founder-headshot-edited.jpg \
    --output assets/signed/founder-headshot-edited.jpg \
    --brand "Acme Corp" \
    --generator "Adobe Generative Fill" \
    --ai-claim ai-assisted-edits

# Production sign with a real C2PA signing certificate
/digital-marketing-pro:c2pa-metadata \
    --input assets/q3-launch-hero.png \
    --output assets/signed/q3-launch-hero.png \
    --brand "Acme Corp" \
    --generator "Vertex AI / Nano Banana Pro" \
    --ai-claim ai-generated-content \
    --signing-cert /secure/c2pa-prod-cert.pem \
    --signing-key /secure/c2pa-prod-key.pem

AI claim values (IPTC digital source type)

ValueWhen to useMaps to IPTC URI
ai-generated-contentAsset fully generated by AIalgorithmicMedia
ai-assisted-editsHuman-created + AI-edited (e.g. Generative Fill)compositeWithTrainedAlgorithmicMedia
ai-no-substantive-changesAI used (e.g. upscaling) but no semantic changeminorHumanEdits

The IPTC vocabulary is what EU AI Act regulators reference — using these values rather than ad-hoc strings makes the asset interoperable with the Article 50 enforcement tooling.

Show full SKILL.md (354 more words)Show less

Supported asset formats

.png · .jpg/.jpeg · .webp · .gif · .tiff · .mp4 · .mov · .webm · .mp3 · .wav · .pdf

Signing certificate

Production C2PA signatures require a certificate from a CAI-recognized signing authority. The script will use one if you pass --signing-cert and --signing-key. If you omit them, the script generates a self-signed 90-day dev certificate for development testing only — a self-signed asset will verify as "signature present but signer not in trust list" at contentcredentials.org/verify.

For production deployment:

  1. Obtain a C2PA-compatible signing certificate from a CAI-recognized authority (Adobe, Truepic, Numbers Protocol, Microsoft Azure Confidential Ledger).
  2. Store the cert + key securely (do NOT commit to git; use an environment-variable path or secret store).
  3. Pass --signing-cert and --signing-key on every production invocation.

Reference: opensource.contentauthenticity.org/docs/manifest/signing-manifests/

Python dependencies

  • c2pa-python==0.38.0: required for signing and for --verify
  • cryptography==46.0.3: only needed for the dev self-signed cert path

The script never installs anything. If either package is missing it prints the exact python -m pip install "…" command and exits with code 2; show that command to the user and let them decide whether to run it. Do not run pip on their behalf.

Each signature requests a timestamp from http://timestamp.digicert.com (a hash of the claim, not the asset). The dev key, when used, is deleted as soon as the script exits.

Output

The script prints a JSON status report to stdout:

json
{
  "status": "success",
  "input": "assets/q3-launch-hero.png",
  "output": "assets/signed/q3-launch-hero.png",
  "size_bytes": 482371,
  "brand": "Acme Corp",
  "generator": "Vertex AI / Nano Banana Pro",
  "ai_claim": "ai-generated-content",
  "created": "2026-05-16T10:30:00+00:00",
  "manifest_assertions": ["c2pa.actions", "stds.schema-org.CreativeWork"],
  "using_dev_cert": false,
  "verify_url": "https://contentcredentials.org/verify"
}

Integration with the engagement workflow

In a full 12-part engagement, this skill plugs in at Part 11 — AI Creative Instructions output. After a creative brief is rendered as an actual asset (by your creative tooling or a manual creative process), the resulting file passes through c2pa-metadata before being checked in to engagements/<slug>/11-creative-briefs/signed/.

The /digital-marketing-pro:check pre-publish gate should also verify that all AI-generated assets in an EU-targeted campaign carry a C2PA manifest. v3.4 adds this verification to the EU jurisdiction rule pack in skills/context-engine/compliance-rules.md.

© indranilbanerjee, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/c2pa-metadata of indranilbanerjee/digital-marketing-pro.

Open the folder on GitHubat commit 9e949f3

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in indranilbanerjee/digital-marketing-pro, which our catalogue first saw on October 7, 2026.

Compare with similar skills

C2pa Metadata next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

C2pa Metadata compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
C2pa Metadata this skillindranilbanerjee/digital-marketing-pro8621 repos~2.5kAutomated safety check: PassMIT
Markdown Article FormatterJimLiu/baoyu-skills27k6 repos~3.5kAutomated safety check: PassMIT
MarkitdownImCa0/just-laws78114 repos~3.2kAutomated safety check: NotesMIT
Obsidian MarkdownAtmosphere/atmosphere3.8k20 repos~1.3kAutomated safety check: PassApache-2.0
DOCXrvdbreemen/OTGW-firmware20733 repos~4.3kAutomated safety check: PassProprietary
Word Document Reader and WriterHKUDS/DeepTutor41k—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Markdown Article Formatter

    JimLiu/baoyu-skills

    Reformats plain text or Markdown articles with frontmatter, a title, a summary, headings, bold, lists and code blocks, and saves a separate formatted copy.

    27k GitHub starsUsed in 6 repos~3.5k tokens
    Documents & OfficeAuto-check passed
  • Markitdown

    ImCa0/just-laws

    Convert files and office documents to Markdown. An agent skill from ImCa0/just-laws.

    781 GitHub starsUsed in 14 repos~3.2k tokens
    Documents & OfficeAuto-check: notes
  • Obsidian Markdown

    Atmosphere/atmosphere

    Create and edit Obsidian Flavored Markdown with wikilinks, embeds, callouts, properties, and other Obsidian-specific syntax.

    3.8k GitHub starsUsed in 20 repos~1.3k tokens
    Documents & OfficeAuto-check passed
  • DOCX

    rvdbreemen/OTGW-firmware

    A skill your agent uses whenever the user wants to create, read, edit, or manipulate Word documents (.docx files).

    207 GitHub starsUsed in 33 repos~4.3k tokens
    Documents & OfficeAuto-check passed
  • Reads, creates and edits Word .docx files with python-docx, and drops to raw OOXML for tracked changes, comments and byte-exact edits.

    41k GitHub stars~2.5k tokensUpdated 3 days ago
    Documents & OfficeAuto-check passed
  • Crossposting

    wasp-lang/wasp

    Crosspost Wasp blog articles (MDX) to DEV.to and Medium. An agent skill from wasp-lang/wasp.

    19k GitHub stars~1.1k tokensUpdated today
    Documents & OfficeAuto-check passed

More from indranilbanerjee/digital-marketing-pro

All 162 skills in this repo
  • Import Template

    indranilbanerjee/digital-marketing-pro

    Import a deliverable template as a reusable placeholder template per brand.

    862 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed
  • Ab Test Plan

    indranilbanerjee/digital-marketing-pro

    Plan an A/B test by script: sample size per variant, days to run, stopping rules.

    862 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Aeo Audit

    indranilbanerjee/digital-marketing-pro

    Run a one-time AEO audit of six AI answer engines, scored per surface.

    862 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Agent Readiness Audit

    indranilbanerjee/digital-marketing-pro

    Audit agent readiness by script: AI-crawler rules, product schema, no-JS HTML, feeds.

    862 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Backlink Gap

    indranilbanerjee/digital-marketing-pro

    Find backlink gap domains linking to competitors, not you, scored by script.

    862 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Campaign Audit

    indranilbanerjee/digital-marketing-pro

    Audit all campaigns running for a brand across channels, with 4-tier triage.

    862 GitHub starsUsed in 1 repo~4k tokens
    Auto-check: notes

Questions about C2pa Metadata

What does C2pa Metadata do?

Embed C2PA provenance in AI-generated images, video or PDF by script. C2pa Metadata is an agent skill from indranilbanerjee/digital-marketing-pro. Embed C2PA provenance in AI-generated images, video or PDF by script.

When should I use C2pa Metadata?

C2pa Metadata fits situations like: documents & Office work in your project.

How do I install C2pa Metadata in Claude Code?

Run `npx skills add indranilbanerjee/digital-marketing-pro --skill c2pa-metadata -a claude-code`. Or copy the skill folder (skills/c2pa-metadata in indranilbanerjee/digital-marketing-pro) into .claude/skills/c2pa-metadata in your project. Claude Code loads it when a task matches its description.

How do I install C2pa Metadata in Codex?

Run `npx skills add indranilbanerjee/digital-marketing-pro --skill c2pa-metadata -a codex`. Or copy the skill folder (skills/c2pa-metadata in indranilbanerjee/digital-marketing-pro) into .agents/skills/c2pa-metadata in your project. Codex loads it when a task matches its description.

Can I use C2pa Metadata in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add indranilbanerjee/digital-marketing-pro --skill c2pa-metadata -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/c2pa-metadata, .gemini/skills/c2pa-metadata, .github/skills/c2pa-metadata and .opencode/skills/c2pa-metadata in your project.

What does C2pa Metadata need to run?

Going by SKILL.md and its folder, C2pa Metadata needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does C2pa Metadata access the network?

SKILL.md names 6 domains. In commands or code: contentcredentials.org and timestamp.digicert.com; the agent is likely to contact these when it follows the instructions. As links in the text: c2pa.org, spec.c2pa.org, opensource.contentauthenticity.org and contentauthenticity.org. This is read from the text; nothing was executed.

Is C2pa Metadata safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does C2pa Metadata use?

C2pa Metadata is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does C2pa Metadata use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to C2pa Metadata?

Skills that share tags, products or a category with C2pa Metadata: Markdown Article Formatter (JimLiu/baoyu-skills, 27k stars), Markitdown (ImCa0/just-laws, 781 stars), Obsidian Markdown (Atmosphere/atmosphere, 3.8k stars) and DOCX (rvdbreemen/OTGW-firmware, 207 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains C2pa Metadata?

indranilbanerjee (a GitHub user) maintains it in indranilbanerjee/digital-marketing-pro, which has 862 GitHub stars. The repository holds 162 skills in this directory. The repository was last updated on October 9, 2026.

Source: indranilbanerjee/digital-marketing-pro on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.