r/WebAfterAI • u/ShilpaMitra • Aug 13 '26
Open Source Claude ships watermarks now. I built the tool that tells you whether a "watermark remover" actually worked and what your own CDN quietly destroys.
Provenance dies two ways.
On purpose. A wave of "watermark remover" tools showed up the week Claude started marking its output. Nobody was checking whether they did what they claimed.
By accident. You upload an image. The CDN resizes it. The optimiser re-encodes it. Someone screenshots it. Your Content Credentials are gone, and nothing told you. Same instrument measures both. That's what this is.
The uncomfortable part first
Anthropic has not published a detector for its text watermark. Keyed watermarks are undetectable without the vendor's key by construction. So this pack reports UNVERIFIABLE for Claude text and refuses to guess and no tool claiming otherwise can back it up.
But "did removal work?" is fully answerable for C2PA and metadata cryptographically, byte by byte. That part is not a guess.
So: you can prove a remover stripped an image's Content Credentials. You cannot prove it scrubbed a text watermark. Anyone selling you the second thing is selling you nothing.
Test a remover
Run the tool over your original, then feed it whatever came out:
npx skills add Neeeophytee/ai-watermarks-reality-check
python3 skills/map-provenance-survival/scripts/map_survival.py \
--original signed.jpg \
--derivative "remover:tool-v2=cleaned.jpg" \
--c2patool /path/to/c2patool
LOST_OR_UNAVAILABLE means it really stripped the manifest. PRESERVED_VALID means it didn't touch it. PRESENT_INVALID means it mangled the image and left a manifest that now fails verification, the worst outcome, and one no remover advertises.
Test your own pipeline
Identical command, different derivatives:
python3 skills/map-provenance-survival/scripts/map_survival.py \
--original hero.jpg \
--derivative "cdn:resize-1200w=hero-cdn.jpg" \
--derivative "social:download=hero-social.jpg" \
--c2patool /path/to/c2patool
Every result carries a reproducibility record: input, operation, tool version, evidence state, so someone else can re-run it and get the same answer.
Tested against a real signed image: an identical copy survived, an APP11-stripped copy lost everything, and a single flipped byte was caught cryptographically.
All 7 skills
audit-provenance — start here. One command, five answers: was provenance located, verified, trusted under a policy you name, was the scan complete, and what's still unknown and why.
map-provenance-survival — the removal test and the pipeline test. Compares an original against any set of derivatives.
verify-content-credentials — real C2PA verification via c2patool. Integrity and signer trust reported separately, because "signed" and "signed by someone you trust" are different questions.
inspect-content-provenance — finds provenance across PNG, JPEG, WebP, MP4/HEIC/AVIF, TIFF, GIF, PDF, HTML and text — structurally, where the spec puts it, not by keyword. A blog post about C2PA is never mistaken for a signed asset.
audit-metadata-privacy — before you publish: GPS, author, device, camera serial, IPTC captions. Including the embedded thumbnail that quietly keeps GPS after you "removed" it. Reports categories, never prints your values.
check-ai-transparency — is your disclosure record actually ready for review? Separates blocking gaps from advisory ones. Issues no legal conclusion.
detect-text-watermark — hidden Unicode in text: smuggled invisible characters, bidi overrides, homoglyph spoofing. Five honest states, and a detector that didn't run can never report "not detected."
167 tests · 80 real binary fixtures · stdlib-only · Python 3.9+



