c2pa-metadata
Embed a C2PA provenance manifest into an AI-generated marketing asset (PNG, JPG, WebP, GIF, TIFF, MP4, MOV, WebM, MP3, WAV, PDF) via scripts/embed-c2pa.py — produces a signed copy of the file carrying IPTC digital-source-type AI claims, an optional c2pa.ai-disclosure assertion for EU AI Act Article…
Install / Use
npx skills add indranilbanerjee/digital-marketing-pro --skill c2pa-metadataInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
MarketingSupported Platforms
Our assessment of c2pa-metadata
c2pa-metadata scores 89/100 on our quality scale, 243rd of 610 Marketing skills we index (top 40%).
Its SKILL.md is 10.0 KB long, well organised into 17 sections with 2 code examples: a thorough specification that gives an agent plenty to work with.
It has 832 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 26 days ago, so c2pa-metadata is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
c2pa-metadata compared with similar skills
All 4 of these similar skills score higher than c2pa-metadata; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| c2pa-metadata (this skill)by indranilbanerjee | 89 | 832 | 26d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 90.1k | 18d ago | CLAUDE.md |
| LocalAIby mudler | 100 | 49.4k | today | MCP Server |
| algorithmic-artby anthropics | 100 | 177.9k | 11d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 11d ago | SKILL.md |
Frequently asked questions
- How do I install c2pa-metadata?
- Run
npx skills add indranilbanerjee/digital-marketing-pro --skill c2pa-metadata. The install tabs above show the steps for each supported agent. - Which AI agents does c2pa-metadata work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is c2pa-metadata safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is c2pa-metadata still maintained?
- The repository was last updated 26 days ago, so c2pa-metadata is actively maintained.
Skill content
View source on GitHubname: c2pa-metadata description: "Embed a C2PA provenance manifest into an AI-generated marketing asset (PNG, JPG, WebP, GIF, TIFF, MP4, MOV, WebM, MP3, WAV, PDF) via scripts/embed-c2pa.py — produces a signed copy of the file carrying IPTC digital-source-type AI claims, an optional c2pa.ai-disclosure assertion for EU AI Act Article 50 (applicable 2 Aug 2026), and a JSON status report. Triggers on "/digital-marketing-pro:c2pa-metadata", "sign this AI image for EU compliance", "add content credentials to this asset", "embed provenance metadata", "mark this video as AI-generated". Uses a self-signed dev certificate unless --signing-cert/--signing-key are supplied; pairs with /digital-marketing-pro:check, which verifies manifests pre-publish."
/digital-marketing-pro:c2pa-metadata — Embed Content Authenticity Provenance
Purpose
Wraps scripts/embed-c2pa.py to add a C2PA (Coalition for Content Provenance and Authenticity) manifest to any AI-generated marketing asset. The manifest carries a machine-readable provenance trail (who generated it, what generator was used, what prompt produced it, when it was reviewed) plus a visible AI-generation claim in the IPTC digital-source-type vocabulary.
This is the technical mechanism brands use to comply with:
- EU AI Act Article 50 (applicable 2 August 2026) — generative-AI marketing content must be marked in a machine-readable format using open, interoperable standards. C2PA is the emerging backbone. Penalty for non-compliance: up to €15 million or 3% global annual turnover.
- NY synthetic-performer disclosure law (effective June 2026) — $1K–$5K per violation, $10K repeat; applies to synthetic influencers and AI-generated endorsements.
- FTC May 2026 endorsement guidance — covers AI testimonials and synthetic creator content.
- Australia Online Safety Act / UK Online Safety Act — emerging deepfake disclosure requirements.
The resulting asset can be inspected by any C2PA-aware viewer (Adobe Photoshop, Lightroom, Truepic, contentcredentials.org/verify).
C2PA spec versions to be aware of (June 2026)
- Content Credentials 2.3 (released 9 February 2026 — launch post) added format support for: live video (broadcast/streaming), plain text documents, OGG Vorbis audio, large AVI video files, and EXIF Original Preservation Images. If a brand is signing live-stream video or text-based assets for the first time, 2.3 is the floor version to target.
- C2PA Spec 2.4 (April 2026 — spec.c2pa.org/specifications/specifications/2.4) introduces the AI Disclosure Assertion (
c2pa.ai-disclosure) for machine-readable AI transparency info — this is the assertion the EU AI Act Article 50 deployer pathway will rely on. The final Code of Practice on Transparency of AI-Generated Content (published 10 June 2026) references C2PA-style assertions as the canonical machine-readable marking mechanism for both providers and deployers. Seeskills/context-engine/eu-code-of-practice.mdfor the full Article 50 context. - The C2PA Trust List is now handled via the public C2PA Conformance Program (any CA meeting the Certificate Policy can join). Production signing certificates should come from a Conformance-Program-listed CA, not an ad-hoc cert.
For DMP outputs: embed-c2pa.py now supports --ai-disclosure. Pass it to embed the C2PA 2.4 c2pa.ai-disclosure assertion alongside the existing IPTC digital-source-type claim. The combination gives you both human-readable (IPTC) and machine-readable (c2pa.ai-disclosure) EU AI Act Article 50 signaling — this is the deployer-side machine-readable pathway the final Code of Practice (10 June 2026) points to as the canonical marking mechanism. See skills/context-engine/eu-code-of-practice.md for the full Article 50 context.
When to invoke
- Right after any AI image / video / audio generation step in the engagement workflow (Part 11 — AI Creative Instructions output)
- Before handing a generated asset to the design team for review
- As a pre-publish gate in
/digital-marketing-pro:checkfor EU-targeted assets - Bulk-applying to a backlog of AI-generated assets before EU AI Act enforcement on 2 Aug 2026
Quick examples
# Single asset — image generated by Vertex AI / Nano Banana Pro
/digital-marketing-pro:c2pa-metadata \
--input assets/q3-launch-hero.png \
--output assets/signed/q3-launch-hero.png \
--brand "Acme Corp" \
--generator "Vertex AI / Nano Banana Pro" \
--ai-claim ai-generated-content \
--prompt "minimalist product hero shot, soft natural lighting"
# Video with human review tracked
/digital-marketing-pro:c2pa-metadata \
--input campaigns/launch-video-v3.mp4 \
--output campaigns/signed/launch-video-v3.mp4 \
--brand "Acme Corp" \
--generator "Runway Gen-4" \
--ai-claim ai-generated-content \
--reviewer "Jane Smith"
# EU-targeted asset — add the machine-readable Article 50 AI-disclosure assertion (C2PA 2.4)
/digital-marketing-pro:c2pa-metadata \
--input assets/q3-launch-hero.png \
--output assets/signed/q3-launch-hero.png \
--brand "Acme Corp" \
--generator "Vertex AI / Nano Banana Pro" \
--ai-claim ai-generated-content \
--ai-disclosure \
--prompt "minimalist product hero shot, soft natural lighting"
# Human-created image with AI-assisted edits
/digital-marketing-pro:c2pa-metadata \
--input assets/founder-headshot-edited.jpg \
--output assets/signed/founder-headshot-edited.jpg \
--brand "Acme Corp" \
--generator "Adobe Generative Fill" \
--ai-claim ai-assisted-edits
# Production sign with a real C2PA signing certificate
/digital-marketing-pro:c2pa-metadata \
--input assets/q3-launch-hero.png \
--output assets/signed/q3-launch-hero.png \
--brand "Acme Corp" \
--generator "Vertex AI / Nano Banana Pro" \
--ai-claim ai-generated-content \
--signing-cert /secure/c2pa-prod-cert.pem \
--signing-key /secure/c2pa-prod-key.pem
AI claim values (IPTC digital source type)
| Value | When to use | Maps to IPTC URI |
|---|---|---|
| ai-generated-content | Asset fully generated by AI | algorithmicMedia |
| ai-assisted-edits | Human-created + AI-edited (e.g. Generative Fill) | compositeWithTrainedAlgorithmicMedia |
| ai-no-substantive-changes | AI used (e.g. upscaling) but no semantic change | minorHumanEdits |
The IPTC vocabulary is what EU AI Act regulators reference — using these values rather than ad-hoc strings makes the asset interoperable with the Article 50 enforcement tooling.
Supported asset formats
.png · .jpg/.jpeg · .webp · .gif · .tiff · .mp4 · .mov · .webm · .mp3 · .wav · .pdf
Signing certificate
Production C2PA signatures require a certificate from a CAI-recognized signing authority. The script will use one if you pass --signing-cert and --signing-key. If you omit them, the script generates a self-signed 90-day dev certificate for development testing only — a self-signed asset will verify as "signature present but signer not in trust list" at contentcredentials.org/verify.
For production deployment:
- Obtain a C2PA-compatible signing certificate from a CAI-recognized authority (Adobe, Truepic, Numbers Protocol, Microsoft Azure Confidential Ledger).
- Store the cert + key securely (do NOT commit to git; use an environment-variable path or secret store).
- Pass
--signing-certand--signing-keyon every production invocation.
Reference: opensource.contentauthenticity.org/docs/manifest/signing-manifests/
Python dependencies
c2pa-python>=0.5.0— auto-installed on first run viapip installcryptography— only needed for the dev self-signed cert path; auto-installed if missing
Both are part of the plugin's Full mode (~50 MB) — see pip install -r scripts/requirements.txt in the README.
Output
The script prints a JSON status report to stdout:
{
"status": "success",
"input": "assets/q3-launch-hero.png",
"output": "assets/signed/q3-launch-hero.png",
"size_bytes": 482371,
"brand": "Acme Corp",
"generator": "Vertex AI / Nano Banana Pro",
"ai_claim": "ai-generated-content",
"created": "2026-05-16T10:30:00+00:00",
"manifest_assertions": ["c2pa.actions", "stds.schema-org.CreativeWork"],
"using_dev_cert": false,
"verify_url": "https://contentcredentials.org/verify"
}
Integration with the engagement workflow
In a full 12-part engagement, this skill plugs in at Part 11 — AI Creative Instructions output. After a creative brief is rendered as an actual asset (by your creative tooling or a manual creative process), the resulting file passes through c2pa-metadata before being checked in to engagements/<slug>/11-creative-briefs/signed/.
The /digital-marketing-pro:check pre-publish gate should also verify that all AI-generated assets in an EU-targeted campaign carry a C2PA manifest. v3.4 adds this verification to the EU jurisdiction rule pack in skills/context-engine/compliance-rules.md.
Related
/digital-marketing-pro:check— pre-publish quality gate (now verifies C2PA manifest on AI assets for EU campaigns)skills/context-engine/compliance-rules.md— EU AI Act Article 50 rule packskills/influencer-creator/ftc-compliance.md— FTC endorsement disclosure requirements- C2PA Specification 2.4 (April 2026) — defines the
c2pa.ai-disclosureassertion (Article 50 machine-readable pathway); Content Credentials 2.3 launch (Feb 2026) - Content Authenticity Initiative
Related Skills
Agent-Reach
90.1kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
LocalAI
49.4kLocalAI is the open-source AI engine. Run any model - LLMs, vision, voice, image, video - on any hardware. No GPU required.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
