Skip to content
CAI
Software that uses CAICheck a score

guillaumemeyer/watermarks-remover

71.0

Strong · 19 September 2026

23.6k

lines of production code

Python

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a Dockerized service and Claude Code plugin designed to detect, audit, and remove AI-generated content watermarks and provenance metadata from text and image files. It provides capabilities for black-box watermark stealing, cross-platform file hygiene hooks, and comprehensive auditing with SARIF export, while also offering benchmarks to evaluate watermark removal resilience across multiple languages. The architecture isolates optional detection and removal components via pinned dependencies to ensure reproducible builds and security.

Features

Add Cursor text hygiene skill

A new 'Clean user-facing text' skill has been added for the Cursor integration. This skill instructs the AI to apply text hygiene to natural-language content (such as articles, documentation, and emails) before finalizing it, while strictly preserving facts, formatting, code, and URLs. It also includes guidelines on authorized processing and best-effort statistical watermark reduction.

integrations · high confidence

Docker distribution for the watermark-removal service

The service is now distributed as a set of Docker images, providing a hardened, unprivileged HTTP server (port 8765) and optional standalone images for specific watermark removal and detection capabilities (CtrlRegen, MarkDiffusion, MarkLLM, and SynthID scoring). These images pin base OS and Python versions by digest, verify external tool checksums, and run as non-root users to mitigate container security risks.

service · high confidence

Introduce black-box watermark-stealing module and prompt corpus downloader

Adds a new \stealer\ package that implements a black-box attack against SynthID-class text watermarks. The module provides a CLI (\steal.py\) to query a watermarked model with a prompt corpus, collect replies, and derive a reusable scorer \s\*\ that estimates which tokens the watermark boosts. It includes a prompt corpus downloader (\download\_prompts.py\) that fetches data from Hugging Face, and scoring utilities (\scorer.py\, \tokens.py\) to apply the stolen scorer for demoting green tokens or spoofing. The implementation is stdlib-only and supports dry-run mode for offline testing.

stealer · high confidence

Introduce directory and website AI-provenance audit scripts with SARIF export

Added \audit\_dir.py\ and \audit\_website.py\ to recursively scan local directories and remote sitemaps for AI-generated content markers (C2PA manifests, AI metadata, and Layer A text anomalies). The directory auditor supports concurrent scanning, configurable output formats (human-readable, JSON, and OASIS SARIF 2.1.0), and optional stylometry checks for text files. The website auditor mirrors this logic for remote URLs, parsing sitemaps and classifying content types via headers and magic bytes. Both scripts rely on \audit\_lib.py\ for normalized reporting and \check\_staged.py\ for pre-commit integration, ensuring consistent actionable-file detection across CI and local workflows.

service/scripts · high confidence

Introduce text cleaning and AI-detection scripts for the clean-user-facing-text skill

This change adds the core Python scripts for the \clean-user-facing-text\ skill, enabling users to detect and remove invisible Unicode characters (such as zero-width spaces, BOMs, and directional marks) and normalize space homoglyphs. It also introduces a zero-LLM stylometry detector that flags AI-generated text patterns (e.g., specific phrasing, burstiness, and lexical diversity metrics) without requiring external model dependencies. The new \clean\_text.py\ script allows in-place cleaning with backup, while \inspect\_text.py\ provides audit and reporting capabilities, including JSON output and stylometry scoring.

skills/clean-user-facing-text/scripts · high confidence

New SynthID-text watermark removal benchmarks and Polish corpus

The benchmarks directory now includes a complete evaluation suite for testing the resilience of SynthID-text watermarks against various text rewrites. This adds a \benchmark-full.sh\ script for comprehensive testing (including paraphrase, back-translation, and minimal-rewrite-level scans) and a \benchmark-smoke.sh\ for quick validation. The suite uses a new seed corpus (\corpus/\ and \corpus-large/\) containing 30 diverse English documents to generate watermarked artifacts via MarkLLM. Additionally, a new Polish benchmark corpus (\corpus-polish/\) with 50 texts is introduced to evaluate watermark removal in languages with complex grammatical structures, ensuring the benchmark can assess robustness across different linguistic contexts.

benchmarks · high confidence

Repository restructured as a distributable Claude Code plugin with Dockerized service and pre-commit hooks

The project has been reorganized to ship as a Claude Code plugin and marketplace entry, introducing a dedicated \install\_skill.py\ installer for multiple agent hosts (Claude Code, Cursor, Cowork) and a \Makefile\ for build and test automation. A new Docker Compose stack (\compose.yaml\) and environment configuration (\.env.example\) provide a local HTTP service (\wr-core\) alongside optional heavy/harness sidecars for watermark detection and removal. Deterministic cleaning is now supported via a \PostToolUse\ hook for files written by the agent and pre-commit hooks (\.pre-commit-hooks.yaml\) that check or clean staged files. The repository also adds a CodeRabbit configuration (\.coderabbit.yaml\) for automated review guidance, standardizes development with \ruff.toml\ and \pytest.ini\, and enforces a stricter \.gitignore\ to exclude local artifacts while preserving source and configuration.

(repo-wide) · high confidence

Removals

Removal of the 'remove-claude-marks' skill and its cleaning scripts

The 'remove-claude-marks' skill has been deleted from the system. This change removes the capability to strip invisible Unicode characters, statistical text watermarks, and C2PA/AI provenance metadata from text and image files (PNG/JPEG). Users will no longer have access to the associated Python scripts (inspect\_text.py, clean\_text.py, inspect\_image.py, clean\_image.py) or the documentation that guided the multi-layer cleaning workflow.

skills/remove-claude-marks · high confidence

Behavioural changes

Cross-platform support for PostToolUse file-provenance hook

The system now reliably executes the PostToolUse hook (which reports or strips AI/C2PA provenance marks after the agent writes files) on Windows, macOS, and Linux. A new Node.js launcher script (\hooks/run\_hook.js\) replaces platform-specific assumptions by probing for available Python interpreters (\py\, \python\, \python3\) and verifying they meet the minimum Python 3.10 requirement before invoking the underlying \hook\_written\_file.py\ script, ensuring consistent behavior regardless of the host OS.

hooks · high confidence

Test coverage

Expanded test coverage for AI metadata detection, cleaning, and audit tooling

Added a comprehensive test suite for the watermarks-remover service, including shared pytest fixtures that bypass the Layer B rewrite backend for non-strategy tests. The tests verify AI generator product-name detection in PNG metadata (e.g., ChatGPT, Midjourney), confidence classification for audit findings, and SARIF 2.1.0 export formatting. They also cover audio/video metadata inspection and stripping (MP4, WAV, FLAC), AVIF/HEIC C2PA and XMP removal, binary input guards for text-only tools, backup preservation logic, and robust handling of c2patool execution states (crashes, timeouts, missing claims).

tests · high confidence

Dependencies

Introduce isolated, pinned dependency files for optional watermarks and benchmarks

The project now uses dedicated requirements files (requirements-dev.txt, requirements-ctrlregen.txt, requirements-markdiffusion.txt, requirements-markllm.txt, requirements-semantic.txt, requirements-synthid-scorer.txt) to isolate optional components—CtrlRegen, MarkDiffusion, MarkLLM, semantic divergence, and SynthID scorers—from the main service. These files pin specific versions of libraries such as Pillow 12.3.0, transformers, diffusers, and accelerate to ensure reproducible builds and mitigate known security vulnerabilities (e.g., CVEs in Pillow) while preventing dependency drift. This separation ensures that optional features do not interfere with the core service environment.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 71.

Lenses

  • Code Health 74
  • Architecture 100
  • Maturity 62
  • Readiness 78
  • Security 84

Changes since last survey

  • 293 commits — 173 feature/other, 120 fixes

By area

  • service/scripts — 95 commits
  • (root) — 67 commits
  • (repo) — 60 commits
  • skills/remove-ai-marks — 35 commits
  • .github/CODEOWNERS — 5 commits
  • skills/clean-user-facing-text — 5 commits
  • .github/workflows — 3 commits
  • service/Dockerfile — 3 commits
  • tests/test_child_console_windows.py — 3 commits
  • docs/synthid-text-benchmark.md — 2 commits
  • tests/test_precommit_hooks.py — 2 commits
  • .claude-plugin/marketplace.json — 1 commit
  • .github/PULL_REQUEST_TEMPLATE.md — 1 commit
  • benchmarks/corpus — 1 commit
  • benchmarks/corpus-large — 1 commit
  • benchmarks/corpus-polish — 1 commit
  • docs/plans — 1 commit
  • hooks/hooks.json — 1 commit
  • service/Dockerfile.ctrlregen — 1 commit
  • skills/remove-claude-marks — 1 commit

Notable commits

  • fix: Merge branch 'fix/layer-a-script-glue-pua'
  • fix: Merge branch 'main' into fix/emoji-base-vs16-gap
  • fix: Merge branch 'main' into fix/emoji-base-vs16-gap
  • fix: Merge branch 'main' into fix/layer-a-script-glue-pua
  • fix: Merge branch 'main' into fix/makefile-bench-target-swallowed
  • fix: Merge branch 'main' into fix/makefile-bench-target-swallowed
  • fix: Merge branch 'main' into fix/makefile-bench-target-swallowed
  • fix: Merge branch 'main' into fix/makefile-bench-target-swallowed
  • fix: Merge branch 'main' into fix/portable-base64-macos
  • fix: Merge branch 'main' into fix/portable-base64-macos
  • fix: Merge branch 'main' into fix/preserve-first-backup-172
  • fix: Merge branch 'main' into fix/preserve-first-backup-172
  • fix: Merge branch 'main' into fix/preserve-first-backup-172
  • fix: Merge branch 'main' into fix/preserve-first-backup-172
  • fix: Merge branch 'main' into fix/preserve-first-backup-172
  • fix: Merge branch 'main' into fix/wav-c2pa-riff-chunk
  • fix: Merge pull request #180 from yzxcj797/fix/preserve-first-backup-172
  • fix: Merge pull request #195 from Belkins/fix/makefile-bench-target-swallowed
  • fix: Merge pull request #200 from mrsausagerolls/fix/emoji-base-vs16-gap
  • fix: Merge pull request #217 from yearth/fix/wav-c2pa-riff-chunk
  • …and 273 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

guillaumemeyer/watermarks-remover was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e4d2bd49c4cb84c5fddb50f5361618cfb3b75def — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.