media-provenance-rights

media-provenance-rights is a skill for Claude Code, Codex from calesthio/generative-media-skills. It costs 114 tokens per session (5,666 once invoked), scanned A, original, MIT.

A production checklist for proving where AI-generated media came from, what permissions support it, and what disclosures or approvals it needs.

In plain words
What is it for?
Use it to review rights, consent, licenses, platform rules, technical metadata, and release notes for generated media before delivery.
Why use it?
It helps prevent unsupported claims that an image, video, audio track, or campaign asset is cleared for release. It also records missing evidence and issues that need escalation.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to review rights, consent, licenses, platform rules, technical metadata, and release notes for generated media before delivery.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/calesthio/generative-media-skills/media-provenance-rights
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add calesthio/generative-media-skills --skill media-provenance-rights
Clone the repo
git clone --depth 1 https://github.com/calesthio/generative-media-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for media-provenance-rights

README.md
[![agentmods](https://agentmods.dev/badge/skills/calesthio/generative-media-skills/media-provenance-rights/github.svg)](https://agentmods.dev/skills/calesthio/generative-media-skills/media-provenance-rights)
Your own site
<a href="https://agentmods.dev/skills/calesthio/generative-media-skills/media-provenance-rights"><img src="https://agentmods.dev/badge/skills/calesthio/generative-media-skills/media-provenance-rights/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for media-provenance-rights

Your own site · 80×15
<a href="https://agentmods.dev/skills/calesthio/generative-media-skills/media-provenance-rights"><img src="https://agentmods.dev/badge/skills/calesthio/generative-media-skills/media-provenance-rights.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 114 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 5,666 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector warn 7 Sept 2026
SkillSpector: 2 findings, up to medium

These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →

  • medium Excessive Agency · line 238
    Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
    Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
  • medium Excessive Agency · line 143
    Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
    Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00114 $0.05666
Opus 5 $0.00057 $0.02833
Sonnet 5 $0.00023 $0.01133
Haiku 4.5 $0.00011 $0.00567

Measured 12d ago against content hash c26794e8b4c6, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

media-provenance-rights scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/production/governance-delivery/media-provenance-rights/SKILL.md · 317 lines

How it starts

The opening of the file, as written. The whole thing — 317 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Media provenance and rights governance

Use this skill to make generated media releasable, auditable, and explainable. It is not legal advice. It is a production governance workflow that helps an agent identify rights evidence, missing permissions, disclosure duties, and escalation points before a client or platform receives the asset.

Default posture: do not claim an asset is "cleared," "copyright-safe," "commercially safe," or "owned" unless the production record shows the exact basis for that statement. Prefer "approved for this release under the documented assumptions" plus a dated caveat.

Separate facts, observations, and heuristics

Treat these as different evidence classes in your work product:

  • Documented facts: directly supported by contracts, licenses, provider terms, platform rules, consent forms, official guidance, or technical metadata. Cite the source and verification date for volatile facts.
  • Empirical observations: things observed in the actual workflow, such as "metadata survived this export" or "the uploaded platform copy retained no visible credential." Record the test, file hash, date, tool, and result.
  • Production heuristics: conservative operating rules used to reduce risk when legal certainty is unavailable. Label them as heuristics, not law.

Documented facts to keep in mind

Facts below were verified on 2026-07-10 unless otherwise noted. Re-check them for high-value, regulated, political, public-company, celebrity, or international releases.

  • C2PA/Content Credentials represent provenance through signed manifests, assertions, claims, signatures, and content bindings. A C2PA manifest can be embedded in an asset or stored externally, and authenticity depends on validation of the signed claim and bindings, not on a human-readable note alone. Source: C2PA Technical Specification 2.4.
  • The U.S. Copyright Office's AI report series covers digital replicas, copyrightability, and generative AI training. Part 1 was published July 31, 2024; Part 2 on copyrightability was published January 29, 2025; Part 3 on training was released as a pre-publication version on May 9, 2025 with final publication expected later. Source: U.S. Copyright Office AI initiative.
  • U.S. copyright registration guidance for works containing AI-generated material requires attention to human authorship and may annotate registrations to clarify the claimed human-authored scope. Source: Federal Register, 88 FR 16190.
  • FTC endorsement guidance focuses on preventing deceptive advertising and includes disclosure of material connections between advertisers and endorsers. Source: FTC endorsements, influencers, and reviews guidance.
  • Trademark risk is mainly a consumer-confusion and brand-use issue, not just an image-generation issue. Review visible marks, lookalike marks, product packaging, slogans, and trade dress against the release context. Source: USPTO trademark resources.
  • SAG-AFTRA frames AI performance guardrails around consent, fair compensation, and control over performances; NAVA recommends performer contracts cover consent, limits on use, opt-outs or term limits, payment, exclusivity, and secure tracking of voice/likeness products. Sources: SAG-AFTRA AI framework, NAVA Synth & AI.
  • Creative Commons licenses vary materially. Some permit commercial use, some restrict noncommercial use, some prohibit derivatives, and attribution is generally required unless the work is CC0/public-domain-dedicated. Source: Creative Commons license overview.
  • YouTube requires creators to disclose realistic AI-generated or meaningfully AI-altered content through the upload flow; non-realistic or minor edits are treated differently. Source: YouTube Help: disclosing GenAI content.
  • TikTok lets creators label content that is completely generated or significantly edited by AI and requires creators to label AI-generated content that contains realistic images, audio, or video. Source: TikTok Support: AI-generated content.
  • Meta describes "AI info" labels for some AI-created or significantly edited ad images and says social issue, election, or political ads already require disclosure in relevant cases. Source: Meta Help: AI-generated images in ads.
  • Provider output rights and restrictions differ. For example, OpenAI terms assign output rights as between user and OpenAI while requiring users to have rights for inputs and comply with law; Runway states users retain rights and commercial-use ability as between user and Runway; ElevenLabs prohibits unauthorized, deceptive, or harmful voice impersonation; Adobe's generative AI guidelines prohibit violating third-party copyright, trademark, privacy, publicity, or other rights and may attach Content Credentials. Sources: OpenAI Terms of Use, Runway usage rights, ElevenLabs Prohibited Use Policy, Adobe Generative AI User Guidelines.

Read the full file on GitHub · 317 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 317 lines · 114 tokens per session scan A c26794e8b4c6

Subscribe to this mod's changes

media-provenance-rights is a skill published in the GitHub repository calesthio/generative-media-skills (170 stars, last pushed 2mo ago), licensed MIT. It adds 114 tokens to every session and 5,666 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

procurement-audit

A procurement review workflow that checks contracts and purchase documents against uploaded purchasing rules. It links each finding to the relevant rule and supporting text.

vixues/LeAgent · 39 tokens

travel-expense-audit

A travel-expense review workflow that checks reimbursement claims against policy handbooks and rate tables. It covers items such as hotel, transport, and daily meal allowances.

vixues/LeAgent · 51 tokens

security-guide

A Chinese-language checklist for securing and checking compliance of AI tools. It covers prompt protection, dangerous commands, prompt injection, sensitive-data transfers, and Chinese requirements such as PIPL and information-security standards.

TencentCloud/Octop · 54 tokens

cliptalk-cover-director

Produces evidence-backed cover candidates and reviewable cover variants for a ClipTalk video. Use when the user asks for a cover, poster frame, thumbnail, or multiple cover directions; do not use for timeline editing or social-video reframing.

GML-MMGroup/ClipTalk · 53 tokens

cliptalk-smart-reframe

Creates a subject-aware, time-varying crop track and a review-only social-format preview from an accepted ClipTalk cut. Use for automatic vertical, square, or portrait reframing; do not use for a fixed manual crop or before content editing is accepted.

GML-MMGroup/ClipTalk · 58 tokens

cliptalk-content-extractor

Locates and assembles source passages matching a semantic request. Use for extracting explanations, topics, quotes, demonstrations, or other specifically described content.

GML-MMGroup/ClipTalk · 35 tokens