Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add calesthio/generative-media-skills --skill media-provenance-rightsgit clone --depth 1 https://github.com/calesthio/generative-media-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/calesthio/generative-media-skills/media-provenance-rights)<a href="https://agentmods.dev/skills/calesthio/generative-media-skills/media-provenance-rights"><img src="https://agentmods.dev/badge/skills/calesthio/generative-media-skills/media-provenance-rights/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/calesthio/generative-media-skills/media-provenance-rights"><img src="https://agentmods.dev/badge/skills/calesthio/generative-media-skills/media-provenance-rights.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 238 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
- medium Excessive Agency · line 143 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00114 | $0.05666 |
| Opus 5 | $0.00057 | $0.02833 |
| Sonnet 5 | $0.00023 | $0.01133 |
| Haiku 4.5 | $0.00011 | $0.00567 |
Grade A, and why
media-provenance-rights scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 317 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Media provenance and rights governance
Use this skill to make generated media releasable, auditable, and explainable. It is not legal advice. It is a production governance workflow that helps an agent identify rights evidence, missing permissions, disclosure duties, and escalation points before a client or platform receives the asset.
Default posture: do not claim an asset is "cleared," "copyright-safe," "commercially safe," or "owned" unless the production record shows the exact basis for that statement. Prefer "approved for this release under the documented assumptions" plus a dated caveat.
Separate facts, observations, and heuristics
Treat these as different evidence classes in your work product:
- Documented facts: directly supported by contracts, licenses, provider terms, platform rules, consent forms, official guidance, or technical metadata. Cite the source and verification date for volatile facts.
- Empirical observations: things observed in the actual workflow, such as "metadata survived this export" or "the uploaded platform copy retained no visible credential." Record the test, file hash, date, tool, and result.
- Production heuristics: conservative operating rules used to reduce risk when legal certainty is unavailable. Label them as heuristics, not law.
Documented facts to keep in mind
Facts below were verified on 2026-07-10 unless otherwise noted. Re-check them for high-value, regulated, political, public-company, celebrity, or international releases.
- C2PA/Content Credentials represent provenance through signed manifests, assertions, claims, signatures, and content bindings. A C2PA manifest can be embedded in an asset or stored externally, and authenticity depends on validation of the signed claim and bindings, not on a human-readable note alone. Source: C2PA Technical Specification 2.4.
- The U.S. Copyright Office's AI report series covers digital replicas, copyrightability, and generative AI training. Part 1 was published July 31, 2024; Part 2 on copyrightability was published January 29, 2025; Part 3 on training was released as a pre-publication version on May 9, 2025 with final publication expected later. Source: U.S. Copyright Office AI initiative.
- U.S. copyright registration guidance for works containing AI-generated material requires attention to human authorship and may annotate registrations to clarify the claimed human-authored scope. Source: Federal Register, 88 FR 16190.
- FTC endorsement guidance focuses on preventing deceptive advertising and includes disclosure of material connections between advertisers and endorsers. Source: FTC endorsements, influencers, and reviews guidance.
- Trademark risk is mainly a consumer-confusion and brand-use issue, not just an image-generation issue. Review visible marks, lookalike marks, product packaging, slogans, and trade dress against the release context. Source: USPTO trademark resources.
- SAG-AFTRA frames AI performance guardrails around consent, fair compensation, and control over performances; NAVA recommends performer contracts cover consent, limits on use, opt-outs or term limits, payment, exclusivity, and secure tracking of voice/likeness products. Sources: SAG-AFTRA AI framework, NAVA Synth & AI.
- Creative Commons licenses vary materially. Some permit commercial use, some restrict noncommercial use, some prohibit derivatives, and attribution is generally required unless the work is CC0/public-domain-dedicated. Source: Creative Commons license overview.
- YouTube requires creators to disclose realistic AI-generated or meaningfully AI-altered content through the upload flow; non-realistic or minor edits are treated differently. Source: YouTube Help: disclosing GenAI content.
- TikTok lets creators label content that is completely generated or significantly edited by AI and requires creators to label AI-generated content that contains realistic images, audio, or video. Source: TikTok Support: AI-generated content.
- Meta describes "AI info" labels for some AI-created or significantly edited ad images and says social issue, election, or political ads already require disclosure in relevant cases. Source: Meta Help: AI-generated images in ads.
- Provider output rights and restrictions differ. For example, OpenAI terms assign output rights as between user and OpenAI while requiring users to have rights for inputs and comply with law; Runway states users retain rights and commercial-use ability as between user and Runway; ElevenLabs prohibits unauthorized, deceptive, or harmful voice impersonation; Adobe's generative AI guidelines prohibit violating third-party copyright, trademark, privacy, publicity, or other rights and may attach Content Credentials. Sources: OpenAI Terms of Use, Runway usage rights, ElevenLabs Prohibited Use Policy, Adobe Generative AI User Guidelines.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 317 lines · 114 tokens per session scan A c26794e8b4c6
media-provenance-rights is a skill published in the GitHub repository calesthio/generative-media-skills (170 stars, last pushed 2mo ago), licensed MIT. It adds 114 tokens to every session and 5,666 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
procurement-audit
A procurement review workflow that checks contracts and purchase documents against uploaded purchasing rules. It links each finding to the relevant rule and supporting text.
travel-expense-audit
A travel-expense review workflow that checks reimbursement claims against policy handbooks and rate tables. It covers items such as hotel, transport, and daily meal allowances.
security-guide
A Chinese-language checklist for securing and checking compliance of AI tools. It covers prompt protection, dangerous commands, prompt injection, sensitive-data transfers, and Chinese requirements such as PIPL and information-security standards.
cliptalk-cover-director
Produces evidence-backed cover candidates and reviewable cover variants for a ClipTalk video. Use when the user asks for a cover, poster frame, thumbnail, or multiple cover directions; do not use for timeline editing or social-video reframing.
cliptalk-smart-reframe
Creates a subject-aware, time-varying crop track and a review-only social-format preview from an accepted ClipTalk cut. Use for automatic vertical, square, or portrait reframing; do not use for a fixed manual crop or before content editing is accepted.
cliptalk-content-extractor
Locates and assembles source passages matching a semantic request. Use for extracting explanations, topics, quotes, demonstrations, or other specifically described content.