agentsclimarketplace

C2pa metadata

Skill indranilbanerjee/digital-marketing-pro/skills/c2pa-metadata

Embed C2PA (Content Authenticity Initiative) provenance manifests in AI-generated marketing assets (image/video/audio/PDF). Use when: preparing AI-generated ad creative, social images, or video for EU markets to comply with EU AI Act Article 50 (applicable 2 Aug 2026); embedding visible AI-generation disclosure in assets; meeting brand-trust transparency requirements.From its SKILL.md

Install
npx -y skills add indranilbanerjee/digital-marketing-pro --skill c2pa-metadata

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • runs commandsInstructs the agent to run 5 commands, including `/digital-marketing-pro:c2pa-metadata --input assets/q3-launch-hero.png --output assets/signed/q3-launch-hero.png --brand "Acme Corp" --generator "Vertex AI / Nano Banana Pro" --ai-claim ai-generated-c` and 4 more.

SKILL.md

9.6 KB, ~2.4k tokens by cl100k_base, as published. Nobody here has run it

/digital-marketing-pro:c2pa-metadata — Embed Content Authenticity Provenance

Purpose

Wraps scripts/embed-c2pa.py to add a C2PA (Coalition for Content Provenance and Authenticity) manifest to any AI-generated marketing asset. The manifest carries a machine-readable provenance trail (who generated it, what generator was used, what prompt produced it, when it was reviewed) plus a visible AI-generation claim in the IPTC digital-source-type vocabulary.

This is the technical mechanism brands use to comply with:

  • EU AI Act Article 50 (applicable 2 August 2026) — generative-AI marketing content must be marked in a machine-readable format using open, interoperable standards. C2PA is the emerging backbone. Penalty for non-compliance: up to €15 million or 3% global annual turnover.
  • NY synthetic-performer disclosure law (effective June 2026) — $1K–$5K per violation, $10K repeat; applies to synthetic influencers and AI-generated endorsements.
  • FTC May 2026 endorsement guidance — covers AI testimonials and synthetic creator content.
  • Australia Online Safety Act / UK Online Safety Act — emerging deepfake disclosure requirements.

The resulting asset can be inspected by any C2PA-aware viewer (Adobe Photoshop, Lightroom, Truepic, contentcredentials.org/verify).

C2PA spec versions to be aware of (June 2026)

  • Content Credentials 2.3 (released 9 February 2026 — launch post) added format support for: live video (broadcast/streaming), plain text documents, OGG Vorbis audio, large AVI video files, and EXIF Original Preservation Images. If a brand is signing live-stream video or text-based assets for the first time, 2.3 is the floor version to target.
  • C2PA Spec 2.4 (April 2026 — spec.c2pa.org/specifications/specifications/2.4) introduces the AI Disclosure Assertion (c2pa.ai-disclosure) for machine-readable AI transparency info — this is the assertion the EU AI Act Article 50 deployer pathway will rely on. The Code of Practice WG1 (providers) and WG2 (deployers) draft guidance both reference C2PA-style assertions as the canonical machine-readable marking mechanism. See skills/context-engine/eu-code-of-practice.md for the full Article 50 context.
  • The C2PA Trust List is now handled via the public C2PA Conformance Program (any CA meeting the Certificate Policy can join). Production signing certificates should come from a Conformance-Program-listed CA, not an ad-hoc cert.

For DMP outputs: embed-c2pa.py now supports --ai-disclosure. Pass it to embed the C2PA 2.4 c2pa.ai-disclosure assertion alongside the existing IPTC digital-source-type claim. The combination gives you both human-readable (IPTC) and machine-readable (c2pa.ai-disclosure) EU AI Act Article 50 signaling — this is the deployer-side machine-readable pathway the Code of Practice draft points to as the canonical marking mechanism. See skills/context-engine/eu-code-of-practice.md for the full Article 50 context.

When to invoke

  • Right after any AI image / video / audio generation step in the engagement workflow (Part 11 — AI Creative Instructions output)
  • Before handing a generated asset to the design team for review
  • As a pre-publish gate in /digital-marketing-pro:check for EU-targeted assets
  • Bulk-applying to a backlog of AI-generated assets before EU AI Act enforcement on 2 Aug 2026

Quick examples

# Single asset — image generated by Vertex AI / Nano Banana Pro
/digital-marketing-pro:c2pa-metadata \
    --input assets/q3-launch-hero.png \
    --output assets/signed/q3-launch-hero.png \
    --brand "Acme Corp" \
    --generator "Vertex AI / Nano Banana Pro" \
    --ai-claim ai-generated-content \
    --prompt "minimalist product hero shot, soft natural lighting"

# Video with human review tracked
/digital-marketing-pro:c2pa-metadata \
    --input campaigns/launch-video-v3.mp4 \
    --output campaigns/signed/launch-video-v3.mp4 \
    --brand "Acme Corp" \
    --generator "Runway Gen-4" \
    --ai-claim ai-generated-content \
    --reviewer "Jane Smith"

# EU-targeted asset — add the machine-readable Article 50 AI-disclosure assertion (C2PA 2.4)
/digital-marketing-pro:c2pa-metadata \
    --input assets/q3-launch-hero.png \
    --output assets/signed/q3-launch-hero.png \
    --brand "Acme Corp" \
    --generator "Vertex AI / Nano Banana Pro" \
    --ai-claim ai-generated-content \
    --ai-disclosure \
    --prompt "minimalist product hero shot, soft natural lighting"

# Human-created image with AI-assisted edits
/digital-marketing-pro:c2pa-metadata \
    --input assets/founder-headshot-edited.jpg \
    --output assets/signed/founder-headshot-edited.jpg \
    --brand "Acme Corp" \
    --generator "Adobe Generative Fill" \
    --ai-claim ai-assisted-edits

# Production sign with a real C2PA signing certificate
/digital-marketing-pro:c2pa-metadata \
    --input assets/q3-launch-hero.png \
    --output assets/signed/q3-launch-hero.png \
    --brand "Acme Corp" \
    --generator "Vertex AI / Nano Banana Pro" \
    --ai-claim ai-generated-content \
    --signing-cert /secure/c2pa-prod-cert.pem \
    --signing-key /secure/c2pa-prod-key.pem

AI claim values (IPTC digital source type)

ValueWhen to useMaps to IPTC URI
ai-generated-contentAsset fully generated by AIalgorithmicMedia
ai-assisted-editsHuman-created + AI-edited (e.g. Generative Fill)compositeWithTrainedAlgorithmicMedia
ai-no-substantive-changesAI used (e.g. upscaling) but no semantic changeminorHumanEdits

The IPTC vocabulary is what EU AI Act regulators reference — using these values rather than ad-hoc strings makes the asset interoperable with the Article 50 enforcement tooling.

Supported asset formats

.png · .jpg/.jpeg · .webp · .gif · .tiff · .mp4 · .mov · .webm · .mp3 · .wav · .pdf

Signing certificate

Production C2PA signatures require a certificate from a CAI-recognized signing authority. The script will use one if you pass --signing-cert and --signing-key. If you omit them, the script generates a self-signed 90-day dev certificate for development testing only — a self-signed asset will verify as "signature present but signer not in trust list" at contentcredentials.org/verify.

For production deployment:

  1. Obtain a C2PA-compatible signing certificate from a CAI-recognized authority (Adobe, Truepic, Numbers Protocol, Microsoft Azure Confidential Ledger).
  2. Store the cert + key securely (do NOT commit to git; use an environment-variable path or secret store).
  3. Pass --signing-cert and --signing-key on every production invocation.

Reference: opensource.contentauthenticity.org/docs/manifest/signing-manifests/

Python dependencies

  • c2pa-python>=0.5.0 — auto-installed on first run via pip install
  • cryptography — only needed for the dev self-signed cert path; auto-installed if missing

Both are part of the plugin's Full mode (~50 MB) — see pip install -r scripts/requirements.txt in the README.

Output

The script prints a JSON status report to stdout:

{
  "status": "success",
  "input": "assets/q3-launch-hero.png",
  "output": "assets/signed/q3-launch-hero.png",
  "size_bytes": 482371,
  "brand": "Acme Corp",
  "generator": "Vertex AI / Nano Banana Pro",
  "ai_claim": "ai-generated-content",
  "created": "2026-05-16T10:30:00+00:00",
  "manifest_assertions": ["c2pa.actions", "stds.schema-org.CreativeWork"],
  "using_dev_cert": false,
  "verify_url": "https://contentcredentials.org/verify"
}

Integration with the engagement workflow

In a full 12-part engagement, this skill plugs in at Part 11 — AI Creative Instructions output. After a creative brief is rendered as an actual asset (by your creative tooling or a manual creative process), the resulting file passes through c2pa-metadata before being checked in to engagements/<slug>/11-creative-briefs/signed/.

The /digital-marketing-pro:check pre-publish gate should also verify that all AI-generated assets in an EU-targeted campaign carry a C2PA manifest. v3.4 adds this verification to the EU jurisdiction rule pack in skills/context-engine/compliance-rules.md.

Related

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Gives 0 of the 12 instructions most marketing audience skills give in ~2.4k tokens

Counted across 690 of the 894 authors here whose files we hold, read 2026-08-07

  • Apply Poppins font to headingsin 41 of 690, across 6 files
  • Apply Lora font to body textin 41 of 690, across 6 files
  • Use Arial fallback for headingsin 39 of 690, across 4 files
  • Use Georgia fallback for body textin 39 of 690, across 4 files
  • Maintain text hierarchy and formattingin 39 of 690, across 4 files
  • Use accent colors for non-text shapesin 38 of 690, across 3 files
  • Use RGB values for precise color matchingin 38 of 690, across 3 files
  • Use brand colors for primary text and backgroundsin 36 of 690, across 1 file
  • Read product marketing context file before asking questions, starting, or auditingin 35 of 690, across 23 files
  • Use active voice instead of passive voicein 26 of 690, across 10 files
  • Implement or generate appropriate JSON-LD structured datain 24 of 690, across 17 files
  • Prioritize clarity over clevernessin 22 of 690, across 8 files

Said here and by no other author read

  • invoke right after any ai generation step
  • run the embed script on ai generated marketing assets
  • use the specified iptc ai claim values
  • pass the ai-disclosure flag for eu targeted assets
  • use a production certificate for production assets
  • store signing certificates securely

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.