ai-act-verify
v0.1.0
Published
Check whether a media file carries a C2PA provenance manifest. Detects presence, not validity.
Maintainers
Readme
ai-act-verify
Does this file carry a provenance manifest? One command, no dependencies, no account.
npx ai-act-verify ./generated-image.pnggenerated-image.png (PNG, 412.7 KB)
C2PA manifest PRESENT — PNG 'caBX' chunk
manifest size 18.2 KB
XMP present
validation NOT PERFORMED — presence is not validity
Summary 1 with a manifest · 0 withoutWhy this exists
If you generate images or audio with AI and ship them to users in the EU, you are probably relying on your model provider to mark the output. That reliance is allowed — but the responsibility to demonstrate it stays with you.
Most teams have never actually looked at whether the files leaving their pipeline carry a manifest at all. This tool takes ten seconds to find out.
What it does
Reads the container and reports whether a C2PA/JUMBF manifest is present:
| Container | Where it looks |
|---|---|
| JPEG | APP11 segments with the JP JUMBF prefix |
| PNG | caBX chunk |
| WebP / WAV | C2PA RIFF chunk |
| MP4 / M4A / MOV / HEIC / AVIF | uuid box carrying the C2PA UUID |
| MP3 | GEOB frame in the ID3v2 tag |
| SVG | c2pa reference in embedded XMP |
Anything else comes back UNSUPPORTED rather than guessing.
What it deliberately does NOT do
It does not validate. It tells you a manifest is there, not that it is signed by someone you trust, not that it matches the bytes of the file, not that it has not been tampered with. Cryptographic validation needs the real C2PA toolchain (c2pa-node, c2patool) and a trust list — not a container parser.
That is why every report says NOT PERFORMED instead of quietly implying a green light. A tool that blurs "present" into "valid" is worse than no tool.
It is not legal advice. A manifest being present does not prove compliance with Article 50 of the EU AI Act, and its absence does not prove a breach — the Commission Guidelines place several kinds of output outside the marking obligation entirely (source code, machine-to-machine communication, short sequences, standard editing, and more).
Options
--json machine-readable report, for CI and scripts
--strict exit 1 if any file comes back ABSENT
--quiet one result line per fileExit codes: 0 fine · 1 --strict and something was ABSENT · 2 bad usage or unreadable file.
In CI
- run: npx ai-act-verify dist/assets/*.png --strictAs a library
import { inspect } from 'ai-act-verify';
import { readFile } from 'node:fs/promises';
const report = inspect(await readFile('output.jpg'));
// { type: 'JPEG', status: 'PRESENT', where: "JUMBF in APP11 (1 segment)",
// validation: 'NOT_PERFORMED', ... }Requirements
Node 18+. No dependencies, by design — you are running this over your own media.
The part this tool cannot do for you
Running the check is easy. Being able to show, in eight months, that you ran it, on which files, and what it said at the time is the hard part. That is dated evidence, and a CLI does not produce it.
We are building the infrastructure for that: transparency controls and verifiable evidence for teams shipping AI-generated content, without building it in-house.
Licence
MIT.
