npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

ai-act-verify

v0.1.0

Published

Check whether a media file carries a C2PA provenance manifest. Detects presence, not validity.

Readme

ai-act-verify

Does this file carry a provenance manifest? One command, no dependencies, no account.

npx ai-act-verify ./generated-image.png
generated-image.png  (PNG, 412.7 KB)
  C2PA manifest   PRESENT   — PNG 'caBX' chunk
  manifest size   18.2 KB
  XMP             present
  validation      NOT PERFORMED — presence is not validity

Summary  1 with a manifest · 0 without

Why this exists

If you generate images or audio with AI and ship them to users in the EU, you are probably relying on your model provider to mark the output. That reliance is allowed — but the responsibility to demonstrate it stays with you.

Most teams have never actually looked at whether the files leaving their pipeline carry a manifest at all. This tool takes ten seconds to find out.

What it does

Reads the container and reports whether a C2PA/JUMBF manifest is present:

| Container | Where it looks | |---|---| | JPEG | APP11 segments with the JP JUMBF prefix | | PNG | caBX chunk | | WebP / WAV | C2PA RIFF chunk | | MP4 / M4A / MOV / HEIC / AVIF | uuid box carrying the C2PA UUID | | MP3 | GEOB frame in the ID3v2 tag | | SVG | c2pa reference in embedded XMP |

Anything else comes back UNSUPPORTED rather than guessing.

What it deliberately does NOT do

It does not validate. It tells you a manifest is there, not that it is signed by someone you trust, not that it matches the bytes of the file, not that it has not been tampered with. Cryptographic validation needs the real C2PA toolchain (c2pa-node, c2patool) and a trust list — not a container parser.

That is why every report says NOT PERFORMED instead of quietly implying a green light. A tool that blurs "present" into "valid" is worse than no tool.

It is not legal advice. A manifest being present does not prove compliance with Article 50 of the EU AI Act, and its absence does not prove a breach — the Commission Guidelines place several kinds of output outside the marking obligation entirely (source code, machine-to-machine communication, short sequences, standard editing, and more).

Options

--json      machine-readable report, for CI and scripts
--strict    exit 1 if any file comes back ABSENT
--quiet     one result line per file

Exit codes: 0 fine · 1 --strict and something was ABSENT · 2 bad usage or unreadable file.

In CI

- run: npx ai-act-verify dist/assets/*.png --strict

As a library

import { inspect } from 'ai-act-verify';
import { readFile } from 'node:fs/promises';

const report = inspect(await readFile('output.jpg'));
// { type: 'JPEG', status: 'PRESENT', where: "JUMBF in APP11 (1 segment)",
//   validation: 'NOT_PERFORMED', ... }

Requirements

Node 18+. No dependencies, by design — you are running this over your own media.

The part this tool cannot do for you

Running the check is easy. Being able to show, in eight months, that you ran it, on which files, and what it said at the time is the hard part. That is dated evidence, and a CLI does not produce it.

We are building the infrastructure for that: transparency controls and verifiable evidence for teams shipping AI-generated content, without building it in-house.

→ Early access

Licence

MIT.