Skip to content
Report library
Purpose / Other

Is This Photo Real Skill Security Audit

What the author says it does (original text)

>-

Independent security check

Do not install or run it yet

Files checked
3
Risks found
4
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 2
High risk

Originals, crops, and video keyframes may be disclosed to multiple search or forensic services

Source references: 4
What we found

The workflow calls for submitting the full frame to at least three reverse-image engines, then submitting crops, mirrored versions, and video keyframes. The reference also says some hosted forensic services retain or publicly display submissions. The Skill warns users to check publication policies, but does not enforce local-only handling or consent for sensitive cases.

Why this matters

KYC documents, faces, accident, crime, victim, or intimate imagery could be retained or processed by third parties and may appear in public galleries. An upload may not be reliably retractable.

The workflow calls for submitting full images, multiple video keyframes, crops, and mirrored versions to several reverse-search engines, disclosing sensitive media to those services. The source explicitly warns that some forensic services publish uploads and recommends local tools for sensitive files. The risk arises only when online services are actually used, and the Skill does warn about it, but local processing is not mandatory. Users can restrict analysis to local tools and verify retention, publication, and deletion policies before uploading.

reference/verification-checklist.md:26In the instructionsOpen original file
- [ ] Reverse image search: full frame across at least three engines. For video, extract      keyframes and search several.- [ ] Crop the distinctive elements and re-search each. Mirror and re-search.- [ ] Sort for the **oldest** copy where the engine allows.- [ ] Open every match page. Harvest: caption, date, photographer credit, agency, named      people, image filename.- [ ] Corroborate the earliest page's date against an independent archive capture.- [ ] Search the caption text and any distinctive on-image text as a string, in the      original language.
Show 3 other places
reference/tool-catalogue.md:7In the instructionsOpen original file
Before anything: check whether a tool **publishes** your submission. Some forensicservices maintain public galleries of uploads. For anything sensitive, prefer localtools.
reference/tool-catalogue.md:89In the instructionsOpen original file
### FotoForensicsHosted suite built around ELA, plus JPEG quality estimation, last-save quality,metadata, embedded thumbnail extraction, and hidden-pixel and string checks. Thenon-ELA parts are the useful parts.**Failure mode:** ELA is the headline feature and the most misread analysis in thefield — see the parent skill. The service also retains and may display submissions;do not upload sensitive material.
SKILL.md:252In the instructionsOpen original file
Publishing an accusation of fabrication against a named person carries defamationrisk in most jurisdictions, and "our tool said so" is not a defence. Uploadingmaterial to online forensic services discloses it to those services and, for some, topublic galleries — check whether a tool publishes submissions before submittinganything sensitive. If the media depicts a crime, a victim, or intimate content:minimise copies, do not redistribute, and in the case of child sexual abuse materialstop immediately and report to the appropriate authority rather than analysing it. See[../../ETHICS.md](../../ETHICS.md).
Medium risk

Photo verification can expand into broad investigation of people, accounts, and social activity

Source references: 2
What we found

The “Pivots” section directs follow-up into account amplification, social pattern-of-life analysis, leak searching, and identification of named people in the media. These tasks exceed what is necessary to determine media authenticity, and the supplied material does not require consent, necessity, or collection limits.

Why this matters

Following these pivots could aggregate identities, account relationships, activity patterns, or leaked data, creating privacy, harassment, or false-association risks for ordinary subjects, journalists, victims, or unrelated people.

The “Pivots” section explicitly redirects media verification toward account tracing, social-activity patterns, leak searches, network mapping, and finding named individuals. These are optional follow-on paths rather than automatic actions, and they may be legitimate in disinformation investigations. If followed, however, they broaden collection about people and connected accounts, while the table itself sets no necessity, consent, or minimization condition. Users can limit authorization to media provenance and require separate purpose, scope, and legal-basis approval for personal or social-network investigation.

SKILL.md:245In the instructionsOpen original file
| Deleted or altered source pages | `read-deleted-pages` || Publishing or seeding domain | `who-owns-this-domain`, `recon-a-domain-passively` || Accounts amplifying the media | `hunt-a-handle`, `pattern-of-life-from-socials` || Coordinated network behind the spread | `graph-the-network`, `find-leaks-in-the-wild` || Named individuals in or credited on the media | `find-anyone` |
Show 1 other places
SKILL.md:239In the instructionsOpen original file
| What you got | Send to ||---|---|| Earlier copies, credits, original caption | `find-the-original-image` || Editing chain, device, timestamps | `secrets-in-file-metadata` || Location and date verification | `geolocate-from-pixels`, `where-was-this-taken` || Deleted or altered source pages | `read-deleted-pages` || Publishing or seeding domain | `who-owns-this-domain`, `recon-a-domain-passively` || Accounts amplifying the media | `hunt-a-handle`, `pattern-of-life-from-socials` || Coordinated network behind the spread | `graph-the-network`, `find-leaks-in-the-wild` || Named individuals in or credited on the media | `find-anyone` |
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.Risks found: 1
Medium risk

The workflow opens every matching webpage without isolating malicious page instructions

Source references: 4
What we found

The verification procedure tells the agent to open every result page, read its text, and use web archives. External pages are controlled by untrusted publishers and can contain prompt injection aimed at AI agents. The supplied instructions do not say to ignore page commands, constrain tool calls, or extract only specified evidence fields.

Why this matters

If an agent has browser, file, or account tools and treats page text as operational instructions, a webpage could influence the conclusion or induce unrelated reading, uploading, or account actions.

What this evidence establishes

The workflow does require opening match pages and consulting web archives, so it encounters untrusted web content. However, the visible instructions limit the task to extracting captions, dates, credits, and similar evidence; they do not tell an agent to obey page instructions, and no script is provided that executes page text. Prompt-injection impact therefore cannot be established from this source. Users can require read-only browsing, extraction of only the listed fields, and a ban on page content triggering tools or permission changes.

This assessment concerns the code and conditions shown, not proof that harm has occurred.
reference/verification-checklist.md:26In the instructionsOpen original file
- [ ] Reverse image search: full frame across at least three engines. For video, extract      keyframes and search several.- [ ] Crop the distinctive elements and re-search each. Mirror and re-search.- [ ] Sort for the **oldest** copy where the engine allows.- [ ] Open every match page. Harvest: caption, date, photographer credit, agency, named      people, image filename.- [ ] Corroborate the earliest page's date against an independent archive capture.- [ ] Search the caption text and any distinctive on-image text as a string, in the      original language.
Show 3 other places
SKILL.md:47In the instructionsOpen original file
   downstream conclusion.2. **Provenance.** Run `find-the-original-image`; for video, extract and search   keyframes. You want an earlier appearance, a different caption, a photographer   credit, and an on-page date corroborated through `read-deleted-pages`. An earlier copy   with a different caption ends the case.3. **Metadata.** Run `secrets-in-file-metadata`: editing chain, thumbnail-versus-image
reference/verification-checklist.md:30In the instructionsOpen original file
- [ ] Sort for the **oldest** copy where the engine allows.- [ ] Open every match page. Harvest: caption, date, photographer credit, agency, named      people, image filename.- [ ] Corroborate the earliest page's date against an independent archive capture.- [ ] Search the caption text and any distinctive on-image text as a string, in the      original language.
reference/tool-catalogue.md:22In the instructionsOpen original file
### Web archivesArchived captures date a page independently of what the page claims about itself. See`read-deleted-pages`.**Failure mode:** no capture means no evidence either way; robots-directiveretroactivity and takedowns can remove captures that existed.
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Medium risk

Subjective verification grades are positioned for KYC, insurance, and evidentiary decisions

Source references: 7
What we found

The Skill expressly targets KYC, onboarding, insurance claims, and evidence admissibility, while permitting “probably manipulated” or “probably synthetic” grades based on physical anomalies, generative tells, and missing provenance. These involve human judgment and incomplete evidence; they do not prove identity fraud, a fraudulent claim, or legal admissibility.

Why this matters

If used directly for automated or single-reviewer decisions, genuine users could be denied onboarding, employment, or claims. People depicted could also face false accusations, reputational harm, or legal consequences.

The Skill explicitly targets high-impact contexts including KYC, onboarding fraud, insurance claims, and evidence admissibility, while permitting “probably manipulated” or “probably synthetic” findings based on explainable but judgment-dependent indicators. Treating those findings as sufficient grounds to reject an identity, claim, or evidence could cause serious errors. The source mitigates this by requiring claim-by-claim grading, limitations, and more than a bare real/fake verdict, but the risk remains. Users can require results to serve only as investigative leads subject to authorized human review and independent evidence.

SKILL.md:4In the instructionsOpen original file
description: >-  Verify whether an image or video is authentic, original and correctly captioned — provenance  checks, error level analysis, noise and JPEG compression analysis, clone and copy-move  detection, lighting and shadow consistency, C2PA Content Credentials, deepfake and  AI-generation tells, and the honest limits of AI-detector tools. Use when fact-checking a  photo or video, checking for a deepfake or AI-generated image, spotting manipulation, or  testing whether footage is recycled or miscaptioned. Applies to KYC and onboarding fraud,  insurance claim review, disinformation analysis, and evidence admissibility. Reference at  useosint.com/skills/is-this-photo-real.
Show 6 other places
SKILL.md:182In the instructionsOpen original file
  `investigate-without-getting-made`.- **Identification from resemblance** is the highest-consequence error here — "this is  person Z because they look alike" is not a finding.
SKILL.md:193In the instructionsOpen original file
  details consistent, nothing contradicted in metadata or geometry.- **Confirmed recontextualised** — the same image demonstrably published earlier with  a different, better-sourced caption. The most common positive finding here.- **Probably manipulated** — a specific, describable physical or geometric  inconsistency you can point at, ideally with a source for the inserted element.  Not a heatmap.- **Probably synthetic** — multiple durable generative tells, no provenance history,  no camera-consistent compression or metadata, no earlier copies. Name the tells.- **Unconfirmed** — no earlier copy found, nothing wrong found. Where most cases end.- **Cannot be assessed** — the available copy is too processed for the tests the question
SKILL.md:252In the instructionsOpen original file
Publishing an accusation of fabrication against a named person carries defamationrisk in most jurisdictions, and "our tool said so" is not a defence. Uploadingmaterial to online forensic services discloses it to those services and, for some, to
SKILL.md:7In the instructionsOpen original file
  detection, lighting and shadow consistency, C2PA Content Credentials, deepfake and  AI-generation tells, and the honest limits of AI-detector tools. Use when fact-checking a  photo or video, checking for a deepfake or AI-generated image, spotting manipulation, or  testing whether footage is recycled or miscaptioned. Applies to KYC and onboarding fraud,  insurance claim review, disinformation analysis, and evidence admissibility. Reference at  useosint.com/skills/is-this-photo-real.
SKILL.md:195In the instructionsOpen original file
  a different, better-sourced caption. The most common positive finding here.- **Probably manipulated** — a specific, describable physical or geometric  inconsistency you can point at, ideally with a source for the inserted element.  Not a heatmap.- **Probably synthetic** — multiple durable generative tells, no provenance history,  no camera-consistent compression or metadata, no earlier copies. Name the tells.- **Unconfirmed** — no earlier copy found, nothing wrong found. Where most cases end.- **Cannot be assessed** — the available copy is too processed for the tests the question  needs. Say which tests were invalid and why.
SKILL.md:228In the instructionsOpen original file
**Reporting standard.** State what you verified, what you could not, and what eachconclusion rests on — never a bare "fake" or "real". A defensible line reads: *theimage was published at least three years before the claimed event, on a news site,credited to a named photographer; the location matches that credit and not the claim; nomanipulation was detected, but the only available copy was a platform re-encode, sosignal-level tests were not meaningful.* "Our analysis shows this is fake" is not.Include the tests you ran and their negative results, the file's processing history, and

Inside this skill

8 instruction sections

This Skill is a media-verification workflow that checks origin and captions first, followed by metadata, location, and physical consistency, with error-prone pixel forensics used last.

View source
SKILL.md:17In the instructionsOpen original file
Verification order is the whole skill: **provenance first, pixels last.** Finding theearliest copy and reading its caption settles more cases than every forensic filtercombined, and it produces evidence you can show someone. Pixel forensics produces acolourful heatmap and an argument.
SKILL.md:43In the instructionsOpen original file
1. **Get the best copy.** Every re-encode, resize and screenshot destroys forensic   signal. Chase the original upload or the agency version, not the platform rendition.   Hash it, work on copies. If all you have is a screenshot, say so and lower every   downstream conclusion.2. **Provenance.** Run `find-the-original-image`; for video, extract and search   keyframes. You want an earlier appearance, a different caption, a photographer   credit, and an on-page date corroborated through `read-deleted-pages`. An earlier copy   with a different caption ends the case.3. **Metadata.** Run `secrets-in-file-metadata`: editing chain, thumbnail-versus-image   comparison, timestamp inconsistencies, whether MakerNotes fit the claimed device.4. **Provenance signing.** Check for C2PA Content Credentials.5. **Internal consistency.** Signage language, plates, currency, uniforms, vehicle   models, season, weather and shadows against the claimed date and place, via   `geolocate-from-pixels`. Ordinary detective work, more productive than forensics.6. **Physical consistency.** Lighting, shadows, reflections, perspective.7. **Signal-level forensics.** Noise residuals, JPEG quantisation and double compression,   clone detection, colour-filter-array traces. Easy to over-read, worthless on a   platform-processed file.8. **Write what you verified**, not a verdict.

The supplied material consists of Markdown operating instructions and references. It lists local media-inspection commands but supplies no executable automation or installation procedure to verify.

View source
reference/tool-catalogue.md:59In the instructionsOpen original file
### ffprobe and MediaInfoContainer and stream inspection for video: encoder strings, frame rate, rotationmatrices, per-track metadata, frame types and timestamps.```bashffprobe -v error -show_format -show_streams video.mp4ffprobe -v error -select_streams v -show_frames -show_entries frame=pict_type,pkt_pts_time video.mp4mediainfo video.mp4```
reference/verification-checklist.md:16In the instructionsOpen original file
      things specifically later.- [ ] Obtain the best available copy. Original file over platform rendition, platform      rendition over screenshot. For platform video use `yt-dlp` rather than a screen      recording.- [ ] Hash it. `sha256sum` the file, record the hash, and work only on copies.- [ ] Record the **processing history you know**: where you got it, whether it was      re-encoded, whether it is a crop or screenshot. This determines which tiers below      are valid at all.

The Skill explicitly recognizes the evidentiary limits of detectors, metadata, and C2PA, and calls for separate statements of what was verified, unverified, or unassessable instead of a bare real/fake verdict.

View source
SKILL.md:103In the instructionsOpen original file
C2PA binds a cryptographically signed manifest to a file recording capture and edithistory. Where it exists it is the strongest provenance evidence available, because itis verifiable rather than inferential. A **valid** manifest means the signer assertsthis history, the file is unchanged since signing, and you know who to holdresponsible — not that the content is true. A signed photograph of a staged scene is asigned photograph.**Absence** means almost nothing: most cameras do not sign, most editing pipelines donot preserve manifests, and platforms strip them during re-encoding. Missingcredentials are the default state, not a red flag. Same for the IPTCdigital-source-type field used to label synthetic media, and for model-specificinvisible watermarks — a positive is strong where you can check it, a negative onlysays one vendor's mark was not found.
SKILL.md:228In the instructionsOpen original file
**Reporting standard.** State what you verified, what you could not, and what eachconclusion rests on — never a bare "fake" or "real". A defensible line reads: *theimage was published at least three years before the claimed event, on a news site,credited to a named photographer; the location matches that credit and not the claim; nomanipulation was detected, but the only available copy was a platform re-encode, sosignal-level tests were not meaningful.* "Our analysis shows this is fake" is not.Include the tests you ran and their negative results, the file's processing history, andyour assumptions, then hand the package to `write-the-intel-brief`.

The core workflow depends on several other Skills not included in the supplied material, such as original-image search, metadata analysis, geolocation, and deleted-page retrieval. Their network, retention, and permission behavior therefore cannot be verified from this source.

View source
SKILL.md:47In the instructionsOpen original file
   downstream conclusion.2. **Provenance.** Run `find-the-original-image`; for video, extract and search   keyframes. You want an earlier appearance, a different caption, a photographer   credit, and an on-page date corroborated through `read-deleted-pages`. An earlier copy   with a different caption ends the case.3. **Metadata.** Run `secrets-in-file-metadata`: editing chain, thumbnail-versus-image   comparison, timestamp inconsistencies, whether MakerNotes fit the claimed device.4. **Provenance signing.** Check for C2PA Content Credentials.5. **Internal consistency.** Signage language, plates, currency, uniforms, vehicle   models, season, weather and shadows against the claimed date and place, via   `geolocate-from-pixels`. Ordinary detective work, more productive than forensics.6. **Physical consistency.** Lighting, shadows, reflections, perspective.
SKILL.md:239In the instructionsOpen original file
| What you got | Send to ||---|---|| Earlier copies, credits, original caption | `find-the-original-image` || Editing chain, device, timestamps | `secrets-in-file-metadata` || Location and date verification | `geolocate-from-pixels`, `where-was-this-taken` || Deleted or altered source pages | `read-deleted-pages` || Publishing or seeding domain | `who-owns-this-domain`, `recon-a-domain-passively` || Accounts amplifying the media | `hunt-a-handle`, `pattern-of-life-from-socials` || Coordinated network behind the spread | `graph-the-network`, `find-leaks-in-the-wild` || Named individuals in or credited on the media | `find-anyone` |
Start here · InstructionsSKILL.md
is-this-photo-real
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 4 more sections are available in the original file.

File reference map

References: 2
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records3 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • reference/tool-catalogue.mdFull text included
  • reference/verification-checklist.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • reference/tool-catalogue.mdSupporting file
  • reference/verification-checklist.mdSupporting file

Operations mentioned in code and instructions

Read keys or account settings
SKILL.md:6In the instructionsOpen original file
  checks, error level analysis, noise and JPEG compression analysis, clone and copy-move  detection, lighting and shadow consistency, C2PA Content Credentials, deepfake and  AI-generation tells, and the honest limits of AI-detector tools. Use when fact-checking a
SKILL.md:53In the instructionsOpen original file
   comparison, timestamp inconsistencies, whether MakerNotes fit the claimed device.4. **Provenance signing.** Check for C2PA Content Credentials.5. **Internal consistency.** Signage language, plates, currency, uniforms, vehicle
SKILL.md:101In the instructionsOpen original file
## C2PA and Content Credentials
Run commands
reference/tool-catalogue.md:64In the instructionsOpen original file
```bashffprobe -v error -show_format -show_streams video.mp4
Lines read
677
File checksum (to compare versions)
90f1bb32280b52030d1938de41bda7f15dd15ee2613ce10b404ff4b654f8df3d