Israeli Media Authenticity Verifier
Legal notice
This skill produces an assistive verification summary. It is not legal advice, not a forensic certification, and not admissible expert evidence. What it is, positively: a structured record of which signals were found, which were absent, and how much weight each carries. It performs no chain-of-custody handling, no bit-level forensic analysis of the file, and no laboratory-grade classification, which are the steps a qualified examiner performs and which is why its output is not one. It does not determine whether any publication is lawful, and it does not identify people. Where the stakes are legal (defamation, a criminal complaint, an election-propaganda dispute, employment or custody consequences), the user needs a licensed lawyer and, for evidentiary purposes, a qualified forensic examiner.
Note also that the user is usually about to forward something, and forwarding is not a neutral act. Israeli defamation law defines publication broadly rather than by medium, so a forward may itself amount to publishing the content. Separately, sharing violent or terror-related material with approving framing may carry criminal exposure, quite apart from whether the footage is authentic. Both are questions for a lawyer on the specific facts. This skill only flags that the exposures exist; it does not assess them and does not tell the user where the line falls.
Problem
Israelis are flooded with images and videos forwarded on WhatsApp and Telegram, especially during security events, and it is genuinely hard to tell what is real. The June 2025 Iran-Israel conflict was, in the words of experts, the first major conflict where generative AI shaped the information battlefield: fake clips of missile damage in Tel Aviv and at Ben Gurion Airport circulated, and flight-simulator footage passed off as real airstrikes reached over 21 million views before removal. Most people have no reliable way to check, and the automated "AI detector" websites are themselves unreliable, so a forwarded lie spreads faster than the correction.
What this skill is (and is not)
This skill makes you a disciplined verifier, not a detector. There is no button that says "fake" or "real." Instead you combine four kinds of evidence, weight them, and report a verdict with an honest confidence level.
| Layer |
What it checks |
How conclusive |
| 1. Provenance |
C2PA Content Credentials, SynthID watermark, EXIF metadata |
Strong WHEN present; absence proves nothing |
| 2. Visual inspection |
Your own vision against an artifact checklist |
Suggestive, never proof |
| 3. Source tracing |
Reverse-image search, earliest appearance, geolocation |
Best for catching recycled or miscaptioned real media |
| 4. Ecosystem verifiers |
Content Credentials Verify, OpenAI Verify, SynthID via the Gemini app |
A hit is informative; a miss concludes nothing. Generic AI-detector sites stay unreliable |
Four honesty rules, always:
- A missing Content Credential or watermark is NOT evidence that media is fake or real. Screenshotting and re-encoding strip these signals from real and fake content alike.
- You cannot run a forensic AI-classifier yourself. Do not pretend to. Your vision pass is informed judgment, not a measurement.
- Automated AI-image detector websites mislead users. A NewsGuard audit found such tools "declared authentic images to be AI-generated 13.33 percent of the time, and one tool got it wrong 40 percent of the time." Treat any detector score as one weak signal, never the verdict.
- The most common wartime fake is not a deepfake at all: it is real footage that is old, from another place, or from a video game, just miscaptioned. As Poynter put it, viral war imagery is "often ... generated with artificial intelligence or else it's old footage misrepresented as if it's new." Always include "authentic but miscaptioned" as a possible verdict.
Instructions
Work the layers in order. Stop early only when provenance gives a cryptographically signed answer; otherwise gather all four and weigh them.
Step 0: Intake
Ask for the actual file if you only have a screenshot or a forwarded clip. A re-screenshotted image has lost its metadata and credentials, which changes what Layer 1 can do. Note the claim attached to the media ("this is Tel Aviv last night") separately from the media itself, because a real image with a false caption is a distinct verdict.
If this is an active security incident, check the authoritative source first. When the user is asking "is a missile hitting Tel Aviv right now," the fastest correct move is not forensics, it is the primary source: the Home Front Command (Pikud HaOref) official app and alerts, and established news desks. Tell the user not to act on or re-share a forward before confirming against an authority. Run the verification layers below in parallel, but never let the analysis delay the user from the real-time source.
Try to recover the original. Provenance and metadata survive only on the original file from the account or platform that first posted it. If you only have a forward, the highest-value step is to trace back to the earliest poster (see Step 3) and get their upload, or check whether the hosting platform shows its own "made with AI" label on the original post. A platform label is a zero-effort check for a user who has no shell.
Step 1: Provenance (run the scripts)
Provenance is the only layer that can be cryptographically conclusive, so start here.
Content Credentials (C2PA). Run scripts/check_provenance.py <file>. It wraps c2patool and reports the signer, the claim generator (for example a field naming the AI tool that made it), and the validation status. A valid signed manifest that says the asset was generated by an AI tool is near-conclusive. A manifest that says "captured by camera X" with a verified signature is strong evidence of authenticity. No manifest is the common case and means nothing on its own.
Metadata (EXIF). Run scripts/dump_metadata.py <file>. It wraps exiftool and surfaces camera Make/Model, DateTimeOriginal, GPS, and the Software field (an edit fingerprint like an image editor or generator name). It can also write an Error Level Analysis (ELA) image as a hint for spliced regions. Read absence as "no signal," not as "fake."
No-code fallback (three free checks). If you have no shell, none of Layer 1 is lost. Each of these is ecosystem-scoped, so a hit is informative and a miss concludes nothing:
- Before you upload anything, check who is in it. These three tools send the file to a foreign server. Never upload intimate or sexual imagery, media showing a minor, or any identifiable person other than the user, to a third-party verifier: for those items run only the local scripts and read the originating platform's own AI label. Uploading another person's identifiable media without their consent is a transfer of their personal data, and for intimate imagery it is a second harm on top of the first. The local scripts in Step 1.1 and 1.2 never leave the machine.
- Content Credentials Verify at https://verify.contentauthenticity.org (the old Content Credentials verify address redirects here). Drag the file in to read any C2PA manifest and its edit history. It accepts images, video, audio and PDF.
- OpenAI Verify at https://openai.com/research/verify/. It reports whether a file carries OpenAI provenance signals, checking both Content Credentials and the SynthID watermark, and it covers images and (since 31 July 2026) supported audio. It only covers content made with ChatGPT, the OpenAI API or Codex, and it deliberately draws no conclusion when it finds nothing.
- SynthID via the Gemini app. Upload the image, video or audio clip into a Gemini chat and ask whether it was created or altered by Google AI; Gemini checks for a SynthID watermark. (Google also runs a separate SynthID Detector portal aimed at journalists and researchers rather than the general public, so the Gemini app is the route an ordinary user actually has.)
- Also check whether the originating platform shows its own "made with AI" label on the ORIGINAL post.
All three upload the file to a remote server. Apply the rule above before using any of them.
See references/provenance.md for how to read a manifest, what SynthID covers, and the limits of each tool.
Step 2: Visual inspection (your vision + the checklist)
Look at the actual pixels using references/artifact-checklist.md. The checklist is current for 2026 and, importantly, flags which old tells are now unreliable (hands and Latin-script text are largely fixed in modern generators, so a correct hand proves nothing). Focus on the tells that still hold: garbled non-Latin text and signage (Hebrew and Arabic especially), broken shadow and reflection physics, impossible jewelry or accessories, over-smooth skin, and warped backgrounds and architecture. For video, run scripts/extract_frames.py <file> to pull frames and step through them for temporal flicker, identity drift and motion warping. Lip-sync is no longer a usable tell: current generators produce the speech and the picture together (Google says of Veo that it generates all audio natively), so matched lips are what a good generation looks like, not evidence of a real recording. Blink cadence should be treated the same way, though as reasoning rather than a cited finding: a fully generated clip renders the eyes along with everything else, so there is no face-swap seam for a blink anomaly to come from. Accept that a modern text-to-video clip of a talking person may leave NO visual signal at all, in which case the verdict has to come from provenance and source tracing.
Record each observation as a signal with a direction (leans-synthetic, leans-authentic, neutral). Do not collapse them into a verdict yet.
Step 3: Source and context tracing
This layer catches the dominant real-world case: recycled or miscaptioned real media. Follow references/source-tracing.md.
- Reverse-image search the still (or a representative frame) across more than one engine. Use TinEye for the EARLIEST appearance (that is the question this layer is answering), Yandex for scene matching, Lens for identifying a place or object. Lens answers "what is similar", not "when was this first posted", so do not let it stand in for the earliest-appearance question.
- For video, there is still no true reverse-video search. Say so rather than letting the user hunt for one, while noting it is a statement about tool availability that could change. Extract keyframes (
scripts/extract_frames.py --keyframes) and reverse-search several of them; browser users can use the InVID/WeVerify plugin to do the same in one step.
- Work the platform's own provenance. Telegram exposes the forwarded-from chain, a no-account channel view at
t.me/s/<channel>, and sequential message IDs you can date-bracket. On a WhatsApp screenshot, crop the chat chrome before searching, and read the "Forwarded many times" label and the visible timestamps as evidence in their own right.
- Geolocate and chronolocate with named tools, not by eye: Google Earth Pro historical imagery, Mapillary street level, Overpass Turbo for OSM features, and SunCalc to work a shadow back to a time of day. Check Israeli specifics (Hebrew vs Arabic vs Farsi signage, plate colour and format compared against current photos of the claimed area, bus liveries).
- Check whether an Israeli verification outlet has already addressed it: המשרוקית at Globes is the Hebrew claim-rating desk (see
references/israeli-context.md).
- Do not use a face-recognition or face-search engine at all (PimEyes and similar), and decline requests to. Even when the goal is legitimate verification, running a face through recognition search is itself processing a biometric identifier, which Israel's Privacy Protection Law treats as "מידע בעל רגישות מיוחדת", the strictest category, and the purpose you had in mind does not change that. To verify a CLAIMED KNOWN identity, do it the permitted way instead: reverse-search the whole image (not a cropped face) and compare it against the person's own published photographs from their verified accounts or from news archives.
Step 4: External corroboration (optional, caveated)
Keep the two kinds of external tool apart, because they deserve opposite levels of trust:
- Ecosystem verifiers (Content Credentials Verify, OpenAI Verify, SynthID via Gemini) read a signal the generator actually put there. They belong in Step 1, and you should already have run them. A hit is real evidence; a miss concludes nothing.
- Generic AI-detector websites guess from pixels. Apply honesty rule 3: state explicitly that a single detector score does not decide the verdict, and never paste a detector percentage as if it were proof.
Election-period campaign media (Israel): the label is itself a signal
If the item is election propaganda (a party clip, a candidate image, a campaign audio message), Israel now has a labelling duty that changes how you read it. Under the Elections Law for the Twenty-Sixth Knesset (Special Provisions and Legislative Amendments), 5786-2026, "אדם המפרסם תעמולת בחירות הכוללת תוכן שנוצר באמצעי דיגיטלי ונחזה להיות מקורי, חייב לציין באופן ברור ובולט שהתוכן לא תועד במקור". Rules published by the Elections Committee chair, in force since 26 July 2026, specify the two accepted forms: a statement that the content was digitally created and not originally documented, or a logo bearing "AI" with that same wording.
How to use this in a verification:
- A present, conforming label is a disclosed synthetic, not a discovery. Report it as digitally created per the publisher's own disclosure, and move on rather than running the full forensic stack.
- An absent label is NOT proof the clip is authentic. It means either the clip is genuine footage, or the duty was breached. Keep both hypotheses live and let the other layers decide.
- The absence of a required label is itself reportable. Route the user to the Central Elections Committee, which handles propaganda complaints and has already ordered AI campaign videos taken down. That is a different route from 119 or 105 (see
references/israeli-context.md).
- Do not tell the user whether a specific publication is lawful. Describe what the rule requires, what you observed, and where to complain.
Context outside Israel: EU AI Act Article 50 has applied since 2 August 2026 and requires deployers to disclose deepfake content on first exposure, which is why platform-side AI labels have become more common on recent content. Content published before that date was never in scope, so an unlabelled older item tells you nothing.
Audio and voice notes (a separate, weaker lane)
If the item is a voice note or a call recording (a cloned-voice "CEO," a "family member in trouble," a public figure saying something), the image and video layers above do not apply. Be honest that audio is the hardest case:
- No reliable consumer audio detector, especially on WhatsApp or phone-compressed voice notes. Compression destroys the very artifacts detectors look for. Do not paste an audio-detector score as a verdict.
- Ecosystem-scoped provenance still helps when present (same logic as C2PA for images: a positive is informative, absence proves nothing). Two concrete checks:
- ElevenLabs AI Speech Classifier (free): it estimates whether a clip was made with ElevenLabs. Two limits the tool states itself, and they matter: it "does not reliably classify audio generated with the Eleven v3 model", and it cannot detect audio from other providers. So a hit is strong, a miss says nothing about other tools, and a miss says nothing even about ElevenLabs if the voice came from v3.
- OpenAI Verify (free, https://openai.com/research/verify/): since 31 July 2026 it verifies supported audio as well as images, checking Content Credentials and SynthID. Scoped to audio generated with OpenAI tools.
- Google SynthID: upload the clip into the Gemini app and ask whether it was created or altered by Google AI. Note the scope changed: SynthID is no longer a Google-only signal, because OpenAI now adds cross-platform SynthID watermarking through a partnership with Google. A SynthID hit therefore means "watermarked by a participating generator", not "made by Google". Compression or re-encoding can still strip it.
- Do NOT use a general "voice deepfake detector" score as your verdict: compression is exactly what destroys the artifacts those tools look for, and a WhatsApp voice note is compressed by definition, so their output on the material you actually have is not something you can put a number on. Treat any such score as a weak corroborating signal only.
- The same upload rule applies to voice notes: a recording of a third party goes to the local checks only.
- The strongest move is out-of-band verification. Tell the user to confirm through a known, independent channel: call the person back on a number they already have (not one supplied in the message), or contact the institution through its official line. A cloned voice cannot survive a callback to a trusted number.
- Listen for tells (suggestive only): flat or mismatched emotional tone, unnatural pacing and breath, missing room or background noise, abrupt edits, and a request that creates urgency or asks for money or codes (the classic scam shape).
- If it is fraud or impersonation, route it (see
references/israeli-context.md): the National Cyber Directorate 119 hotline for cyber incidents, the bank's fraud line for financial impersonation, and 105 specifically when the target is a minor.
Report an audio item with the same verdict structure, but expect inconclusive more often, and lead with the out-of-band verification advice.
Step 5: Write the verdict report
Produce the report using this structure (template in references/verdict-report-template.md):
- Verdict: one of
authentic / AI-generated / digitally manipulated / authentic but miscaptioned / inconclusive.
- Confidence: low / medium / high, with one sentence on why.
- Evidence by layer: what each of the four layers found, including null results.
- What would change the verdict: the missing piece that would raise or lower confidence.
- Sources: every external link or tool used.
Prefer inconclusive over a confident guess. Calling real content fake is itself a harm (the "liar's dividend"), so distinguish "no evidence of manipulation found" from "proven authentic."
Step 6: Before the user acts on the verdict
The verdict feeds a decision the user is about to make, usually "do I forward this". Close with the two things that decision needs:
- Preserve first, if any reporting or complaint may follow. Keep the original file rather than a fresh screenshot, do not delete the thread, and record the sender identifier, the timestamps and when they received it. Every route in
references/israeli-context.md works better with an intact artefact, and it degrades by the hour.
- Name the right channel for the harm, and note the exposure that comes with forwarding. Route by who was harmed: 119 for a cyber or impersonation incident, the bank's fraud line plus 119 for financial impersonation, 105 only when the target is a minor, StopNCII plus the police complaint route for an adult targeted by synthetic sexual imagery, the Central Elections Committee for unlabelled campaign propaganda. Remind the user that forwarding can itself be publication, and point them to the Legal notice above rather than assessing their exposure.
Examples
Example 1: Forwarded war clip on WhatsApp
User says: "Got this video of a missile hitting a Tel Aviv tower last night, is it real?"
Actions:
- Ask for the original file, not the WhatsApp re-encode, if available.
scripts/check_provenance.py clip.mp4 and scripts/dump_metadata.py clip.mp4 (likely stripped on a forward, note that).
scripts/extract_frames.py clip.mp4, then inspect frames against the checklist (skyline geometry, smoke physics, temporal flicker).
- Reverse-image search key frames for earliest appearance; check whether it is a known recycled or game clip.
Result: A verdict report, for example "authentic but miscaptioned: footage matches a 2024 event in another city, confidence medium," or "inconclusive: no provenance, no prior match, minor frame artifacts."
Example 2: Suspicious image of a public figure
User says: "Is this photo of the minister saying X real?"
Actions:
- Run provenance and metadata scripts.
- Vision pass focused on text/signage, hands-in-context, lighting consistency.
- Reverse-image search; look for the original and the earliest publication.
Result: Report with verdict and confidence, plus a pointer to report impersonation if it targets a minor (105) or appears to be financial-impersonation fraud (see
references/israeli-context.md).
Bundled Resources
Scripts
scripts/check_provenance.py -- reads C2PA Content Credentials via c2patool. Run: python scripts/check_provenance.py <file>
scripts/dump_metadata.py -- dumps key EXIF fields via exiftool and can write an ELA image. Run: python scripts/dump_metadata.py <file>
scripts/extract_frames.py -- extracts frames from a video via ffmpeg for frame-by-frame inspection. Run: python scripts/extract_frames.py <video>
References
references/provenance.md -- how to read a C2PA manifest, what SynthID and EXIF do, and the limits of each.
references/artifact-checklist.md -- the 2026 visual-inspection checklist, including which tells are now obsolete.
references/source-tracing.md -- reverse-image, earliest-appearance, geolocation and chronolocation.
references/israeli-context.md -- the Iran-Israel media-manipulation landscape and Israeli verification and reporting channels.
references/verdict-report-template.md -- the output structure.
references/domain-checklist.md -- coverage contract this skill is maintained against.
Recommended MCP Servers
No MCP server currently provides media-authenticity data for Israel. The genuinely Israeli player in this space (deepfake and disinformation detection) is enterprise-only with no public API, and global AI-detector APIs are unreliable (see honesty rule 3), so this skill deliberately does not wrap one. The companion israeli-fact-checker skill handles numeric and textual claim verification against official Israeli data.
Gotchas
- Treating "no Content Credentials" as proof of fake. Most authentic media has no manifest, and forwarding strips manifests from real and fake content alike. Absence is a null result, not a verdict.
- Trusting an AI-detector website's percentage. These tools false-flag authentic photos at material rates (NewsGuard found 13.33 percent on average, 40 percent for one tool). Use them only as a weak corroborating signal.
- Defaulting to "it's a deepfake." The most common manipulation in the 2025 Iran-Israel flood was recycled or miscaptioned real footage and even flight-simulator clips, not synthesis. Always test the "authentic but miscaptioned" hypothesis with reverse-image search.
- Relying on obsolete visual tells. Modern generators fixed hands and Latin-script text; a clean hand or readable English caption is not evidence of authenticity. Lean on shadow physics, non-Latin text, and reflections instead.
- Reading a SynthID hit as "made by Google". That stopped being true: OpenAI now embeds cross-platform SynthID through a partnership with Google, so a hit means "watermarked by a participating generator". Attribute the tool from the C2PA manifest, not from the watermark.
- Forgetting the liar's dividend. Wrongly calling real footage fake also spreads disinformation. Distinguish "no manipulation evidence found" from "proven authentic," and prefer inconclusive over a confident guess.
Reference Links
Troubleshooting
Error: "c2patool: command not found"
Cause: The C2PA tool is not installed.
Solution: Install with brew install c2patool (macOS). The script will print this hint and continue with metadata-only analysis if the tool is missing.
Error: "exiftool: command not found"
Cause: ExifTool is not installed.
Solution: Install with brew install exiftool (macOS) or your platform package manager. Metadata analysis is skipped without it; the other three layers still work.
Issue: "Every layer is null / inconclusive"
Cause: The media was forwarded and stripped, has no prior online match, and shows no clear artifacts.
Solution: This is a legitimate inconclusive verdict. Report it honestly with the missing pieces that would change it, rather than guessing. Suggest the user obtain the original file or wait for a verification outlet to weigh in.
1---2name: israeli-media-authenticity-verifier3description: Run a structured check on whether an image or video is AI-generated, digitally manipulated, or authentic-but-miscaptioned, and produce a sourced verdict with a confidence level. Use when a user forwards a dramatic war or news photo or clip on WhatsApp or Telegram and asks if it is real, when a journalist or community moderator needs a repeatable verification report before sharing or debunking, or when someone gets a suspicious image or voice claiming to be a known person. Combines cryptographic provenance (C2PA Content Credentials, SynthID, EXIF metadata), the agent's own visual inspection against an artifact checklist, and source tracing (reverse-image search, earliest-appearance, geolocation). This is a verifier, not a magic detector: it never claims certainty from one signal and says can't-verify when evidence is thin. Do NOT use for numeric or textual claim fact-checking (use israeli-fact-checker), for generating or removing deepfakes, or as court-admissible forensic certification.4license: MIT5---67# Israeli Media Authenticity Verifier89## Legal notice1011This skill produces an assistive verification summary. It is not legal advice, not a forensic certification, and not admissible expert evidence. What it is, positively: a structured record of which signals were found, which were absent, and how much weight each carries. It performs no chain-of-custody handling, no bit-level forensic analysis of the file, and no laboratory-grade classification, which are the steps a qualified examiner performs and which is why its output is not one. It does not determine whether any publication is lawful, and it does not identify people. Where the stakes are legal (defamation, a criminal complaint, an election-propaganda dispute, employment or custody consequences), the user needs a licensed lawyer and, for evidentiary purposes, a qualified forensic examiner.1213Note also that the user is usually about to forward something, and forwarding is not a neutral act. Israeli defamation law defines publication broadly rather than by medium, so a forward may itself amount to publishing the content. Separately, sharing violent or terror-related material with approving framing may carry criminal exposure, quite apart from whether the footage is authentic. Both are questions for a lawyer on the specific facts. This skill only flags that the exposures exist; it does not assess them and does not tell the user where the line falls.1415## Problem1617Israelis are flooded with images and videos forwarded on WhatsApp and Telegram, especially during security events, and it is genuinely hard to tell what is real. The June 2025 Iran-Israel conflict was, in the words of experts, the first major conflict where generative AI shaped the information battlefield: fake clips of missile damage in Tel Aviv and at Ben Gurion Airport circulated, and flight-simulator footage passed off as real airstrikes reached over 21 million views before removal. Most people have no reliable way to check, and the automated "AI detector" websites are themselves unreliable, so a forwarded lie spreads faster than the correction.1819## What this skill is (and is not)2021This skill makes you a disciplined verifier, not a detector. There is no button that says "fake" or "real." Instead you combine four kinds of evidence, weight them, and report a verdict with an honest confidence level.2223| Layer | What it checks | How conclusive |24|-------|----------------|----------------|25| 1. Provenance | C2PA Content Credentials, SynthID watermark, EXIF metadata | Strong WHEN present; absence proves nothing |26| 2. Visual inspection | Your own vision against an artifact checklist | Suggestive, never proof |27| 3. Source tracing | Reverse-image search, earliest appearance, geolocation | Best for catching recycled or miscaptioned real media |28| 4. Ecosystem verifiers | Content Credentials Verify, OpenAI Verify, SynthID via the Gemini app | A hit is informative; a miss concludes nothing. Generic AI-detector sites stay unreliable |2930**Four honesty rules, always:**311. A missing Content Credential or watermark is NOT evidence that media is fake or real. Screenshotting and re-encoding strip these signals from real and fake content alike.322. You cannot run a forensic AI-classifier yourself. Do not pretend to. Your vision pass is informed judgment, not a measurement.333. Automated AI-image detector websites mislead users. A NewsGuard audit found such tools "declared authentic images to be AI-generated 13.33 percent of the time, and one tool got it wrong 40 percent of the time." Treat any detector score as one weak signal, never the verdict.344. The most common wartime fake is not a deepfake at all: it is real footage that is old, from another place, or from a video game, just miscaptioned. As Poynter put it, viral war imagery is "often ... generated with artificial intelligence or else it's old footage misrepresented as if it's new." Always include "authentic but miscaptioned" as a possible verdict.3536## Instructions3738Work the layers in order. Stop early only when provenance gives a cryptographically signed answer; otherwise gather all four and weigh them.3940### Step 0: Intake4142Ask for the actual file if you only have a screenshot or a forwarded clip. A re-screenshotted image has lost its metadata and credentials, which changes what Layer 1 can do. Note the claim attached to the media ("this is Tel Aviv last night") separately from the media itself, because a real image with a false caption is a distinct verdict.4344**If this is an active security incident, check the authoritative source first.** When the user is asking "is a missile hitting Tel Aviv right now," the fastest correct move is not forensics, it is the primary source: the Home Front Command (Pikud HaOref) official app and alerts, and established news desks. Tell the user not to act on or re-share a forward before confirming against an authority. Run the verification layers below in parallel, but never let the analysis delay the user from the real-time source.4546**Try to recover the original.** Provenance and metadata survive only on the original file from the account or platform that first posted it. If you only have a forward, the highest-value step is to trace back to the earliest poster (see Step 3) and get their upload, or check whether the hosting platform shows its own "made with AI" label on the original post. A platform label is a zero-effort check for a user who has no shell.4748### Step 1: Provenance (run the scripts)4950Provenance is the only layer that can be cryptographically conclusive, so start here.51521. **Content Credentials (C2PA).** Run `scripts/check_provenance.py <file>`. It wraps `c2patool` and reports the signer, the claim generator (for example a field naming the AI tool that made it), and the validation status. A valid signed manifest that says the asset was generated by an AI tool is near-conclusive. A manifest that says "captured by camera X" with a verified signature is strong evidence of authenticity. No manifest is the common case and means nothing on its own.532. **Metadata (EXIF).** Run `scripts/dump_metadata.py <file>`. It wraps `exiftool` and surfaces camera Make/Model, DateTimeOriginal, GPS, and the Software field (an edit fingerprint like an image editor or generator name). It can also write an Error Level Analysis (ELA) image as a hint for spliced regions. Read absence as "no signal," not as "fake."543. **No-code fallback (three free checks).** If you have no shell, none of Layer 1 is lost. Each of these is ecosystem-scoped, so a hit is informative and a miss concludes nothing:55 - **Before you upload anything, check who is in it.** These three tools send the file to a foreign server. Never upload intimate or sexual imagery, media showing a minor, or any identifiable person other than the user, to a third-party verifier: for those items run only the local scripts and read the originating platform's own AI label. Uploading another person's identifiable media without their consent is a transfer of their personal data, and for intimate imagery it is a second harm on top of the first. The local scripts in Step 1.1 and 1.2 never leave the machine.56 - **Content Credentials Verify** at https://verify.contentauthenticity.org (the old Content Credentials verify address redirects here). Drag the file in to read any C2PA manifest and its edit history. It accepts images, video, audio and PDF.57 - **OpenAI Verify** at https://openai.com/research/verify/. It reports whether a file carries OpenAI provenance signals, checking both Content Credentials and the SynthID watermark, and it covers images and (since 31 July 2026) supported audio. It only covers content made with ChatGPT, the OpenAI API or Codex, and it deliberately draws no conclusion when it finds nothing.58 - **SynthID via the Gemini app.** Upload the image, video or audio clip into a Gemini chat and ask whether it was created or altered by Google AI; Gemini checks for a SynthID watermark. (Google also runs a separate SynthID Detector portal aimed at journalists and researchers rather than the general public, so the Gemini app is the route an ordinary user actually has.)59 - Also check whether the originating platform shows its own "made with AI" label on the ORIGINAL post.6061 All three upload the file to a remote server. Apply the rule above before using any of them.6263See `references/provenance.md` for how to read a manifest, what SynthID covers, and the limits of each tool.6465### Step 2: Visual inspection (your vision + the checklist)6667Look at the actual pixels using `references/artifact-checklist.md`. The checklist is current for 2026 and, importantly, flags which old tells are now unreliable (hands and Latin-script text are largely fixed in modern generators, so a correct hand proves nothing). Focus on the tells that still hold: garbled non-Latin text and signage (Hebrew and Arabic especially), broken shadow and reflection physics, impossible jewelry or accessories, over-smooth skin, and warped backgrounds and architecture. For video, run `scripts/extract_frames.py <file>` to pull frames and step through them for temporal flicker, identity drift and motion warping. **Lip-sync is no longer a usable tell**: current generators produce the speech and the picture together (Google says of Veo that it generates all audio natively), so matched lips are what a good generation looks like, not evidence of a real recording. Blink cadence should be treated the same way, though as reasoning rather than a cited finding: a fully generated clip renders the eyes along with everything else, so there is no face-swap seam for a blink anomaly to come from. Accept that a modern text-to-video clip of a talking person may leave NO visual signal at all, in which case the verdict has to come from provenance and source tracing.6869Record each observation as a signal with a direction (leans-synthetic, leans-authentic, neutral). Do not collapse them into a verdict yet.7071### Step 3: Source and context tracing7273This layer catches the dominant real-world case: recycled or miscaptioned real media. Follow `references/source-tracing.md`.74751. Reverse-image search the still (or a representative frame) across more than one engine. Use TinEye for the EARLIEST appearance (that is the question this layer is answering), Yandex for scene matching, Lens for identifying a place or object. Lens answers "what is similar", not "when was this first posted", so do not let it stand in for the earliest-appearance question.762. **For video, there is still no true reverse-video search.** Say so rather than letting the user hunt for one, while noting it is a statement about tool availability that could change. Extract keyframes (`scripts/extract_frames.py --keyframes`) and reverse-search several of them; browser users can use the InVID/WeVerify plugin to do the same in one step.773. **Work the platform's own provenance.** Telegram exposes the forwarded-from chain, a no-account channel view at `t.me/s/<channel>`, and sequential message IDs you can date-bracket. On a WhatsApp screenshot, crop the chat chrome before searching, and read the "Forwarded many times" label and the visible timestamps as evidence in their own right.784. Geolocate and chronolocate with named tools, not by eye: Google Earth Pro historical imagery, Mapillary street level, Overpass Turbo for OSM features, and SunCalc to work a shadow back to a time of day. Check Israeli specifics (Hebrew vs Arabic vs Farsi signage, plate colour and format compared against current photos of the claimed area, bus liveries).795. Check whether an Israeli verification outlet has already addressed it: המשרוקית at Globes is the Hebrew claim-rating desk (see `references/israeli-context.md`).806. **Do not use a face-recognition or face-search engine at all** (PimEyes and similar), and decline requests to. Even when the goal is legitimate verification, running a face through recognition search is itself processing a biometric identifier, which Israel's Privacy Protection Law treats as "מידע בעל רגישות מיוחדת", the strictest category, and the purpose you had in mind does not change that. To verify a CLAIMED KNOWN identity, do it the permitted way instead: reverse-search the whole image (not a cropped face) and compare it against the person's own published photographs from their verified accounts or from news archives.8182### Step 4: External corroboration (optional, caveated)8384Keep the two kinds of external tool apart, because they deserve opposite levels of trust:8586- **Ecosystem verifiers** (Content Credentials Verify, OpenAI Verify, SynthID via Gemini) read a signal the generator actually put there. They belong in Step 1, and you should already have run them. A hit is real evidence; a miss concludes nothing.87- **Generic AI-detector websites** guess from pixels. Apply honesty rule 3: state explicitly that a single detector score does not decide the verdict, and never paste a detector percentage as if it were proof.8889### Election-period campaign media (Israel): the label is itself a signal9091If the item is election propaganda (a party clip, a candidate image, a campaign audio message), Israel now has a labelling duty that changes how you read it. Under the Elections Law for the Twenty-Sixth Knesset (Special Provisions and Legislative Amendments), 5786-2026, "אדם המפרסם תעמולת בחירות הכוללת תוכן שנוצר באמצעי דיגיטלי ונחזה להיות מקורי, חייב לציין באופן ברור ובולט שהתוכן לא תועד במקור". Rules published by the Elections Committee chair, in force since 26 July 2026, specify the two accepted forms: a statement that the content was digitally created and not originally documented, or a logo bearing "AI" with that same wording.9293How to use this in a verification:94- **A present, conforming label is a disclosed synthetic**, not a discovery. Report it as digitally created per the publisher's own disclosure, and move on rather than running the full forensic stack.95- **An absent label is NOT proof the clip is authentic.** It means either the clip is genuine footage, or the duty was breached. Keep both hypotheses live and let the other layers decide.96- **The absence of a required label is itself reportable.** Route the user to the Central Elections Committee, which handles propaganda complaints and has already ordered AI campaign videos taken down. That is a different route from 119 or 105 (see `references/israeli-context.md`).97- Do not tell the user whether a specific publication is lawful. Describe what the rule requires, what you observed, and where to complain.9899Context outside Israel: EU AI Act Article 50 has applied since 2 August 2026 and requires deployers to disclose deepfake content on first exposure, which is why platform-side AI labels have become more common on recent content. Content published before that date was never in scope, so an unlabelled older item tells you nothing.100101### Audio and voice notes (a separate, weaker lane)102103If the item is a voice note or a call recording (a cloned-voice "CEO," a "family member in trouble," a public figure saying something), the image and video layers above do not apply. Be honest that audio is the hardest case:104105- **No reliable consumer audio detector**, especially on WhatsApp or phone-compressed voice notes. Compression destroys the very artifacts detectors look for. Do not paste an audio-detector score as a verdict.106- **Ecosystem-scoped provenance still helps when present** (same logic as C2PA for images: a positive is informative, absence proves nothing). Two concrete checks:107 - **ElevenLabs AI Speech Classifier** (free): it estimates whether a clip was made with ElevenLabs. Two limits the tool states itself, and they matter: it "does not reliably classify audio generated with the Eleven v3 model", and it cannot detect audio from other providers. So a hit is strong, a miss says nothing about other tools, and a miss says nothing even about ElevenLabs if the voice came from v3.108 - **OpenAI Verify** (free, https://openai.com/research/verify/): since 31 July 2026 it verifies supported audio as well as images, checking Content Credentials and SynthID. Scoped to audio generated with OpenAI tools.109 - **Google SynthID**: upload the clip into the Gemini app and ask whether it was created or altered by Google AI. Note the scope changed: SynthID is no longer a Google-only signal, because OpenAI now adds cross-platform SynthID watermarking through a partnership with Google. A SynthID hit therefore means "watermarked by a participating generator", not "made by Google". Compression or re-encoding can still strip it.110 - Do NOT use a general "voice deepfake detector" score as your verdict: compression is exactly what destroys the artifacts those tools look for, and a WhatsApp voice note is compressed by definition, so their output on the material you actually have is not something you can put a number on. Treat any such score as a weak corroborating signal only.111- The same upload rule applies to voice notes: a recording of a third party goes to the local checks only.112- **The strongest move is out-of-band verification.** Tell the user to confirm through a known, independent channel: call the person back on a number they already have (not one supplied in the message), or contact the institution through its official line. A cloned voice cannot survive a callback to a trusted number.113- **Listen for tells** (suggestive only): flat or mismatched emotional tone, unnatural pacing and breath, missing room or background noise, abrupt edits, and a request that creates urgency or asks for money or codes (the classic scam shape).114- **If it is fraud or impersonation, route it** (see `references/israeli-context.md`): the National Cyber Directorate 119 hotline for cyber incidents, the bank's fraud line for financial impersonation, and 105 specifically when the target is a minor.115116Report an audio item with the same verdict structure, but expect `inconclusive` more often, and lead with the out-of-band verification advice.117118### Step 5: Write the verdict report119120Produce the report using this structure (template in `references/verdict-report-template.md`):121122- **Verdict:** one of `authentic` / `AI-generated` / `digitally manipulated` / `authentic but miscaptioned` / `inconclusive`.123- **Confidence:** low / medium / high, with one sentence on why.124- **Evidence by layer:** what each of the four layers found, including null results.125- **What would change the verdict:** the missing piece that would raise or lower confidence.126- **Sources:** every external link or tool used.127128Prefer `inconclusive` over a confident guess. Calling real content fake is itself a harm (the "liar's dividend"), so distinguish "no evidence of manipulation found" from "proven authentic."129130### Step 6: Before the user acts on the verdict131132The verdict feeds a decision the user is about to make, usually "do I forward this". Close with the two things that decision needs:1331341. **Preserve first, if any reporting or complaint may follow.** Keep the original file rather than a fresh screenshot, do not delete the thread, and record the sender identifier, the timestamps and when they received it. Every route in `references/israeli-context.md` works better with an intact artefact, and it degrades by the hour.1352. **Name the right channel for the harm, and note the exposure that comes with forwarding.** Route by who was harmed: 119 for a cyber or impersonation incident, the bank's fraud line plus 119 for financial impersonation, 105 only when the target is a minor, StopNCII plus the police complaint route for an adult targeted by synthetic sexual imagery, the Central Elections Committee for unlabelled campaign propaganda. Remind the user that forwarding can itself be publication, and point them to the Legal notice above rather than assessing their exposure.136137## Examples138139### Example 1: Forwarded war clip on WhatsApp140User says: "Got this video of a missile hitting a Tel Aviv tower last night, is it real?"141Actions:1421. Ask for the original file, not the WhatsApp re-encode, if available.1432. `scripts/check_provenance.py clip.mp4` and `scripts/dump_metadata.py clip.mp4` (likely stripped on a forward, note that).1443. `scripts/extract_frames.py clip.mp4`, then inspect frames against the checklist (skyline geometry, smoke physics, temporal flicker).1454. Reverse-image search key frames for earliest appearance; check whether it is a known recycled or game clip.146Result: A verdict report, for example "authentic but miscaptioned: footage matches a 2024 event in another city, confidence medium," or "inconclusive: no provenance, no prior match, minor frame artifacts."147148### Example 2: Suspicious image of a public figure149User says: "Is this photo of the minister saying X real?"150Actions:1511. Run provenance and metadata scripts.1522. Vision pass focused on text/signage, hands-in-context, lighting consistency.1533. Reverse-image search; look for the original and the earliest publication.154Result: Report with verdict and confidence, plus a pointer to report impersonation if it targets a minor (105) or appears to be financial-impersonation fraud (see `references/israeli-context.md`).155156## Bundled Resources157158### Scripts159- `scripts/check_provenance.py` -- reads C2PA Content Credentials via `c2patool`. Run: `python scripts/check_provenance.py <file>`160- `scripts/dump_metadata.py` -- dumps key EXIF fields via `exiftool` and can write an ELA image. Run: `python scripts/dump_metadata.py <file>`161- `scripts/extract_frames.py` -- extracts frames from a video via `ffmpeg` for frame-by-frame inspection. Run: `python scripts/extract_frames.py <video>`162163### References164- `references/provenance.md` -- how to read a C2PA manifest, what SynthID and EXIF do, and the limits of each.165- `references/artifact-checklist.md` -- the 2026 visual-inspection checklist, including which tells are now obsolete.166- `references/source-tracing.md` -- reverse-image, earliest-appearance, geolocation and chronolocation.167- `references/israeli-context.md` -- the Iran-Israel media-manipulation landscape and Israeli verification and reporting channels.168- `references/verdict-report-template.md` -- the output structure.169- `references/domain-checklist.md` -- coverage contract this skill is maintained against.170171## Recommended MCP Servers172173No MCP server currently provides media-authenticity data for Israel. The genuinely Israeli player in this space (deepfake and disinformation detection) is enterprise-only with no public API, and global AI-detector APIs are unreliable (see honesty rule 3), so this skill deliberately does not wrap one. The companion `israeli-fact-checker` skill handles numeric and textual claim verification against official Israeli data.174175## Gotchas176177- **Treating "no Content Credentials" as proof of fake.** Most authentic media has no manifest, and forwarding strips manifests from real and fake content alike. Absence is a null result, not a verdict.178- **Trusting an AI-detector website's percentage.** These tools false-flag authentic photos at material rates (NewsGuard found 13.33 percent on average, 40 percent for one tool). Use them only as a weak corroborating signal.179- **Defaulting to "it's a deepfake."** The most common manipulation in the 2025 Iran-Israel flood was recycled or miscaptioned real footage and even flight-simulator clips, not synthesis. Always test the "authentic but miscaptioned" hypothesis with reverse-image search.180- **Relying on obsolete visual tells.** Modern generators fixed hands and Latin-script text; a clean hand or readable English caption is not evidence of authenticity. Lean on shadow physics, non-Latin text, and reflections instead.181- **Reading a SynthID hit as "made by Google".** That stopped being true: OpenAI now embeds cross-platform SynthID through a partnership with Google, so a hit means "watermarked by a participating generator". Attribute the tool from the C2PA manifest, not from the watermark.182- **Forgetting the liar's dividend.** Wrongly calling real footage fake also spreads disinformation. Distinguish "no manipulation evidence found" from "proven authentic," and prefer inconclusive over a confident guess.183184## Reference Links185186| Source | URL | What to Check |187|--------|-----|---------------|188| Content Credentials Verify tool | https://verify.contentauthenticity.org/ | No-code provenance check for an image, video, audio or PDF |189| OpenAI Verify | https://openai.com/research/verify/ | Free check for OpenAI Content Credentials and SynthID in images and audio |190| Israeli election AI-labelling rules | https://www.law.co.il/news/2026/07/27/deep-fake-and-ai-elections-propaganda-rules/ | The disclosure a campaign item must carry, in force 26.07.2026 |191| c2patool docs | https://opensource.contentauthenticity.org/docs/sdk-repos/c2pa-rs/cli/ | Install and read C2PA manifests from the command line |192| Google SynthID | https://deepmind.google/science/synthid/ | What the SynthID watermark covers and its limits |193| ElevenLabs AI Speech Classifier | https://elevenlabs.io/ai-speech-classifier | Free check for whether audio was made with ElevenLabs |194| NewsGuard detector audit | https://www.newsguardtech.com/special-reports/leading-ai-image-detection-tools-mislead-online-users-often-declaring-authentic-content-fake/ | Why automated AI-image detectors are unreliable |195| Poynter, spotting fake war images | https://www.poynter.org/fact-checking/2026/fake-images-iran-war-how-spot-them/ | Recycled and miscaptioned footage as the dominant fake |196| Israel 105 (Child Online Protection) | https://www.gov.il/en/departments/units/105_call_center | Reporting online harm to minors |197| Bank of Israel fraud warning | https://www.boi.org.il/en/information-and-service-to-the-public/consumer-enquiries-and-inspections/warning-to-the-public-with-regard-to-fraud-by-impersonating-the-bank-of-israel-or-commercial-banks/ | Impersonation-fraud guidance |198199## Troubleshooting200201### Error: "c2patool: command not found"202Cause: The C2PA tool is not installed.203Solution: Install with `brew install c2patool` (macOS). The script will print this hint and continue with metadata-only analysis if the tool is missing.204205### Error: "exiftool: command not found"206Cause: ExifTool is not installed.207Solution: Install with `brew install exiftool` (macOS) or your platform package manager. Metadata analysis is skipped without it; the other three layers still work.208209### Issue: "Every layer is null / inconclusive"210Cause: The media was forwarded and stripped, has no prior online match, and shows no clear artifacts.211Solution: This is a legitimate `inconclusive` verdict. Report it honestly with the missing pieces that would change it, rather than guessing. Suggest the user obtain the original file or wait for a verification outlet to weigh in.