gwt-e3b0c4 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited gwt-e3b0c4 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
GeminiWatermarkTool (GWT) removes visible Gemini AI watermarks from images using mathematically accurate reverse alpha blending, with optional AI denoising (FDnCNN + NCNN Vulkan GPU) for residual cleanup.
Source: https://github.com/allenk/GeminiWatermarkTool
Search in this order:
GWT_BINARY_PATHGeminiWatermarkTool (or .exe on Windows)%USERPROFILE%\.claude\skills\gwt\bin\GeminiWatermarkTool.exe~/.claude/skills/gwt/bin/GeminiWatermarkTool.\bin\GeminiWatermarkTool.exe./bin/GeminiWatermarkToolIf not found, run the installer:
python ~/.claude/skills/gwt/install.pyFor local validation inside this repo only:
python ~/.claude/skills/gwt/install.py --dir ./binAlways pass `--no-banner` when calling GWT — suppresses ASCII art that wastes tokens.
GWT ships with two watermark profiles. The default targets Gemini 3.5 and later, with automatic legacy fallback.
| Profile | Targets | When tried |
|---|---|---|
| Current (V2) | Gemini 3.5 and later outputs | first, by default |
| Legacy (V1) | Pre-Gemini-3.5 outputs | automatically retried if V2 skips |
This means remove_watermark(input, output) already handles mixed Gemini-3.5+ and pre-3.5 inputs without supervision — the CLI tries the current profile, and on skip retries with the legacy profile before reporting the final outcome. Two opt-out paths exist for the rare case where you need to pin a profile:
no_legacy=True parameter — disable the automatic fallback (current only)remove_watermark_legacy / remove_watermark_batch_legacy — pin legacy onlyAlways start with `remove_watermark` / `remove_watermark_batch`. The auto-fallback handles the common case. The dedicated *_legacy tools are mostly there for callers that have side knowledge an image is pre-3.5 and want to skip the V2 attempt entirely.
A skipped=True result from the default tool means both profiles tried their best and neither matched. The two indistinguishable causes are:
by heavy editing/resizing/re-encoding.
Do NOT silently re-invoke `remove_watermark_legacy` — the automatic fallback has already attempted that. Instead, surface the result to the user and ask whether to escalate:
"I couldn't detect a Gemini watermark on this image (confidence X% on the current profile, Y% on legacy). Either it isn't a Gemini output, or the watermark has been damaged by post-processing. I can try forcing removal at a custom region if you can point me at one — otherwise there's nothing to do."
Escalation paths the agent can offer:
--fallback-region br:64,64,500,500 --snap — multi-scale search in auser-supplied area (good for resized / cropped images)
--threshold (e.g. 0.15) — relaxes the safety gate; risky onnon-Gemini files but legitimate when the user is certain
| Flags | Internal behavior |
|---|---|
| No advanced flags | Standard 3-stage NCC detection → process or skip |
--fallback-region only | Standard detection first → if not found, apply to fallback region |
--fallback-region --snap | Skip standard detection entirely → snap search directly |
--force | Skip detection, process unconditionally |
--legacy | Pin V1 profile (pre-Gemini-3.5 outputs); skip the V2 attempt entirely |
--no-legacy | Disable the auto V2 → V1 fallback (current profile only) |
_no --legacy and no --no-legacy_ | V2 first; auto-retry on V1 if V2 skips (v0.3.1+ default) |
GeminiWatermarkTool --no-banner -i input.jpg -o clean.jpgDetection on by default (threshold 25%). Non-watermarked images are skipped safely.
--fallback-region --snap together skips standard detection and goes straight to multi-scale snap search:
GeminiWatermarkTool --no-banner \
-i input.jpg -o clean.jpg \
--fallback-region br:64,64,500,500 \
--snap --snap-max-size 320 --snap-threshold 0.60 \
--denoise ai --sigma 50 --strength 120Use --fallback-region without --snap. Standard detection runs first; fallback region only activates if standard detection fails:
GeminiWatermarkTool --no-banner \
-i input.jpg -o clean.jpg \
--fallback-region br:64,64,500,500 \
--denoise ai --sigma 50 --strength 120| Flag | Default | Description |
|---|---|---|
-i, --input <path> | — | Input file or directory |
-o, --output <path> | — | Output file or directory |
-f, --force | false | Skip detection, process unconditionally |
-t, --threshold <0.0-1.0> | 0.25 | Detection confidence threshold |
--force-small | — | Force small watermark size |
--force-large | — | Force large watermark size |
--legacy | — | Pin pre-Gemini-3.5 profile (V1); skips V2 attempt. |
--no-legacy | — | Disable the automatic V2 → V1 fallback. |
-v, --verbose | false | Detailed output |
-q, --quiet | false | Suppress output except errors |
--no-banner | — | Hide ASCII banner (always use in this skill) |
| Flag | Description |
|---|---|
--region <spec> | Explicit watermark region |
--fallback-region <spec> | Search region when standard detection fails |
Region spec formats:
| Format | Meaning |
|---|---|
x,y,w,h | Absolute pixel coordinates |
br:mx,my,w,h | Bottom-right: margin_right, margin_bottom, width, height |
bl:mx,my,w,h | Bottom-left relative |
tr:mx,my,w,h | Top-right relative |
tl:mx,my,w,h | Top-left / absolute |
br:auto | Gemini default position for this image size |
| Flag | Default | Description |
|---|---|---|
--snap | false | Multi-scale snap within region/fallback-region |
--snap-max-size <32-320> | 160 | Maximum watermark size to search |
--snap-threshold <0.0-1.0> | 0.60 | Minimum confidence to accept match |
| Flag | Default | Description | ||||
|---|---|---|---|---|---|---|
--denoise <method> | off | ai \ | ns \ | telea \ | soft \ | off |
--sigma <1-150> | 50 | FDnCNN noise sigma (ai only) | ||||
--strength <0-300> | 120 (ai) / 85 (others) | Blend strength in percent | ||||
--radius <1-25> | 10 | Inpaint radius (ns / telea / soft only) |
| Profile | Small logo | Large logo | Threshold |
|---|---|---|---|
| V2 (default — Gemini 3.5+) | 36×36 | 96×96 | long side > 1024 → large |
V1 (--legacy, pre-3.5) | 48×48 | 96×96 | long side > 1024 → large |
Override with --force-small or --force-large. Profile is selected by --legacy (off = V2, on = V1).
| Situation | Action |
|---|---|
| Faint residual | --denoise ai --sigma 50 --strength 120 |
| Visible edge artifacts | --sigma 75 --strength 180 |
| Strong residual (heavily resized) | --sigma 100 --strength 250 |
| Detection keeps skipping | Lower --threshold 0.15 or add --fallback-region |
| Snap finds nothing | Widen region, increase --snap-max-size 320 |
| Snap confidence too low | Lower --snap-threshold 0.40 |
| Wrong size detected | --force-small or --force-large |
| Code | Meaning |
|---|---|
| 0 | File processed (or batch directory completed without errors) |
| 1 | Single-file invocation skipped — no watermark detected on any profile that the chosen flag combination tried |
| 2 | Real failure — bad arguments, missing input, IO/write error |
Batch directory mode keeps lenient semantics (exit 0 unless something actually fails) since partial skips are expected when scanning a folder.
automatically. If AI init fails entirely, GWT falls back to NS inpainting.
inseparable from image content.
-i dir/ -o dir/ processes all images; non-watermarked filesare skipped safely by default.
profile, then automatically retries with the legacy profile on skip. Pin a single profile with --legacy (V1 only) or --no-legacy (V2 only) if the auto-fallback isn't what you want.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.