{
  "schema": "declawd.github-repository-review/v1",
  "observed_at": "2026-08-27T19:23:27Z",
  "capture": {
    "path": "declawd/reports/github-repository-scan-2026-08-27.json",
    "sha256": "f371825900d0de2d97d4ea8680371718aa4853346c194e86474442bf50d45607",
    "query_counts": [
      15,
      2,
      426
    ],
    "union_count": 434,
    "readmes_captured": 419,
    "readmes_reviewed": 419,
    "capture_gaps": 15
  },
  "selection": "The three searches cover repositories created from 15 to 27 August 2026. The lower bound is the fixed discovery floor rather than the previous scan's upper edge, because a repository created before a moving start can acquire a matching name, description or README at any time afterwards and would then be too old for every later sweep. Re-running the whole horizon at 27 August returned 15, 2 and 426 against the 2, 1 and 156 a 22 to 27 August window returned, so the moving window had been missing repositories rather than deferring them. Every captured README was re-fetched at its recorded default-branch head and its SHA-256 compared with the capture before it was read. Each was then searched for a claim to detect Claude's mark across the combined text of repository name, description and README. Repositories whose combined text named Anthropic or Claude alongside a detection or key term were read in full; identical README texts were read once and the duplicates recorded against that reading. Source was opened wherever a reading could not settle whether a detector was real.",
  "conclusion": "No reviewed repository included a detector compatible with Anthropic's production text watermark. The Claude and Anthropic matches were removal tools, Unicode or metadata cleaners, forks of one upstream cleaner, explainers, or detection under a key the operator holds. Several repositories state the boundary themselves: one records its Claude row as UNKNOWN with the verifier unavailable, one carries a dedicated Claude limitation section saying Anthropic has published no deployed configuration, key, calibrated threshold or detector contract, and one is a longitudinal collection of Claude output whose operator records that watermark ground truth is not yet available because they are waiting on an Anthropic verifier API. The widened horizon changed the size of the reviewed set and not the boundary.",
  "notable": [
    {
      "repository": "cpeoples/ai-watermark-detector",
      "revision": "098d585f09a5079dee66e4bf68e7e34de7bb3d7e",
      "classification": "reported_result",
      "finding": "Reproduces six published schemes bit for bit against their official implementations: kgw, synthid, exp, unigram, sweet and exp-edit. Every text verdict is scored against a key the operator supplies, and its own table reads \"Needs a key? Yes (the vendor's, or your own)\". Its kgw scheme is annotated as matching Anthropic's published description of Claude, which is a statement about the scheme family rather than possession of Anthropic's key, and its \"100% path\" is explicitly conditional on a vendor publishing a production key. The closest case in this sweep, and still on the public-reference side of the boundary."
    },
    {
      "repository": "natzir/synthid-text-watermark-attacks",
      "revision": "57ae0159c23b14ea12abfefc3ba69cf2a172d815",
      "classification": "reported_result",
      "finding": "Attacks the public SynthID-Text reference under the author's own key, with a quantized Qwen 7B standing in for Claude. The detector is the Nature paper's mean-score z-test. It states twice, unprompted, that it is not evidence about Claude."
    },
    {
      "repository": "aloshdenny/claude-awm",
      "revision": "90f39752ff06c16460cfb58f8e37827dc397c419",
      "classification": "reported_result",
      "finding": "A robustness study of the public SynthID-Text scheme on open-weight models the author generates himself, watermarking under his own key and then attacking it. Reports an insertion-rate scaling law and finds low-entropy code output close to unwatermarkable. The repository name says Claude; the work does not touch Claude output or any Anthropic key. It carries no declared licence, so nothing in it can be reused."
    },
    {
      "repository": "AnirudhDabas/scrubts",
      "revision": "5af4edea4b2d1ed82807b19d3868c3b619e126f2",
      "classification": "reported_result",
      "finding": "An inspection tool that observes Unicode and C2PA evidence and then refuses to promote it into a Claude conclusion, holding the Claude row at UNKNOWN with the verifier recorded as unavailable. Independently reaches the boundary this review reports."
    },
    {
      "repository": "cyzanfar/text-watermark-remover",
      "revision": "fd620a93b9d96c7a4730d80be2d7aa90d5017575",
      "classification": "reported_result",
      "finding": "Carries a dedicated Claude limitation section stating that Anthropic has not published the deployed configuration, keys, calibrated thresholds or detector contract, so the tool returns unsupported for Claude and does not claim that Unicode cleaning removes a Claude mark."
    },
    {
      "repository": "fedec65/I-Tipp-Ex",
      "revision": "f8d1fbf7508ee50bb1e8447eafe1beeb953bc108",
      "classification": "reported_result",
      "finding": "Delegates all statistical detection: a Gemini backend calls Google's SynthID-Text detector with the operator's own key, and a MarkLLM backend shells out to an external checkout. It maps the boundary precisely, in that an operator-key route exists for Google and no Anthropic equivalent is wired up or referenced."
    },
    {
      "repository": "GeoGizmodo/ProvenanceLab-Manifests",
      "revision": "7f10ac323cb13b176f0c6c64dced975f5f73451a",
      "classification": "reported_result",
      "finding": "A timestamping ledger of SHA-256 manifest roots over a private longitudinal collection of Claude and Gemini output gathered to study the rollout. It contains no model outputs and no detection results. Its operator records that watermark ground truth is not yet available because an Anthropic verifier API is still awaited."
    },
    {
      "repository": "tsushanth/claude-statistical-watermark-audit",
      "revision": "f67e23cceb40d3c4b9ba08eb767f6bc823feefa3",
      "classification": "reported_result",
      "finding": "Asks whether Claude output carries an unkeyed statistical signature, using surface metrics validated against a self-injected synthetic green-list bias as a positive control. The result is negative: the metrics move opposite to green-list theory. No key, no detector, no decision rule."
    }
  ],
  "watched_repositories": [
    {
      "repository": "guillaumemeyer/watermarks-remover",
      "revision": null,
      "status": "Still the upstream that the largest class of matches copies. Its text-detector table carries `claude-text` as a placeholder, described as a seam that activates when a detection API exists. Forks inherit that placeholder together with the vendor vocabulary, which is why the Claude name recurs across repositories that only strip Unicode."
    }
  ],
  "limitations": [
    "A README and a default-branch head record what a repository said, not what an unexecuted binary does.",
    "Repository descriptions can change without a commit, so the description half of each reading is reproducible only as of the observation time. The README half is fixed by the recorded head.",
    "Repository topics are read by GitHub's search but are not stored in the capture, so no claim here rests on them.",
    "Fifteen repositories have no README in the capture: three were empty at observation and twelve carry no README file. They were judged on name and description alone.",
    "Absence of a compatible detector in this set is an observation over three bounded queries at one time, not a proof that none exists anywhere."
  ]
}
