Credentials before pixels.
Antimony is a Linux browser built on Chromium with an engine-layer content-provenance gate: C2PA content credentials are inspected inside the browser, in C++, and a throttle acts on the result before images render. No extension. No proxy.
What the gate does
Four modes, all user-overridable, set in chrome://settings/provenance. The omnibox chip shows gate state per page; blocked navigations get an interstitial, not a silent failure.
off
The gate is disabled. Nothing is inspected, nothing is blocked.
block_on_detect default
Render unless a signal fires. If the verifier is down, pages load and the badge reports it: fail-open by design.
soft_block_images
Gate-flagged images are replaced in-page with same-dimension notices. A per-page Allow button relays an exemption up to the browser.
provenance_required
Fail-closed. Media must carry a valid, trusted C2PA manifest with no AI-generation action. Verifier down means blocked. This mode blocks most of today's web on purpose.
Also on board: session / page / persistent per-origin exemptions, and an optional toggle that removes the browser's on-device AI models (Writer, Rewriter, Summarizer) from the scripting context, with its own exemption list.
Install the prerelease
Official builds (is_official_build=true, thin LTO + CFI, stripped binaries) from the pinned Chromium 153.0.8010.36 series. The deb installs to /opt/antimony as the package antimony.
| Package | Arch | Size | SHA256 |
|---|---|---|---|
| antimony-stable_153.0.8010.36-1_amd64.deb | x86_64 | 120.7 MB | 3ffedd4165db5fa6a29e318bdfa4d1eaeebb36d7b91afabcb6a84429db1bbea0 |
| antimony-stable_153.0.8010.36-1_arm64.deb | arm64 | 107.7 MB | 1046f0f5c809e1e3785d77f2013f2cc4ce64b3225335ee1abce94be02631e763 |
| antimony-stable-153.0.8010.36-1.x86_64.rpm | x86_64 | 122.1 MB | cdfc72060e48c0b4cc7902edc53707d63f1ae32a368633753b33b2552f87e518 |
| antimony-stable-153.0.8010.36-1.aarch64.rpm | arm64 | 109.1 MB | 5472c7a92a9d66bef89daf2fcdc7b506215b938902d1bf278a155cea00ba2c47 |
sha256sum antimony-stable_153.0.8010.36-1_amd64.deband compare against the table above (also in the release notes).
What it can and cannot promise
- Shipped detector: C2PA AI-action declarations. Images carrying unverified AI-generation claims can be gated in every mode.
- Planned, not shipped: Google SynthID, OpenAI provenance signals, Adobe TrustMark, the Anthropic Claude text watermark (private-preview API), calibrated text classifiers, and a Binoculars backend (off until its false-positive rate is measured).
- Cannot: certify that content is human-made. Every vendor states in writing that absence of a mark is not evidence of human authorship. Unwatermarked models, paraphrased text, and pre-2026-08-02 output are invisible to watermark detectors. The interstitial says so.
- Never claimed: "human-verified". Classifier-only blocks use bounded floors (800+ characters, 0.98 confidence) and stay user-overridable.
- Chromium base is pinned at 153.0.8010.36. The rebase cadence is tracked in PINNED.md; we make no claim of being security-current with upstream. Packages are not GPG-signed yet; verify with the SHA256 table.
For reviewers
The whole delta against Chromium lives in a 22-patch series, each patch described in patches/SERIES.md: the C2PA parser in the data-decoder service (0007), the throttle and interstitial (0010-0012), the modes and settings page (0013-0016), the on-device model toggle (0017), the Antimony branding (0018), deb identity (0019), and the cross-build toolchain work (0020-0022). A test page in demo/ carries a synthetic C2PA-tagged image and a human-generated control. False-positive reports and true negatives are equally welcome as issues.