bug-reproduce
Turn a known bug into a tight, red-capable reproducer, then prove the reproducer locks that…
X/Twitter via xurl CLI: raw post search, posting, DM, media.
$ npx -y skills add Prismer-AI/PrismerCloud --skill prismer-xurl --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/prismer-xurlContext preview
The summary Claude sees to decide when to auto-load this skill.
X/Twitter via xurl CLI: raw post search, posting, DM, media.
name: prismer-xurl
scope: common
category: social-media
description: "X/Twitter via xurl CLI: raw post search, posting, DM, media."
version: 1.1.3
author: xdevplatform + openclaw + Hermes Agent
license: MIT
platforms: [ linux, macos ]
prerequisites:
commands: [ xurl ]
metadata:
nativeReplaces: [ xurl ]
hermes:
tags: [ twitter, x, social-media, xurl, official-api ]
homepage: https://github.com/xdevplatform/xurl
upstream_skill: https://github.com/openclaw/openclaw/blob/main/skills/xurl/SKILL.md
requiresExplicitGrant: true`xurl` is the X developer platform's official CLI for the X API. It supports shortcut commands for common actions AND raw curl-style access to any v2 endpoint. All commands return JSON to stdout.
Use this skill for:
This skill replaces the older `xitter` skill (which wrapped a third-party Python CLI). `xurl` is maintained by the X developer platform team, supports OAuth 2.0 PKCE with auto-refresh, and covers a substantially larger API surface.
---
Critical rules when operating inside an agent/LLM session:
Forbidden flags in agent commands (they accept inline secrets): `--bearer-token`, `--consumer-key`, `--consumer-secret`, `--access-token`, `--token-secret`, `--client-id`, `--client-secret`
App credential registration and credential rotation must be done by the user manually, outside the agent session. After credentials are registered, the user authenticates with `xurl auth oauth2` — also outside the agent session. Tokens persist to `~/.xurl` in YAML. Each app has isolated tokens. OAuth 2.0 tokens auto-refresh.
---
Pick ONE method. On Linux, the shell script or `go install` are the easiest.
# Shell script (installs to ~/.local/bin, no sudo, works on Linux + macOS)
# Prefer a reviewed, version-pinned package; never pipe a remote installer to a shell.
# Homebrew (macOS)
brew install --cask xdevplatform/tap/xurl
# npm
npm install -g @xdevplatform/xurl
# Go
go install "github.com/xdevplatform/xurl@${XURL_VERSION:?Set an exact reviewed release or commit}"Verify:
xurl --help xurl auth status
If `xurl` is installed but `auth status` shows no apps or tokens, the user needs to complete auth manually — see the next section.
---
These steps must be performed by the user directly, NOT by the agent, because they involve pasting secrets. Direct the user to this block; do not execute it for them.
1. Create or open an app at https://developer.x.com/en/portal/dashboard 2. Set the redirect URI to `http://localhost:8080/callback` 3. Copy the app's Client ID and Client Secret 4. Register the app locally (user runs this):
xurl auth apps add my-app --client-id YOUR_CLIENT_ID --client-secret YOUR_CLIENT_SECRET
5. Authenticate (specify `--app` to bind the token to your app):
xurl auth oauth2 --app my-app
(This opens a browser for the OAuth 2.0 PKCE flow.)
If X returns a `UsernameNotFound` error or 403 on the post-OAuth `/2/users/me` lookup, pass your handle explicitly (xurl v1.1.0+):
xurl auth oauth2 --app my-app YOUR_USERNAME
This binds the token to your handle and skips the broken `/2/users/me` call. 6. Set the app as default so all commands use it:
xurl auth default my-app
7. Verify:
xurl auth status xurl whoami
After this, the agent can use any command below without further setup. OAuth 2.0 tokens auto-refresh.
> **Common pitfall:** If you omit `--app my-app` from `xurl auth oauth2`, the OAuth token is saved to the built-in `default` app profile — which has no client-id or client-secret. Commands will fail with auth errors even though the OAuth flow appeared to succeed. If you hit this, re-run `xurl auth oauth2 --app my-app` and `xurl auth default my-app`.
> **Docker HOME pitfall:** In the official Hermes Docker layout, `/opt/data` is `HERMES_HOME`, but Hermes tool subprocesses use `${HOME}` as `HOME`. That means `~/.xurl` resolves to `${HOME}/.xurl` for Hermes-run `xurl` commands, not `/opt/data/.xurl`. Run the user setup with the same HOME: > ```bash > HOME=${HOME} xurl auth apps add my-app --client-id YOUR_CLIENT_ID --client-secret YOUR_CLIENT_SECRET > HOME=${HOME} xurl auth oauth2 --app my-app YOUR_USERNAME > HOME=${HOME} xurl auth default my-app YOUR_USERNAME > HOME=${HOME} xurl auth status > ``` > If `HOME=/opt/data xurl auth status` succeeds but `HOME=${HOME} xurl auth status` shows no apps or tokens, Hermes tool calls will not see the credentials.
---
| Action | Command | | --- | --- | | Post | `xurl post "Hello world!"` | | Reply | `xurl reply POST_ID "Nice post!"` | | Quote | `xurl quote POST_ID "My take"` | | Delete a post | `xurl delete POST_ID` | | Read a post | `xurl read POST_ID` | | Search posts | `xurl search "QUERY" -n 10` | | Who am I | `xurl whoami` | | Look up a user | `xurl user @handle` | | Home timeline | `xurl t
Repo: Prismer-AI/PrismerCloud
Turn a known bug into a tight, red-capable reproducer, then prove the reproducer locks that…
Review a diff against its acceptance criteria in four segments (convention adherence, bug…
Five-dimension design audit (frontend UI/UX · server data-model & flow · endpoint spec ·…
Before merge, mechanize Documentation-First — derive the code delta from git diff, then…
Diagnose the local dev machine before any APC loop step — run apc env doctor, classify each…
Close out a local coding task on the bound daemon — stage, commit, branch, merge, push via…