Safety-reviewed Agent Skill for using TweetClaw, the OpenClaw plugin for X and Twitter search, posting, follower export, media workflows, monitors, webhooks, and giveaway draws through Xquik.
TweetClaw can perform public X account actions after OpenClaw tool opt-in and approval; review exact posts, replies, DMs, follows, media, monitors, webhooks, and draws before allowing a call., Keep `tweetclaw` as an optional OpenClaw tool and start with read-only `explore` until the user confirms the workflow., Do not use TweetClaw for spam, deceptive engagement, harassment, credential collection, impersonation, or bulk unsolicited outreach.
Privacy notes
Xquik API keys and MPP signing keys must stay in OpenClaw plugin config or environment variables, never in prompts, shared logs, PRs, or committed files., Tweet searches, timelines, DMs, bookmarks, follower exports, media metadata, monitors, webhook details, and account usage can expose private or account-scoped data., Use the Xquik dashboard and public docs for current billing, account, and data-handling details.
4 prerequisites to line up before setup. Have accounts and credentials ready first.
0/4 ready
Account & credentials2Network & hosting1General1
Safety & privacy surface
Safety & privacy surface
3 safety and 3 privacy notes across 4 risk areas. Review closely: credentials & tokens, permissions & scopes, network access.
4 areas
SafetyNetwork accessTweetClaw can perform public X account actions after OpenClaw tool opt-in and approval; review exact posts, replies, DMs, follows, media, monitors, webhooks, and draws before allowing a call.
SafetyGeneralKeep `tweetclaw` as an optional OpenClaw tool and start with read-only `explore` until the user confirms the workflow.
SafetyCredentials & tokensDo not use TweetClaw for spam, deceptive engagement, harassment, credential collection, impersonation, or bulk unsolicited outreach.
PrivacyCredentials & tokensXquik API keys and MPP signing keys must stay in OpenClaw plugin config or environment variables, never in prompts, shared logs, PRs, or committed files.
PrivacyPermissions & scopesTweet searches, timelines, DMs, bookmarks, follower exports, media metadata, monitors, webhook details, and account usage can expose private or account-scoped data.
PrivacyGeneralUse the Xquik dashboard and public docs for current billing, account, and data-handling details.
Safety notes
TweetClaw can perform public X account actions after OpenClaw tool opt-in and approval; review exact posts, replies, DMs, follows, media, monitors, webhooks, and draws before allowing a call.
Keep `tweetclaw` as an optional OpenClaw tool and start with read-only `explore` until the user confirms the workflow.
Do not use TweetClaw for spam, deceptive engagement, harassment, credential collection, impersonation, or bulk unsolicited outreach.
Privacy notes
Xquik API keys and MPP signing keys must stay in OpenClaw plugin config or environment variables, never in prompts, shared logs, PRs, or committed files.
Tweet searches, timelines, DMs, bookmarks, follower exports, media metadata, monitors, webhook details, and account usage can expose private or account-scoped data.
Use the Xquik dashboard and public docs for current billing, account, and data-handling details.
Prerequisites
OpenClaw 2026.6.1 or newer for the current plugin metadata
Xquik account and API key before using account-backed reads, writes, monitors, webhooks, media, or extraction workflows
Agent client with Agent Skills support for `npx skills add`
Explicit user approval before any visible, private, paid, recurring, or account-changing action
.gemini/skills/<skill-name>/SKILL.md or .agents/skills/<skill-name>/SKILL.md
cursor
Adapter
.cursor/rules/<skill-name>.mdc
cli
Manual
AGENTS.md or tool-specific context file
Full copyable content
# Trigger
"Use the TweetClaw skill to set up a safe X/Twitter automation workflow."
# Skill install
npx skills add xquik-dev/tweetclaw
# OpenClaw plugin install
openclaw plugins install npm:@xquik/tweetclaw
About this resource
Overview
TweetClaw is the Agent Skill bundled with the @xquik/tweetclaw OpenClaw plugin. It gives agents a safety-first operating guide for X/Twitter workflows through Xquik: tweet search, reply search, user lookup, follower export, media upload and download, direct messages, monitors, webhooks, giveaway draws, and approval-gated posting.
Use the skill when an agent needs to install TweetClaw, decide which credential mode to use, verify OpenClaw runtime registration, or prepare a workflow that may touch public accounts, private account data, recurring monitors, or paid API calls.
Install
Install the reusable Agent Skill:
npx skills add xquik-dev/tweetclaw
Install the OpenClaw plugin runtime from npm:
openclaw plugins install npm:@xquik/tweetclaw
Verify the runtime before live work:
openclaw plugins inspect tweetclaw --runtime --json
openclaw skills info tweetclaw
The runtime should show the read-only explore catalog tool, optional tweetclaw API tool, approval hook, and bundled status/trends command.
Workflow Scope
Use explore first to inspect available Xquik endpoints without credentials.
Configure an Xquik API key for account-backed reads, writes, media, monitors, webhooks, and extraction workflows.
Configure MPP signing only for read-only pay-per-use workflows.
Add explore and tweetclaw to OpenClaw tool allow settings only when the user wants agent-driven X/Twitter workflows.
Review exact payloads before posts, replies, DMs, follows, profile changes, media uploads, webhooks, monitors, draws, or extraction jobs.
Safety Checklist
Confirm the user owns or is authorized to access the X account.
Keep API keys and signing keys out of chat, logs, screenshots, issues, and commits.
Start with read-only lookup before allowing writes or recurring workflows.
Show final text and media before publishing.
Re-confirm when scope, target account, limits, or recurring behavior changes.
Show that TweetClaw OpenClaw X Automation Skill is listed on HeyClaude. Paste this Markdown into your README — it renders the badge and links back to this page.
[](https://heyclau.de/entry/skills/tweetclaw-openclaw-x-automation)
How it compares
TweetClaw OpenClaw X Automation Skill side by side with 3 alternatives on trust, install, platform support, and disclosed safety notes — all from reviewed registry metadata.
2 trust signals differ across this comparison (Source provenance, Submitter).
Safety-reviewed Agent Skill for using TweetClaw, the OpenClaw plugin for X and Twitter search, posting, follower export, media workflows, monitors, webhooks, and giveaway draws through Xquik.
Safety-reviewed Agent Skill for Hermes Tweet, the Hermes Agent plugin for X/Twitter endpoint discovery, credentialed reads, and approval-gated actions through Xquik.
✓TweetClaw can perform public X account actions after OpenClaw tool opt-in and approval; review exact posts, replies, DMs, follows, media, monitors, webhooks, and draws before allowing a call.
Keep `tweetclaw` as an optional OpenClaw tool and start with read-only `explore` until the user confirms the workflow.
Do not use TweetClaw for spam, deceptive engagement, harassment, credential collection, impersonation, or bulk unsolicited outreach.
✓Start with `tweet_explore` for credential-free planning before using credentialed tools.
Treat `tweet_action` as approval-gated and review exact endpoint, method, and payload before any public or account-changing action.
Do not use Hermes Tweet for spam, deceptive engagement, harassment, impersonation, credential collection, or bulk unsolicited outreach.
✓Installing reg-suit adds npm packages to the selected project environment; pin the reviewed package version and avoid global installs for review work.
reg-suit can publish image snapshots and HTML reports through storage plugins such as S3 or Google Cloud Storage; review destination configuration before running in shared CI.
Visual baselines can normalize accidental UI changes if accepted too casually; require owner approval for broad layout, color, text, or viewport changes.
The source ZIP is external and version-pinned for reference; package trust should remain a maintainer decision.
✓Installing Renovate adds an npm package to the selected project environment; pin the reviewed version and avoid global installs for review work.
Renovate can update dependency manifests and lockfiles; review generated diffs before approving automerge or grouped updates.
Major upgrades, runtime dependencies, toolchain changes, and lockfile churn should be treated as release-blocking until tests and smoke checks pass.
The source ZIP is external and version-pinned for reference; package trust should remain a maintainer decision.
Privacy notes
✓Xquik API keys and MPP signing keys must stay in OpenClaw plugin config or environment variables, never in prompts, shared logs, PRs, or committed files.
Tweet searches, timelines, DMs, bookmarks, follower exports, media metadata, monitors, webhook details, and account usage can expose private or account-scoped data.
Use the Xquik dashboard and public docs for current billing, account, and data-handling details.
✓Xquik API keys must stay in plugin config or environment variables, never in prompts, shared logs, issues, PRs, screenshots, or committed files.
Credentialed reads can expose account-scoped timelines, searches, user data, or workflow context.
Return concise summaries and source URLs without exposing raw private runtime logs or credentials.
✓Rendered UI images and reports can expose environment URLs, branch names, visible UI text, test account data, and product screenshots.
Storage and notification plugins can publish report links to CI systems, pull request comments, chat tools, or cloud buckets.
Keep public review notes focused on changed components, thresholds, artifact links, and summarized findings; omit sensitive rendered content that does not need to be public.
✓Dependency metadata can reveal package names, repository layout, branch names, internal registry hosts, and release cadence.
Keep public review notes focused on package names, versions, config keys, and test results; omit operational details that do not need to be public.
Prerequisites
OpenClaw 2026.6.1 or newer for the current plugin metadata
Xquik account and API key before using account-backed reads, writes, monitors, webhooks, media, or extraction workflows
Agent client with Agent Skills support for `npx skills add`
Explicit user approval before any visible, private, paid, recurring, or account-changing action
Hermes Agent with plugin support
Xquik API key before using account-backed reads
Agent client with Agent Skills support for `npx skills add`
`HERMES_TWEET_ENABLE_ACTIONS=true` plus explicit user approval before posts, follows, likes, reposts, deletes, or other account-changing actions
UI change, pull request, or release candidate with rendered image artifacts
reg-suit configuration such as `regconfig.json`
Baseline image source, actual image directory, and generated report location
Threshold policy for accepted pixel or rate differences
Renovate dependency upgrade PR, config diff, or dependency dashboard item
Dependency manifest and lockfile diff for the reviewed package manager
Renovate config source such as `renovate.json`, package config, or inherited presets
Release notes, changelog, package metadata, or source tag for the updated dependency