Skip to main content
skillsSource-backed

TweetClaw OpenClaw X Automation Skill

Safety-reviewed Agent Skill for using TweetClaw, the OpenClaw plugin for X and Twitter search, posting, follower export, media workflows, monitors, webhooks, and giveaway draws through Xquik.

by Xquik-dev · submitted by kriptoburak·added 2026-06-09·
Level:advancedType:generalVerified:validated
Review first review before installing

Open the source and read safety notes before installing.

Citation facts

Source-backed facts for citing this resource, derived directly from the registry — also available as plain text for AI assistants.

Source URLs
https://github.com/Xquik-dev/tweetclaw#readme, https://github.com/Xquik-dev/tweetclaw
Safety notes
TweetClaw can perform public X account actions after OpenClaw tool opt-in and approval; review exact posts, replies, DMs, follows, media, monitors, webhooks, and draws before allowing a call., Keep `tweetclaw` as an optional OpenClaw tool and start with read-only `explore` until the user confirms the workflow., Do not use TweetClaw for spam, deceptive engagement, harassment, credential collection, impersonation, or bulk unsolicited outreach.
Privacy notes
Xquik API keys and MPP signing keys must stay in OpenClaw plugin config or environment variables, never in prompts, shared logs, PRs, or committed files., Tweet searches, timelines, DMs, bookmarks, follower exports, media metadata, monitors, webhook details, and account usage can expose private or account-scoped data., Use the Xquik dashboard and public docs for current billing, account, and data-handling details.
Platform compatibility
claude-code (native-skill), codex (native-skill), windsurf (native-skill), gemini (native-skill), cursor (adapter), cli (manual-context)
Author
Xquik-dev
Submitted by
kriptoburak
Claim status
unclaimed
Last verified
2026-06-09

Decision playbook

Review trust signals before you adopt

Signals are present but mixed. Use the checklist below to confirm the source and operational safety for your environment.

Compare context
Selected

0

Current score

71

Baseline

Delta

No baseline selected

No major trust-signal divergence detected in the current selection.

Source and provenance checks

Needs review

Confirm ownership and provenance before trusting install instructions.

  • Source link availableRequired

    Open the canonical repository and verify ownership.

    Done
  • Source provenance statusRequired

    Marked as source-backed.

    Done
  • Metadata reviewed

    No reviewed flag detected in metadata.

    Pending

Safety and privacy checks

Complete

Validate risk disclosures before installation or API wiring.

  • Safety notes presentRequired

    Review the listed safety guidance before running commands.

    Done
  • Privacy notes presentRequired

    Review data handling notes before connecting accounts or secrets.

    Done
  • Trust level risk gateRequired

    Trust level does not block evaluation.

    Done

Package and install checks

Needs review

Check package metadata and artifact integrity signals.

  • Install payload available

    Install or copy payload is available for review.

    Done
  • Package verification flag

    No package verification flag provided.

    Pending
  • Checksum metadata

    No checksum provided for downloaded artifact.

    Pending

Compare-driven decision checks

Needs review

Use compare context to validate trade-offs before adoption.

  • Compare tray has multiple entries

    Add at least one more entry to compare trust differences.

    Pending
  • Baseline comparison available

    No baseline peer selected yet.

    Pending
  • Diverging trust signals identified

    No major trust-signal divergence found.

    Pending

Setup at a glance

Package install

Copy-ready — paste the snippet to get started.

Adoption plan

Balanced adoption plan

Current risk score 24/100. Use staged verification before broader rollout.

Risk 24

Pre-adoption checks

Validate source and review signals before any execution.

  • Confirm source provenanceRequired

    Source URL/provenance metadata is present.

    Done
  • Confirm metadata review state

    No review metadata found; increase manual validation.

    Pending
  • Verify install payload

    Install/config payload exists and can be inspected.

    Done

Security checks

Confirm safety, privacy, and package integrity signals.

  • Review safety notesRequired

    Safety notes are present.

    Done
  • Review privacy notesRequired

    Privacy notes are present.

    Done
  • Verify package integrity metadata

    No package verification/checksum metadata.

    Pending

Rollout

Adopt in controlled steps based on the selected plan.

  • Run in isolated sandbox firstRequired

    Use a constrained sandbox and observe behavior across multiple tasks.

    Pending
  • Roll out graduallyRequired

    Roll out to a small cohort before wider usage.

    Pending
  • Set monitoring and fallback

    Define rollback path and monitor errors after adoption.

    Pending

Evidence readiness

Evidence readiness matrix · balanced

Missing required evidence: Metadata review. Risk score 31.

Risk 31

Source provenance

Present

Source repository/provenance is listed.

Required in this preset

Metadata review

Missing

Review metadata is missing.

Required in this preset

Safety notes

Present

Safety notes are present.

Required in this preset

Privacy notes

Present

Privacy notes are present.

Optional in this preset

Package integrity

Missing

Package integrity metadata is missing.

Optional in this preset

Install payload

Present

Install payload is available.

Required in this preset

Required gaps: Metadata review

Decision timeline

Decision timeline · balanced

Blocking gaps: Check metadata review status. Risk 28.

Risk 28

triage

Confirm source provenanceRequired

Source/provenance metadata is available.

Done

triage

Check metadata review statusRequired

Review metadata is missing.

Pending

verify

Review safety notesRequired

Safety notes are available.

Done

verify

Review privacy notes

Privacy notes are available.

Done

verify

Validate package integrity metadata

Package integrity metadata is missing.

Pending

rollout

Verify install payload and commandsRequired

Install payload is available.

Done

Blockers: Check metadata review status

Prerequisite readiness

Prerequisite readiness

4 prerequisites to line up before setup. Have accounts and credentials ready first.

0/4 ready
Account & credentials2Network & hosting1General1

Safety & privacy surface

Safety & privacy surface

3 safety and 3 privacy notes across 4 risk areas. Review closely: credentials & tokens, permissions & scopes, network access.

4 areas
  • SafetyNetwork accessTweetClaw can perform public X account actions after OpenClaw tool opt-in and approval; review exact posts, replies, DMs, follows, media, monitors, webhooks, and draws before allowing a call.
  • SafetyGeneralKeep `tweetclaw` as an optional OpenClaw tool and start with read-only `explore` until the user confirms the workflow.
  • SafetyCredentials & tokensDo not use TweetClaw for spam, deceptive engagement, harassment, credential collection, impersonation, or bulk unsolicited outreach.
  • PrivacyCredentials & tokensXquik API keys and MPP signing keys must stay in OpenClaw plugin config or environment variables, never in prompts, shared logs, PRs, or committed files.
  • PrivacyPermissions & scopesTweet searches, timelines, DMs, bookmarks, follower exports, media metadata, monitors, webhook details, and account usage can expose private or account-scoped data.
  • PrivacyGeneralUse the Xquik dashboard and public docs for current billing, account, and data-handling details.

Safety notes

  • TweetClaw can perform public X account actions after OpenClaw tool opt-in and approval; review exact posts, replies, DMs, follows, media, monitors, webhooks, and draws before allowing a call.
  • Keep `tweetclaw` as an optional OpenClaw tool and start with read-only `explore` until the user confirms the workflow.
  • Do not use TweetClaw for spam, deceptive engagement, harassment, credential collection, impersonation, or bulk unsolicited outreach.

Privacy notes

  • Xquik API keys and MPP signing keys must stay in OpenClaw plugin config or environment variables, never in prompts, shared logs, PRs, or committed files.
  • Tweet searches, timelines, DMs, bookmarks, follower exports, media metadata, monitors, webhook details, and account usage can expose private or account-scoped data.
  • Use the Xquik dashboard and public docs for current billing, account, and data-handling details.

Prerequisites

  • OpenClaw 2026.6.1 or newer for the current plugin metadata
  • Xquik account and API key before using account-backed reads, writes, monitors, webhooks, media, or extraction workflows
  • Agent client with Agent Skills support for `npx skills add`
  • Explicit user approval before any visible, private, paid, recurring, or account-changing action

Schema details

Install type
package
Reading time
5 min
Difficulty score
68
Troubleshooting
Yes
Breaking changes
No
Source repository stats
Scope
Source repo
Skill and platform metadata
Skill type
general
Skill level
advanced
Verification
validated
Verified at
2026-06-09
Retrieval sources
https://github.com/Xquik-dev/tweetclawhttps://raw.githubusercontent.com/Xquik-dev/tweetclaw/master/skills/tweetclaw/SKILL.mdhttps://registry.npmjs.org/%40xquik%2Ftweetclaw/latest
Tested platforms
OpenClawClaudeCodexCursor
PlatformSupportInstall path
claude-codeNative.claude/skills/<skill-name>/SKILL.md
codexNative.agents/skills/<skill-name>/SKILL.md
windsurfNative.windsurf/skills/<skill-name>/SKILL.md
geminiNative.gemini/skills/<skill-name>/SKILL.md or .agents/skills/<skill-name>/SKILL.md
cursorAdapter.cursor/rules/<skill-name>.mdc
cliManualAGENTS.md or tool-specific context file
Full copyable content
# Trigger
"Use the TweetClaw skill to set up a safe X/Twitter automation workflow."

# Skill install
npx skills add xquik-dev/tweetclaw

# OpenClaw plugin install
openclaw plugins install npm:@xquik/tweetclaw

About this resource

Overview

TweetClaw is the Agent Skill bundled with the @xquik/tweetclaw OpenClaw plugin. It gives agents a safety-first operating guide for X/Twitter workflows through Xquik: tweet search, reply search, user lookup, follower export, media upload and download, direct messages, monitors, webhooks, giveaway draws, and approval-gated posting.

Use the skill when an agent needs to install TweetClaw, decide which credential mode to use, verify OpenClaw runtime registration, or prepare a workflow that may touch public accounts, private account data, recurring monitors, or paid API calls.

Install

Install the reusable Agent Skill:

npx skills add xquik-dev/tweetclaw

Install the OpenClaw plugin runtime from npm:

openclaw plugins install npm:@xquik/tweetclaw

Verify the runtime before live work:

openclaw plugins inspect tweetclaw --runtime --json
openclaw skills info tweetclaw

The runtime should show the read-only explore catalog tool, optional tweetclaw API tool, approval hook, and bundled status/trends command.

Workflow Scope

  • Use explore first to inspect available Xquik endpoints without credentials.
  • Configure an Xquik API key for account-backed reads, writes, media, monitors, webhooks, and extraction workflows.
  • Configure MPP signing only for read-only pay-per-use workflows.
  • Add explore and tweetclaw to OpenClaw tool allow settings only when the user wants agent-driven X/Twitter workflows.
  • Review exact payloads before posts, replies, DMs, follows, profile changes, media uploads, webhooks, monitors, draws, or extraction jobs.

Safety Checklist

  1. Confirm the user owns or is authorized to access the X account.
  2. Keep API keys and signing keys out of chat, logs, screenshots, issues, and commits.
  3. Start with read-only lookup before allowing writes or recurring workflows.
  4. Show final text and media before publishing.
  5. Re-confirm when scope, target account, limits, or recurring behavior changes.

Retrieval Sources

Source citations

Add this badge to your README

Show that TweetClaw OpenClaw X Automation Skill is listed on HeyClaude. Paste this Markdown into your README — it renders the badge and links back to this page.

Listed on HeyClaude
[![Listed on HeyClaude](https://heyclau.de/badge/skills/tweetclaw-openclaw-x-automation.svg)](https://heyclau.de/entry/skills/tweetclaw-openclaw-x-automation)

How it compares

TweetClaw OpenClaw X Automation Skill side by side with 3 alternatives on trust, install, platform support, and disclosed safety notes — all from reviewed registry metadata.

2 trust signals differ across this comparison (Source provenance, Submitter).

Field

Safety-reviewed Agent Skill for using TweetClaw, the OpenClaw plugin for X and Twitter search, posting, follower export, media workflows, monitors, webhooks, and giveaway draws through Xquik.

Open dossier

Safety-reviewed Agent Skill for Hermes Tweet, the Hermes Agent plugin for X/Twitter endpoint discovery, credentialed reads, and approval-gated actions through Xquik.

Open dossier

Expert reg-suit review skill for evaluating rendered UI image baselines, thresholds, snapshot storage, report artifacts, and visual QA release readiness.

Open dossier

Expert Renovate review skill for evaluating dependency upgrade PRs, package rules, lockfile changes, grouping, automerge, and release readiness.

Open dossier
Next steps
Trust
Review statusNot reviewedNot reviewedNot reviewedNot reviewed
Package trustPackage not verifiedPackage not verifiedPackage not verifiedPackage not verified
Source provenanceDiffersSource-backedSource-backedSubmission linkedSource submissionSubmission linkedSource submission
SubmitterDifferskriptoburakkriptoburakoktofeesh1oktofeesh1
Install riskReview firstReview firstReview firstReview first
Notes Safety ✓ Privacy ✓ Safety ✓ Privacy ✓ Safety ✓ Privacy ✓ Safety ✓ Privacy ✓
Brand
Categoryskillsskillsskillsskills
SourceSource-backedSource-backedSource-backedSource-backed
AuthorXquik-devXquik-devoktofeesh1oktofeesh1
Added2026-06-092026-06-212026-06-032026-06-03
Platforms
Harness
Source repo
Safety notesTweetClaw can perform public X account actions after OpenClaw tool opt-in and approval; review exact posts, replies, DMs, follows, media, monitors, webhooks, and draws before allowing a call. Keep `tweetclaw` as an optional OpenClaw tool and start with read-only `explore` until the user confirms the workflow. Do not use TweetClaw for spam, deceptive engagement, harassment, credential collection, impersonation, or bulk unsolicited outreach.Start with `tweet_explore` for credential-free planning before using credentialed tools. Treat `tweet_action` as approval-gated and review exact endpoint, method, and payload before any public or account-changing action. Do not use Hermes Tweet for spam, deceptive engagement, harassment, impersonation, credential collection, or bulk unsolicited outreach.Installing reg-suit adds npm packages to the selected project environment; pin the reviewed package version and avoid global installs for review work. reg-suit can publish image snapshots and HTML reports through storage plugins such as S3 or Google Cloud Storage; review destination configuration before running in shared CI. Visual baselines can normalize accidental UI changes if accepted too casually; require owner approval for broad layout, color, text, or viewport changes. The source ZIP is external and version-pinned for reference; package trust should remain a maintainer decision.Installing Renovate adds an npm package to the selected project environment; pin the reviewed version and avoid global installs for review work. Renovate can update dependency manifests and lockfiles; review generated diffs before approving automerge or grouped updates. Major upgrades, runtime dependencies, toolchain changes, and lockfile churn should be treated as release-blocking until tests and smoke checks pass. The source ZIP is external and version-pinned for reference; package trust should remain a maintainer decision.
Privacy notesXquik API keys and MPP signing keys must stay in OpenClaw plugin config or environment variables, never in prompts, shared logs, PRs, or committed files. Tweet searches, timelines, DMs, bookmarks, follower exports, media metadata, monitors, webhook details, and account usage can expose private or account-scoped data. Use the Xquik dashboard and public docs for current billing, account, and data-handling details.Xquik API keys must stay in plugin config or environment variables, never in prompts, shared logs, issues, PRs, screenshots, or committed files. Credentialed reads can expose account-scoped timelines, searches, user data, or workflow context. Return concise summaries and source URLs without exposing raw private runtime logs or credentials.Rendered UI images and reports can expose environment URLs, branch names, visible UI text, test account data, and product screenshots. Storage and notification plugins can publish report links to CI systems, pull request comments, chat tools, or cloud buckets. Keep public review notes focused on changed components, thresholds, artifact links, and summarized findings; omit sensitive rendered content that does not need to be public.Dependency metadata can reveal package names, repository layout, branch names, internal registry hosts, and release cadence. Keep public review notes focused on package names, versions, config keys, and test results; omit operational details that do not need to be public.
Prerequisites
  • OpenClaw 2026.6.1 or newer for the current plugin metadata
  • Xquik account and API key before using account-backed reads, writes, monitors, webhooks, media, or extraction workflows
  • Agent client with Agent Skills support for `npx skills add`
  • Explicit user approval before any visible, private, paid, recurring, or account-changing action
  • Hermes Agent with plugin support
  • Xquik API key before using account-backed reads
  • Agent client with Agent Skills support for `npx skills add`
  • `HERMES_TWEET_ENABLE_ACTIONS=true` plus explicit user approval before posts, follows, likes, reposts, deletes, or other account-changing actions
  • UI change, pull request, or release candidate with rendered image artifacts
  • reg-suit configuration such as `regconfig.json`
  • Baseline image source, actual image directory, and generated report location
  • Threshold policy for accepted pixel or rate differences
  • Renovate dependency upgrade PR, config diff, or dependency dashboard item
  • Dependency manifest and lockfile diff for the reviewed package manager
  • Renovate config source such as `renovate.json`, package config, or inherited presets
  • Release notes, changelog, package metadata, or source tag for the updated dependency
Install
npx skills add xquik-dev/tweetclaw
npx skills add xquik-dev/hermes-tweet
npm install --save-dev reg-suit@0.14.5
npm install --save-dev renovate@43.210.1
Config
Citations
ClaimUnclaimedUnclaimedUnclaimedUnclaimed
Open 4 picks in the interactive comparison tool

Related guides

Signals

Loading live community signals…

More like this, weekly

A short, calm digest of reviewed Claude resources. Unsubscribe any time.