Skip to content
Back to skills

Xurl

ASecurity

Paid X API fallback through xurl after cheaper X reads fail, or for authorized account actions unsupported by bird.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 2, 2026
ai-agentsbashnodeapi

Works with

  • cli
  • api

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add transitive-bullshit/skills --skill xurl --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Xurl?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Xurl
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/transitive-bullshit-xurl/badge)](https://www.skillsdirectory.com/skills/transitive-bullshit-xurl)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: xurl
description: "Paid X API fallback through xurl after cheaper X reads fail, or for authorized account actions unsupported by bird."
metadata:
  {
    "openclaw":
      {
        "emoji": "🐦",
        "requires": { "bins": ["xurl"] },
        "install":
          [
            {
              "id": "brew",
              "kind": "brew",
              "formula": "xdevplatform/tap/xurl",
              "bins": ["xurl"],
              "label": "Install xurl (brew)",
            },
            {
              "id": "npm",
              "kind": "node",
              "package": "@xdevplatform/xurl",
              "bins": ["xurl"],
              "label": "Install xurl (npm)",
            },
          ],
      },
  }
---

# xurl

Use this as the paid X API reference. For reads/search, follow [x-data](../x-data/SKILL.md), which owns source precedence, freshness, and the paid-fallback conditions.

For authorized posts/replies, prefer a supported `bird` command. Use `xurl` for an unavailable or failed operation, including account actions that the installed `bird` does not implement. Shortcut commands return JSON; raw mode works for any v2 endpoint.

## Secret safety

- Never read, print, summarize, upload, or inspect `~/.xurl`.
- Never ask user to paste tokens/secrets into chat.
- Do not run auth commands with inline secrets.
- Do not use `--verbose` in agent sessions; it can expose auth headers.
- Check auth with `xurl auth status`.

## Common shortcuts

```bash
xurl post "Hello world!"
xurl reply POST_ID "Nice."
xurl quote POST_ID "My take"
xurl delete POST_ID
xurl read POST_ID
xurl search "query" -n 20
xurl whoami
xurl user @handle
xurl timeline -n 20
xurl mentions -n 10
xurl like POST_ID
xurl unlike POST_ID
xurl repost POST_ID
xurl unrepost POST_ID
xurl bookmark POST_ID
xurl unbookmark POST_ID
xurl followers -n 20
xurl following -n 20
xurl follow @handle
xurl unfollow @handle
xurl block @handle
xurl unblock @handle
xurl mute @handle
xurl unmute @handle
xurl dm @handle "message"
xurl dms -n 10
```

`POST_ID` can be a full `https://x.com/<user>/status/<id>` URL.

## Media

```bash
xurl media upload image.jpg
xurl media upload clip.mp4
xurl media status MEDIA_ID
xurl post "caption" --media-id MEDIA_ID
```

Videos may need processing; poll `media status`.

## Auth/app management

```bash
xurl auth status
xurl auth apps list
xurl auth default
xurl auth default APP_NAME USERNAME
xurl auth apps remove APP_NAME
```

Per request:

```bash
xurl --app APP_NAME /2/users/me
xurl --auth oauth2 /2/users/me
```

## Raw API

```bash
xurl /2/users/me
xurl -X POST /2/tweets -d '{"text":"Hello world!"}'
xurl '/2/tweets/search/recent?query=openclaw&max_results=10'
```

Use raw mode when shortcuts do not cover the endpoint. Keep payloads in temp files for complex JSON.

## Output and errors

- JSON stdout on success.
- Non-zero exit on API/auth/network errors.
- 401/403: auth, scope, or app mismatch; check `xurl auth status`.
- 429: rate limited; back off.
- Media upload failures: check file type/size and media processing status.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…