Protect MCP Setup
wshobson/agents
Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls.
Zero-knowledge onboarding for x-use that verifies the install, registers the MCP server, then interviews the user to configure their first X account (cookies, niche, keywords, persona).
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add ihuzaifashoukat/x-use --skill x-use-setup -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ihuzaifashoukat/x-use x-use-setup --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ihuzaifashoukat/x-use.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/x-use/skills/x-use-setup .claude/skills/x-use-setup && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "x-use-setup" agent skill from https://github.com/ihuzaifashoukat/x-use/tree/main/plugins/x-use/skills/x-use-setup into .claude/skills/x-use-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "x-use-setup", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ihuzaifashoukat/x-use/tree/main/plugins/x-use/skills/x-use-setupType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ihuzaifashoukat/x-use --skill x-use-setup -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ihuzaifashoukat/x-use x-use-setup --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ihuzaifashoukat/x-use.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/x-use/skills/x-use-setup .agents/skills/x-use-setup && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "x-use-setup" agent skill from https://github.com/ihuzaifashoukat/x-use/tree/main/plugins/x-use/skills/x-use-setup into .agents/skills/x-use-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "x-use-setup", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ihuzaifashoukat/x-use --skill x-use-setup -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ihuzaifashoukat/x-use x-use-setup --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ihuzaifashoukat/x-use.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/x-use/skills/x-use-setup .cursor/skills/x-use-setup && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "x-use-setup" agent skill from https://github.com/ihuzaifashoukat/x-use/tree/main/plugins/x-use/skills/x-use-setup into .cursor/skills/x-use-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "x-use-setup", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ihuzaifashoukat/x-use.git --path plugins/x-use/skills/x-use-setup--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ihuzaifashoukat/x-use --skill x-use-setup -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ihuzaifashoukat/x-use x-use-setup --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ihuzaifashoukat/x-use.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/x-use/skills/x-use-setup .gemini/skills/x-use-setup && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "x-use-setup" agent skill from https://github.com/ihuzaifashoukat/x-use/tree/main/plugins/x-use/skills/x-use-setup into .gemini/skills/x-use-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "x-use-setup", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ihuzaifashoukat/x-use x-use-setupInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ihuzaifashoukat/x-use --skill x-use-setup -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ihuzaifashoukat/x-use.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/x-use/skills/x-use-setup .github/skills/x-use-setup && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "x-use-setup" agent skill from https://github.com/ihuzaifashoukat/x-use/tree/main/plugins/x-use/skills/x-use-setup into .github/skills/x-use-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "x-use-setup", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ihuzaifashoukat/x-use --skill x-use-setup -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ihuzaifashoukat/x-use x-use-setup --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ihuzaifashoukat/x-use.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/x-use/skills/x-use-setup .opencode/skills/x-use-setup && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "x-use-setup" agent skill from https://github.com/ihuzaifashoukat/x-use/tree/main/plugins/x-use/skills/x-use-setup into .opencode/skills/x-use-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "x-use-setup", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
x-use-setupZero-knowledge onboarding for x-use that verifies the install, registers the MCP server, then interviews the user to configure their first X account (cookies, niche, keywords, persona).
X Use Setup is an agent skill from ihuzaifashoukat/x-use. Zero-knowledge onboarding for x-use that verifies the install, registers the MCP server, then interviews the user to configure their first X account (cookies, niche, keywords, persona). Use when x-use is not yet configured, when adding an account, or when the user asks to get started.
Its SKILL.md is about 730 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering MCP servers and Cryptography. It works with Model Context Protocol and X (Twitter). The repository describes itself as: Browser-native AI agents for X (Twitter): multi-account, MCP-ready, no X API key required. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e57e215. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipclaudeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
X Use Setup loads about 731 tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 354 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
- Run `x-use doctor`. It checks Chrome/driver, cookies, LLM key, proxies.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ihuzaifashoukat/x-use at commit e57e215, republished under its MIT licence (© ihuzaifashoukat). 354 words, ~731 tokens.
.claude/skills/x-use-setup/SKILL.md (or your agent's skills folder).Goal: a working account, configured conversationally. The user should never edit a config file by hand. Work through these steps in order, skipping any that are already done, and confirm each before moving on.
x-use doctor. It checks Chrome/driver, cookies, LLM key, proxies.x-use is not found: pip install x-use-mcp, then re-run doctor.claude_desktop_config.json):
{"mcpServers": {"x-use": {"command": "x-use", "args": ["mcp"]}}}claude mcp add x-use -- x-use mcp~/.codex/config.toml):
[mcp_servers.x-use] with command = "x-use", args = ["mcp"]Ask: "What should this account be called (a short id like main or
brand)?" Then explain cookie export:
Then call add_account(account_id, cookie_file=<path>). The file is
validated and copied server-side; cookie values never pass through the chat.
Verify with get_account_health(account); cookie status should be valid.
Ask: "What niche are you in, which keywords should I watch, and whose posts
do you want to engage with (profiles)?" Apply with
update_account(account, target_keywords=[...], competitor_profiles=[...]).
Ask how they want to sound. Offer the three starter personas from
presets/personas/ (builder, founder, curator) as starting points, let the
user pick or dictate their own, then apply with
update_account(account, persona=<text>). Keep it under 4000 chars,
markdown, covering: voice, topics, reply style, what to avoid, 1-2 example
replies.
add_proxy(pool, proxy_url) and assign with
update_account(account, proxy="pool:<name>")."auto" text): needs one
OpenAI-compatible key in config/settings.json under llm
(api_key, base_url, model). Interactive use needs no key at all.Stage something real but harmless: use x-use-engage to research one reply
draft, or x-use-content to stage one post draft. Show it via list_drafts.
Tell the user: nothing posts until you say approve_draft(<id>).
© ihuzaifashoukat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/x-use/skills/x-use-setup of ihuzaifashoukat/x-use.
Open the folder on GitHubat commit e57e215
X Use Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| X Use Setup this skillihuzaifashoukat/x-use | 171 | — | ~731 | Automated safety check: Warn | MIT | |
| Protect MCP Setupwshobson/agents | 40k | — | ~2.1k | Automated safety check: Pass | MIT | |
| Bind MCPLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.5k | Automated safety check: Pass | MIT | |
| Xquik MCPXquik-dev/x-twitter-scraper | 210 | 1 repos | ~997 | Automated safety check: Pass | MIT | |
| Unifapiunifapi-agent/agents | 589 | — | ~741 | Automated safety check: Pass | MIT | |
| Webcrypt MCPputervision/state-memory-mcp | 114 | — | ~847 | Automated safety check: Pass | MIT |
wshobson/agents
Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls.
LeoYeAI/openclaw-master-skills
Bind Protocol MCP server for credential verification, policy authoring, and zero-knowledge proof generation.
Xquik-dev/x-twitter-scraper
Connect, verify, and troubleshoot Xquik's remote MCP server.
unifapi-agent/agents
A skill your agent uses when working with UnifAPI public-data APIs or the UnifAPI MCP server: connecting OAuth MCP clients, discovering operations, calling social/search/scrape/news APIs…
putervision/state-memory-mcp
Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.
aeonfun/aeon
Live-data research via the glim.sh MCP - web search, full page extraction, X/Twitter, Reddit, GitHub, Amazon, and YouTube transcripts - synthesized into a cited digest.
ihuzaifashoukat/x-use
Install, register, and configure x-use, the browser-native MCP server for X (Twitter) automation that needs no X API key.
ihuzaifashoukat/x-use
Overview and routing for the x-use X (Twitter) automation MCP server, covering tool groups, the two safety gates, and usage conventions.
ihuzaifashoukat/x-use
Create original X content in the user's persona by researching what works in the niche, drafting posts, and staging them one by one for review.
ihuzaifashoukat/x-use
Research the user's niche on X and draft persona-voice replies for review, searching keywords or profiles, reading tweets AND their images, composing replies, and staging drafts.
ihuzaifashoukat/x-use
Daily digest for an x-use account covering health, metrics, pending drafts, and queued work in one pass, then approve/reject/process per the user's direction.
Works with
Categories
Zero-knowledge onboarding for x-use that verifies the install, registers the MCP server, then interviews the user to configure their first X account (cookies, niche, keywords, persona). X Use Setup is an agent skill from ihuzaifashoukat/x-use. Zero-knowledge onboarding for x-use that verifies the install, registers the MCP server, then interviews the user to configure their first X account (cookies, niche, keywords, persona).
X Use Setup fits situations like: X-use is not yet configured; adding an account; the user asks to get started.
Run `npx skills add ihuzaifashoukat/x-use --skill x-use-setup -a claude-code`. Or copy the skill folder (plugins/x-use/skills/x-use-setup in ihuzaifashoukat/x-use) into .claude/skills/x-use-setup in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ihuzaifashoukat/x-use --skill x-use-setup -a codex`. Or copy the skill folder (plugins/x-use/skills/x-use-setup in ihuzaifashoukat/x-use) into .agents/skills/x-use-setup in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ihuzaifashoukat/x-use --skill x-use-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/x-use-setup, .gemini/skills/x-use-setup, .github/skills/x-use-setup and .opencode/skills/x-use-setup in your project.
Going by SKILL.md and its folder, X Use Setup needs the command-line tools its instructions call (pip and claude). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
X Use Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 731 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with X Use Setup: Protect MCP Setup (wshobson/agents, 40k stars), Bind MCP (LeoYeAI/openclaw-master-skills, 2.2k stars), Xquik MCP (Xquik-dev/x-twitter-scraper, 210 stars) and Unifapi (unifapi-agent/agents, 589 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ihuzaifashoukat (a GitHub user) maintains it in ihuzaifashoukat/x-use, which has 171 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on August 18, 2026.
Source: ihuzaifashoukat/x-use on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.