Install the "prismer-xurl" agent skill from https://github.com/Prismer-AI/PrismerCloud/tree/main/sdk/cloud/catalog/skills/prismer-xurl into .claude/skills/prismer-xurl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prismer-xurl", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add Prismer-AI/PrismerCloud --skill prismer-xurl -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "prismer-xurl" agent skill from https://github.com/Prismer-AI/PrismerCloud/tree/main/sdk/cloud/catalog/skills/prismer-xurl into .agents/skills/prismer-xurl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prismer-xurl", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Prismer-AI/PrismerCloud --skill prismer-xurl -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "prismer-xurl" agent skill from https://github.com/Prismer-AI/PrismerCloud/tree/main/sdk/cloud/catalog/skills/prismer-xurl into .cursor/skills/prismer-xurl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prismer-xurl", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add Prismer-AI/PrismerCloud --skill prismer-xurl -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "prismer-xurl" agent skill from https://github.com/Prismer-AI/PrismerCloud/tree/main/sdk/cloud/catalog/skills/prismer-xurl into .gemini/skills/prismer-xurl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prismer-xurl", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add Prismer-AI/PrismerCloud --skill prismer-xurl -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "prismer-xurl" agent skill from https://github.com/Prismer-AI/PrismerCloud/tree/main/sdk/cloud/catalog/skills/prismer-xurl into .github/skills/prismer-xurl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prismer-xurl", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Prismer-AI/PrismerCloud --skill prismer-xurl -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "prismer-xurl" agent skill from https://github.com/Prismer-AI/PrismerCloud/tree/main/sdk/cloud/catalog/skills/prismer-xurl into .opencode/skills/prismer-xurl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prismer-xurl", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
prismer-xurl
GitHub stars
1.6k
Used in
1 other repo
Token cost
~4.2k tokens
SKILL.md length
1,800 words
Files
5
Skills in repo
88
Repo updated
First seen
Licence
MIT
At a glance
X/Twitter via xurl CLI: raw post search, posting, DM, media.
Works in 7 steps: Create or open an app at… → Set the redirect URI to… → Copy the app's Client ID and Client Secret → …
SKILL.md covers Secret Safety (MANDATORY), Installation, One-Time User Setup (user runs… and Quick Reference, plus 12 more sections
Calls go, brew and npm; reaches x.com and api.x.com
What it does
Prismer Xurl is an agent skill from Prismer-AI/PrismerCloud. X/Twitter via xurl CLI: raw post search, posting, DM, media.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `PROVENANCE.md` and `provenance/category-DESCRIPTION.md`).
It works with X (Twitter). The licence is MIT.
Example prompts
“/prismer-xurl”
Requirements
Python 3
Node.js
Docker
A credential in YOUR_CLIENT_SECRET
Workflow steps
7 steps, taken from the first numbered list in SKILL.md.
1Create or open an app at https://developer.x.com/en/portal/dashboard
2Set the redirect URI to http://localhost:8080/callback
3Copy the app's Client ID and Client Secret
4Register the app locally (user runs this)
5Authenticate (specify --app to bind the token to your app)
6Set the app as default so all commands use it
7Verify
What it can do on your machine
Read from SKILL.md and the folder at commit e5d9444. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
go
brew
npm
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
x.com
api.x.com
Also links to:
github.com
developer.x.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Prismer Xurl loads about 4.2k tokens when it runs. Until then it costs about 18 tokens; SKILL.md has 1,800 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~18
When it runs· the whole SKILL.md, loaded when a task matches
~4.2k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/prismer-xurl/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
prismer-xurl
description
X/Twitter via xurl CLI: raw post search, posting, DM, media.
scope
common
category
social-media
version
1.1.3
author
xdevplatform + openclaw + Hermes Agent
license
MIT
platforms
linux, macos
prerequisites.commands
xurl
metadata.nativeReplaces
xurl
metadata.requiresExplicitGrant
true
xurl — X (Twitter) API via the Official CLI
xurl is the X developer platform's official CLI for the X API. It supports shortcut commands for common actions AND raw curl-style access to any v2 endpoint. All commands return JSON to stdout.
Use this skill for:
posting, replying, quoting, deleting posts
searching for raw posts (actual post JSON with IDs you can engage with) and reading timelines/mentions
liking, reposting, bookmarking
following, unfollowing, blocking, muting
direct messages
media uploads (images and video)
raw access to any X API v2 endpoint
multi-app / multi-account workflows
This skill replaces the older xitter skill (which wrapped a third-party Python CLI). xurl is maintained by the X developer platform team, supports OAuth 2.0 PKCE with auto-refresh, and covers a substantially larger API surface.
Secret Safety (MANDATORY)
Critical rules when operating inside an agent/LLM session:
Never read, print, parse, summarize, upload, or send ~/.xurl to LLM context.
Never ask the user to paste credentials/tokens into chat.
The user must fill ~/.xurl with secrets manually on their own machine. In Docker, this must be the ~ seen by Hermes tool subprocesses; see the Docker note below.
Never recommend or execute auth commands with inline secrets in agent sessions.
Never use --verbose / -v in agent sessions — it can expose auth headers/tokens.
To verify credentials exist, only use: xurl auth status.
App credential registration and credential rotation must be done by the user manually, outside the agent session. After credentials are registered, the user authenticates with xurl auth oauth2 — also outside the agent session. Tokens persist to ~/.xurl in YAML. Each app has isolated tokens. OAuth 2.0 tokens auto-refresh.
Installation
Pick ONE method. On Linux, the shell script or go install are the easiest.
bash
# Shell script (installs to ~/.local/bin, no sudo, works on Linux + macOS)
# Prefer a reviewed, version-pinned package; never pipe a remote installer to a shell.
# Homebrew (macOS)
brew install --cask xdevplatform/tap/xurl
# npm
npm install -g @xdevplatform/xurl
# Go
go install "github.com/xdevplatform/xurl@${XURL_VERSION:?Set an exact reviewed release or commit}"
Verify:
bash
xurl --help
xurl auth status
If xurl is installed but auth status shows no apps or tokens, the user needs to complete auth manually — see the next section.
One-Time User Setup (user runs these outside the agent)
These steps must be performed by the user directly, NOT by the agent, because they involve pasting secrets. Direct the user to this block; do not execute it for them.
Authenticate (specify --app to bind the token to your app):
bash
xurl auth oauth2 --app my-app
(This opens a browser for the OAuth 2.0 PKCE flow.)
If X returns a UsernameNotFound error or 403 on the post-OAuth /2/users/me lookup, pass your handle explicitly (xurl v1.1.0+):
bash
xurl auth oauth2 --app my-app YOUR_USERNAME
This binds the token to your handle and skips the broken /2/users/me call.
Set the app as default so all commands use it:
bash
xurl auth default my-app
Verify:
bash
xurl auth status
xurl whoami
After this, the agent can use any command below without further setup. OAuth 2.0 tokens auto-refresh.
Common pitfall: If you omit --app my-app from xurl auth oauth2, the OAuth token is saved to the built-in default app profile — which has no client-id or client-secret. Commands will fail with auth errors even though the OAuth flow appeared to succeed. If you hit this, re-run xurl auth oauth2 --app my-app and xurl auth default my-app.
Docker HOME pitfall: In the official Hermes Docker layout, /opt/data is HERMES_HOME, but Hermes tool subprocesses use ${HOME} as HOME. That means ~/.xurl resolves to ${HOME}/.xurl for Hermes-run xurl commands, not /opt/data/.xurl. Run the user setup with the same HOME:
If HOME=/opt/data xurl auth status succeeds but HOME=${HOME} xurl auth status shows no apps or tokens, Hermes tool calls will not see the credentials.
Quick Reference
Action
Command
Post
xurl post "Hello world!"
Reply
xurl reply POST_ID "Nice post!"
Quote
xurl quote POST_ID "My take"
Delete a post
xurl delete POST_ID
Read a post
xurl read POST_ID
Search posts
xurl search "QUERY" -n 10
Who am I
xurl whoami
Look up a user
xurl user @handle
Home timeline
xurl timeline -n 20
Mentions
xurl mentions -n 10
Like / Unlike
xurl like POST_ID / xurl unlike POST_ID
Repost / Undo
xurl repost POST_ID / xurl unrepost POST_ID
Bookmark / Remove
xurl bookmark POST_ID / xurl unbookmark POST_ID
List bookmarks / likes
xurl bookmarks -n 10 / xurl likes -n 10
Follow / Unfollow
xurl follow @handle / xurl unfollow @handle
Following / Followers
xurl following -n 20 / xurl followers -n 20
Block / Unblock
xurl block @handle / xurl unblock @handle
Mute / Unmute
xurl mute @handle / xurl unmute @handle
Send DM
xurl dm @handle "message"
List DMs
xurl dms -n 10
Upload media
xurl media upload path/to/file.mp4
Media status
xurl media status MEDIA_ID
List apps
xurl auth apps list
Remove app
xurl auth apps remove NAME
Set default app
xurl auth default APP_NAME [USERNAME]
Per-request app
xurl --app NAME /2/users/me
Auth status
xurl auth status
Notes:
POST_ID accepts full URLs too (e.g. https://x.com/user/status/1234567890) — xurl extracts the ID.
Usernames work with or without a leading @.
Command Details
Posting
bash
xurl post "Hello world!"
xurl post "Check this out" --media-id MEDIA_ID
xurl post "Thread pics" --media-id 111 --media-id 222
xurl reply 1234567890 "Great point!"
xurl reply https://x.com/user/status/1234567890 "Agreed!"
xurl reply 1234567890 "Look at this" --media-id MEDIA_ID
xurl quote 1234567890 "Adding my thoughts"
xurl delete 1234567890
Reading & Search
xurl search queries the X index as your authenticated account and returns raw post objects — IDs, authors, full text — so results can be immediately engaged with (reply, like, repost, quote). Use it when you need the actual posts rather than a summarized answer about a topic.
For X Articles, use raw API mode instead of the read shortcut. xurl read
expects a post ID or post URL; do not put read before a /2/tweets/...
endpoint. Request the article tweet field and ingest data.article.plain_text
from the JSON response:
# Auto-detect type
xurl media upload photo.jpg
xurl media upload video.mp4
# Explicit type/category
xurl media upload --media-type image/jpeg --category tweet_image photo.jpg
# Videos need server-side processing — check status (or poll)
xurl media status MEDIA_ID
xurl media status --wait MEDIA_ID
# Full workflow
xurl media upload meme.png # returns media id
xurl post "lol" --media-id MEDIA_ID
Raw API Access
The shortcuts cover common operations. For anything else, use raw curl-style mode against any X API v2 endpoint:
bash
# GET
xurl /2/users/me
# POST with JSON body
xurl -X POST /2/tweets -d '{"text":"Hello world!"}'
# DELETE / PUT / PATCH
xurl -X DELETE /2/tweets/1234567890
# Custom headers
xurl -H "Content-Type: application/json" /2/some/endpoint
# Force streaming
xurl -s /2/tweets/search/stream
# Full URLs also work
xurl https://api.x.com/2/users/me
Global Flags
Flag
Short
Description
--app
Use a specific registered app (overrides default)
--auth
Force auth type: oauth1, oauth2, or app
--username
-u
Which OAuth2 account to use (if multiple exist)
--verbose
-v
Forbidden in agent sessions — leaks auth headers
--trace
-t
Add X-B3-Flags: 1 trace header
Streaming
Streaming endpoints are auto-detected. Known ones include:
/2/tweets/search/stream
/2/tweets/sample/stream
/2/tweets/sample10/stream
Force streaming on any endpoint with -s.
Output Format
All commands return JSON to stdout. Structure mirrors X API v2:
xurl auth default prod alice # prod app, alice user
xurl --app staging /2/users/me # one-off against staging
Show full SKILL.md (743 more words)Show less
Error Handling
Non-zero exit code on any error.
API errors are still printed as JSON to stdout, so you can parse them.
Auth errors → have the user re-run xurl auth oauth2 outside the agent session.
Commands that need the caller's user ID (like, repost, bookmark, follow, etc.) will auto-fetch it via /2/users/me. An auth failure there surfaces as an auth error.
Agent Workflow
Verify prerequisites: xurl --help and xurl auth status.
Before using xurl search, check intent. Reach for it when the task needs actual post objects, authenticated account context, or leads into an X write action — it is the right surface when the user wants posts they can engage with, not just a summary of a topic.
Check default app has credentials. Parse the auth status output. The default app is marked with ▸. If the default app shows oauth2: (none) but another app has a valid oauth2 user, tell the user to run xurl auth default <that-app> to fix it. This is the most common setup mistake — the user added an app with a custom name but never set it as default, so xurl keeps trying the empty default profile.
If auth is missing entirely, stop and direct the user to the "One-Time User Setup" section — do NOT attempt to register apps or pass secrets yourself.
Start with a cheap read (xurl whoami, xurl user @handle, xurl search ... -n 3) to confirm reachability.
Confirm the target post/user and the user's intent before any write action (post, reply, like, repost, DM, follow, block, delete).
Only the xurl command output (or the raw X API response) proves that a state-changing X action happened. Never report a write as done based on any other source — search results, summaries, or prior context.
Use JSON output directly — every response is already structured.
Never paste ~/.xurl contents back into the conversation.
Troubleshooting
Symptom
Cause
Fix
Auth errors after successful OAuth flow
Token saved to default app (no client-id/secret) instead of your named app
xurl auth oauth2 --app my-app then xurl auth default my-app
unauthorized_client during OAuth
App type set to "Native App" in X dashboard
Change to "Web app, automated app or bot" in User Authentication Settings
UsernameNotFound or 403 on /2/users/me right after OAuth
X not returning username reliably from /2/users/me
Re-run xurl auth oauth2 --app my-app YOUR_USERNAME (xurl v1.1.0+) to pass the handle explicitly
401 on every request
Token expired or wrong default app
Check xurl auth status — verify ▸ points to an app with oauth2 tokens
client-forbidden / client-not-enrolled
X platform enrollment issue
Dashboard → Apps → Manage → Move to "Pay-per-use" package → Production environment
CreditsDepleted
$0 balance on X API
Buy credits (min $5) in Developer Console → Billing
media processing failed on image upload
Default category is amplify_video
Add --category tweet_image --media-type image/png
Two "Client Secret" values in X dashboard
UI bug — first is actually Client ID
Confirm on the "Keys and tokens" page; ID ends in MTpjaQ
Notes
Rate limits: X enforces per-endpoint rate limits. A 429 means wait and retry. Write endpoints (post, reply, like, repost) have tighter limits than reads.
Scopes: OAuth 2.0 tokens use broad scopes. A 403 on a specific action usually means the token is missing a scope — have the user re-run xurl auth oauth2.
Token refresh: OAuth 2.0 tokens auto-refresh. Nothing to do.
Multiple apps: Each app has isolated credentials/tokens. Switch with xurl auth default or --app.
Multiple accounts per app: Select with -u / --username, or set a default with xurl auth default APP USER.
Token storage:~/.xurl is YAML. In Docker, use the Hermes subprocess HOME (${HOME} in the official image) so tokens land under ${HOME}/.xurl. Never read or send this file to LLM context.
Cost: X API access is typically paid for meaningful usage. Many failures are plan/permission problems, not code problems.
Keep the skill discoverable when the CLI or account is absent; report the exact missing prerequisite. Record CLI version, intended account and operation scopes separately. Existing user authorization covers only its stated operation/content/recipient: do not demand duplicate approval, and do not infer permission for new posts or DMs. Authentication is handled through the user's credential workflow, never by printing tokens or bypassing Runtime-owned model login. Quotas and prices must be checked at use time, not inferred from historical examples.
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Prismer-AI/PrismerCloud, which our catalogue first saw on October 7, 2026.
Prismer Xurl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
When the user wants help creating, scheduling, or optimizing social media content for LinkedIn, Twitter/X, Instagram, TikTok, or Facebook, or wants to do social listening and engagement triage.
Walks through designing a banner for social media, ads, a website hero or print, from gathering requirements to building 2 or 3 art-direction options in HTML and CSS.
Routes web research and platform lookups across 16 sites, including Twitter, Reddit, YouTube, Bilibili, Xiaohongshu and GitHub, through one command-line tool.
When the user wants help creating, scheduling, or optimizing social media content for LinkedIn, Twitter/X, Instagram, TikTok, Facebook, or other platforms.
Operates a mailbox from the terminal with the external Himalaya CLI over IMAP, SMTP, Notmuch or Sendmail, separate from any built-in email gateway adapter.
Produces 3Blue1Brown-style explainer animations with Manim Community Edition for math, algorithms, equations and architecture diagrams, with planning and rendering references.
Creates or updates Prismer role templates from a persona, SOP or job description, and turns a role into a working agent that runs its first task through a bundled script.
X/Twitter via xurl CLI: raw post search, posting, DM, media. Prismer Xurl is an agent skill from Prismer-AI/PrismerCloud. X/Twitter via xurl CLI: raw post search, posting, DM, media.
How do I install Prismer Xurl in Claude Code?
Run `npx skills add Prismer-AI/PrismerCloud --skill prismer-xurl -a claude-code`. Or copy the skill folder (sdk/cloud/catalog/skills/prismer-xurl in Prismer-AI/PrismerCloud) into .claude/skills/prismer-xurl in your project. Claude Code loads it when a task matches its description.
How do I install Prismer Xurl in Codex?
Run `npx skills add Prismer-AI/PrismerCloud --skill prismer-xurl -a codex`. Or copy the skill folder (sdk/cloud/catalog/skills/prismer-xurl in Prismer-AI/PrismerCloud) into .agents/skills/prismer-xurl in your project. Codex loads it when a task matches its description.
Can I use Prismer Xurl in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Prismer-AI/PrismerCloud --skill prismer-xurl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/prismer-xurl, .gemini/skills/prismer-xurl, .github/skills/prismer-xurl and .opencode/skills/prismer-xurl in your project.
What does Prismer Xurl need to run?
Going by SKILL.md and its folder, Prismer Xurl needs the command-line tools its instructions call (go, brew and npm). Our summary lists: Python 3; Node.js; Docker; A credential in YOUR_CLIENT_SECRET.
Does Prismer Xurl access the network?
SKILL.md names 4 domains. In commands or code: x.com and api.x.com; the agent is likely to contact these when it follows the instructions. As links in the text: github.com and developer.x.com. This is read from the text; nothing was executed.
Is Prismer Xurl safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Prismer Xurl use?
Prismer Xurl is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Prismer Xurl use?
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Prismer Xurl?
Skills that share tags, products or a category with Prismer Xurl: Social (coreyhaines31/marketingskills, 54k stars), Banner Design System (nextlevelbuilder/ui-ux-pro-max-skill, 135k stars), Agent Reach (Panniantong/Agent-Reach, 95k stars) and X to Markdown Converter (JimLiu/baoyu-skills, 27k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Prismer Xurl?
Prismer-AI (a GitHub organization) maintains it in Prismer-AI/PrismerCloud, which has 1,555 GitHub stars. The repository holds 88 skills in this directory. The repository was last updated on September 30, 2026.
Source: Prismer-AI/PrismerCloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.