{"id":"cdc8a36b-4679-44cb-a839-8c27465505c7","entityType":"agent","slug":"clawhub-xquik-hermes-tweet","name":"Hermes Tweet","canonicalUrl":"https://www.xpersona.co/agent/clawhub-xquik-hermes-tweet","canonicalPath":"/agent/clawhub-xquik-hermes-tweet","generatedAt":"2026-10-11T07:41:49.300Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:34:52.063Z","emptyReason":null},"description":"Uses Xquik from Hermes Agent for X research, monitoring, and approval-gated actions. Not affiliated with X Corp. Use when the user requests X data or an appr...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s170jwjc10myqbr6rstn6gwcwn849144:hermes-tweet","sourceUrl":"https://clawhub.ai/xquik/hermes-tweet","homepage":"https://clawhub.ai/xquik/skills/hermes-tweet","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/xquik/hermes-tweet","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/xquik/skills/hermes-tweet","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Hermes Tweet technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:34:52.063Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:34:52.063Z","emptyReason":null},"stars":null,"forks":null,"downloads":1145,"packageName":null,"latestVersion":"1.0.3","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:34:52.051Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T05:34:52.063Z","lastCrawledAt":"2026-10-11T05:34:52.051Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T05:34:52.051Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.3","createdAt":"2026-07-13T21:49:17.524Z","changelog":"Ship Hermes Tweet 0.1.7 with current catalog guidance, stronger permission boundaries, and trusted release verification.","fileCount":4,"zipByteSize":7581},{"version":"1.0.2","createdAt":"2026-05-07T00:29:49.515Z","changelog":"Refresh Hermes Tweet skill metadata for the 0.1.6 catalog release.","fileCount":3,"zipByteSize":3433},{"version":"1.0.1","createdAt":"2026-05-06T22:26:15.071Z","changelog":"- Added version, author, tags, and metadata fields for registry and directory compatibility - Expanded usage and decision rules for workflow clarity in Hermes Agent sessions - Included detailed safety guidelines and common pitfalls to avoid mistakes or leaks - Outlined clear testing steps and CLI commands for plugin installation and tool verification - Added version history documenting changes for 0.1.4 and 0.1.5","fileCount":2,"zipByteSize":2124},{"version":"1.0.0","createdAt":"2026-05-06T11:55:59.318Z","changelog":"hermes-tweet 1.0.0 - Initial release of Hermes Tweet skill. - Enables searching, posting, replying, liking, retweeting, following, DMs, monitoring, data extraction, draws, media management, and trend analysis on X via Hermes Agent. - Provides clear workflow and safety guidelines for using public and private API endpoints. - Includes usage examples for searching and posting tweets.","fileCount":2,"zipByteSize":1083}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s170jwjc10myqbr6rstn6gwcwn849144:hermes-tweet","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s170jwjc10myqbr6rstn6gwcwn849144:hermes-tweet` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/xquik/hermes-tweet before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T07:41:49.300Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-xquik-hermes-tweet/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:34:52.063Z","emptyReason":null},"readme":"Skill: Hermes Tweet\n\nOwner: xquik\n\nSummary: Uses Xquik from Hermes Agent for X research, monitoring, and approval-gated actions. Not affiliated with X Corp. Use when the user requests X data or an appr...\n\nTags: automation:1.0.3, hermes-agent:1.0.3, latest:1.0.3, social-media:1.0.3, twitter:1.0.3, x:1.0.3, xquik:1.0.3\n\nVersion history:\n\nv1.0.3 | 2026-07-13T21:49:17.524Z | user\n\nShip Hermes Tweet 0.1.7 with current catalog guidance, stronger permission boundaries, and trusted release verification.\n\nv1.0.2 | 2026-05-07T00:29:49.515Z | user\n\nRefresh Hermes Tweet skill metadata for the 0.1.6 catalog release.\n\nv1.0.1 | 2026-05-06T22:26:15.071Z | user\n\n- Added version, author, tags, and metadata fields for registry and directory compatibility\n- Expanded usage and decision rules for workflow clarity in Hermes Agent sessions\n- Included detailed safety guidelines and common pitfalls to avoid mistakes or leaks\n- Outlined clear testing steps and CLI commands for plugin installation and tool verification\n- Added version history documenting changes for 0.1.4 and 0.1.5\n\nv1.0.0 | 2026-05-06T11:55:59.318Z | user\n\nhermes-tweet 1.0.0\n\n- Initial release of Hermes Tweet skill.\n- Enables searching, posting, replying, liking, retweeting, following, DMs, monitoring, data extraction, draws, media management, and trend analysis on X via Hermes Agent.\n- Provides clear workflow and safety guidelines for using public and private API endpoints.\n- Includes usage examples for searching and posting tweets.\n\nArchive index:\n\nArchive v1.0.3: 4 files, 7581 bytes\n\nFiles: references/endpoint-contract.md (2531b), skill-card.md (2626b), SKILL.md (11500b), _meta.json (131b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: hermes-tweet\ndescription: >-\n  Uses Xquik from Hermes Agent for X research, monitoring, and approval-gated actions. Not affiliated with X Corp. Use when the user requests X data or an approved X action. Trigger with \"search X\", \"monitor X\", \"post tweet\", or \"X trends\".\nallowed-tools:\n  - tweet_explore\n  - tweet_read\n  - tweet_action\nversion: 0.1.7\nauthor: Burak Bayır (@kriptoburak), Xquik\nlicense: MIT\ncompatibility: Requires Hermes Agent plugin support and Xquik API access.\nargument-hint: \"[X task, endpoint, or approved action]\"\ntags:\n  - hermes-agent\n  - xquik\n  - twitter\n  - x\n  - social-media\n  - automation\nmetadata:\n  version: 0.1.7\n  author: Xquik\n  tags:\n    - hermes-agent\n    - xquik\n    - twitter\n    - x\n    - social-media\n    - automation\nrequired_environment_variables:\n  - name: XQUIK_API_KEY\n    prompt: Xquik API key\n    help: Create an API key at https://dashboard.xquik.com\n    required_for: tweet_read, /xstatus, /xtrends, and authenticated Xquik API calls\ncapabilities:\n  shell:\n    required: false\n    justification: Optional Hermes CLI checks are used only for installation and registry diagnostics.\n  network:\n    required: true\n    justification: Hermes Tweet tools call Xquik API routes for X/Twitter reads and approved actions.\n  files:\n    required: false\n    justification: Normal use does not require local file reads or writes.\n  environment:\n    required: true\n    variables:\n      - XQUIK_API_KEY\n      - HERMES_TWEET_ENABLE_ACTIONS\n      - HERMES_ENABLE_PROJECT_PLUGINS\n    justification: Runtime configuration controls authenticated reads, gated actions, and trusted project-local plugin loading.\n  mcp:\n    required: false\n    justification: No MCP server access is required.\n  tools:\n    - tweet_explore\n    - tweet_read\n    - tweet_action\n---\n\n# Hermes Tweet\n\n## Overview\n\nHermes Tweet solves X research and automation tasks without direct HTTP fallbacks\nor guessed endpoints. It discovers catalog-listed Xquik routes, performs\nauthenticated reads, and keeps write-like or private operations behind an\nexplicit environment gate and user approval.\n\nUse the skill for read-first workflows. Enable action tooling only for a named\noperation whose endpoint, payload, account, and side effects the user approves.\n\n## When to Use\n\nUse this skill for Hermes Agent sessions that need X/Twitter data or controlled\nX actions through the Hermes Tweet plugin.\n\nUse this skill especially for social listening, launch monitoring, support\ntriage, creator research, brand research, giveaway audits, community audits,\nand controlled publishing workflows.\n\nUse `tweet_explore` first when the user asks for a capability, endpoint, route,\nor Xquik API surface. Use `tweet_read` only after a read-only endpoint is known.\nUse `tweet_action` only after the user requests a write, private read, monitor,\nwebhook, extraction job, giveaway draw, or media operation that requires action\npermissions.\n\n## Prerequisites\n\n- Install and enable the plugin with\n  `hermes plugins install Xquik-dev/hermes-tweet --enable`.\n- Configure `XQUIK_API_KEY` on the Hermes runtime host for authenticated reads.\n  `tweet_explore` remains available without the key or network access.\n- Leave `HERMES_TWEET_ENABLE_ACTIONS` unset or false unless the workflow needs\n  an approved write-like or private operation.\n- For project-local plugins, set `HERMES_ENABLE_PROJECT_PLUGINS=true` only in a\n  trusted repository.\n- Restart a gateway after environment changes and start a new session. Active\n  CLI sessions can use `/reload`.\n\n## Permissions and Capabilities\n\n- Use `tweet_explore`, `tweet_read`, and `tweet_action` only through the enabled\n  Hermes Tweet toolset.\n- Network access is limited to catalog-listed Xquik API routes reached by those\n  tools. Do not create direct HTTP fallbacks.\n- Shell access is not part of normal operation. Use Hermes CLI commands only for\n  the install and registry checks listed in Testing.\n- Local file access is not part of normal operation. Do not write reports,\n  credentials, logs, screenshots, or cached API payloads unless the user asks\n  for an explicit export workflow.\n- Environment access is limited to configuration presence checks for\n  `XQUIK_API_KEY`, `HERMES_TWEET_ENABLE_ACTIONS`, and\n  `HERMES_ENABLE_PROJECT_PLUGINS`. Never request or echo their values.\n- MCP access is not required.\n\n## Instructions\n\n1. Confirm the plugin is enabled with `hermes plugins list` and confirm tool\n   registration with `hermes tools list`.\n2. Use `tweet_explore` to find the catalog endpoint and method.\n3. Use `tweet_read` for public read-only endpoints after the API key is\n   configured.\n4. Before `tweet_action`, state the exact endpoint, payload, account, reason,\n   and expected side effects, then get explicit approval.\n5. Verify the tool response. Report policy, authentication, validation, or\n   account errors without retrying through alternate routes.\n\n## Decision Rules\n\n- IF the task is endpoint discovery, THEN call `tweet_explore` with a short\n  query.\n- IF the endpoint method is `GET` and the catalog does not mark it as an\n  action, THEN call `tweet_read`.\n- IF the endpoint method is not `GET`, or the route touches private account\n  state, THEN call `tweet_action` only when actions are enabled and the user has\n  approved the operation.\n- IF `tweet_action` is unavailable or disabled, THEN explain that action tools\n  are intentionally gated by `HERMES_TWEET_ENABLE_ACTIONS=true`.\n- IF `XQUIK_API_KEY` is missing, THEN ask the user to set it in the Hermes\n  runtime environment without requesting the key value in chat.\n- IF Hermes lists the plugin as `not enabled`, THEN tell the user to run\n  `hermes plugins enable hermes-tweet` or reinstall with `--enable`.\n- IF the plugin is installed as a project-local `.hermes/plugins/` copy, THEN\n  remind the user that Hermes requires `HERMES_ENABLE_PROJECT_PLUGINS=true` for\n  trusted repositories.\n- IF the task is unattended, scheduled, gateway-driven, or cron-driven, THEN\n  prefer `tweet_read` and keep `tweet_action` disabled unless the workflow has a\n  clear approval step.\n- IF the user is in Hermes Desktop with a remote gateway profile, THEN remind\n  them that Hermes Tweet must be installed, enabled, and configured on the\n  remote Hermes host where plugin tools execute.\n- IF the user uses the Hermes dashboard for gateway administration or\n  credentials, THEN keep Hermes Tweet secrets in the runtime environment and do\n  not ask for key values in chat.\n\n## Safety\n\n- Never ask for or reveal API keys, signing keys, passwords, cookies, or TOTP secrets.\n- Never pass credentials in tool arguments.\n- Use only catalog-listed `/api/v1/...` endpoints.\n- Copied endpoint URLs are accepted only when they resolve to catalog-listed paths.\n- Do not use account connection, re-authentication, API key, billing, credit top-up, or support-ticket endpoints.\n- For posting, deleting, following, DMs, profile changes, monitors, webhooks, extraction jobs, and draws, summarize the action before calling `tweet_action`.\n\n## Known Risks and Mitigations\n\n- Risk: A broad X/Twitter request may map to a write-capable route.\n  Mitigation: Start with `tweet_explore`, prefer `tweet_read`, and require a\n  user-approved endpoint plus payload before `tweet_action`.\n- Risk: Secrets may be pasted into chat or examples.\n  Mitigation: Ask only for environment configuration, never for key values, and\n  never put credentials in tool arguments.\n- Risk: Endpoint guessing may bypass catalog review.\n  Mitigation: Accept only catalog-listed `/api/v1/...` paths and reject direct\n  HTTP fallbacks.\n- Risk: Automated X/Twitter actions can affect real accounts.\n  Mitigation: Keep `HERMES_TWEET_ENABLE_ACTIONS=false` by default and summarize\n  side effects before any account-changing call.\n\n## Output\n\n- Output type: endpoint selection, API-result summaries, action previews, and\n  troubleshooting guidance.\n- Output format: concise Markdown for humans and JSON-like tool payloads for\n  Hermes Tweet calls.\n- Side effects: `tweet_explore` has no external side effects, `tweet_read`\n  performs authenticated reads, and `tweet_action` may change account or\n  workflow state only after explicit approval.\n\n## Error Handling\n\nUse the narrowest recovery step that preserves the read-first and action-gated\ncontract:\n\n- Missing tool: confirm the plugin is enabled, then run `hermes tools list`.\n- Missing API key: configure `XQUIK_API_KEY` on the runtime host without pasting\n  its value into chat, then run `/reload` in an active CLI session or run\n  `hermes gateway restart` and start a new gateway session.\n- Unknown endpoint: call `tweet_explore` again. Never guess paths or create a\n  direct HTTP fallback.\n- Disabled action: keep the action blocked unless the user requested it and\n  `HERMES_TWEET_ENABLE_ACTIONS=true` is intentionally configured.\n- Policy, authentication, validation, or account error: return the sanitized\n  failure and corrective step. Do not retry through another route.\n- Missing slash command: verify it in an active Hermes session or plugin\n  registry test rather than treating prompt text as registration proof.\n- Secret in input: stop and ask the user to rotate it before continuing.\n\n## Examples\n\n**Example: Search tweets**\n\n```json\n{\"query\":\"tweet search\",\"method\":\"GET\"}\n```\n\nThen call:\n\n```json\n{\"path\":\"/api/v1/x/tweets/search\",\"query\":{\"q\":\"AI agents\",\"limit\":25}}\n```\n\n**Example: Inspect trends**\n\nRun `/xtrends` in an active Hermes session. Use `tweet_explore` when the task\nneeds a catalog endpoint or structured response instead of the slash command.\n\n**Example: Post a tweet**\n\n```json\n{\"query\":\"post tweet\",\"include_actions\":true}\n```\n\nThen call `tweet_action` with:\n\n```json\n{\"path\":\"/api/v1/x/tweets\",\"method\":\"POST\",\"body\":{\"account\":\"@example\",\"text\":\"Hello from Hermes Tweet\"},\"reason\":\"Post the user-approved tweet.\"}\n```\n\n## Testing\n\nAfter installing or upgrading the plugin in Hermes Agent:\n\n1. Run `hermes plugins enable hermes-tweet` unless the install used `--enable`.\n2. Run `hermes plugins list` and confirm the plugin is `enabled`.\n3. Run `hermes tools list` and confirm the `hermes-tweet` toolset is enabled.\n4. Confirm `tweet_explore` is available without `XQUIK_API_KEY`.\n5. Confirm `tweet_read` appears only when `XQUIK_API_KEY` is configured.\n6. Confirm `tweet_action` stays hidden or disabled unless `HERMES_TWEET_ENABLE_ACTIONS=true`.\n\nUseful CLI checks:\n\n```bash\nhermes plugins enable hermes-tweet\nhermes tools list\n```\n\n## Release Trust Gate\n\nBefore presenting this skill as NVIDIA-verified or ready for broad enterprise\ndeployment:\n\n1. Run SkillSpector against the complete skill directory and resolve critical or\n   high findings.\n2. Complete `skill-card.md` with owner, license, use case, deployment\n   geography, risks, references, output shape, and release version.\n3. Include Tier-3 eval data and `BENCHMARK.md` for the reviewed release.\n4. Sign the exact reviewed skill directory and publish `skill.oms.sig`.\n5. Verify the published directory with the expected certificate chain.\n\nDo not claim NVIDIA verification when those release artifacts are absent.\n\n## Resources\n\n- [Endpoint and approval contract](references/endpoint-contract.md)\n- [Skill card](skill-card.md)\n- [Hermes Tweet repository](https://github.com/Xquik-dev/hermes-tweet)\n- [Hermes Agent plugin guide](https://github.com/NousResearch/hermes-agent/blob/main/website/docs/user-guide/features/plugins.md)\n- [Xquik Hermes Tweet guide](https://docs.xquik.com/guides/hermes-tweet)\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn76ca1rwgw8wa5d27x5ayq5mh82m3fv\",\n  \"slug\": \"hermes-tweet\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1783979357524\n}\n\nFile v1.0.3:references/endpoint-contract.md\n\n# Endpoint and Approval Contract\n\nUse this reference when the selected Xquik route or approval boundary is\nunclear. The rules apply to CLI, Desktop, dashboard, gateway, scheduled, and\ndelegated Hermes Agent sessions.\n\n## Tool Matrix\n\n| Tool | API key | Network | Action gate | User approval |\n|---|---:|---:|---:|---:|\n| `tweet_explore` | No | No | No | No |\n| `tweet_read` | Yes | Yes | No | No for public read-only routes |\n| `tweet_action` | Yes | Yes | Yes | Yes for the exact operation |\n\n`tweet_explore` reads the bundled catalog. `tweet_read` accepts only\ncatalog-listed read-only routes. `tweet_action` handles writes, private reads,\nmonitors, webhooks, extraction jobs, giveaway draws, and media operations.\n\n## Approval Checklist\n\nBefore calling `tweet_action`, state and confirm:\n\n1. The catalog-listed endpoint and method.\n2. The target account or workflow.\n3. The complete payload without credentials.\n4. The expected side effects and reason.\n5. The user's explicit approval for this operation.\n\nApproval for one operation does not authorize retries, related operations, or\nfuture scheduled runs. Stop after policy, authentication, validation, or\naccount-state failures.\n\n## Hermes Agent Surfaces\n\nHermes Tweet uses the same plugin entry point across Desktop, TUI, CLI,\ndashboard, and gateway sessions. Install and configure the plugin on the Hermes\nruntime host where tools execute. Remote Desktop profiles do not move secrets or\nplugin state from the gateway host.\n\nUse active CLI or gateway sessions for `/xstatus` and `/xtrends`. Keep\n`HERMES_TWEET_ENABLE_ACTIONS=false` unless the session intentionally permits an\napproved account-changing operation.\n\n## Runtime Checks\n\n```bash\nhermes plugins list\nhermes tools list\n```\n\nConfirm that `tweet_explore` remains available without `XQUIK_API_KEY`,\n`tweet_read` appears only with the key, and `tweet_action` remains unavailable\nunless `HERMES_TWEET_ENABLE_ACTIONS=true` is intentionally configured.\n\nAfter environment changes, reload an active CLI session. For gateway use, run\n`hermes gateway restart`, then start a new session.\n\n## Version History\n\n- 0.1.7: Align prepaid read and direct MPP metadata with the current API.\n- Unreleased: Add marketplace metadata, required sections, and reference docs.\n- Unreleased: Add capability declarations, risk controls, and release gates.\n- 0.1.6: Refresh catalog wording from the current Xquik OpenAPI.\n- 0.1.5: Add registry metadata and Hermes runtime guidance.\n- 0.1.4: Add public registry frontmatter for skill discovery.\n\nFile v1.0.3:skill-card.md\n\n## Description:\n\nUses Xquik from Hermes Agent for X research, monitoring, and approval-gated actions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[xquik](https://clawhub.ai/user/xquik)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and Hermes Agent users use this skill for X/Twitter research, monitoring, social listening, support triage, creator or brand research, and controlled publishing workflows through Xquik routes.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The install guidance enables an unpinned external Hermes Tweet plugin that may later run with Xquik API and account-action privileges.\n\nMitigation: Review and pin the exact Hermes Tweet plugin version before enabling it.\n\nRisk: Automated X/Twitter operations can affect real accounts or private workflow state.\n\nMitigation: Keep HERMES_TWEET_ENABLE_ACTIONS disabled unless needed, and approve only a specific endpoint, payload, account, and side effect before using tweet_action.\n\nRisk: Credential exposure could occur if users paste API keys into chat or tool arguments.\n\nMitigation: Configure XQUIK_API_KEY only in the Hermes runtime environment, never request or echo key values, and stop if a secret is pasted.\n\nRisk: Endpoint guessing or direct HTTP fallbacks could bypass the catalog and approval boundary.\n\nMitigation: Use tweet_explore first, call only catalog-listed Xquik routes, and reject direct HTTP fallbacks.\n\n## Reference(s):\n\n- [Endpoint and Approval Contract](references/endpoint-contract.md)\n- [Hermes Tweet ClawHub Listing](https://clawhub.ai/xquik/skills/hermes-tweet)\n- [Xquik Hermes Tweet Guide](https://docs.xquik.com/guides/hermes-tweet)\n- [Hermes Agent Plugin Guide](https://github.com/NousResearch/hermes-agent/blob/main/website/docs/user-guide/features/plugins.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, API calls, shell commands, configuration, guidance]\n\n**Output Format:** [Concise Markdown for humans with JSON-like tool payloads and shell command snippets when needed]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include endpoint selections, API-result summaries, action previews, sanitized errors, and troubleshooting guidance.]\n\n## Skill Version(s):\n\n1.0.3 (source: server release metadata; artifact frontmatter version 0.1.7)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.2: 3 files, 3433 bytes\n\nFiles: skill-card.md (2460b), SKILL.md (4095b), _meta.json (131b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: hermes-tweet\nversion: 0.1.6\nauthor: Xquik\ndescription: Use Xquik from Hermes Agent for X search, posting, replies, likes, retweets, follows, DMs, monitors, extraction jobs, draws, media, and trends.\ntags:\n  - hermes-agent\n  - xquik\n  - twitter\n  - x\n  - social-media\n  - automation\nmetadata:\n  version: 0.1.6\n  author: Xquik\n  tags:\n    - hermes-agent\n    - xquik\n    - twitter\n    - x\n    - social-media\n    - automation\n---\n\n# Hermes Tweet\n\nUse Hermes Tweet when the user wants to automate or inspect X through Xquik.\n\n## When to Use\n\nUse this skill for Hermes Agent sessions that need X/Twitter data or controlled\nX actions through the Hermes Tweet plugin.\n\nUse `tweet_explore` first when the user asks for a capability, endpoint, route,\nor Xquik API surface. Use `tweet_read` only after a read-only endpoint is known.\nUse `tweet_action` only after the user requests a write, private read, monitor,\nwebhook, extraction job, giveaway draw, or media operation that requires action\npermissions.\n\n## Workflow\n\n1. Use `tweet_explore` to find the endpoint.\n2. Use `tweet_read` for public read-only endpoints.\n3. Use `tweet_action` only for writes or private reads after stating the exact endpoint and payload.\n\n## Decision Rules\n\n- IF the task is endpoint discovery, THEN call `tweet_explore` with a short\n  query.\n- IF the endpoint method is `GET` and the catalog does not mark it as an\n  action, THEN call `tweet_read`.\n- IF the endpoint method is not `GET`, or the route touches private account\n  state, THEN call `tweet_action` only when actions are enabled and the user has\n  approved the operation.\n- IF `tweet_action` is unavailable or disabled, THEN explain that action tools\n  are intentionally gated by `HERMES_TWEET_ENABLE_ACTIONS=true`.\n- IF `XQUIK_API_KEY` is missing, THEN ask the user to set it in the Hermes\n  runtime environment without requesting the key value in chat.\n\n## Safety\n\n- Never ask for or reveal API keys, signing keys, passwords, cookies, or TOTP secrets.\n- Never pass credentials in tool arguments.\n- Use only catalog-listed `/api/v1/...` endpoints.\n- Do not use account connection, re-authentication, API key, billing, credit top-up, or support-ticket endpoints.\n- For posting, deleting, following, DMs, profile changes, monitors, webhooks, extraction jobs, and draws, summarize the action before calling `tweet_action`.\n\n## Pitfalls\n\n- Do not guess endpoint paths. Always use the catalog returned by `tweet_explore`.\n- Do not treat a slash command prompt as proof that Hermes registered the\n  command. Verify slash commands through an active Hermes session or plugin\n  registry test.\n- Do not use bare `hermes tools` for scripted diagnostics. Run\n  `hermes tools list` instead.\n- Do not retry writes through alternate routes after a policy, auth, or account\n  state error.\n- Do not include secrets in examples, logs, prompts, issue bodies, or tool input.\n\n## Examples\n\nSearch tweets:\n\n```json\n{\"query\":\"tweet search\",\"method\":\"GET\"}\n```\n\nThen call:\n\n```json\n{\"path\":\"/api/v1/x/tweets/search\",\"query\":{\"q\":\"AI agents\",\"limit\":25}}\n```\n\nPost a tweet:\n\n```json\n{\"query\":\"post tweet\",\"include_actions\":true}\n```\n\nThen call `tweet_action` with:\n\n```json\n{\"path\":\"/api/v1/x/tweets\",\"method\":\"POST\",\"body\":{\"account\":\"@example\",\"text\":\"Hello from Hermes Tweet\"},\"reason\":\"Post the user-approved tweet.\"}\n```\n\n## Testing\n\nAfter installing or upgrading the plugin in Hermes Agent:\n\n1. Run `hermes plugins enable hermes-tweet`.\n2. Run `hermes tools list` and confirm the `hermes-tweet` toolset is enabled.\n3. Confirm `tweet_explore` is available without `XQUIK_API_KEY`.\n4. Confirm `tweet_read` appears only when `XQUIK_API_KEY` is configured.\n5. Confirm `tweet_action` stays hidden or disabled unless `HERMES_TWEET_ENABLE_ACTIONS=true`.\n\nUseful CLI checks:\n\n```bash\nhermes plugins enable hermes-tweet\nhermes tools list\n```\n\n## Version History\n\n- 0.1.6: Refresh catalog wording from current Xquik OpenAPI.\n- 0.1.5: Add registry-compatible nested metadata and clearer Hermes runtime guidance.\n- 0.1.4: Add public registry frontmatter for skill directory discovery.\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn76ca1rwgw8wa5d27x5ayq5mh82m3fv\",\n  \"slug\": \"hermes-tweet\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1778113789515\n}\n\nFile v1.0.2:skill-card.md\n\n## Description: <br>\nUse Xquik from Hermes Agent for X search, posting, replies, likes, retweets, follows, DMs, monitors, extraction jobs, draws, media, and trends. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[xquik](https://clawhub.ai/user/xquik) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operators use this skill in Hermes Agent sessions to inspect X/Twitter data and perform controlled Xquik actions such as posting, replies, follows, DMs, monitors, extraction jobs, draws, media operations, and trend checks. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can support externally visible X/Twitter actions such as posts, replies, likes, retweets, follows, DMs, deletes, monitors, webhooks, extraction jobs, draws, and media operations. <br>\nMitigation: Keep action tools disabled until needed and review the exact endpoint, payload, and user intent before approving any write, private-read, or account-changing operation. <br>\nRisk: The skill depends on sensitive Xquik credentials for authenticated reads and actions. <br>\nMitigation: Set XQUIK_API_KEY only in the Hermes runtime environment and never ask for, paste, reveal, log, or pass credentials in chat or tool arguments. <br>\nRisk: Runtime permissions depend on the separate Hermes Tweet plugin rather than this skill file alone. <br>\nMitigation: Review the plugin separately for actual runtime permissions before deployment. <br>\n\n\n## Reference(s): <br>\n- [Hermes Tweet on ClawHub](https://clawhub.ai/xquik/hermes-tweet) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, API calls, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with JSON payload examples and inline shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May require XQUIK_API_KEY in the Hermes runtime environment; write and private-account actions are gated by HERMES_TWEET_ENABLE_ACTIONS and user approval.] <br>\n\n## Skill Version(s): <br>\n1.0.2 (source: server release metadata; artifact frontmatter version 0.1.6) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.1: 2 files, 2124 bytes\n\nFiles: SKILL.md (4034b), _meta.json (131b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: hermes-tweet\nversion: 0.1.5\nauthor: Xquik\ndescription: Use Xquik from Hermes Agent for X search, posting, replies, likes, retweets, follows, DMs, monitors, extraction jobs, draws, media, and trends.\ntags:\n  - hermes-agent\n  - xquik\n  - twitter\n  - x\n  - social-media\n  - automation\nmetadata:\n  version: 0.1.5\n  author: Xquik\n  tags:\n    - hermes-agent\n    - xquik\n    - twitter\n    - x\n    - social-media\n    - automation\n---\n\n# Hermes Tweet\n\nUse Hermes Tweet when the user wants to automate or inspect X through Xquik.\n\n## When to Use\n\nUse this skill for Hermes Agent sessions that need X/Twitter data or controlled\nX actions through the Hermes Tweet plugin.\n\nUse `tweet_explore` first when the user asks for a capability, endpoint, route,\nor Xquik API surface. Use `tweet_read` only after a read-only endpoint is known.\nUse `tweet_action` only after the user requests a write, private read, monitor,\nwebhook, extraction job, giveaway draw, or media operation that requires action\npermissions.\n\n## Workflow\n\n1. Use `tweet_explore` to find the endpoint.\n2. Use `tweet_read` for public read-only endpoints.\n3. Use `tweet_action` only for writes or private reads after stating the exact endpoint and payload.\n\n## Decision Rules\n\n- IF the task is endpoint discovery, THEN call `tweet_explore` with a short\n  query.\n- IF the endpoint method is `GET` and the catalog does not mark it as an\n  action, THEN call `tweet_read`.\n- IF the endpoint method is not `GET`, or the route touches private account\n  state, THEN call `tweet_action` only when actions are enabled and the user has\n  approved the operation.\n- IF `tweet_action` is unavailable or disabled, THEN explain that action tools\n  are intentionally gated by `HERMES_TWEET_ENABLE_ACTIONS=true`.\n- IF `XQUIK_API_KEY` is missing, THEN ask the user to set it in the Hermes\n  runtime environment without requesting the key value in chat.\n\n## Safety\n\n- Never ask for or reveal API keys, signing keys, passwords, cookies, or TOTP secrets.\n- Never pass credentials in tool arguments.\n- Use only catalog-listed `/api/v1/...` endpoints.\n- Do not use account connection, re-authentication, API key, billing, credit top-up, or support-ticket endpoints.\n- For posting, deleting, following, DMs, profile changes, monitors, webhooks, extraction jobs, and draws, summarize the action before calling `tweet_action`.\n\n## Pitfalls\n\n- Do not guess endpoint paths. Always use the catalog returned by `tweet_explore`.\n- Do not treat a slash command prompt as proof that Hermes registered the\n  command. Verify slash commands through an active Hermes session or plugin\n  registry test.\n- Do not use bare `hermes tools` for scripted diagnostics. Run\n  `hermes tools list` instead.\n- Do not retry writes through alternate routes after a policy, auth, or account\n  state error.\n- Do not include secrets in examples, logs, prompts, issue bodies, or tool input.\n\n## Examples\n\nSearch tweets:\n\n```json\n{\"query\":\"tweet search\",\"method\":\"GET\"}\n```\n\nThen call:\n\n```json\n{\"path\":\"/api/v1/x/tweets/search\",\"query\":{\"q\":\"AI agents\",\"limit\":25}}\n```\n\nPost a tweet:\n\n```json\n{\"query\":\"post tweet\",\"include_actions\":true}\n```\n\nThen call `tweet_action` with:\n\n```json\n{\"path\":\"/api/v1/x/tweets\",\"method\":\"POST\",\"body\":{\"account\":\"@example\",\"text\":\"Hello from Hermes Tweet\"},\"reason\":\"Post the user-approved tweet.\"}\n```\n\n## Testing\n\nAfter installing or upgrading the plugin in Hermes Agent:\n\n1. Run `hermes plugins enable hermes-tweet`.\n2. Run `hermes tools list` and confirm the `hermes-tweet` toolset is enabled.\n3. Confirm `tweet_explore` is available without `XQUIK_API_KEY`.\n4. Confirm `tweet_read` appears only when `XQUIK_API_KEY` is configured.\n5. Confirm `tweet_action` stays hidden or disabled unless `HERMES_TWEET_ENABLE_ACTIONS=true`.\n\nUseful CLI checks:\n\n```bash\nhermes plugins enable hermes-tweet\nhermes tools list\n```\n\n## Version History\n\n- 0.1.5: Add registry-compatible nested metadata and clearer Hermes runtime guidance.\n- 0.1.4: Add public registry frontmatter for skill directory discovery.\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn76ca1rwgw8wa5d27x5ayq5mh82m3fv\",\n  \"slug\": \"hermes-tweet\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1778106375071\n}\n\nArchive v1.0.0: 2 files, 1083 bytes\n\nFiles: SKILL.md (1403b), _meta.json (131b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: hermes-tweet\ndescription: Use Xquik from Hermes Agent for X search, posting, replies, likes, retweets, follows, DMs, monitors, extraction jobs, draws, media, and trends.\n---\n\n# Hermes Tweet\n\nUse Hermes Tweet when the user wants to automate or inspect X through Xquik.\n\n## Workflow\n\n1. Use `tweet_explore` to find the endpoint.\n2. Use `tweet_read` for public read-only endpoints.\n3. Use `tweet_action` only for writes or private reads after stating the exact endpoint and payload.\n\n## Safety\n\n- Never ask for or reveal API keys, signing keys, passwords, cookies, or TOTP secrets.\n- Never pass credentials in tool arguments.\n- Use only catalog-listed `/api/v1/...` endpoints.\n- Do not use account connection, re-authentication, API key, billing, credit top-up, or support-ticket endpoints.\n- For posting, deleting, following, DMs, profile changes, monitors, webhooks, extraction jobs, and draws, summarize the action before calling `tweet_action`.\n\n## Examples\n\nSearch tweets:\n\n```json\n{\"query\":\"tweet search\",\"method\":\"GET\"}\n```\n\nThen call:\n\n```json\n{\"path\":\"/api/v1/x/tweets/search\",\"query\":{\"q\":\"AI agents\",\"limit\":25}}\n```\n\nPost a tweet:\n\n```json\n{\"query\":\"post tweet\",\"include_actions\":true}\n```\n\nThen call `tweet_action` with:\n\n```json\n{\"path\":\"/api/v1/x/tweets\",\"method\":\"POST\",\"body\":{\"account\":\"@example\",\"text\":\"Hello from Hermes Tweet\"},\"reason\":\"Post the user-approved tweet.\"}\n```\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn76ca1rwgw8wa5d27x5ayq5mh82m3fv\",\n  \"slug\": \"hermes-tweet\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1778068559318\n}","readmeExcerpt":"Skill: Hermes Tweet Owner: xquik Summary: Uses Xquik from Hermes Agent for X research, monitoring, and approval-gated actions. Not affiliated with X Corp. Use when the user requests X data or an appr... Tags: automation:1.0.3, hermes-agent:1.0.3, latest:1.0.3, social-media:1.0.3, twitter:1.0.3, x:1.0.3, xquik:1.0.3 Version history: v1.0.3 | 2026-07-13T21:49:17.524Z | user Ship Hermes Tweet 0.1.7 with current catalog ","codeSnippets":[],"executableExamples":[{"language":"json","snippet":"{\"query\":\"tweet search\",\"method\":\"GET\"}"},{"language":"json","snippet":"{\"path\":\"/api/v1/x/tweets/search\",\"query\":{\"q\":\"AI agents\",\"limit\":25}}"},{"language":"json","snippet":"{\"query\":\"post tweet\",\"include_actions\":true}"},{"language":"json","snippet":"{\"path\":\"/api/v1/x/tweets\",\"method\":\"POST\",\"body\":{\"account\":\"@example\",\"text\":\"Hello from Hermes Tweet\"},\"reason\":\"Post the user-approved tweet.\"}"},{"language":"bash","snippet":"hermes plugins enable hermes-tweet\nhermes tools list"},{"language":"bash","snippet":"hermes plugins list\nhermes tools list"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: hermes-tweet\ndescription: >-\n  Uses Xquik from Hermes Agent for X research, monitoring, and approval-gated actions. Not affiliated with X Corp. Use when the user requests X data or an approved X action. Trigger with \"search X\", \"monitor X\", \"post tweet\", or \"X trends\".\nallowed-tools:\n  - tweet_explore\n  - tweet_read\n  - tweet_action\nversion: 0.1.7\nauthor: Burak Bayır (@kriptoburak), Xquik\nlicense: MIT\ncompatibility: Requires Hermes Agent plugin support and Xquik API access.\nargument-hint: \"[X task, endpoint, or approved action]\"\ntags:\n  - hermes-agent\n  - xquik\n  - twitter\n  - x\n  - social-media\n  - automation\nmetadata:\n  version: 0.1.7\n  author: Xquik\n  tags:\n    - hermes-agent\n    - xquik\n    - twitter\n    - x\n    - social-media\n    - automation\nrequired_environment_variables:\n  - name: XQUIK_API_KEY\n    prompt: Xquik API key\n    help: Create an API key at https://dashboard.xquik.com\n    required_for: tweet_read, /xstatus, /xtrends, and authenticated Xquik API calls\ncapabilities:\n  shell:\n    required: false\n    justification: Optional Hermes CLI checks are used only for installation and registry diagnostics.\n  network:\n    required: true\n    justification: Hermes Tweet tools call Xquik API routes for X/Twitter reads and approved actions.\n  files:\n    required: false\n    justification: Normal use does not require local file reads or writes.\n  environment:\n    required: true\n    variables:\n      - XQUIK_API_KEY\n      - HERMES_TWEET_ENABLE_ACTIONS\n      - HERMES_ENABLE_PROJECT_PLUGINS\n    justification: Runtime configuration controls authenticated reads, gated actions, and trusted project-local plugin loading.\n  mcp:\n    required: false\n    justification: No MCP server access is required.\n  tools:\n    - tweet_explore\n    - tweet_read\n    - tweet_action\n---\n\n# Hermes Tweet\n\n## Overview\n\nHermes Tweet solves X research and automation tasks without direct HTTP fallbacks\nor guessed endpoints. It discovers catalog-listed Xquik routes, performs\nauthenticated reads, and keeps write-like or private operations behind an\nexplicit environment gate and user approval.\n\nUse the skill for read-first workflows. Enable action tooling only for a named\noperation whose endpoint, payload, account, and side effects the user approves.\n\n## When to Use\n\nUse this skill for Hermes Agent sessions that need X/Twitter data or controlled\nX actions through the Hermes Tweet plugin.\n\nUse this skill especially for social listening, launch monitoring, support\ntriage, creator research, brand research, giveaway audits, community audits,\nand controlled publishing workflows.\n\nUse `tweet_explore` first when the user asks for a capability, endpoint, route,\nor Xquik API surface. Use `tweet_read` only after a read-only endpoint is known.\nUse `tweet_action` only after the user requests a write, private read, monitor,\nwebhook, extraction job, giveaway draw, or media operation that requires action\npermissions.\n\n## Prerequisites\n\n- Install and enable the plugin with\n  `hermes plugins "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76ca1rwgw8wa5d27x5ayq5mh82m3fv\",\n  \"slug\": \"hermes-tweet\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1783979357524\n}"},{"path":"references/endpoint-contract.md","content":"# Endpoint and Approval Contract\n\nUse this reference when the selected Xquik route or approval boundary is\nunclear. The rules apply to CLI, Desktop, dashboard, gateway, scheduled, and\ndelegated Hermes Agent sessions.\n\n## Tool Matrix\n\n| Tool | API key | Network | Action gate | User approval |\n|---|---:|---:|---:|---:|\n| `tweet_explore` | No | No | No | No |\n| `tweet_read` | Yes | Yes | No | No for public read-only routes |\n| `tweet_action` | Yes | Yes | Yes | Yes for the exact operation |\n\n`tweet_explore` reads the bundled catalog. `tweet_read` accepts only\ncatalog-listed read-only routes. `tweet_action` handles writes, private reads,\nmonitors, webhooks, extraction jobs, giveaway draws, and media operations.\n\n## Approval Checklist\n\nBefore calling `tweet_action`, state and confirm:\n\n1. The catalog-listed endpoint and method.\n2. The target account or workflow.\n3. The complete payload without credentials.\n4. The expected side effects and reason.\n5. The user's explicit approval for this operation.\n\nApproval for one operation does not authorize retries, related operations, or\nfuture scheduled runs. Stop after policy, authentication, validation, or\naccount-state failures.\n\n## Hermes Agent Surfaces\n\nHermes Tweet uses the same plugin entry point across Desktop, TUI, CLI,\ndashboard, and gateway sessions. Install and configure the plugin on the Hermes\nruntime host where tools execute. Remote Desktop profiles do not move secrets or\nplugin state from the gateway host.\n\nUse active CLI or gateway sessions for `/xstatus` and `/xtrends`. Keep\n`HERMES_TWEET_ENABLE_ACTIONS=false` unless the session intentionally permits an\napproved account-changing operation.\n\n## Runtime Checks\n\n```bash\nhermes plugins list\nhermes tools list\n```\n\nConfirm that `tweet_explore` remains available without `XQUIK_API_KEY`,\n`tweet_read` appears only with the key, and `tweet_action` remains unavailable\nunless `HERMES_TWEET_ENABLE_ACTIONS=true` is intentionally configured.\n\nAfter environment changes, reload an active CLI session. For gateway use, run\n`hermes gateway restart`, then start a new session.\n\n## Version History\n\n- 0.1.7: Align prepaid read and direct MPP metadata with the current API.\n- Unreleased: Add marketplace metadata, required sections, and reference docs.\n- Unreleased: Add capability declarations, risk controls, and release gates.\n- 0.1.6: Refresh catalog wording from the current Xquik OpenAPI.\n- 0.1.5: Add registry metadata and Hermes runtime guidance.\n- 0.1.4: Add public registry frontmatter for skill discovery."},{"path":"skill-card.md","content":"## Description:\n\nUses Xquik from Hermes Agent for X research, monitoring, and approval-gated actions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[xquik](https://clawhub.ai/user/xquik)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and Hermes Agent users use this skill for X/Twitter research, monitoring, social listening, support triage, creator or brand research, and controlled publishing workflows through Xquik routes.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The install guidance enables an unpinned external Hermes Tweet plugin that may later run with Xquik API and account-action privileges.\n\nMitigation: Review and pin the exact Hermes Tweet plugin version before enabling it.\n\nRisk: Automated X/Twitter operations can affect real accounts or private workflow state.\n\nMitigation: Keep HERMES_TWEET_ENABLE_ACTIONS disabled unless needed, and approve only a specific endpoint, payload, account, and side effect before using tweet_action.\n\nRisk: Credential exposure could occur if users paste API keys into chat or tool arguments.\n\nMitigation: Configure XQUIK_API_KEY only in the Hermes runtime environment, never request or echo key values, and stop if a secret is pasted.\n\nRisk: Endpoint guessing or direct HTTP fallbacks could bypass the catalog and approval boundary.\n\nMitigation: Use tweet_explore first, call only catalog-listed Xquik routes, and reject direct HTTP fallbacks.\n\n## Reference(s):\n\n- [Endpoint and Approval Contract](references/endpoint-contract.md)\n- [Hermes Tweet ClawHub Listing](https://clawhub.ai/xquik/skills/hermes-tweet)\n- [Xquik Hermes Tweet Guide](https://docs.xquik.com/guides/hermes-tweet)\n- [Hermes Agent Plugin Guide](https://github.com/NousResearch/hermes-agent/blob/main/website/docs/user-guide/features/plugins.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, API calls, shell commands, configuration, guidance]\n\n**Output Format:** [Concise Markdown for humans with JSON-like tool payloads and shell command snippets when needed]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include endpoint selections, API-result summaries, action previews, sanitized errors, and troubleshooting guidance.]\n\n## Skill Version(s):\n\n1.0.3 (source: server release metadata; artifact frontmatter version 0.1.7)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1560,"uniquenessScore":41,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T05:34:52.063Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T05:34:52.063Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T07:41:49.300Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}