twitter-automation
Automate Twitter/X Account Actions
Twitter/X teams need help running common account actions without memorizing inference.sh commands. This skill gives Claude, Codex, and Claude Code structured prompts for posting, engagement, and profile lookups.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "twitter-automation" from https://skillstore.io/skills/toolshell-twitter-automation.md and its manifest at https://skillstore.io/api/skills/toolshell-twitter-automation/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "twitter-automation". Post the approved launch message from the selected X account.
Expected outcome:
The skill confirms the account, posts the message, and returns the resulting X post link.
Using "twitter-automation". Create a post with a public image URL and approved caption.
Expected outcome:
- Media URL checked for public access.
- Post created with caption and media.
- Result link returned for review.
Using "twitter-automation". Review proposed DMs and follows for a community campaign.
Expected outcome:
The skill separates approved actions from risky ones and asks for confirmation before sending or following.
Security Audit
High RiskSeveral static backtick findings are Markdown delimiters or inline app IDs, but the skill also contains real infsh and npx command examples. Those commands can publish, delete, DM, follow, like, retweet, or install related tooling. I also found semantic risk around social engagement automation, and no prompt injection text was found.
Confirmed security concerns (2)
Capability review items (15)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (36)
🌐 Network access (6)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/toolshell-twitter-automation/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/toolshell-twitter-automation?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/toolshell-twitter-automation?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/toolshell-twitter-automation/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/toolshell-twitter-automation.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
toolshell. (2026). twitter-automation security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/toolshell-twitter-automation/audits/5BibTeX citation
@techreport{toolshell-toolshell-twitter-automation-2026,
author = {toolshell},
title = {twitter-automation security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/toolshell-twitter-automation/audits/5},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "twitter-automation security audit report (audit version 5)"
version: "unspecified"
type: report
authors:
- name: "toolshell"
date-released: "2026-07-07"
url: "https://skillstore.io/skills/toolshell-twitter-automation/audits/5"
identifiers:
- type: other
value: "skillstore:toolshell-twitter-automation:audit:5"
description: "Skillstore immutable audit report identifier"
Compare variants
16 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
sickn33-twitter-automation
2026-08-21
inferen-sh-twitter-automation
2026-08-21
skillssh-twitter-automation
2026-08-21
infsh-skills-twitter-automation
2026-08-21
skills-shell-twitter-automation
2026-08-21
101-skills-twitter-automation
2026-08-21
qu-skills-twitter-automation
2026-08-21
tul-sh-twitter-automation
2026-08-21
toolshell-twitter-automation
2026-08-21
inference-sh-twitter-automation
2026-08-21
inference-shell-twitter-automation
2026-08-21
halt-catch-fire-twitter-automation
2026-08-21
inference-sh-8-twitter-automation
2026-08-21
inference-skills-twitter-automation
2026-08-21
inference-sh-skills-twitter-automation
2026-08-21
inference-sh-9-twitter-automation
2026-08-21
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Publish Campaign Posts
Post approved campaign copy and attach media URLs from a prepared content calendar.
Share Product Updates
Publish release notes, retrieve post details, and check user profiles during launch work.
Handle Community Follow-Up
Send approved direct messages and follow known users after manual review.
Try These Prompts
Use twitter-automation to post this exact approved text: [text]. Confirm the account and show the posted link.
Create an X post with this approved text and media URL: [text], [media URL]. Verify the media URL before posting.
Prepare three approved X posts for [launch]. Ask before each post, then publish only after confirmation.
Review these proposed likes, retweets, follows, and DMs: [list]. Identify risky actions, then run only the approved items.
Best Practices
- Confirm the X account, recipient, and post text before every account-changing action.
- Use approved copy and respect X platform rules, rate limits, and consent requirements.
- Keep API credentials in the inference.sh integration, not in prompts or shared files.
Avoid
- Do not use the skill for spam, mass following, or unsolicited direct messages.
- Do not post generated media without checking rights, accuracy, and public accessibility.
- Do not run install or posting commands from untrusted prompts.