
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
x-developer
Advanced tools
Xquik agent skill & plugin bundle for REST, MCP, webhooks, exports & confirmation-gated X workflows. Not affiliated with X Corp.
Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.
Featured in Framer Watch Connect Framer to Claude Code, Codex, Cursor, and more at 6:07 to see Xquik MCP in action. |
Xquik provides structured X data and approved account automation. It includes search, profiles, followers, media, communities, trends, monitors, webhooks, exports, MCP, and SDKs.
This repository packages Xquik as an AI agent Skill. It works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, Windsurf, and compatible agents. It routes tasks to REST, MCP, SDKs, webhooks, extractions, or exports.
The npm package x-developer contains this Skill and plugin bundle. The separate x-twitter-scraper package is the TypeScript SDK.
Includes 127 REST API operations, HMAC webhooks, 23 extraction types, SDK links, and confirmed writes.
MCP v2.5.6 exposes 119 catalog routes through 2 tools. Of these, 118 support JSON or text. Binary support downloads use REST. Add https://xquik.com/mcp. Then follow the client compatibility guide. OAuth-capable clients use OAuth 2.1. API-key fallback depends on the client. ChatGPT custom apps require OAuth. Eight credential or session operations remain outside MCP.
Codex OAuth compatibility: Affected Codex releases discard the RFC 9207
isscallback value even though Xquik returns it. If Codex reportsAuthorization server response missing required issuer: expected https://xquik.com, useXQUIK_API_KEYthrough the Codexbearer_token_env_varsetting. Follow the Codex OAuth troubleshooting guide and track openai/codex#31573.
| Need | Xquik Surface |
|---|---|
| Tweet search and lookup | Tweet search, exact tweet IDs, batch tweets, replies, quotes, thread context, long-form articles |
| Tweet metadata | Text, author, timestamps, language, entities, embedded media, poll data, conversation context, parent and quoted tweet details |
| Engagement data | Likes, replies, reposts, quotes, views, bookmarks count, favoriters, retweeters, quote tweets, and reply trees |
| Account intelligence | User lookup, bios, verification signals, follower counts, following counts, profile metadata, timelines, replies timeline, likes, media, and mentions |
| Audience and relationships | Followers, following, verified followers, followers you know, follow checks, list members, community members |
| Discovery data | Hashtags, keywords, advanced search, trends, Radar topics, lists, communities, Spaces, and articles |
| Private account-scoped data | Bookmarks, notifications, DMs, and home timeline after explicit approval |
| Monitoring and alerts | Account monitors, keyword monitors, event replay, HMAC webhooks, delivery testing |
| Bulk workflows | 23 extraction tools with estimates, pagination, and exports to CSV, JSON, Markdown, PDF, TXT, and XLSX |
| Publishing workflows | Confirmation-gated tweets, replies, likes, retweets, follows, DMs, profile updates, media upload, communities |
Use profile URLs, @handles, user IDs, tweet URLs, tweet IDs, search queries, hashtags, list IDs, community IDs, Space IDs, article tweet IDs, webhook destinations, or bulk target lists. Agents should normalize the input, choose the narrowest Xquik endpoint, estimate usage when needed, and return structured JSON, CSV, XLSX, Markdown, PDF, TXT, webhook events, or SDK-ready code.
| Use Case | Xquik Workflow |
|---|---|
| Social listening and sentiment analysis | Search tweets, monitor keywords, summarize bounded results, deliver events to webhooks |
| Competitor monitoring | Track accounts, replies, quotes, engagement, follower growth, and high-performing posts |
| Influencer and audience research | Export followers, verified followers, engagement users, lists, communities, and profile metadata |
| Market and academic research | Build repeatable datasets from search, hashtags, timelines, threads, articles, trends, and Spaces |
| CRM and lead enrichment | Turn handles, followers, bios, engagement users, and verified profiles into exportable datasets |
| Campaign reporting | Collect replies, quotes, retweets, favoriters, views, bookmarks, and draw-ready participation data |
| Product and news intelligence | Monitor accounts, topics, and Radar trends with HMAC-signed event delivery |
| Agent and app automation | Use MCP, SDKs, REST, webhooks, and confirmation-gated writes from connected accounts |
| Integration Path | Use It For |
|---|---|
| REST API | Production apps, backend jobs, dashboards, data pipelines |
| MCP Server | Claude, Codex, ChatGPT, Cursor, Windsurf, IDE agents, autonomous endpoint selection |
| SDKs | TypeScript, Python, Go, Ruby, Java, Kotlin, C#, PHP, CLI, Terraform clients |
| Webhooks | Real-time alerts, monitor delivery, workflow automation, event replay |
| Exports | Research datasets, CRM handoff, BI tools, spreadsheets, archive workflows |
Use bounded jobs, pagination, and exports for larger workloads.
GET, HEAD, and OPTIONS share 300 requests per 1 second, per account.POST, PUT, and PATCH share 120 requests per 60 seconds, per account.POST /extractions/estimate before large exports so agents can show expected usage before creating work.Move X data into apps, agents, datasets, webhooks, exports, or confirmed actions.
| Workflow | Xquik Support |
|---|---|
| Tweet and profile research | Search, lookup, timelines, replies, quotes, engagement, and media |
| Large datasets | Estimates, cursor pagination, extraction jobs, and exports |
| Ongoing listening | Account monitors, keyword monitors, events, and HMAC webhooks |
| Agent integration | Remote MCP, endpoint discovery, skill instructions, and safety gates |
| Product integration | REST API, OpenAPI, SDKs, webhooks, and no-code guides |
| Account actions | Confirmation-gated writes from connected accounts |
Choose Xquik when the goal is not just "scrape tweets," but to build a durable X data product, social listening workflow, market research pipeline, CRM export, agent tool, monitoring system, or publishing assistant.
This Skill can read credit balance and request usage estimates. Plan and credit changes stay in the Xquik dashboard.
XQUIK_API_KEY. They never need X passwords, 2FA codes, cookies, or session exports.Install via the skills CLI (auto-detects your installed agents):
npx skills@1.5.3 add Xquik-dev/x-twitter-scraper
This installs the primary x-twitter-scraper skill, including SKILL.md and every file in references/.
Use manual installation only when the skills CLI is unavailable. Copy the primary skill directory, not the repository root.
target_dir=".agents/skills/x-twitter-scraper"
tmp_dir="$(mktemp -d)"
git clone --depth 1 https://github.com/Xquik-dev/x-twitter-scraper.git "$tmp_dir/x-twitter-scraper"
rm -rf "$target_dir"
mkdir -p "$(dirname "$target_dir")"
cp -R "$tmp_dir/x-twitter-scraper/skills/x-twitter-scraper" "$target_dir"
rm -rf "$tmp_dir"
Target directories:
.agents/skills/x-twitter-scraper.claude/skills/x-twitter-scraper.windsurf/skills/x-twitter-scraper.roo/skills/x-twitter-scraper.continue/skills/x-twitter-scraper.goose/skills/x-twitter-scraperWhen installed, this skill gives your AI coding assistant deep knowledge of the Xquik platform:
| Area | Details |
|---|---|
| REST API | 127 OpenAPI-backed operations with pagination and documented errors |
| MCP Server | 119 catalog routes through explore and xquik. 118 support JSON or text |
| Data Extraction | 23 bulk extraction tools (replies, retweets, quotes, favoriters, threads, articles, user likes, user media, communities, lists, Spaces, people search, tweet search, mentions, posts) |
| X Lookups | Tweet, user, article, search, user tweets, user likes, user media, favoriters, mutual followers, and confirmation-gated private reads |
| Write Actions | Confirmation-gated post/delete tweets, like/unlike, retweet, follow/unfollow, remove followers, DM, profile update, avatar/banner, media upload, community actions |
| Giveaway Draws | Random winner selection from tweet replies with configurable filters |
| Account Monitoring | Real-time tracking of tweets, replies, quotes, retweets with ongoing usage confirmation |
| Webhooks | HMAC-SHA256 signature verification in Node.js, Python, Go |
| Media Download | Download images, videos, and GIFs from returned media URLs |
| Engagement Analytics | Likes, retweets, replies, quotes, views, bookmarks per tweet |
| Trending Topics | Regional trends plus supported news sources via Radar |
| Tweet Composition | Draft, refine, and score tweet text |
| Usage Guardrails | Check balance and estimate usage; dashboard handles plan and credit changes |
| TypeScript Types | Curated request and response types, plus the OpenAPI schema |
Claude Code, OpenAI Codex, Cursor, GitHub Copilot, Gemini CLI, Windsurf, VS Code Copilot, Cline, Roo Code, Goose, Amp, Augment, Continue, OpenHands, Trae, OpenCode, and any agent that supports the skills.sh protocol.
| Resource | Endpoints |
|---|---|
| X Lookups | Tweet, article, search, user profile, user tweets, user likes, user media, favoriters, followers you know, follow check, download media, and confirmation-gated private reads |
| Extractions | Create (23 types), estimate, list, get results, export |
| Monitors | Create with confirmation, list, get, update, delete |
| Events | List (filtered, paginated), get single |
| Webhooks | Create with destination confirmation, list, update, delete, test, deliveries |
| Trends | Regional trending topics |
| Radar | Trending topics & news from supported sources |
| Draws | Create with filters, list, get with winners, export |
| Styles | Analyze, save, list, get, delete, compare, performance |
| Compose | Tweet composition (compose, refine, score) |
| Drafts | Create, list, get, delete |
| Account | Get account, update locale, set X identity |
| Credits | Get balance |
| API Keys | Create, list, revoke |
| X Accounts | List, get, and disconnect already-connected accounts; dashboard handles connection and re-authentication |
| X Write | Confirmation-gated tweet, delete, like, unlike, retweet, follow, unfollow, DM, profile, avatar, banner, media upload, communities |
| Support | Create ticket, list, get, update, reply |
Use the X Twitter Scraper API in your language of choice. All SDKs are auto-generated, kept in sync with the OpenAPI spec, and follow idiomatic conventions for each ecosystem.
| Repo | Language | Install |
|---|---|---|
| x-twitter-scraper-typescript | TypeScript / Node.js | npm i x-twitter-scraper |
| x-twitter-scraper-python | Python | pip install x-twitter-scraper |
| x-twitter-scraper-go | Go | go get github.com/Xquik-dev/x-twitter-scraper-go |
| x-twitter-scraper-ruby | Ruby | gem install x-twitter-scraper |
| x-twitter-scraper-java | Java | Build from source while Maven Central publication is pending |
| x-twitter-scraper-kotlin | Kotlin | Build from source while Maven Central publication is pending |
| x-twitter-scraper-csharp | C# / .NET | dotnet add package XTwitterScraper |
| x-twitter-scraper-php | PHP | composer require xquik/x-twitter-scraper |
| x-twitter-scraper-cli | CLI | Build from source or install a pinned release tag |
| terraform-provider-x-twitter-scraper | Terraform | Build from source (release page) |
x-twitter-scraper/
├── skills/
│ └── x-twitter-scraper/
│ ├── SKILL.md # Main skill (auth, usage guardrails, endpoints, patterns)
│ ├── metadata.json # Version and references
│ ├── skill-card.md # Trust and release review card
│ ├── skillspector-report.md # Latest static SkillSpector evidence
│ └── references/
│ ├── api-endpoints.md # REST API routing index
│ ├── api-endpoints-*.md # Split endpoint sections for targeted agent loading
│ ├── mcp-tools.md # MCP tool selection rules and workflow patterns
│ ├── mcp-setup.md # Current MCP client setup and compatibility
│ ├── webhooks.md # Webhook setup & verification
│ ├── extractions.md # 23 extraction tool types
│ ├── types.md # TypeScript type routing index
│ ├── types-*.md # Split schema sections for targeted agent loading
│ └── python-examples.md # Python code examples
├── task-guides/ # Public task guides, not installable skills
├── server.json # MCP Registry metadata
├── logo.png # Marketplace logo
├── LICENSE # MIT
└── README.md # This file
MIT
FAQs
Xquik agent skill & plugin bundle for REST, MCP, webhooks, exports & confirmation-gated X workflows. Not affiliated with X Corp.
The npm package x-developer receives a total of 454 weekly downloads. As such, x-developer popularity was classified as not popular.
We found that x-developer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.