by nirholas
⚡ The Complete X/Twitter Automation Toolkit — Scrapers, MCP server for AI agents (Claude/GPT), CLI, browser scripts. No API fees. Open source. Unfollow people who don't follow back. Monitor real-time analytics. Auto follow, like, comment, scrape, without API. Follow Bot. Like bot. Grow your account automatically.
# Add to your Claude Code skills
git clone https://github.com/nirholas/XActionsLast scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@remotion/bundler: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@remotion/cli: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@remotion/renderer: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@remotion/studio: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@remotion/studio-server: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "axios: Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF",
"severity": "high"
},
{
"type": "npm-audit",
"message": "basic-ftp: Basic FTP has Path Traversal Vulnerability in its downloadToDir() method",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "body-parser: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "bull: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "cookie: cookie accepts cookie name, path, and domain with out of bounds characters",
"severity": "low"
},
{
"type": "npm-audit",
"message": "engine.io: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ethers: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "exceljs: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "express: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "express-rate-limit: express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to path traversal via percent-encoded dot segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "follow-redirects: follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "hono: Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "lodash: lodash vulnerable to Code Injection via `_.template` imports key names",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "node-cron: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict",
"severity": "high"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "qs: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "serialize-javascript: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "socket.io: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "socket.io-adapter: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "socket.io-parser: socket.io allows an unbounded number of binary attachments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "terser-webpack-plugin: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tmp: tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape",
"severity": "high"
},
{
"type": "npm-audit",
"message": "undici: Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "viem: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "medium"
}
],
"status": "FAILED",
"scannedAt": "2026-05-30T15:06:56.511Z",
"npmAuditRan": true,
"pipAuditRan": true
}XActions is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by nirholas. ⚡ The Complete X/Twitter Automation Toolkit — Scrapers, MCP server for AI agents (Claude/GPT), CLI, browser scripts. No API fees. Open source. Unfollow people who don't follow back. Monitor real-time analytics. Auto follow, like, comment, scrape, without API. Follow Bot. Like bot. Grow your account automatically. It has 518 GitHub stars.
XActions failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/nirholas/XActions" and add it to your Claude Code skills directory (see the Installation section above).
XActions is primarily written in HTML. It is open-source under nirholas on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh XActions against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Website · npm · Docs · MCP Server · Docker · API Ref
npx xactions profile nasa
⚡ @NASA
Name: NASA
Bio: Making the seemingly impossible, possible. ✨
Location: Pale Blue Dot
Website: http://www.nasa.gov/
Joined: 2007-12-19
Following: 117 Followers: 92.4M
Tweets: 74.2K Listed: 0
✓ Verified
No API key. No account. No browser. Real data in about a second.
npx xactions tweets nasa --limit 100 --output nasa.csv # timeline to a spreadsheet
npx xactions login # unlock search, followers, DMs
npx xactions search "your brand" --limit 50 # what people are saying
Why build with XActions instead of the alternatives?
| Feature | XActions | twikit | twscrape | x-use | xmcp (official) | bird | twitter-cli | Agent-Reach |
|---|---|---|---|---|---|---|---|---|
| No API Key Required | ✅ | ✅ Cookies | ✅ Account pool | ✅ Browser | ❌ X API keys | ✅ Cookies | ❌ X API keys | ✅ |
| MCP Server (AI agents) | ✅ 153 tools | ❌ | ❌ | ✅ (33-tool server) | ✅ (140-tool, metered) | ❌ | ❌ | ❌ Skills, not MCP |
| Browser Console Scripts | ✅ 95 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| AI Voice Agent in Spaces | ✅ Join, listen, speak | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| CLI | ✅ 56 commands | ❌ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ |
| Human approval gate on writes | ✅ Every write held as a draft | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Daily action caps that survive a restart | ✅ Per account, on disk | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Account pool with rotation | ✅ SQLite, per-operation windows | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
| Resumable long scrapes | ✅ Cursor checkpoints | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| Cookies from your installed browser | ✅ --from-browser, --cookies-file |
❌ | ❌ | ❌ | ❌ | ✅ | ✅ | ❌ |
| Official X archive import | ✅ xactions archive |
❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| Language | JavaScript | Python | Python | TypeScript | TypeScript | TypeScript | Python | Python |
XActions is the only toolkit that works in the browser, terminal, and with AI agents, all without an API key.
Competitor columns come from the competitive audit, which names each project and what it does better than us. Where a rival led, we built it: the approval gate and the daily caps follow x-use, the account pool follows twscrape, cursor resume follows Scweet, and browser cookie import follows bird and twitter-cli.
| Area | What changed |
|---|---|
| Delete every reply you sent one account | scripts/searchSweep.js turns any X search into a bulk action. Open x.com/search?q=from:you @someone&f=live, paste it, and delete, like, repost, or reply to every result, with a floating panel, a dry run, filters that protect posts that did numbers, and multiple passes because X search returns a slice at a time. Deletes only ever touch your own posts. Docs. |
| Sweep a whole profile | scripts/engageProfile.js likes, reposts, and replies to every post on an account from the console, with a floating panel, dry run, resume, undo, and replies from your templates or from an LLM given a one-line brief (Grok works straight from the console; any provider through the extension). xactions engage USERNAME --like --repost --comment --prompt "..." does the same from the terminal with any provider. Docs. |
| A CLI you can find your way around | All 56 commands are now grouped by task instead of listed alphabetically. xactions quickstart gives a guided first run that adapts to what you already have set up. |
| Tab completion | xactions completion bash|zsh|fish prints a completion script generated from the live command tree, so every command, sub-command, and flag completes. |
| Log in without touching DevTools | xactions login --from-browser reads x.com cookies straight out of an installed Chrome, Chromium, Brave, Edge, Arc or Firefox profile. --cookies-file imports a Netscape cookies.txt, a Cookie-Editor or EditThisCookie JSON export, or a Playwright / Puppeteer storageState. A full cookie jar beats a bare auth_token, because it carries the ct0 every write needs. |
| Query IDs that heal themselves | X rotates its GraphQL query IDs and every pinned client 404s at once. Ours are discovered from x.com's own bundles and cached, so a rotation is invisible. xactions doctor reports the cache age. |
| Requests signed like the real client | Every GraphQL call carries an x-client-transaction-id header computed the way x.com's own web client computes it, so reads get the answer the browser gets. |
| An account pool, and scrapes that resume | Sessions live in a SQLite database with their own proxy and a per-operation rate-limit window read from X's own headers. The pooled client rotates on a 429 and locks an account on a 401. A checkpoint written after every page means a 50,000-follower scrape that dies at page 400 restarts from its cursor, not from page one. |
| Daily action caps | Every MCP write is charged against a rolling 24 hour per-account budget stored on disk. The cap survives a restart, a crash, and a fresh npx xactions-mcp, and a call that would go over is refused before it reaches X. Defaults follow X's own published limits. |
| Writes a human releases | XACTIONS_MCP_REQUIRE_APPROVAL=1 turns every write tool into a draft. Review with xactions drafts list, release with xactions drafts approve <id>, or use the x_list_drafts / x_approve_draft / x_discard_draft tools. |
| MCP tool groups | The tool list is filterable: --tools read,analytics or XACTIONS_MCP_TOOLS=read advertises only what the session needs, and a filtered tool is neither advertised nor callable. Groups: read, write, dm, lists, spaces, analytics, ai, grok, automation, monitoring, workflows, persona, graph, data, x402, drafts, auth. |
| MCP over HTTP | xactions-mcp --http serves the Streamable HTTP transport on /mcp for remote and hosted clients, with optional bearer auth via XACTIONS_MCP_TOKEN. stdio is still the default. |
| One-drag install for Claude Desktop | The .mcpb bundle carries the server and its dependencies and prompts for the session cookie and tool groups at install time, so nothing is typed into |