复制安装命令
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
Sign in your way. AI works on your behalf.
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
来源文件:README.md
Sign in your way. AI works on your behalf.
AI agents need access to your work systems — Jira, wikis, calendars, internal APIs. But passing credentials through shell history, environment variables, and agent context windows is a security nightmare.
sig handles browser SSO, encrypts credentials at rest, and injects them into any process — so your agents authenticate without ever seeing secrets.
npm install -g @sigcli/cli
sig init # create ~/.sig/config.yaml
sig login https://jira.example.com # authenticate via browser SSO — once
# now your AI agent can work on your behalf:
sig request https://jira.example.com/rest/api/2/myself
sig request https://jira.example.com/rest/api/2/search --method POST --body '{"jql":"assignee=currentUser()"}'
For APIs that use OAuth2 Client Credentials (no browser needed):
sig login https://oauth-mock.mock.beeceptor.com \
--strategy oauth2 \
--token-url https://oauth-mock.mock.beeceptor.com/oauth/token/google \
--client-id test-client \
--client-secret test-secret
This mock server accepts any client_id/secret and returns a JWT token. After setup:
sig status oauth-mock # check token status
sig get oauth-mock --no-redaction # see raw Bearer token
sig logout oauth-mock # clear token (keeps secrets)
sig get oauth-mock # auto-refreshes using stored credentials
Configure once, then all commands work the same as browser-based providers — sig get, sig run, sig proxy all inject the Bearer token automatically.
HTTP_PROXY and credentials are injected transparently. Zero-trust.You log in once sig extracts & encrypts AI agent operates
in your browser --> credentials locally --> on your behalf
(any SSO/login flow) (~/.sig/credentials/) (sig request / sig proxy)
sig login opens a browser, you log in normally (SSO, MFA, anything). sig extracts credentials based on extract[] rules, validates them against validateUrl or validateRule (or detects login redirects), encrypts with AES-256-GCM, and stores locally. When your agent needs a request, apply[] rules inject credentials into HTTP headers, body, or query params.
Most enterprise/SSO sites work with zero config. Public sites need a bit more. Here's the progression from simple to advanced:
For SSO-protected internal tools, just run:
sig login https://jira.example.com
sig opens a real browser, you log in, and it writes config automatically:
# ~/.sig/config.yaml (auto-generated)
jira-example:
domains:
- jira.example.com
entryUrl: https://jira.example.com/
strategy: browser
extract:
- from: cookies
as: session
match: '*'
apply:
- in: header
name: Cookie
value: '${session}'
validateUrl + validateRule)Public sites set tracking cookies to all visitors. sig can't tell auth cookies from junk using redirect detection alone. Use validateUrl, validateRule, or both:
validateUrl — point to a protected endpoint. sig probes it and accepts credentials only on 2xx:
reddit:
domains:
- www.reddit.com
- reddit.com
entryUrl: https://www.reddit.com/
validateUrl: https://www.reddit.com/prefs/friends
strategy: browser
extract:
- from: cookies
as: cookie
match: '*'
apply:
- in: header
name: Cookie
value: '${cookie}'
sig validates extracted credentials against validateUrl — 401/403 means not logged in, 2xx means success.
| Site | validateUrl |
|---|---|
https://www.reddit.com/prefs/friends | |
| X (Twitter) | https://x.com/i/api/2/notifications/all.json?count=1 |
https://www.linkedin.com/voyager/api/me | |
| YouTube | https://www.youtube.com/account |
| V2EX | https://www.v2ex.com/notifications |
| Zhihu | https://www.zhihu.com/api/v4/me |
validateRule — a JS expression for APIs that return 200 even when unauthenticated (e.g. with an error code in the JSON body). Use alone or together with validateUrl:
douyin:
domains:
- www.douyin.com
entryUrl: https://www.douyin.com
validateUrl: https://www.douyin.com/aweme/v1/web/notice/count/
validateRule: 'res.body.status_code === 0'
strategy: browser
extract:
- from: cookies
as: cookie
match: '*'
apply:
- in: header
name: Cookie
value: '${cookie}'
validateRule is a JavaScript expression with access to res (the validation response):
| Field | Type | Description |
|---|---|---|
res.status | number | HTTP status code |
res.body | object | string | Parsed JSON body (or raw string if not JSON) |
res.headers | Record<string, string> | Response headers |
The expression must return a truthy value for credentials to be accepted. Examples:
# API returns { "status_code": 0 } on success
validateRule: 'res.body.status_code === 0'
# API returns { "logged_in": true }
validateRule: 'res.body.logged_in === true'
# Accept any 2xx that isn't an error page
validateRule: 'res.status >= 200 && res.status < 300 && !res.body.error'
When validateRule is set, it overrides the built-in status-code and redirect detection logic entirely.
Some sites use multiple domains (e.g. x.com migrated from twitter.com). List all domains so sig captures cookies from both:
x:
domains:
- x.com
- twitter.com
entryUrl: https://x.com/
validateUrl: https://x.com/i/api/2/notifications/all.json?count=1
strategy: browser
networkProxy: socks5://127.0.0.1:3333
extract:
- from: cookies
as: cookie
match: '*'
- from: cookies
as: ct0
match: 'ct0'
apply:
- in: header
name: Cookie
value: '${cookie}'
- in: header
name: x-csrf-token
value: '${ct0}'
- in: header
name: authorization
value: 'Bearer AAAAAAAAAAAAAAAAAAAAANRILgAAAAAAnNwIzUejRCOuH5E6I8xnZz4puTs%3D1Zv7ttfk8LF81IUq16cHjhLTvJu4FA33AGWWjCpTnA'
Some apps store tokens in localStorage instead of cookies. Use from: localStorage with match (key pattern) and jsonPath (nested field):
app-slack:
domains:
- your-org.enterprise.slack.com
entryUrl: https://app.slack.com/client/YOUR_TEAM_ID
strategy: browser
extract:
- from: cookies
as: session
match: '*'
- from: localStorage
as: xoxc-token
match: localConfig_v2
jsonPath: teams.YOUR_TEAM_ID.token
apply:
- in: header
name: Cookie
value: '${session}'
- in: header
name: Authorization
value: 'Bearer ${xoxc-token}'
Full guide with debugging tips at sigcli.ai.
Pre-built Python scripts that let AI agents operate 14+ web services — email, chat, forums, video platforms, social networks, and more. Each skill includes scripts + documentation that agents read and execute autonomously.
Install skills to your coding agent (Claude Code, Cursor, Windsurf, Cline):
npx @sigcli/skills # install skills to your coding agent
See the full skills catalog for details.
Full docs, configuration, SDK, and AI agent integration guide at sigcli.ai.
Report an issue https://github.com/sigcli/sigcli/issues
Or contact me: syncviip@gmail.com
name: x
description: 'Interact with X (Twitter) — view profiles, read tweets and threads, search posts, check trending topics, view followers, post tweets, like, retweet, follow users, and bookmark tweets. Use this skill whenever the user mentions X, Twitter, tweets, @handles, wants to browse X posts, search X, view user profiles, or interact with X content. Also trigger when the user pastes an x.com or twitter.com URL.'<SKILL_DIR> is the directory containing this SKILL.md file. To find it, look at the path where this skill was loaded from. It is typically ~/.claude/skills/x (installed) or wherever this file lives. Determine it ONCE at the start and reuse it.
You MUST complete this setup before running any script. Do NOT skip this step.
sig status x 2>&1
Check the JSON output fields configured and valid:
configured: false → run Provider Setup below. Do NOT proceed without completing it.valid: false (but configured: true) → run sig login x, then re-check.valid: true → detect proxy (see below), then execute the user's request.<SKILL_DIR>/references/provider-config.yaml~/.sig/config.yaml under providers:networkProxy: <url> under the provider in config.yamlsig login x (with --network-proxy <url> if proxy was specified)sig status x again — must show valid: true before proceedinggrep -A15 "^\s*x:" ~/.sig/config.yaml | grep networkProxy | awk '{print $2}'
If this outputs a URL, prefix ALL python3 commands with HTTPS_PROXY=<url> HTTP_PROXY=<url>.
If using socks5, convert to socks5h for python (e.g. socks5://... → socks5h://...).
If empty, no proxy needed.
All scripts require setup to be completed first (see above).
| Script | Purpose | Args |
|---|---|---|
x_user.py | User profile | --username NAME |
x_tweets.py | User's tweet timeline | --username NAME [--limit N] |
x_tweet.py | Single tweet + thread | --id ID_OR_URL [--limit N] |
x_search.py | Search tweets | --query TEXT [--limit N] [--type top|latest] |
x_trending.py | Trending topics | [--limit N] |
x_followers.py | Followers or following | --username NAME [--limit N] [--mode followers|following] |
| Script | Purpose | Args |
|---|---|---|
x_post.py | Create a tweet | --cookie COOKIE --text TEXT [--reply-to ID] |
x_delete.py | Delete a tweet | --cookie COOKIE --id ID_OR_URL |
x_like.py | Like or unlike | --cookie COOKIE --id ID_OR_URL [--undo] |
x_retweet.py | Retweet or unretweet | --cookie COOKIE --id ID_OR_URL [--undo] |
x_follow.py | Follow or unfollow | --cookie COOKIE --username NAME [--undo] |
x_bookmark.py | Bookmark or unbookmark | --cookie COOKIE --id ID_OR_URL [--undo] |
All examples assume you've cd'd into <SKILL_DIR> and set proxy if needed.
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_search.py --query "Claude AI" --type top --limit 10'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_user.py --username elonmusk'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_tweets.py --username elonmusk --limit 10'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_tweet.py --id "https://x.com/user/status/12345678"'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_post.py --cookie "$SIG_X_COOKIE" --text "Hello from sigcli!"'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_post.py --cookie "$SIG_X_COOKIE" --text "Great point!" --reply-to 2050336207561724307'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_delete.py --cookie "$SIG_X_COOKIE" --id 2050417089987711033'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_like.py --cookie "$SIG_X_COOKIE" --id 12345'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_like.py --cookie "$SIG_X_COOKIE" --id 12345 --undo'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_follow.py --cookie "$SIG_X_COOKIE" --username elonmusk'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_follow.py --cookie "$SIG_X_COOKIE" --username elonmusk --undo'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_bookmark.py --cookie "$SIG_X_COOKIE" --id 12345'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_bookmark.py --cookie "$SIG_X_COOKIE" --id 12345 --undo'
--undo to reverse.When a command fails, follow this decision tree:
| Error | Meaning | Action |
|---|---|---|
ConnectionError | Can't reach x.com | Ask user for proxy URL, then retry with HTTPS_PROXY=<url> |
Timeout | Network too slow | Retry once. If still fails, check proxy. |
AUTH_REQUIRED / 401 | Cookie missing or expired | Auto-run sig login x (do NOT ask user), then retry the failed command. |
HTTP_403 | IP blocked or query IDs stale | Retry once (auto-refresh kicks in). If still 403, change proxy or wait. |
HTTP_429 | Rate limited | Wait 30 seconds, then retry. |
NOT_FOUND | User/tweet doesn't exist | Verify the ID or username with the user. |
POST_FAILED | Tweet creation failed | Show error details to user. May be duplicate or policy violation. |
| Query ID / GraphQL error | Stale query IDs, refresh failed | Clear cache (restart script), retry. If persistent, bundles changed. |
Key principle: if ANY command fails on first run, do NOT silently proceed. Diagnose using this table, fix the issue, and re-validate before continuing with the user's request.
scripts/.query_id_cache.json) so they persist across script calls. First script invocation fetches from X's JS bundles (~3s), all subsequent calls within 1 hour read from disk instantly. The file auto-refreshes when the TTL expires.x-client-transaction-id header. Generated automatically using the XClientTransaction library.
评论 (0)
暂无评论,成为第一个评论者吧!