SkillAtlasSkill 详情

x

Sign in your way. AI works on your behalf.

审核状态:已审核Quality 72Security 52

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年7月29日

Sigcli

Sign in your way. AI works on your behalf.

sig demo

AI agents need access to your work systems — Jira, wikis, calendars, internal APIs. But passing credentials through shell history, environment variables, and agent context windows is a security nightmare.

sig handles browser SSO, encrypts credentials at rest, and injects them into any process — so your agents authenticate without ever seeing secrets.

npm install -g @sigcli/cli

Quick Start

sig init                              # create ~/.sig/config.yaml
sig login https://jira.example.com    # authenticate via browser SSO — once

# now your AI agent can work on your behalf:
sig request https://jira.example.com/rest/api/2/myself
sig request https://jira.example.com/rest/api/2/search --method POST --body '{"jql":"assignee=currentUser()"}'

OAuth2 / API Tokens

For APIs that use OAuth2 Client Credentials (no browser needed):

sig login https://oauth-mock.mock.beeceptor.com \
  --strategy oauth2 \
  --token-url https://oauth-mock.mock.beeceptor.com/oauth/token/google \
  --client-id test-client \
  --client-secret test-secret

This mock server accepts any client_id/secret and returns a JWT token. After setup:

sig status oauth-mock                # check token status
sig get oauth-mock --no-redaction    # see raw Bearer token
sig logout oauth-mock                # clear token (keeps secrets)
sig get oauth-mock                   # auto-refreshes using stored credentials

Configure once, then all commands work the same as browser-based providers — sig get, sig run, sig proxy all inject the Bearer token automatically.

Why sig

  • Browser SSO — signs in through a real browser. Works with any website, any login flow.
  • OAuth2 Client Credentials — configure once, sig manages token exchange, expiry, and silent refresh. No browser needed.
  • Encrypted at rest — AES-256-GCM encryption. Every access is audit-logged.
  • Declarative config — define what to extract (cookies, localStorage, tokens) and how to apply them to requests.
  • Multi-provider — inject credentials from multiple systems in a single command.
  • MITM proxy — agents set HTTP_PROXY and credentials are injected transparently. Zero-trust.
  • AI-native — stable CLI with predictable exit codes and JSON output. Built for agents.

How It Works

You log in once               sig extracts & encrypts           AI agent operates
in your browser         -->   credentials locally          -->  on your behalf
(any SSO/login flow)          (~/.sig/credentials/)             (sig request / sig proxy)

sig login opens a browser, you log in normally (SSO, MFA, anything). sig extracts credentials based on extract[] rules, validates them against validateUrl or validateRule (or detects login redirects), encrypts with AES-256-GCM, and stores locally. When your agent needs a request, apply[] rules inject credentials into HTTP headers, body, or query params.

Provider Configuration

Most enterprise/SSO sites work with zero config. Public sites need a bit more. Here's the progression from simple to advanced:

1. Zero config (auto-provision)

For SSO-protected internal tools, just run:

sig login https://jira.example.com

sig opens a real browser, you log in, and it writes config automatically:

# ~/.sig/config.yaml (auto-generated)
jira-example:
    domains:
        - jira.example.com
    entryUrl: https://jira.example.com/
    strategy: browser
    extract:
        - from: cookies
          as: session
          match: '*'
    apply:
        - in: header
          name: Cookie
          value: '${session}'

2. Public sites (validateUrl + validateRule)

Public sites set tracking cookies to all visitors. sig can't tell auth cookies from junk using redirect detection alone. Use validateUrl, validateRule, or both:

validateUrl — point to a protected endpoint. sig probes it and accepts credentials only on 2xx:

reddit:
    domains:
        - www.reddit.com
        - reddit.com
    entryUrl: https://www.reddit.com/
    validateUrl: https://www.reddit.com/prefs/friends
    strategy: browser
    extract:
        - from: cookies
          as: cookie
          match: '*'
    apply:
        - in: header
          name: Cookie
          value: '${cookie}'

sig validates extracted credentials against validateUrl — 401/403 means not logged in, 2xx means success.

SitevalidateUrl
Reddithttps://www.reddit.com/prefs/friends
X (Twitter)https://x.com/i/api/2/notifications/all.json?count=1
LinkedInhttps://www.linkedin.com/voyager/api/me
YouTubehttps://www.youtube.com/account
V2EXhttps://www.v2ex.com/notifications
Zhihuhttps://www.zhihu.com/api/v4/me

validateRule — a JS expression for APIs that return 200 even when unauthenticated (e.g. with an error code in the JSON body). Use alone or together with validateUrl:

douyin:
    domains:
        - www.douyin.com
    entryUrl: https://www.douyin.com
    validateUrl: https://www.douyin.com/aweme/v1/web/notice/count/
    validateRule: 'res.body.status_code === 0'
    strategy: browser
    extract:
        - from: cookies
          as: cookie
          match: '*'
    apply:
        - in: header
          name: Cookie
          value: '${cookie}'

validateRule is a JavaScript expression with access to res (the validation response):

FieldTypeDescription
res.statusnumberHTTP status code
res.bodyobject | stringParsed JSON body (or raw string if not JSON)
res.headersRecord<string, string>Response headers

The expression must return a truthy value for credentials to be accepted. Examples:

# API returns { "status_code": 0 } on success
validateRule: 'res.body.status_code === 0'

# API returns { "logged_in": true }
validateRule: 'res.body.logged_in === true'

# Accept any 2xx that isn't an error page
validateRule: 'res.status >= 200 && res.status < 300 && !res.body.error'

When validateRule is set, it overrides the built-in status-code and redirect detection logic entirely.

3. Multiple domains

Some sites use multiple domains (e.g. x.com migrated from twitter.com). List all domains so sig captures cookies from both:

x:
    domains:
        - x.com
        - twitter.com
    entryUrl: https://x.com/
    validateUrl: https://x.com/i/api/2/notifications/all.json?count=1
    strategy: browser
    networkProxy: socks5://127.0.0.1:3333
    extract:
        - from: cookies
          as: cookie
          match: '*'
        - from: cookies
          as: ct0
          match: 'ct0'
    apply:
        - in: header
          name: Cookie
          value: '${cookie}'
        - in: header
          name: x-csrf-token
          value: '${ct0}'
        - in: header
          name: authorization
          value: 'Bearer AAAAAAAAAAAAAAAAAAAAANRILgAAAAAAnNwIzUejRCOuH5E6I8xnZz4puTs%3D1Zv7ttfk8LF81IUq16cHjhLTvJu4FA33AGWWjCpTnA'

4. localStorage extraction (advanced)

Some apps store tokens in localStorage instead of cookies. Use from: localStorage with match (key pattern) and jsonPath (nested field):

app-slack:
    domains:
        - your-org.enterprise.slack.com
    entryUrl: https://app.slack.com/client/YOUR_TEAM_ID
    strategy: browser
    extract:
        - from: cookies
          as: session
          match: '*'
        - from: localStorage
          as: xoxc-token
          match: localConfig_v2
          jsonPath: teams.YOUR_TEAM_ID.token
    apply:
        - in: header
          name: Cookie
          value: '${session}'
        - in: header
          name: Authorization
          value: 'Bearer ${xoxc-token}'

Full guide with debugging tips at sigcli.ai.

AI Agent Skills

Pre-built Python scripts that let AI agents operate 14+ web services — email, chat, forums, video platforms, social networks, and more. Each skill includes scripts + documentation that agents read and execute autonomously.

X (Twitter) skill: search and reply from your terminal

Install skills to your coding agent (Claude Code, Cursor, Windsurf, Cline):

npx @sigcli/skills            # install skills to your coding agent

See the full skills catalog for details.

Talks

  • Agentic Conf 2026 — From Zero-Trust Proxy to Skill-Ecosystem Governance: An Engineering Practice in Agentic Harness Engineering — slides (PDF)

Documentation

Full docs, configuration, SDK, and AI agent integration guide at sigcli.ai.

Issues

Report an issue https://github.com/sigcli/sigcli/issues

Or contact me: syncviip@gmail.com

License

MIT

研究与检索内容与创作Agent / MCP / Skill 创作

高风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 可能需要外部 token、网络权限或第三方服务。
  • 存在潜在风险命令,请谨慎安装。
  • 扫描发现:4 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/sigcli/sigcli.git
  3. 将 "skills/x" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/sigcli/sigcli.git
  3. 将 "skills/x" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/sigcli/sigcli.git
  3. 将 "skills/x" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/sigcli/sigcli.git
  3. 将 "skills/x" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/sigcli/sigcli.git
  3. 将 "skills/x" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: x
description: 'Interact with X (Twitter) — view profiles, read tweets and threads, search posts, check trending topics, view followers, post tweets, like, retweet, follow users, and bookmark tweets. Use this skill whenever the user mentions X, Twitter, tweets, @handles, wants to browse X posts, search X, view user profiles, or interact with X content. Also trigger when the user pastes an x.com or twitter.com URL.'

X (Twitter)

Skill Directory

<SKILL_DIR> is the directory containing this SKILL.md file. To find it, look at the path where this skill was loaded from. It is typically ~/.claude/skills/x (installed) or wherever this file lives. Determine it ONCE at the start and reuse it.

Setup (run FIRST — every time, before any operation)

You MUST complete this setup before running any script. Do NOT skip this step.

sig status x 2>&1

Check the JSON output fields configured and valid:

  • configured: false → run Provider Setup below. Do NOT proceed without completing it.
  • valid: false (but configured: true) → run sig login x, then re-check.
  • valid: true → detect proxy (see below), then execute the user's request.

Provider Setup

  1. Read <SKILL_DIR>/references/provider-config.yaml
  2. Append the provider block to ~/.sig/config.yaml under providers:
  3. Ask the user: "Do you need a proxy to access this site?" — if yes, add networkProxy: <url> under the provider in config.yaml
  4. Run sig login x (with --network-proxy <url> if proxy was specified)
  5. Verify: run sig status x again — must show valid: true before proceeding

Proxy Detection (after provider is valid)

grep -A15 "^\s*x:" ~/.sig/config.yaml | grep networkProxy | awk '{print $2}'

If this outputs a URL, prefix ALL python3 commands with HTTPS_PROXY=<url> HTTP_PROXY=<url>. If using socks5, convert to socks5h for python (e.g. socks5://... → socks5h://...). If empty, no proxy needed.

Running Scripts

All scripts require setup to be completed first (see above).


Scripts Reference

Read Operations

ScriptPurposeArgs
x_user.pyUser profile--username NAME
x_tweets.pyUser's tweet timeline--username NAME [--limit N]
x_tweet.pySingle tweet + thread--id ID_OR_URL [--limit N]
x_search.pySearch tweets--query TEXT [--limit N] [--type top|latest]
x_trending.pyTrending topics[--limit N]
x_followers.pyFollowers or following--username NAME [--limit N] [--mode followers|following]

Write Operations

ScriptPurposeArgs
x_post.pyCreate a tweet--cookie COOKIE --text TEXT [--reply-to ID]
x_delete.pyDelete a tweet--cookie COOKIE --id ID_OR_URL
x_like.pyLike or unlike--cookie COOKIE --id ID_OR_URL [--undo]
x_retweet.pyRetweet or unretweet--cookie COOKIE --id ID_OR_URL [--undo]
x_follow.pyFollow or unfollow--cookie COOKIE --username NAME [--undo]
x_bookmark.pyBookmark or unbookmark--cookie COOKIE --id ID_OR_URL [--undo]

Command Examples

All examples assume you've cd'd into <SKILL_DIR> and set proxy if needed.

Search tweets

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_search.py --query "Claude AI" --type top --limit 10'

View user profile

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_user.py --username elonmusk'

Read recent tweets

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_tweets.py --username elonmusk --limit 10'

Read a tweet thread

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_tweet.py --id "https://x.com/user/status/12345678"'

Post a tweet (ALWAYS confirm with user first)

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_post.py --cookie "$SIG_X_COOKIE" --text "Hello from sigcli!"'

Reply to a tweet

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_post.py --cookie "$SIG_X_COOKIE" --text "Great point!" --reply-to 2050336207561724307'

Delete a tweet (confirm with user first — irreversible)

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_delete.py --cookie "$SIG_X_COOKIE" --id 2050417089987711033'

Like / unlike

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_like.py --cookie "$SIG_X_COOKIE" --id 12345'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_like.py --cookie "$SIG_X_COOKIE" --id 12345 --undo'

Follow / unfollow

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_follow.py --cookie "$SIG_X_COOKIE" --username elonmusk'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_follow.py --cookie "$SIG_X_COOKIE" --username elonmusk --undo'

Bookmark / unbookmark

sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_bookmark.py --cookie "$SIG_X_COOKIE" --id 12345'
sig run x -- bash -c 'cd <SKILL_DIR> && python3 scripts/x_bookmark.py --cookie "$SIG_X_COOKIE" --id 12345 --undo'

Safety Rules

  1. ALWAYS show tweet text to user and get explicit confirmation before posting. Tweets are public.
  2. Tweets and replies must be ≤ 280 characters. Check length before posting. URLs count as ~23 characters (t.co shortening). If the text exceeds 280 characters, shorten it or split into a thread.
  3. Like, retweet, follow, bookmark are reversible — use --undo to reverse.
  4. Delete is irreversible — confirm with user before deleting.

Error Recovery

When a command fails, follow this decision tree:

ErrorMeaningAction
ConnectionErrorCan't reach x.comAsk user for proxy URL, then retry with HTTPS_PROXY=<url>
TimeoutNetwork too slowRetry once. If still fails, check proxy.
AUTH_REQUIRED / 401Cookie missing or expiredAuto-run sig login x (do NOT ask user), then retry the failed command.
HTTP_403IP blocked or query IDs staleRetry once (auto-refresh kicks in). If still 403, change proxy or wait.
HTTP_429Rate limitedWait 30 seconds, then retry.
NOT_FOUNDUser/tweet doesn't existVerify the ID or username with the user.
POST_FAILEDTweet creation failedShow error details to user. May be duplicate or policy violation.
Query ID / GraphQL errorStale query IDs, refresh failedClear cache (restart script), retry. If persistent, bundles changed.

Key principle: if ANY command fails on first run, do NOT silently proceed. Diagnose using this table, fix the issue, and re-validate before continuing with the user's request.


Technical Notes

  • Query ID caching: Query IDs are cached to a file (scripts/.query_id_cache.json) so they persist across script calls. First script invocation fetches from X's JS bundles (~3s), all subsequent calls within 1 hour read from disk instantly. The file auto-refreshes when the TTL expires.
  • Transaction ID: X requires x-client-transaction-id header. Generated automatically using the XClientTransaction library.
  • Pagination: Timeline endpoints paginate internally (up to 5 pages).
  • Cookie TTL: Cookies typically last 7 days. After that, re-authenticate.

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!