Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ashish7802/awesome-api-skills --skill xquikgit clone --depth 1 https://github.com/ashish7802/awesome-api-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ashish7802/awesome-api-skills/xquik)<a href="https://agentmods.dev/skills/ashish7802/awesome-api-skills/xquik"><img src="https://agentmods.dev/badge/skills/ashish7802/awesome-api-skills/xquik/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ashish7802/awesome-api-skills/xquik"><img src="https://agentmods.dev/badge/skills/ashish7802/awesome-api-skills/xquik.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00807 |
| Opus 5 | $0.00000 | $0.00404 |
| Sonnet 5 | $0.00000 | $0.00161 |
| Haiku 4.5 | $0.00000 | $0.00081 |
Grade A, and why
xquik scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 83 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Xquik API Skill
Quick Start
Xquik provides REST APIs and SDKs for X/Twitter data workflows: tweet lookup, search, user profiles, communities, lists, trends, media, monitors, webhooks, and write actions.
npm install [email protected]
pip install x-twitter-scraper==0.4.1
Common Workflows
Read X/Twitter Data
Use the public OpenAPI spec to choose the endpoint for tweet search, tweet lookup, user lookup, follower checks, trends, communities, lists, or media workflows. Preserve IDs as strings and store capture timestamps with any research output.
Monitor Accounts And Keywords
Use monitor endpoints when the integration needs repeated account or keyword tracking. Route downstream notifications through webhooks and keep delivery handlers idempotent.
Build Analytics Dashboards
Normalize tweet, user, trend, community, and monitor records before inserting them into analytics tables. Keep pagination cursors with the captured batch so jobs can resume without duplicating rows.
Production Patterns
Use the official OpenAPI spec as the source of truth for endpoint paths, request bodies, and response contracts. Prefer the generated SDK for the target language when available, and keep any raw HTTP client behind a narrow adapter.
For paginated endpoints, persist next_cursor or the endpoint-specific cursor field with the job state. Retry transient 429 and 5xx responses with exponential backoff and a maximum retry budget.
Error Recovery
Handle structured API errors by status code and response body. Treat 401 and 403 as credential or permission issues, 429 as a rate-limit signal, and 5xx responses as transient service failures that may be retried.
Security Notes
Store API keys in environment variables or an approved credential store. Do not print keys in logs, test output, traces, or issue comments. Redact authorization headers before persisting request diagnostics.
Testing Guidance
Use fixture JSON for parser and normalization tests. For live smoke tests, call a low-impact read endpoint with a scoped key from the runtime environment and assert response shape rather than full payload values.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 83 lines · 0 tokens per session scan A 3ae87a50f1a9
xquik is a skill published in the GitHub repository ashish7802/awesome-api-skills (13 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 807 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
composio
Build AI agents and apps with Composio - access 200+ external tools with Tool Router or direct execution.
composio
Use 1000+ external apps via Composio - either directly through the CLI or by building AI agents and apps with the SDK.
analyzing-api-gateway-access-logs
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis of request patterns and anomaly detection. Use when investigating API abuse or building API-specific threat detection rules.
composio
Use 1000+ external apps via Composio - either directly through the CLI or by building AI agents and apps with the SDK.
composio
Use 1000+ external apps via Composio - either directly through the CLI or by building AI agents and apps with the SDK.
ios-simulator
Verify and debug native, React Native, Expo, or Flutter apps on an iOS Simulator with agent-device. Use when an agent needs to launch an app, inspect its live UI, tap, type, scroll, validate a code change, collect failure evidence, or reproduce a workflow on an iPhone or iPad Simulator.