Security

Read-Only X Access and Approved Agent-Skill Installs

How XSkills limits X permissions, preserves evidence, grades risk, binds approval to a checksum, and verifies every file before installation.

Published July 22, 2026 · Updated July 22, 2026

XSkills automates qualification, research, and package preparation. It does not automate the decision to install a new capability. The security model keeps source access narrow, evidence attached, and final authority with the person who owns the coding environment.

Read-only access to X

XSkills requests the access needed to read bookmarks, posts, and account identity. It does not request permission to publish, reply, delete, follow, or alter the connected X account. Access can be disconnected from XSkills settings and is marked for reauthorization when credentials expire.

Qualification before generation

Not every bookmark reaches the compiler. Candidates must describe a repeatable workflow with enough specificity and evidence to support useful instructions. News, announcements, opinions, and vague inspiration are rejected early. This reduces the chance that fluent prose is mistaken for a trustworthy procedure.

Evidence travels with the package

The original post, inspected sources, evidence map, quality grade, risk assessment, and unresolved prerequisites stay associated with the draft. Unsupported claims are excluded or identified as missing requirements; they are not silently converted into commands.

Approval applies to one exact version

Every file is hashed and the package receives an aggregate checksum. Your approval records that checksum—not merely the skill name. Editing an instruction, reference, manifest, or evaluation query produces a different checksum and requires another review.

The connector verifies before writing

What still requires your judgment

A correctly packaged skill can still be inappropriate for a particular repository, dataset, or account. Review the workflow, sources, requested side effects, and target environment before approval. Downstream agent and tool permissions continue to govern what the installed skill can actually do.

Operational details are in the review documentation and connector guide. Privacy and retention terms are described in the Privacy Policy.