---
name: xurl
description: Use when reading or posting on X/Twitter via the official xurl CLI through Oracle's bounded xurl tool.
---

# xurl (Oracle-bounded)

Oracle has no shell. Talk to X only through the `xurl` tool.

## Preconditions
- `ORACLE_XURL_ENABLED=true` in `~/.config/oracle/env`
- Local `xurl` binary on PATH (or `ORACLE_XURL_BIN`)
- Operator already ran `xurl auth oauth2` outside the agent; tokens live in `~/.xurl`
- Never read `~/.xurl` into context. Never pass `--verbose` or inline secrets.

## Read (default)
```
xurl command=whoami
xurl command=user handle=demi_hl
xurl command=read id=https://x.com/user/status/123
xurl command=search query="from:demi_hl" limit=5
xurl command=timeline limit=10
xurl command=mentions limit=10
xurl command=auth args=["status"]
```

## Write (requires ORACLE_XURL_ALLOW_WRITE=true)
```
xurl command=post text="gm"
xurl command=reply id=123 text="agreed"
xurl command=like id=123
xurl command=follow handle=someone
```

Confirm target + wording with the user before any write.

## Failures
- `CreditsDepleted` / free-tier: reads need Basic. For public or authenticated page context, load `chrome-profile-browser` and have the user grant the exact X tab through Oracle Sidecar. Use `browser_exec` only for isolated, unauthenticated public pages when its sandbox is explicitly enabled.
- Auth errors: tell the user to re-run `xurl auth oauth2 --app <app> <user>` in their own terminal.
- Never attempt `auth apps add` or oauth from the agent.
