Bankr Twitter AgentBLOCK
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Overview
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
4029e336cef5OBSERVED · 2026-10-09What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: twitter-agent description: Build and run a Twitter/X agent with a distinct personality and automated workflows emoji: 🐦 tags: [twitter, x, social, agent, automation] visibility: public --- # Twitter Agent Skill This skill provides a framework for creating, managing, and automating a Twitter/X agent with a persistent personality and voice. ## Prerequisites ### X Account Setup (REQUIRED — Do This First) Before anything else, the agent's X account MUST be marked as an **automated account**. X requires this disclosure for any account posting with API automation; skipping it is the fastest way to get the account suspended. **Exact path (do this once, while logged in as the agent account):** 1. Log in to x.com as the agent account. 2. Go to **Settings and privacy** → **Your account** → **Account information**. 3. Scroll to **Automation** and tap it. 4. Re-enter the password when prompted. 5. Set **Managing account** to the human/handle responsible for the bot and save. Direct link: https://x.com/settings/account/automation This adds the "Automated by @..." label to the profile and replies. It is non-negotiable — do not run this skill against an account that has not been labeled. ### Environment Variables Set these 4 variables in your Bankr settings (gear icon -> Env Vars). Generate them from the [X Developer Portal](https://developer.x.com/en/portal/dashboard) with **Read and Write** permissions enabled: - `X_API_KEY`: Consumer Key (OAuth 1.0a) - `X_API_KEY_SECRET`: Consumer Secret - `X_ACCESS_TOKEN`: User Access Token - `X_ACCESS_TOKEN_SECRET`: User Access Token Secret ### Approval Channel for Automations Bankr automations natively support routing their output to Telegram. When creating an automation, choose **Telegram** as the delivery destination — the automation's final message is delivered to your linked Telegram directly, no bot token or custom code required. Automations used as "approval-gated" drafters rely on this: the automation composes drafts, runs guardrail checks, and instead of posting flagged drafts, it ends its run by sending them to Telegram for you to approve manually. No env vars are needed for this — just link your Telegram to your Bankr account and select Telegram as the output when setting up each automation. ## The Personality & Storyline System Every agent requires two files in the Bankr file system to maintain a consistent voice and narrative: 1. `twitter-personality.md`: Defines the character, voice, and style rules. 2. `twitter-storyline.md`: Tracks the ongoing narrative, recent events, and current state of the character. ### Building a Personality If no personality file exists, the agent should walk the user through creating one by asking: 1. "what's the account about? give me the elevator pitch" 2. "how would you describe the vibe? pick a few: sharp, witty, degen, serious, chaotic, chill, academic, edgy, wholesome, provocative, technical, meme-heavy" 3. "what topics do you want to tweet about? what's strictly off-limits?" 4. "short punchy tweets or longer form? threads?" 5. "emojis? hashtags? lowercase or proper grammar?" 6. "any signature phrases or words you always use?" 7. "give me 2-3 example tweets that sound like you -- or accounts you want to sound like" 8. "is there a character or persona the account should tweet as? or is it just you?" After gathering answers, the agent composes the personality file and saves it as `twitter-personality.md`. ### Pre-Flight Checklist Before composing or posting any tweet, the agent MUST: 1. Load `twitter-personality.md` using `read_file`. 2. Load `twitter-storyline.md` using `read_file` to understand the current narrative context. 3. Filter the proposed content through the personality directives and ensure it continues the storyline. 4. Cross-reference all drafted content against the storyline file to prevent repeating jokes, themes, or phrases already used. 5. Run the Guardrail Check (see below) before any post -- manual OR automated. 6. After posting, update `twitter-storyline.md` with the new tweet and any narrative developments using `edit_file` (NOT `create_file` -- see File Management below). ## Guardrails (CRITICAL -- Apply to Manual AND Automated Posts) These apply to every tweet the agent drafts, whether running manually or on a schedule. A draft that violates any of these routes to approval instead of posting. ### Never Reply Unprompted (Hard Rule) The agent MUST NEVER reply to a post it was not invited into. An agent that cold-replies to strangers' timelines is the single fastest path to an X suspension. There are exactly three legal post types: 1. **Top-level posts** composed by the agent itself. 2. **Replies to mentions** — only when the agent's handle is *explicitly* tagged in the tweet text (case-insensitive `@handle` token in `text`, not merely an `in_reply_to_user_id` match). 3. **Replies to comments on the agent's own posts** — i.e. replies where `in_reply_to_user_id` is the agent's own user ID AND the parent tweet in the conversation tree is authored by the agent. Anything outside those three categories is FORBIDDEN and must be dropped from the draft set before the guardrail check even runs. Quote-tweets of random accounts, reply-chains the agent isn't tagged in, trending-topic replies, "drive-by" replies to big accounts the agent admires — all prohibited under autonomous operation. If the user manually drafts one of these in a session, it still requires explicit approval and is never posted automatically. Mention-scan filter (enforce in the fetch step): - Keep a mention only if `text` contains the agent's `@handle` as a standalone token. - OR keep it if `in_reply_to_user_id === agentUserId` AND the root of `conversation_id` is authored by the agent. - Discard everything else before ranking. ### Hard Blocks (Always Route to Approval) 1. **Never autonomously tag `@bankrbot`.** Bankr's X agent executes onchain actions (transfers, swaps, deploys) when tagged from a w
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
> Run the twitter-agent skill for a mentions reply sweep. Steps: (1) Load the twitter-agent skill. (2) Read twitter-personality.md and twitter-storyline.md. (3) Fetch the last 50 mentions via the X AP
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
4029e336cef5full audit observations/trust-audit/skill/bankrbot__bankr-twitter-agent.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4029e336cef5 | BLOCK | D | 69 | first audit |
Questions
What does the Bankr Twitter Agent skill do?
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Is Bankr Twitter Agent safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What can Bankr Twitter Agent access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (4029e336cef5), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.