neynar — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited neynar (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Interact with the Farcaster decentralized social protocol via Neynar's API.
mkdir -p ~/.clawdbot/skills/neynar
cat > ~/.clawdbot/skills/neynar/config.json << 'EOF'
{
"apiKey": "YOUR_NEYNAR_API_KEY",
"signerUuid": "YOUR_SIGNER_UUID"
}
EOFNote: signerUuid is only required for posting casts. Get one via Neynar's signer management.
scripts/neynar.sh user dwr.eth# By username
scripts/neynar.sh user vitalik.eth
# By FID
scripts/neynar.sh user --fid 5650
# Multiple users
scripts/neynar.sh users dwr.eth,v,jessepollak# User's casts
scripts/neynar.sh feed --user dwr.eth
# Channel feed
scripts/neynar.sh feed --channel base
# Trending feed
scripts/neynar.sh feed --trending
# Following feed (requires signer)
scripts/neynar.sh feed --following# Search casts
scripts/neynar.sh search "ethereum"
# Search users
scripts/neynar.sh search-users "vitalik"
# Search in channel
scripts/neynar.sh search "onchain summer" --channel base# By hash
scripts/neynar.sh cast 0x1234abcd...
# By URL
scripts/neynar.sh cast "https://warpcast.com/dwr.eth/0x1234"# Simple cast
scripts/neynar.sh post "gm farcaster"
# Reply to cast
scripts/neynar.sh post "great point!" --reply-to 0x1234abcd
# Cast in channel
scripts/neynar.sh post "hello base" --channel base
# Cast with embed
scripts/neynar.sh post "check this out" --embed "https://example.com"# Like a cast
scripts/neynar.sh like 0x1234abcd
# Recast
scripts/neynar.sh recast 0x1234abcdscripts/neynar.sh follow dwr.eth
scripts/neynar.sh unfollow dwr.eth| Action | Endpoint | Auth |
|---|---|---|
| User lookup | GET /v2/farcaster/user/by_username | API key |
| User by FID | GET /v2/farcaster/user/bulk | API key |
| User feed | GET /v2/farcaster/feed/user/casts | API key |
| Channel feed | GET /v2/farcaster/feed/channels | API key |
| Trending | GET /v2/farcaster/feed/trending | API key |
| Search casts | GET /v2/farcaster/cast/search | API key |
| Get cast | GET /v2/farcaster/cast | API key |
| Post cast | POST /v2/farcaster/cast | API key + Signer |
| React | POST /v2/farcaster/reaction | API key + Signer |
| Follow | POST /v2/farcaster/user/follow | API key + Signer |
All responses are JSON. The script extracts key fields for readability:
{
"user": {
"fid": 3,
"username": "dwr.eth",
"display_name": "Dan Romero",
"follower_count": 450000,
"following_count": 2800,
"verified_addresses": ["0x..."]
}
}# Get latest casts from /base channel
scripts/neynar.sh feed --channel base --limit 20# Search for users by keyword
scripts/neynar.sh search-users "ethereum developer"# Post same content to Farcaster
scripts/neynar.sh post "gm, just shipped a new feature 🚀"# Get your notifications (requires signer)
scripts/neynar.sh notifications
# Reply to specific cast
scripts/neynar.sh post "thanks!" --reply-to 0xabc123| Error | Cause | Fix |
|---|---|---|
| 401 Unauthorized | Invalid API key | Check config.json |
| 403 Forbidden | Signer required | Set up signer for write operations |
| 404 Not Found | User/cast doesn't exist | Verify username/hash |
| 429 Rate Limited | Too many requests | Wait and retry |
For write operations (posting, liking, following), you need a signer:
signerUuid to your configManaged signers are easiest — Neynar handles the key custody.
X-RateLimit-Remaining header# Verify key works
curl -H "x-api-key: YOUR_KEY" \
"https://api.neynar.com/v2/farcaster/user/bulk?fids=1"~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.