agentCLAWHUBUnverified

kiaaccess

This skill should be used when the user asks about their Kia vehicle through the Kia Access / Kia Owners account. Triggers on phrases like "is the car locked", "unlock the Kia", "start the car's climate", "warm up the car", "where is my car", "what's the EV charge at", "check the car's battery", "lock the doors", or any request to read or command a Kia vehicle. Skill: kiaaccess Owner: chrischall Summary: This skill should be used when the user asks about their Kia vehicle through the Kia Access / Kia Owners account. Triggers on phrases like "is the car locked", "unlock the Kia", "start the car's climate", "warm up the car", "where is my car", "what's the EV charge at", "check the car's battery", "lock the doors", or any request to read or command a Kia vehicle. Tags: latest

OpenClaw

Rank

62

Safety

84

Downloads

1.8k

Updated

Oct 10, 2026

Version

2.0.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.8K downloadsadoption · observed Oct 10, 2026
Latest release
2.0.0release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cjx1a349nz5apaqp02vgz4h85728z:kiaaccess
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess/snapshot"

Documentation

CLAWHUB

104,868 characters of source documentation, loaded on request.

Extracted files

3 files captured from the source.

SKILL.md

---
name: kiaaccess
description: This skill should be used when the user asks about their Kia vehicle through the Kia Access / Kia Owners account. Triggers on phrases like "is the car locked", "unlock the Kia", "start the car's climate", "warm up the car", "where is my car", "what's the EV charge at", "check the car's battery", "lock the doors", or any request to read or command a Kia vehicle.
---

# kiaaccess-mcp

MCP server for the Kia Owners API used by the Kia Access app — vehicle status, location, EV charge state, and confirmation-gated door, climate, and charging commands, using the user's own Kia account.

- **npm:** [npmjs.com/package/kiaaccess-mcp](https://www.npmjs.com/package/kiaaccess-mcp)
- **Source:** [github.com/chrischall/kiaaccess-mcp](https://github.com/chrischall/kiaaccess-mcp)

## Setup

Add to `.mcp.json` in your project or `~/.claude/mcp.json`:

```json
{
  "mcpServers": {
    "kiaaccess": {
      "command": "npx",
      "args": ["-y", "kiaaccess-mcp"],
      "env": {
        "KIA_USERNAME": "[email protected]",
        "KIA_PASSWORD": "your-password",
        "KIA_WRITE_MODE": "comfort"
      }
    }
  }
}
```

`KIA_WRITE_MODE` decides which command tools are registered at all: `none` (reads only), `comfort` (climate + charging, the default), `all` (also door lock/unlock). An unrecognised value fails closed to `none`.

## First run — the one-time MFA bootstrap

Kia challenges each new device once. Start with `kia_session_status`; if it reports `hasSession: false`:

1. `kia_start_login`, confirmed (see [Confirmations](#confirmations)) → returns `otpKey` + `xid` and the masked destinations Kia has on file.
2. `kia_send_otp(otpKey, xid, notifyType)` — ask the user whether they can read `SMS` or `EMAIL` right now. The code expires in ~2 minutes.
3. `kia_verify_otp(otpKey, xid, otp)` — same `otpKey`/`xid`, plus the code the user received.
4. `kia_list_vehicles` to confirm, and to get the `vehicleKey` every other tool needs.

The remember-me token is then stored locally and refreshes sessions silently forever; MFA is never needed again on that machine. `kia_forget_session` (confirmation-gated) throws it away so the bootstrap can be repeated.

A server with no one to read an OTP cannot run these steps at all. Bootstrap it elsewhere and have the user copy the `rmtoken` from that machine's `~/.kiaaccess-mcp/session.json` into `KIA_RMTOKEN` themselves (no tool returns it, and it must never pass through the conversation), with `KIA_DEVICE_ID` set to the same uuid on both machines — the token is minted against a device uuid and is worthless with a different one. `KIA_RMTOKEN` wins over the local store.

**If a login is rejected, STOP.** Kia counts failed logins and eventually enforces reCAPTCHA, which breaks server-side login for that account permanently. Tell the user to check the credentials in the Kia Access app and fix the environment — never retry with a guessed password.

## Tools

### Account
| Tool | Notes |
|------|-------|
| `k

_meta.json

{
  "ownerId": "kn700jq4sjtf2anb0rk3ft4p7n856872",
  "slug": "kiaaccess",
  "version": "2.0.0",
  "publishedAt": 1791588253194
}

skill-card.md

## Description:

Helps users check Kia vehicle status, location, and charging and request confirmation-gated vehicle commands through their Kia Access account.

This skill is ready for commercial/non-commercial use.

## Publisher:

[chrischall](https://clawhub.ai/user/chrischall)

### License/Terms of Use:

MIT-0

## Use Case:

Kia owners use this skill to ask an agent about their vehicle's status, location, and EV charging, and to approve climate, charging, or door commands for a selected vehicle.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Vehicle location and Kia account data are sensitive.

Mitigation: Install only when comfortable granting access; keep passwords, remember-me tokens, and session files out of chat and shared logs.

Risk: Vehicle commands can change climate, charging, or door lock state; unlocking leaves the vehicle unsecured.

Mitigation: Use read-only mode unless writes are needed, restrict write permissions to the required actions, and confirm the selected vehicle and user approval before each command.

Risk: An accepted command or cached status may not reflect the vehicle's current state.

Mitigation: Re-read vehicle status to verify changes; do not resend a command merely because confirmation times out.

## Reference(s):

- [kiaaccess on ClawHub](https://clawhub.ai/chrischall/skills/kiaaccess)
- [kiaaccess-mcp npm package](https://www.npmjs.com/package/kiaaccess-mcp)

## Skill Output:

**Output Type(s):** [Text, Guidance, Configuration instructions]

**Output Format:** [Markdown and structured vehicle tool responses]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Vehicle commands require user confirmation; reported command acceptance does not necessarily confirm the vehicle changed state.]

## Skill Version(s):

2.0.0 (source: ClawHub release evidence)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 9h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/chrischall/skills/kiaaccess",
      "sourceUrl": "https://clawhub.ai/chrischall/skills/kiaaccess",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T01:57:59.101Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T01:57:59.101Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.8K downloads",
      "href": "https://clawhub.ai/chrischall/kiaaccess",
      "sourceUrl": "https://clawhub.ai/chrischall/kiaaccess",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T01:57:59.101Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.0.0",
      "href": "https://clawhub.ai/chrischall/kiaaccess",
      "sourceUrl": "https://clawhub.ai/chrischall/kiaaccess",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:24:13.194Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-chrischall-kiaaccess/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.0.0",
      "description": "kiaaccess 2.0.0 - Updated MFA bootstrap instructions: rmtoken must now be copied manually from a file, and never shared in conversation. - Removed the insecure `kia_export_refresh_token` tool for bypassing MFA. - Tool arguments and documentation clarified — all commands now consistently require `vehicle_key`. - Caution sections improved with stronger warnings and more explicit vehicle key handling. - Removed file: skill-card.md.",
      "href": "https://clawhub.ai/chrischall/kiaaccess",
      "sourceUrl": "https://clawhub.ai/chrischall/kiaaccess",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T23:24:13.194Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to kiaaccess and adjacent AI workflows.