Home Assistant Hub
Real-time Home Assistant monitoring, alert rules, TTS voice notifications on Echo devices, Telegram delivery, entity inspection. Service calls are HARD-DENIE...
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
1.5.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.5.1release · observed Jul 11, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s170wrqqnm5nbbk85av1t8vdx1855dyb:home-assistant-hub- Install using `clawhub skill install s170wrqqnm5nbbk85av1t8vdx1855dyb:home-assistant-hub` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/vincsta/home-assistant-hub before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-vincsta-home-assistant-hub/snapshot"
Documentation
CLAWHUB
148,408 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: "home-assistant-hub"
description: "Real-time Home Assistant monitoring, alert rules, TTS voice notifications on Echo devices, Telegram delivery, entity inspection. Service calls are HARD-DENIED by default — require explicit safe-domains opt-in."
homepage: https://github.com/openclaw/openclaw
metadata:
{
"openclaw":
{
"emoji": "🏡",
"requires": { "bins": ["node"] },
"permissions": [
{ "kind": "network", "direction": "outbound", "targets": ["Home Assistant API/WebSocket (HTTP + WSS)", "Telegram Bot API (HTTPS)", "Echo devices via HA notify service"], "reason": "Real-time monitoring of home device states, alert delivery to Telegram servers, and voice announcements on Echo devices require outbound network connections" },
{ "kind": "network", "direction": "local-bind", "targets": ["localhost:9123 (on-demand API)"], "reason": "Local HTTP API for ha-cmd.js service calls when configured. Disabled by default." },
{ "kind": "secrets", "direction": "local-read", "targets": ["config/hub.json"], "reason": "Reads HA long-lived bearer token, Telegram bot token, and chat ID. File is gitignored — never commit to version control" }
]
},
}
---
# ⚠️ SECURITY & PRIVACY WARNINGS — READ FIRST
## 🔴 Device Control — Hardened Defaults
This skill can invoke Home Assistant services to change physical device states. **Service calls are disabled by default.**
### ⛔ Always Blocked (never configurable)
The following domains are HARD-LOCKED in code and cannot be enabled:
- `lock.*` — door locks (physical security)
- `alarm_control_panel.*` — alarm systems (safety-critical)
- `cover.*` — blinds/doors/garage (privacy/security)
### ✅ Safe Domains — Explicit Opt-In Required
Service calls require domains to be listed in `call_safe_domains` in `config/hub.json`. **An empty list means all service calls are blocked.**
Default safe domains in the example config: `light`, `climate`, `scene`, `media_player`, `automation`, `notify`
To add a new domain, edit hub.json:
```json
"call_safe_domains": ["light", "climate", "scene", "media_player", "automation", "notify"]
```
### 🔍 Dry-Run Mode
Before executing any service call, use `--dry-run` to preview what would happen:
```bash
node scripts/ha-cmd.js call climate.set_temperature entity_id=climate.hvac temperature=22 --dry-run
# Output: Service URL + payload WITHOUT executing
## 📡 External Data Transmission
This skill transmits data to third-party services:
- **Telegram Bot API** — alert messages including occupancy, sensor states, routines → exposes household patterns and security-relevant information
- **Echo devices via HA** — TTS announcements broadcast inside the home environment
- **Home Assistant instance** — all device telemetry sent over network
**Do NOT include sensitive personal data in alert templates.** Notification content is visible on Telegram accounts and potentially logged by Telegram servers.
### 🚫 No Hardcoded CredentialREADME.md
# ⚠️ SECURITY & PRIVACY WARNINGS — READ BEFORE INSTALLING ## 🔴 Live Device Control — Hardened Defaults This skill can invoke Home Assistant services to change physical device states. **Service calls are DISABLED BY DEFAULT.** ### Always Blocked (never configurable) The following domains are HARD-LOCKED in code: - `lock.*` → door locks (physical security) - `alarm_control_panel.*` → alarm systems (safety-critical) - `cover.*` → blinds/doors/garage (privacy/security) ### Safe Domains — Explicit Opt-In Required Service calls require domains to be listed in `call_safe_domains` in `config/hub.json`. **An empty list blocks all service calls.** Default safe domains: `light`, `climate`, `scene`, `media_player`, `automation`, `notify` ### Dry-Run Mode Always use `--dry-run` first to preview what would be called: ```bash node scripts/ha-cmd.js call climate.set_temperature entity_id=climate.hvac temperature=22 --dry-run # Shows: Service URL + payload WITHOUT executing ## 📡 External Data Transmission This skill sends data to third-party services (Telegram Bot API, Echo devices). Alert messages include occupancy status, sensor states, and routines. Do not include sensitive personal information in alert templates. Notification content is visible on Telegram accounts and potentially logged by Telegram servers. ## 🔐 Credential Sensitivity All secrets (`ha_token`, `telegram_bot_token`, `telegram_chat_id`) are stored in `config/hub.json`. The HA token is a long-lived bearer token with broad API access — treat it like a password. Default URL uses plain HTTP; use HTTPS if possible to prevent credential exposure on the local network. --- # Home Assistant Hub Real-time monitoring of Home Assistant device states with configurable alert rules, TTS voice notifications on Echo devices via Parla entities, Telegram delivery for alerts and events, entity inspection (states, history, persons, areas), and controlled device management through direct service calls. ## What It Does 1. **Monitor** home device states in real-time (polling + WebSocket) 2. **Alert** when conditions change (battery, garage, temperature, occupancy) — delivered via Telegram or voice announcements on Echo devices 3. **Inspect** entities: states, history, persons, areas, scenes 4. **Control** Home Assistant services directly through `ha-cmd.js` calls ### Example use cases - 🔋 **Battery monitoring**: alerts when charge drops below 20% or exceeds 95% (full charge alert) - 🏠 **Security monitoring**: garage door open/close, window sensors, motion detection - 🌡️ **Comfort monitoring**: temperature/humidity thresholds, HVAC status - 💡 **Device control**: turn lights on/off, set thermostat, activate scenes *(use with caution)* - 📢 **Voice announcements**: TTS broadcasts to Echo devices via Parla entities ## How It Works ``` ┌───────────┐ HTTP/WS ┌───────────────┐ JSON file ┌─────────────────┐ │ Home │ ◄──────────► │ ha-hub.js │ ───────────► │ telegram-deliver│ │ Assi
_meta.json
{
"ownerId": "kn7438bzbbzvnb37f1vmr6y141854jsa",
"slug": "home-assistant-hub",
"version": "1.5.1",
"publishedAt": 1783801468974
}references/setup.md
# Home Assistant Hub — Setup Guide
## ⚠️ Security Warning
You are about to create a **long-lived bearer token** with broad API access to your Home Assistant instance. Treat this token like a password:
- Never share it publicly or commit it to version control
- The file `config/hub.json` is gitignored — verify `.gitignore` includes it
- Rotate the token in HA if you suspect compromise (Profile → Long-Lived Access Tokens → Revoke)
## 1. Get a Long-Lived Access Token
1. Open Home Assistant → Profile (bottom-left)
2. Scroll to **Long-Lived Access Tokens**
3. Click **CREATE TOKEN**
4. Name it `openclaw-hub`
5. **Copy the token** (shown only once!)
## 2. Configure the Hub
```bash
cd ~/.openclaw/workspace/skills/home-assistant-hub
node scripts/ha-hub.js setup
```
Enter your HA URL and token when prompted.
## 3. Test Connection
```bash
node scripts/ha-hub.js test
```
Should show your HA version.
## 4. Add Alert Rules
### Interactive:
```bash
node scripts/ha-hub.js add-rule
```
### Via JSON (recommended for bulk):
```bash
node scripts/ha-hub.js add-rules << 'EOF'
[
{
"name": "Garage aperto",
"entity_id": "binary_sensor.garage_door",
"condition": "state",
"value": "on",
"cooldown": 300,
"title": "Garage",
"template": "Il garage è aperto!"
},
{
"name": "Temperatura bassa",
"entity_id": "sensor.temperatura_interna",
"condition": "below",
"value": "15",
"cooldown": 600,
"title": "🌡️ Temperatura",
"template": "Temperatura bassa: {{state}}°C"
},
{
"name": "Persone via",
"entities": ["person.vincenzo", "person.maria"],
"condition": "not_state",
"value": "home",
"cooldown": 900,
"title": "🏠 Tutti fuori",
"template": "Nessuno è in casa"
}
]
EOF
```
## 5. Start the Hub
```bash
node scripts/ha-hub.js start
```
Verify:
```bash
node scripts/ha-hub.js status
```
## 6. Stop the Hub
```bash
node scripts/ha-hub.js stop
```
## Alert Rules Reference
### Conditions
| Condition | Meaning | Example value |
|-----------|---------|---------------|
| `state` | State equals value | `on`, `home`, `open` |
| `not_state` | State not equals value | `away` |
| `above` | State (numeric) above value | `25` |
| `below` | State (numeric) below value | `10` |
| `changed` | Always trigger on change | — |
### Fields
| Field | Required | Description |
|-------|----------|-------------|
| `name` | Yes | Rule identifier |
| `entity_id` | Yes* | Single entity ID |
| `entities` | Yes* | Array of entity IDs |
| `condition` | Yes | See table above |
| `value` | Condition-dependent | Value to compare |
| `cooldown` | No | Seconds between alerts (default 300) |
| `title` | No | Alert title (default "HA Alert") |
| `template` | No | Custom message (default: entity: old → new) |
| `channel` | No | Notification channel (default: config value) |
| `priority` | No | `normal` or `urgent` |
*Either `entity_id` or `entities` required.
## Quiet Hours
Disable alerts during sleep in `confiskill-card.md
## Description: Provides real-time Home Assistant monitoring, alert rules, Echo voice notifications, Telegram delivery, entity inspection, and opt-in service calls. This skill is ready for commercial/non-commercial use. ## Publisher: [vincsta](https://clawhub.ai/user/vincsta) ### License/Terms of Use: MIT-0 ## Use Case: External developers and Home Assistant users use this skill to monitor device states, define alert rules, inspect entities, send Telegram or Echo notifications, and execute explicitly allowed Home Assistant service calls. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Home Assistant and Telegram credentials may be exposed through local configuration or unencrypted Home Assistant connections. Mitigation: Use HTTPS/WSS, store secrets only in a gitignored config file with restricted permissions, and rotate long-lived tokens if exposure is suspected. Risk: Allowed service-call domains can change physical devices and may permit broader automation effects than intended. Mitigation: Keep service calls disabled until needed, remove scene and automation from call_safe_domains unless fully audited, and test changes with dry-run first. Risk: Alert messages sent to Telegram or Echo devices can reveal household state, occupancy, routines, or other sensitive context. Mitigation: Avoid sensitive personal data in templates and route notifications only to trusted Telegram chats and intended Echo devices. Risk: The provided start script can stop unintended processes because of broad pkill matching. Mitigation: Avoid start.sh until its process matching is narrowed, and verify process state before stopping background services. ## Reference(s): - [Home Assistant Hub setup guide](references/setup.md) - [ClawHub skill page](https://clawhub.ai/vincsta/skills/home-assistant-hub) ## Skill Output: **Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance] **Output Format:** [Markdown guidance with inline shell commands, JSON configuration examples, and code references] **Output Parameters:** [1D] **Other Properties Related to Output:** [May produce Home Assistant service-call examples, alert-rule definitions, setup steps, and operational guidance that should be reviewed before execution.] ## Skill Version(s): 1.5.1 (source: server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/vincsta/skills/home-assistant-hub",
"sourceUrl": "https://clawhub.ai/vincsta/skills/home-assistant-hub",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T06:02:38.802Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-vincsta-home-assistant-hub/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-vincsta-home-assistant-hub/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T06:02:38.802Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/vincsta/home-assistant-hub",
"sourceUrl": "https://clawhub.ai/vincsta/home-assistant-hub",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T06:02:38.802Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.5.1",
"href": "https://clawhub.ai/vincsta/home-assistant-hub",
"sourceUrl": "https://clawhub.ai/vincsta/home-assistant-hub",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-11T20:24:28.974Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-vincsta-home-assistant-hub/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-vincsta-home-assistant-hub/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.5.1",
"description": "home-assistant-hub v1.5.1 - Removed the skill-card.md file for streamlined documentation. - Updated internal documentation (SKILL.md) for improved clarity. - No functional or breaking changes to core scripts or service behavior.",
"href": "https://clawhub.ai/vincsta/home-assistant-hub",
"sourceUrl": "https://clawhub.ai/vincsta/home-assistant-hub",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-11T20:24:28.974Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
