Agent skill

Blink

by HybridAIOne in HybridAIOne/hybridclaw

Read Blink camera and video-doorbell state, list motion clips, and prepare guarded home-security control requests without exposing Blink credentials.

MITAuto-check passed

Install Blink

skills CLI
$ npx skills add HybridAIOne/hybridclaw --skill blink -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HybridAIOne/hybridclaw blink --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/blink .claude/skills/blink && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
blink
GitHub stars
159
Token cost
~4k tokens
SKILL.md length
1,494 words
Files
3
Skills in repo
72
Repo updated
First seen
Licence
MIT

At a glance

Read Blink camera and video-doorbell state, list motion clips, and prepare guarded home-security control requests without exposing Blink credentials.

  • Works in 3 steps: Browser admin: open the active… → Browser /chat or TUI fallback → Local console fallback
  • SKILL.md covers Core Contract, Setup, Helper Commands and Read Workflow, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls node; needs BLINK_PASSWORD and BLINK_AUTH_TOKEN

What it does

Blink is an agent skill from HybridAIOne/hybridclaw. Read Blink camera and video-doorbell state, list motion clips, and prepare guarded home-security control requests without exposing Blink credentials.

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files.

The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.

Example prompts

  • “/blink”

Requirements

  • A credential in BLINK_AUTH_TOKEN
  • A credential in BLINK_REFRESH_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Browser admin: open the active HybridClaw admin URL ending in /admin/secrets and set
  2. Browser /chat or TUI fallback
  3. Local console fallback

What it can do on your machine

Read from SKILL.md and the folder at commit 8162701. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • home-assistant.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BLINK_PASSWORD
    • BLINK_AUTH_TOKEN
    • BLINK_REFRESH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Blink loads about 4k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 1,494 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HybridAIOne/hybridclaw at commit 8162701, republished under its MIT licence (© HybridAIOne). 1,494 words, ~4,001 tokens.

Download SKILL.mdSave it as .claude/skills/blink/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
blink
description
Read Blink camera and video-doorbell state, list motion clips, and prepare guarded home-security control requests without exposing Blink credentials.
user-invocable
true
requires.bins
node

Use this skill for Blink camera, video doorbell, network arm-state, motion event, and clip-metadata workflows. Blink does not publish an official public API; this skill follows the bounded community API surface used by BlinkPy, BlinkMonitorProtocol, and Home Assistant. Treat endpoint behavior as best-effort and stop on the first authentication or verification failure.

Core Contract

  • Build and run all Blink API calls with skills/blink/blink.cjs; do not handcraft Blink URLs, auth headers, or JSON bodies when the helper supports the operation.
  • Use run for live Blink calls. The helper sends its own request objects through the gateway /api/http/request path, so the model does not reconstruct endpoint details.
  • Use http-request only as dry-run JSON for inspection or fallback direct http_request execution when helper live execution is unavailable. Pass emitted httpRequest fields as structured JSON; do not stringify nested fields such as captureResponseFields or secretHeaders.
  • Never call http_request against guessed Blink hosts or paths. Use only the exact structured request emitted by the helper in this turn. If the helper lacks an operation, say the skill does not support that operation instead of probing.
  • For ordinary operator requests, do not read or grep skills/blink/blink.cjs to debug the helper. Trust the helper output. Source inspection is for maintainers changing this skill, not for listing devices.
  • Helper operations use subject-verb names (devices-list, account-login, camera-motion-set). Legacy aliases are accepted, but prefer the canonical names shown below.
  • Credentials and tokens must stay in the SecretRef-backed runtime secret store; never ask the operator to paste BLINK_PASSWORD or BLINK_AUTH_TOKEN into chat, and never include either value in prose.
  • Do not run hybridclaw secret get, call /api/secret, inspect env, or use curl/ad hoc scripts to fetch Blink secrets. If the helper reports missing session secrets such as BLINK_TIER, run run account-refresh once, then run account-login if refresh cannot recover the session; email/password may already be stored.
  • account-login is implemented as OAuth v2 Authorization Code + PKCE in the helper. Run node skills/blink/blink.cjs --format json run account-login; do not call old password login endpoints and do not web-search or endpoint-probe inside the user task.
  • The Blink-specific implementation lives under skills/blink/; the gateway pieces this skill relies on are generic http_request primitives for nested response capture, explicit token bind-domain capture, secret-backed headers, manual redirect inspection, and response-body suppression.
  • The helper owns all Blink host and path selection; arbitrary host/path passthrough is not supported.
  • Clip downloads must go through the gateway artifact path; return artifact handles or metadata only, and rely on the helper-emitted suppressResponseBody: true so raw video bytes do not enter model context.
  • Live-view requests are red and operator-UI-only; the helper emits suppressResponseBody: true, and RTSP/HLS/session handles must not be copied into chat even after approval.
  • Stop after the first 401, invalid-credentials, or verification-required response; do not retry, poll, or fan out more Blink calls until credentials or the PIN handover are resolved.
  • Stop after a 426 app update is required response or OAuth unsupported_grant_type. Do not probe alternate Blink endpoints, try new User-Agents, or attempt OAuth grant_type=password; use the helper's OAuth v2 Authorization Code + PKCE path with cookie and redirect handling outside model context.

Setup

Set the initial secrets in this order:

  1. Browser admin: open the active HybridClaw admin URL ending in /admin/secrets and set BLINK_EMAIL and BLINK_PASSWORD.
  2. Browser /chat or TUI fallback:
text
/secret set BLINK_EMAIL "<account email>"
/secret set BLINK_PASSWORD "<account password>"
  1. Local console fallback:
bash
hybridclaw secret set BLINK_EMAIL "<account email>"
hybridclaw secret set BLINK_PASSWORD "<account password>"

BLINK_DEVICE_ID and BLINK_CLIENT_NAME are not secrets. The helper generates a stable OAuth hardware id automatically; BLINK_DEVICE_ID is only an optional advanced override. BLINK_CLIENT_NAME is retained as a non-secret compatibility label and is not sent to Blink OAuth v2.

bash
node skills/blink/blink.cjs --format json run account-login

Successful OAuth v2 login captures:

BLINK_AUTH_TOKEN, BLINK_REFRESH_TOKEN, BLINK_TIER, BLINK_ACCOUNT_ID, and BLINK_CLIENT_ID. Do not ask the operator to set these manually after login; the gateway writes them to the secret store automatically.

If Blink marks the client as unverified, it sends an email/SMS PIN. Use F14 durable handover to receive that PIN from the operator, then run the login helper with the PIN:

bash
node skills/blink/blink.cjs --format json run account-login --pin "<code>"

The PIN can appear in helper arguments because it is a short-lived operator handover code; the password and auth token must never appear there.

Helper Commands

Use this command surface directly:

text
node skills/blink/blink.cjs [--format json|pretty] http-request <operation> [flags]
node skills/blink/blink.cjs [--format json|pretty] run <operation> [flags]
node skills/blink/blink.cjs [--format json|pretty] plan <operation> [flags]

run account-login [--pin <code>]
run account-refresh
run devices-list

http-request account-login
http-request account-refresh
http-request pin-verify --pin <code>
http-request devices-list
http-request networks-list
http-request network-status-read --network <network-id>
http-request sync-modules-list --network <network-id>
http-request cameras-list --network <network-id>
http-request camera-config-read --network <network-id> --camera <camera-id>
http-request camera-signals-read --network <network-id> --camera <camera-id>
http-request doorbells-list --network <network-id>
http-request motion-events-list --network <network-id> --since 2026-05-26T00:00:00Z
http-request clips-list [--network <network-id>] --since 2026-05-26T00:00:00Z --page 0 --max 50
http-request clip-download --path /api/v2/accounts/<account-id>/media/clip/<file.mp4> [--filename clip.mp4]
http-request thumbnail-download --path /api/v3/media/accounts/<account-id>/networks/<network-id>/<camera-type>/<camera-id>/thumbnail/thumbnail.jpg?ts=<ts>&ext= [--filename camera.jpg]

plan network-arm --network <network-id>
plan network-disarm --network <network-id>
plan camera-motion-set --network <network-id> --camera <camera-id> --enable true
plan camera-thumbnail-refresh --network <network-id> --camera <camera-id> [--camera-type default|mini|doorbell] [--filename camera.jpg]
plan clip-watched-mark --clip <clip-id>
plan clip-delete --clip <clip-id>
plan camera-live-view-start --network <network-id> --camera <camera-id> [--camera-type default|mini|doorbell]

Blink clip listing uses the account-scoped media/changed API. clips-list --network <id> is accepted for the issue-contract command shape, but the helper still calls the account-scoped endpoint and marks the requested network in metadata; filter returned clip metadata by that network before summarizing or choosing a clip path for clip-download. For a current still image, produce a camera-thumbnail-refresh plan and, after operator approval, run the plan's approvedHelperCommandText. Do not manually stitch together refresh, devices-list, and thumbnail-download; the approved live helper command owns that full workflow, polls Blink command status, downloads the thumbnail as a gateway artifact only after a successful command, and returns result.freshness plus result.display. Do not call the image fresh unless result.freshness.ok is true. Only display or link the image artifact when result.display.shouldDisplayArtifact is true. If result.freshness.reason is command-not-completed or command-failed, report the Blink command status fields and do not download, display, or link any thumbnail. If result.freshness.thumbnailPathChanged is false, result.freshness.sameAsPrevious is true, result.display.shouldDisplayArtifact is false, or a freshness warning is present, say Blink accepted the refresh command but returned the same thumbnail instead of calling it a fresh screenshot. Do not speculate about Wi-Fi, camera hardware, firmware, reachability, or Blink service state unless a separate live Blink response explicitly says so. Do not rewrite thumbnail paths or construct media URLs by hand; the helper routes authenticated requests and stores fresh images as artifacts instead of exposing bytes in model context.

Show full SKILL.md (583 more words)Show less

When camera-thumbnail-refresh returns result.failureReportContract, follow it exactly. In particular, do not write a "possible reasons" list for a stale or failed thumbnail. Do not say the camera is offline unless the same successful live Blink response marks that exact camera offline. Do not use homescreen app_updates, code 105, or an account-level app-update warning as the cause of a thumbnail failure unless the refresh or live-view request itself returned HTTP 426. Do not treat camera status: "done", updated_at, or an unchanged thumbnail timestamp as evidence that the camera has not responded since that time. A failed thumbnail report should be limited to: camera name/id if known, command id if known, command status fields, freshness/display guidance, and the fact that no fresh image was verified.

If camera-thumbnail-refresh returns result.freshness.reason: "system-busy", say Blink returned a busy response before accepting the thumbnail command and suggest retrying later. Do not describe this as Blink server overload, rate limiting, repeated-snapshot throttling, or proof for or against a camera problem unless the same response explicitly says so.

plan emits no live side effect. It returns approvalText, approvedHelperCommandText, the exact target host/path/method, and the bounded httpRequest shape. Stop after producing the plan. Only after the operator confirms that exact network/camera/clip/action through F8/F14, run the approved helper command exactly.

Read Workflow

  1. Use devices-list first for a compact account overview; it includes networks, sync modules, cameras, and doorbell-like devices on current Blink accounts.
  2. If devices-list returns blink-login-required or fails because BLINK_AUTH_TOKEN, BLINK_REFRESH_TOKEN, BLINK_TIER, or BLINK_ACCOUNT_ID is missing or stale, run node skills/blink/blink.cjs --format json run account-refresh once before account-login. Do not tell the operator all Blink credentials are missing just because token/tier/account session secrets are not set yet.
  3. If refresh cannot recover the session, run node skills/blink/blink.cjs --format json run account-login once.
  4. If login returns handover-required, ask for the Blink PIN via F14. When the operator provides the PIN, run exactly node skills/blink/blink.cjs --format json run account-login --pin <code>, then immediately run node skills/blink/blink.cjs --format json run devices-list if login succeeds. Do not read source, inspect secrets, call http_request, or try direct gateway/curl calls between those two helper commands.
  5. If login or the PIN resume fails, report the helper error and stop. Do not guess alternate endpoints, read tokens, or retry a fresh login unless the helper explicitly returns another handover-required.
  6. If login reports invalid credentials, app update, unsupported grant, or verification failure, stop immediately; do not try guessed API versions, OAuth password-grant, or User-Agent variants.
  7. Use the narrower list commands when the operator asks for a specific network or device class; use camera-config-read for motion/video/illuminator settings and camera-signals-read for camera battery, Wi-Fi/sync signal, and temperature telemetry when the homescreen response is not enough.
  8. For incident-card summaries, report concrete device ids/names, network ids, offline duration, low battery, poor signal, temperature, and motion bursts only from successful live Blink responses.

Guarded Writes

Network arm/disarm, per-camera motion detection, thumbnail snapshots, clip-state changes, deletion, and live view all affect privacy or retention. They are amber/red and require exact F8/F14 approval with the target network, camera, clip, and action in the approval text.

The bounded Blink API surface used by this skill does not expose camera or sync module reboot/restart commands. Do not claim a remote reboot is available and do not probe for reboot, restart, reset, firmware, or maintenance endpoints.

Do not perform destructive maintenance, account changes, password changes, notification setting changes, or firmware actions through this skill.

References

© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/blink of HybridAIOne/hybridclaw.

  • SKILL.md
  • blink.cjs
  • logo.webp

Open the folder on GitHubat commit 8162701

Compare with similar skills

Blink next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Blink compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Blink this skillHybridAIOne/hybridclaw159—~4kAutomated safety check: PassMIT
HyperFrames Motion Doctrineheygen-com/hyperframes60k1 repos~3kAutomated safety check: PassApache-2.0
Emilkowalski Motionnexu-io/open-design100k—~644Automated safety check: PassApache-2.0
Motion Foundationsaffaan-m/ECC276k1 repos~2.4kAutomated safety check: PassMIT
HyperFrames Motion Graphicsheygen-com/hyperframes60k3 repos~4kAutomated safety check: PassApache-2.0
Motion Patternsaffaan-m/ECC276k1 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • HyperFrames Motion Doctrine

    heygen-com/hyperframes

    Sets the motion rules for HyperFrames videos so scenes read as one continuous camera move, covering exit-to-entry vectors, seams, idle motion and sustained motion.

    60k GitHub starsUsed in 1 repo~3k tokens
    Media & CreativeAuto-check passed
  • Emilkowalski Motion

    nexu-io/open-design

    Motion-design follow-up skill inspired by Emil Kowalski's animation guidance.

    100k GitHub stars~644 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Motion Foundations

    affaan-m/ECC

    Motion tokens, spring presets, performance rules, device adaptation, accessibility enforcement, and SSR safety for React / Next.js using motion/react.

    276k GitHub starsUsed in 1 repo~2.4k tokens
    Frontend & DesignAuto-check passed
  • HyperFrames Motion Graphics

    heygen-com/hyperframes

    Builds short, unnarrated motion graphics such as kinetic type, stat count-ups, logo stings, lower thirds, animated maps and tweets, rendered to MP4 or a transparent overlay.

    60k GitHub starsUsed in 3 repos~4k tokens
    Media & CreativeAuto-check passed
  • Motion Patterns

    affaan-m/ECC

    Production-ready animation patterns for React / Next.js — button, modal, toast, stagger, page transitions, exit animations, scroll, and layout — built on motion-foundations tokens and springs.

    276k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Motion Advanced

    affaan-m/ECC

    Advanced motion patterns for React / Next.js — drag & drop, gestures, text animations, SVG path drawing, custom hooks, imperative sequences (useAnimate), loaders, and the full API decision tree.

    276k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed

More from HybridAIOne/hybridclaw

All 72 skills in this repo
  • Hermes3000 Writing

    HybridAIOne/hybridclaw

    Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.

    159 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Manim Video

    HybridAIOne/hybridclaw

    Plan, script, render, and stitch Manim Community Edition videos in Python.

    159 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check: notes
  • Skill Creator

    HybridAIOne/hybridclaw

    Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.

    159 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • XLSX

    HybridAIOne/hybridclaw

    Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.

    159 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Excalidraw

    HybridAIOne/hybridclaw

    Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.

    159 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Google Ads

    HybridAIOne/hybridclaw

    Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.

    159 GitHub stars~4k tokensUpdated yesterday
    Auto-check passed

Questions about Blink

What does Blink do?

Read Blink camera and video-doorbell state, list motion clips, and prepare guarded home-security control requests without exposing Blink credentials. Blink is an agent skill from HybridAIOne/hybridclaw. Read Blink camera and video-doorbell state, list motion clips, and prepare guarded home-security control requests without exposing Blink credentials.

How do I install Blink in Claude Code?

Run `npx skills add HybridAIOne/hybridclaw --skill blink -a claude-code`. Or copy the skill folder (skills/blink in HybridAIOne/hybridclaw) into .claude/skills/blink in your project. Claude Code loads it when a task matches its description.

How do I install Blink in Codex?

Run `npx skills add HybridAIOne/hybridclaw --skill blink -a codex`. Or copy the skill folder (skills/blink in HybridAIOne/hybridclaw) into .agents/skills/blink in your project. Codex loads it when a task matches its description.

Can I use Blink in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill blink -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blink, .gemini/skills/blink, .github/skills/blink and .opencode/skills/blink in your project.

What does Blink need to run?

Going by SKILL.md and its folder, Blink needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node) and credentials named BLINK_PASSWORD, BLINK_AUTH_TOKEN and BLINK_REFRESH_TOKEN. Our summary lists: A credential in BLINK_AUTH_TOKEN; A credential in BLINK_REFRESH_TOKEN.

Does Blink access the network?

SKILL.md names 2 domains. As links in the text: github.com and home-assistant.io. This is read from the text; nothing was executed.

Is Blink safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Blink use?

Blink is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Blink use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Blink?

Skills that share tags, products or a category with Blink: HyperFrames Motion Doctrine (heygen-com/hyperframes, 60k stars), Emilkowalski Motion (nexu-io/open-design, 100k stars), Motion Foundations (affaan-m/ECC, 276k stars) and HyperFrames Motion Graphics (heygen-com/hyperframes, 60k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Blink?

HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 159 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 9, 2026.

Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.