Agent skill

Homematic

by HybridAIOne in HybridAIOne/hybridclaw

Read Homematic IP Home Control Unit state and prepare guarded smart-home control messages without exposing HCU credentials.

MITAuto-check passedBackend & APIs

Install Homematic

skills CLI
$ npx skills add HybridAIOne/hybridclaw --skill homematic -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HybridAIOne/hybridclaw homematic --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/homematic .claude/skills/homematic && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
homematic
GitHub stars
159
Token cost
~2.9k tokens
SKILL.md length
809 words
Files
3
Skills in repo
72
Repo updated
First seen
Licence
MIT

At a glance

Read Homematic IP Home Control Unit state and prepare guarded smart-home control messages without exposing HCU credentials.

  • Works in 8 steps: Start with plan, summarize-fixture,… → For HCU setup, generate gateway… → For HCU WebSocket operations, use helper… → …
  • Backend & APIs work in your project
  • SKILL.md covers Safety Rules, Command Contract, Required Inputs and Access To Local Devices, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls node; needs HOMEMATIC_HCU_AUTH_TOKEN and HOMEMATIC_HCU_ACTIVATION_KEY

What it does

Homematic is an agent skill from HybridAIOne/hybridclaw. Read Homematic IP Home Control Unit state and prepare guarded smart-home control messages without exposing HCU credentials.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `fixtures/hcu-state.json`).

It sits in Backend & APIs. The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/homematic”

Requirements

  • A credential in HOMEMATIC_HCU_AUTH_TOKEN
  • A credential in HOMEMATIC_HCU_ACTIVATION_KEY

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Start with plan, summarize-fixture, plugin-ready, get-state, or
  2. For HCU setup, generate gateway http-request payloads with the helper.
  3. For HCU WebSocket operations, use helper websocket-message output as the
  4. For a local operator-owned read-only smoke test, run-websocket can open
  5. Reads are green but still privacy-sensitive because home occupancy, alarms,
  6. Mutating device or group actions are amber unless they affect alarms,
  7. Do not execute a write unless the operator granted the exact helper-reported
  8. Do not use shell curl, ad hoc WebSocket scripts, or cleartext headers when

What it can do on your machine

Read from SKILL.md and the folder at commit 8162701. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HOMEMATIC_HCU_AUTH_TOKEN
    • HOMEMATIC_HCU_ACTIVATION_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Homematic loads about 2.9k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 809 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HybridAIOne/hybridclaw at commit 8162701, republished under its MIT licence (© HybridAIOne). 809 words, ~2,859 tokens.

Download SKILL.mdSave it as .claude/skills/homematic/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
homematic
description
Read Homematic IP Home Control Unit state and prepare guarded smart-home control messages without exposing HCU credentials.
user-invocable
true
requires.bins
node

Homematic

Use this skill for Homematic IP Home Control Unit (HCU) state inspection and guarded smart-home control planning. The primary v1 integration target is the official Homematic IP Connect API, which exposes HCU plugin communication over WebSocket. Treat CCU/RaspberryMatic and Homematic IP Access Point cloud support as separate compatibility paths until their protocols are implemented and tested.

This v1 targets remote HCU Connect API clients. The HTTPS port 6969 auth helpers implement the remote-client enrollment flow. Installed HCU plugin containers instead receive their token from the HCU container environment and mounted /TOKEN file; this helper does not implement container installation.

Safety Rules

  1. Start with plan, summarize-fixture, plugin-ready, get-state, or get-system-state.
  2. For HCU setup, generate gateway http-request payloads with the helper. Never ask the operator to paste activation keys or auth tokens into chat.
  3. For HCU WebSocket operations, use helper websocket-message output as the source of truth for connection headers, message type, path, stakes tier, and approval requirement.
  4. For a local operator-owned read-only smoke test, run-websocket can open the HCU WebSocket directly using HOMEMATIC_HCU_AUTH_TOKEN from the helper environment. Do not pass that token as an argument. Use gateway-managed execution for any amber/red operation.
  5. Reads are green but still privacy-sensitive because home occupancy, alarms, temperatures, shutters, and energy state can reveal living patterns.
  6. Mutating device or group actions are amber unless they affect alarms, security zones, locks, or safety state; those are red.
  7. Do not execute a write unless the operator granted the exact helper-reported requiredGrant. Include device/group ids, channel index, target value, rollback, and expected physical effect in the approval text.
  8. Do not use shell curl, ad hoc WebSocket scripts, or cleartext headers when the gateway tool or helper output can express the request.

Command Contract

Show helper usage:

bash
node skills/homematic/homematic.cjs --help

Plan an explicit operation. The model should choose from the documented helper operations instead of asking the helper to parse user prose:

bash
node skills/homematic/homematic.cjs --format json plan get-state
node skills/homematic/homematic.cjs --format json plan set-set-point-temperature

Build HCU auth setup requests. The helper uses <secret:HOMEMATIC_HCU_ACTIVATION_KEY> and <secret:HOMEMATIC_HCU_AUTH_TOKEN> placeholders so the gateway resolves stored secrets server-side.

bash
node skills/homematic/homematic.cjs --format json http-request auth-token \
  --hcu-url https://hcu1-1234.local \
  --plugin-id com.example.hybridclaw.homematic

node skills/homematic/homematic.cjs --format json http-request confirm-token \
  --hcu-url https://hcu1-1234.local

Prepare read-only HCU Connect API messages:

bash
node skills/homematic/homematic.cjs --format json websocket-message plugin-ready \
  --hcu-url https://hcu1-1234.local

node skills/homematic/homematic.cjs --format json websocket-message get-state \
  --hcu-url https://hcu1-1234.local

node skills/homematic/homematic.cjs --format json websocket-message get-system-state \
  --hcu-url https://hcu1-1234.local

node skills/homematic/homematic.cjs --format json --hmip-system-events websocket-message get-state \
  --hcu-url https://hcu1-1234.local

Run a local HCU WebSocket read. This is for operator-owned smoke tests where the helper environment can see the stored token value; normal agent flows should prefer generated payloads and gateway-managed secrets. Use --insecure-local-tls only for operator-owned local/private HCU hosts with self-signed certificates.

bash
HOMEMATIC_HCU_AUTH_TOKEN="<token>" \
  node skills/homematic/homematic.cjs --format json run-websocket get-state \
  --hcu-url https://hcu1-1234.local

Generate policy material for local HCU network access and SecretRef routing:

bash
node skills/homematic/homematic.cjs --format json policy-rules \
  --hcu-url https://hcu1-1234.local \
  --agent main

Prepare guarded write messages:

First produce an approval plan. After explicit operator confirmation, run the exact approvedCommand unchanged.

bash
node skills/homematic/homematic.cjs --format json approval-plan set-switch-state \
  --hcu-url https://hcu1-1234.local \
  --device-id 3014F711A000000000001234 \
  --channel-index 1 \
  --on true
bash
node skills/homematic/homematic.cjs --format json websocket-message set-switch-state \
  --hcu-url https://hcu1-1234.local \
  --device-id 3014F711A000000000001234 \
  --channel-index 1 \
  --on true \
  --operator-grant approve-homematic-write

node skills/homematic/homematic.cjs --format json websocket-message set-set-point-temperature \
  --hcu-url https://hcu1-1234.local \
  --group-id 00000000-1111-2222-3333-444444444444 \
  --temperature 20.5 \
  --operator-grant approve-homematic-write

node skills/homematic/homematic.cjs --format json websocket-message set-shutter-level \
  --hcu-url https://hcu1-1234.local \
  --device-id 3014F711A000000000001234 \
  --channel-index 1 \
  --level 0.25 \
  --operator-grant approve-homematic-write

node skills/homematic/homematic.cjs --format json websocket-message acknowledge-safety-alarm \
  --hcu-url https://hcu1-1234.local \
  --operator-grant approve-homematic-security-write

Summarize a saved HCU state fixture without contacting hardware:

bash
node skills/homematic/homematic.cjs --format json summarize-fixture \
  --fixture skills/homematic/fixtures/hcu-state.json

The helper returns auditEvents payloads for planned and live read/control operations. These are structured for the F2 audit rail and intentionally carry SecretRef ids, never secret values.

Show full SKILL.md (358 more words)Show less

Required Inputs

  • HCU URL: use the local HCUweb hostname, usually https://hcu1-XXXX.local, where XXXX are the last four SGTIN digits shown on the underside of the Home Control Unit.
  • Developer mode: enable HCU developer mode in HCUweb before creating remote Connect API credentials.
  • WebSocket exposure: enable Connect API WebSocket exposure in HCUweb for remote-client reads and guarded message planning.
  • Plugin id: use a stable reverse-DNS style id and keep it identical for auth enrollment and WebSocket messages.
  • Credentials: store activation keys and auth tokens in HybridClaw secrets; never paste values into chat or CLI arguments.

Access To Local Devices

HCU v1 requires local network reachability to hcu1-XXXX.local on HTTPS port 6969 for remote-client auth enrollment and WSS port 9001 for Connect API messages. On macOS, the terminal or agent host may need Local Network access before .local mDNS names resolve or WebSocket connections succeed. If mDNS is unavailable, use the HCU's local IP address and keep the host allowlist scoped to that address.

CCU/RaspberryMatic and Homematic IP Access Point cloud setups are not HCU Connect API endpoints. CCU/RaspberryMatic needs its local CCU API path, and the Access Point cloud path uses a separate cloud REST API. Treat both as follow-up compatibility work, not as prerequisites for this HCU skill.

V1 Coverage

This helper emits PLUGIN_STATE_RESPONSE and HMIP_SYSTEM_REQUEST messages for read/state and guarded native Homematic IP control paths. Connect API plugin device inclusion (DISCOVER_*, INCLUSION_EVENT, EXCLUSION_EVENT), plugin-device control/status (CONTROL_*, STATUS_*), HCUweb configuration templates (CONFIG_TEMPLATE_*, CONFIG_UPDATE_*), system info, and user message flows are intentionally deferred follow-up surfaces.

References

Relevant HCU Connect API notes:

  • Remote HCU plugins connect to wss://hcu1-XXXX.local:9001.
  • WebSocket connection headers include plugin-id and authtoken.
  • HCU auth enrollment uses HTTPS port 6969, header VERSION: 12, and the requestConnectApiAuthToken / confirmConnectApiAuthToken endpoints.
  • Add hmip-system-events: true to the WebSocket handshake when subscribing to HCU HMIP_SYSTEM_EVENT push messages.
  • HCU system requests use type: "HMIP_SYSTEM_REQUEST" and a body.path such as /hmip/home/getState, /hmip/device/control/setSwitchState, /hmip/group/heating/setSetPointTemperature, or /hmip/home/security/acknowledgeSafetyAlarm.
  • /hmip/home/getState is the HCU Connect API path. /hmip/home/getCurrentState belongs to the separate Homematic IP REST / Access Point API surface.

© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/homematic of HybridAIOne/hybridclaw.

  • SKILL.md
  • fixtures/hcu-state.json
  • homematic.cjs

Open the folder on GitHubat commit 8162701

Compare with similar skills

Homematic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Homematic compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Homematic this skillHybridAIOne/hybridclaw159—~2.9kAutomated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from HybridAIOne/hybridclaw

All 72 skills in this repo
  • Hermes3000 Writing

    HybridAIOne/hybridclaw

    Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.

    159 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Manim Video

    HybridAIOne/hybridclaw

    Plan, script, render, and stitch Manim Community Edition videos in Python.

    159 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Skill Creator

    HybridAIOne/hybridclaw

    Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.

    159 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • XLSX

    HybridAIOne/hybridclaw

    Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.

    159 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Excalidraw

    HybridAIOne/hybridclaw

    Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.

    159 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Google Ads

    HybridAIOne/hybridclaw

    Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.

    159 GitHub stars~4k tokensUpdated today
    Auto-check passed

Categories

Questions about Homematic

What does Homematic do?

Read Homematic IP Home Control Unit state and prepare guarded smart-home control messages without exposing HCU credentials. Homematic is an agent skill from HybridAIOne/hybridclaw. Read Homematic IP Home Control Unit state and prepare guarded smart-home control messages without exposing HCU credentials.

When should I use Homematic?

Homematic fits situations like: backend & APIs work in your project.

How do I install Homematic in Claude Code?

Run `npx skills add HybridAIOne/hybridclaw --skill homematic -a claude-code`. Or copy the skill folder (skills/homematic in HybridAIOne/hybridclaw) into .claude/skills/homematic in your project. Claude Code loads it when a task matches its description.

How do I install Homematic in Codex?

Run `npx skills add HybridAIOne/hybridclaw --skill homematic -a codex`. Or copy the skill folder (skills/homematic in HybridAIOne/hybridclaw) into .agents/skills/homematic in your project. Codex loads it when a task matches its description.

Can I use Homematic in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill homematic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/homematic, .gemini/skills/homematic, .github/skills/homematic and .opencode/skills/homematic in your project.

What does Homematic need to run?

Going by SKILL.md and its folder, Homematic needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node) and credentials named HOMEMATIC_HCU_AUTH_TOKEN and HOMEMATIC_HCU_ACTIVATION_KEY. Our summary lists: A credential in HOMEMATIC_HCU_AUTH_TOKEN; A credential in HOMEMATIC_HCU_ACTIVATION_KEY.

Does Homematic access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Homematic safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Homematic use?

Homematic is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Homematic use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Homematic?

Skills that share tags, products or a category with Homematic: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Homematic?

HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 159 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 9, 2026.

Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.