Atlas / MCP servers / coolver / Home Assistant Vibecode

Home Assistant VibecodeCAUTION

mcp/coolver/home-assistant-vibecode

Home Assistant MCP Server. Enable Cursor, VS Code, Claude Code or any MCP-enabled IDE to vibe-code and manage Home Assistant: create automations, design dashboards, tweak themes, modify configs and deploy changes to your HA instance using natural language 🏠🤖

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
93 38r · 43w · 12d
Transport
stdio
License
MIT
Stars
58
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@coolver/home-assistant-mcp) [](https://opensource.org/licenses/MIT)

⚙️ This MCP server works together with the Home Assistant Vibecode Agent, installed as a Home Assistant add-on. The agent runs on your Home Assistant instance and provides “eyes and hands” for AI IDEs like Cursor, VS Code, Claude Code, or any other MCP-enabled IDE.

Let AI build your Home Assistant automations – or act as your DevOps for the ones you write by hand. Just describe what you need in natural language. 🏠🤖

You describe your goal → AI inspects your Home Assistant → designs a custom solution → and deploys it on-board automatically. 🚀

And if you prefer to handcraft your automations and scripts yourself, the agent can simply act as your DevOps and extra pair of hands: quickly uploading your changes, running tests, and analyzing logs on demand. You stay in control and decide how much you delegate to AI and how deep it should go.

Transform the way you manage your smart home. This add-on enables Cursor, Visual Studio Code (VS Code), or any MCP-enabled IDE to:

  • 📝 Analyze your Home Assistant configuration, entities, and devices
  • 🏗️ Create intelligent automations, scripts, and complete systems — including Home Assistant helpers that can be fully managed programmatically
  • 🎨 Design and customize Lovelace dashboards with full control over cards, layouts, and styling
  • 🖌️ Create and tweak themes for a personalized UI
  • 🔄 Safely deploy changes with automatic Git-based versioning
  • 🔍 Monitor and troubleshoot your setup through log analysis
  • 📦 Install and manage HACS integrations and custom repositories

No more manual YAML editing or searching through documentation - just describe what you

Read from source at commit 6091a5835985OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add home-assistant-mcp --env HA_AGENT_KEY=${HA_AGENT_KEY} -- npx -y @coolver/[email protected]
03

Exposed tools (93)

38 read · 43 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ha_add_repositorywrite[WRITE] Add a custom add-on repository to Home Assistant. MODIFIES configuration - requires approval. Use to add community repositories with popular add-ons (Zigbee2MQTT, Node-RED, ESPHome, etc).
ha_addon_infowrite[READ-ONLY] Get detailed information about a specific add-on (configuration, state, version, etc). Safe operation - only reads data.
ha_addon_logswrite[READ-ONLY] Get add-on logs for troubleshooting. Safe operation - only reads data.
ha_analyze_entities_for_dashboardread[READ-ONLY] Get entities for AI-driven dashboard generation with pagination/filtering. Safe operation - only reads data. Use summary_only=true to reduce payload; if has_next=true, request next page.
ha_apply_dashboardwrite[WRITE] Apply generated dashboard configuration to Home Assistant. Creates file, auto-registers in configuration.yaml, and restarts HA. Creates automatic Git backup. MODIFIES configuration - requires approval! Provide a meaningful description of what the dashboard shows (e.g.,
ha_call_servicewrite[WRITE] Call a Home Assistant service. MODIFIES system state - requires approval. Examples: number.set_value, light.turn_on, climate.set_temperature, switch.turn_on, etc.
ha_check_configread[READ-ONLY] Validate Home Assistant configuration. Safe operation - only checks, does not modify.
ha_check_theme_configread[READ-ONLY] Check if themes are configured in configuration.yaml. Safe operation - only reads data.
ha_create_areawrite[WRITE] Create new area in Area Registry. MODIFIES area registry - requires approval.
ha_create_automationwrite[WRITE] Create new automation in Home Assistant. MODIFIES configuration - requires approval. Provide a meaningful description of what the automation does (e.g.,
ha_create_helperwrite[WRITE] Create a Home Assistant helper via YAML configuration. MODIFIES configuration - requires approval. Helper will be created in YAML file and reloaded automatically. Provide a meaningful description of what the helper is for (e.g.,
ha_create_scriptwrite[WRITE] Create new script in Home Assistant. MODIFIES configuration - requires approval. Provide a meaningful description of what the script does (e.g.,
ha_create_themewrite[WRITE] Create a new theme in Home Assistant. MODIFIES configuration - requires approval. After creation, call ha_reload_themes or restart HA. Provide a meaningful description of the theme (e.g.,
ha_create_todowrite[WRITE] Add an item to a todo list. MODIFIES data.
ha_create_zonewrite[WRITE] Create a new zone for presence detection. MODIFIES configuration.
ha_delete_areadestructive[WRITE] Delete area from Area Registry. MODIFIES area registry - requires approval.
ha_delete_automationdestructive[WRITE] Delete automation from Home Assistant. MODIFIES configuration - requires approval.
ha_delete_dashboarddestructive[WRITE] Delete dashboard file and remove from configuration.yaml. Restarts Home Assistant. Creates automatic Git backup. DESTRUCTIVE - requires approval!
ha_delete_filedestructive[WRITE] Delete a file from Home Assistant. DESTRUCTIVE - requires approval!
ha_delete_helperdestructive[WRITE] Delete a Home Assistant helper from YAML configuration. MODIFIES configuration - requires approval.
ha_delete_scriptdestructive[WRITE] Delete script from Home Assistant. MODIFIES configuration - requires approval.
ha_delete_themedestructive[WRITE] Delete a theme from Home Assistant. DESTRUCTIVE - requires approval! After deletion, call ha_reload_themes or restart HA.
ha_delete_zonedestructive[WRITE] Delete a zone. MODIFIES configuration.
ha_end_checkpointwrite[WRITE] End request processing checkpoint. Re-enables auto-commits. Should be called at the end of user request processing.
ha_expose_entitieswrite[WRITE] Expose or unexpose entities to a voice assistant. MODIFIES voice assistant configuration - requires approval. Changes take effect immediately (no HA restart needed).
ha_find_dead_entitiesread[READ-ONLY] Find
ha_get_addon_optionswrite[READ-ONLY] Get add-on configuration options. Safe operation - only reads data.
ha_get_area_registryread[READ-ONLY] Get areas from Area Registry with pagination/filtering. Safe operation - only reads data. If has_next=true, request next page.
ha_get_area_registry_entryread[READ-ONLY] Get single area from Area Registry. Safe operation - only reads data.
ha_get_automationread[READ-ONLY] Get configuration for a single automation from automations.yaml by automation_id. Safe operation - only reads data.
ha_get_calendar_eventsread[READ-ONLY] Get events from a calendar entity for a date range. Safe operation.
ha_get_device_registryread[READ-ONLY] Get devices from Device Registry with metadata and pagination/filtering. Safe operation - only reads data. If has_next=true, request next page.
ha_get_entity_registryread[READ-ONLY] Get entities from Entity Registry with metadata (area_id, device_id, name, disabled status, etc.) and pagination/filtering. Safe operation - only reads data. If has_next=true, request next page.
ha_get_entity_registry_entryread[READ-ONLY] Get single entity from Entity Registry with metadata. Safe operation - only reads data.
ha_get_entity_stateread[READ-ONLY] Get entity state and attributes. Safe operation - only reads data.
ha_get_historyread[READ-ONLY] Get state history for an entity over a time period. Safe operation. Use to analyze trends, check when something changed, or debug automation timing.
ha_get_logsread[READ-ONLY] Get agent logs to troubleshoot issues. Safe operation - only reads data.
ha_get_repairsread[READ-ONLY] Get Home Assistant repair issues (configuration problems, deprecations, broken integrations). Similar to Settings -> System -> Repairs in the HA UI. Use to diagnose configuration issues.
ha_get_scriptread[READ-ONLY] Get configuration for a single script from scripts.yaml by script_id. Safe operation - only reads data.
ha_get_snapshotread[READ-ONLY] Get an aggregated snapshot of the Home Assistant instance: entity states, areas, devices, integrations, and automations in a single call. Use this to get full context about the user\
ha_get_statisticsread[READ-ONLY] Get long-term statistics for an entity (energy consumption, temperature trends, etc.). Safe operation.
ha_get_themeread[READ-ONLY] Get theme content and configuration. Safe operation - only reads data.
ha_git_commitwrite[WRITE] Commit configuration to Git. Creates backup snapshot. If message is not provided and git_versioning_auto=false, returns suggested commit message that needs user confirmation.
ha_git_diffread[READ-ONLY] Show differences between commits. Safe operation - only reads data.
ha_git_historywrite[READ-ONLY] Get Git commit history. Safe operation - only reads data.
ha_git_pendingread[READ-ONLY] Get information about uncommitted changes in shadow repository. Useful when git_versioning_auto=false to see what changes are pending commit. Safe operation - only reads data.
ha_git_rollbackwrite[WRITE] Rollback configuration to specific commit. DESTRUCTIVE - requires approval!
ha_hacs_install_repositorywrite[WRITE] Install integration/theme/plugin from HACS. Requires HACS to be installed. MODIFIES configuration - requires approval!
ha_hacs_list_repositoriesread[READ-ONLY] List available HACS repositories (integrations, themes, plugins) with pagination/filtering. Requires HACS. Safe operation - only reads data. If has_next=true, request next page.
ha_hacs_repository_detailsread[READ-ONLY] Get detailed information about a specific HACS repository (stars, authors, versions, etc). Safe operation - only reads data.
ha_hacs_searchread[READ-ONLY] Search HACS repositories by name, author, or description. If HACS not installed yet, use ha_hacs_status first and offer to install HACS. Safe operation - only reads data.
ha_hacs_statusread[READ-ONLY] Check if HACS is installed and get version info. ALWAYS call this FIRST when user mentions HACS or asks about custom integrations. If not installed, offer to install via ha_install_hacs. Safe operation - only reads data.
ha_hacs_update_allwrite[WRITE] Update all installed HACS repositories to latest versions. Home Assistant restart required after updates. MODIFIES configuration - requires approval!
ha_import_blueprintwrite[WRITE] Import a blueprint from a URL (community forum, GitHub). MODIFIES configuration.
ha_install_addonwrite[WRITE] Install a Home Assistant add-on. MODIFIES system - requires approval. Installation can take several minutes.
ha_install_hacswrite[WRITE] Install HACS (Home Assistant Community Store). Downloads latest HACS from GitHub, installs to custom_components, and restarts Home Assistant. Opens access to 1000+ integrations. MODIFIES configuration - requires approval!
ha_list_addonswrite[READ-ONLY] List available Home Assistant add-ons with pagination/filtering. Safe operation - only reads data. If has_next=true, request next page.
ha_list_blueprintsread[READ-ONLY] List available automation or script blueprints. Safe operation. Use to find community-shared templates.
ha_list_calendarsread[READ-ONLY] List all calendar entities. Safe operation.
ha_list_entitiesread[READ-ONLY] List entities in Home Assistant with optional filters, pagination and lightweight modes. Safe operation - only reads data. Use this instead of dumping all entities at once to avoid overloading LLM context. Use ids_only=true for most token-efficient discovery of what entities exist.
ha_list_exposed_entitiesread[READ-ONLY] List entities exposed to a voice assistant (Assist/Ollama, Alexa, Google Assistant). Safe operation - only reads data. Use to check which entities are available for voice control.
ha_list_filesread[READ-ONLY] List files and directories in Home Assistant with pagination support. Safe operation - only reads data. Default page_size is 250; if response has has_next=true, request next page.
ha_list_helpersread[READ-ONLY] List helpers in Home Assistant with pagination/filtering. Safe operation - only reads data. If has_next=true, request next page.
ha_list_installed_addonswrite[READ-ONLY] List only installed add-ons. Safe operation - only reads data.
ha_list_repositorieswrite[READ-ONLY] List all add-on repositories connected to Home Assistant. Shows which sources provide available add-ons. Safe operation - only reads data.
ha_list_scriptsread[READ-ONLY] List scripts in Home Assistant with pagination/filtering. Safe operation - only reads data. Default page_size is 250. Use ids_only=true for token-efficient listing. If has_next=true, request next page.
ha_list_store_addonswrite[READ-ONLY] List add-ons from add-on store catalog with pagination/filtering. Safe operation - only reads data. If has_next=true, request next page.
ha_list_themesread[READ-ONLY] List all available themes in Home Assistant. Safe operation - only reads data.
ha_list_todosread[READ-ONLY] Get items from a todo list entity. Safe operation.
ha_list_zonesread[READ-ONLY] List all zones configured in Home Assistant (used for presence detection). Safe operation.
ha_logbook_entriesread[READ-ONLY] Fetch Home Assistant logbook entries for analyzing automations, scripts, and other events.
ha_preview_dashboardread[READ-ONLY] Preview current Lovelace dashboard configuration. Shows existing ui-lovelace.yaml if configured. Safe operation - only reads data.
ha_read_fileread[READ-ONLY] Read a file from Home Assistant configuration directory. Safe operation - only reads data.
ha_reload_configwrite[WRITE] Reload Home Assistant configuration. APPLIES changes - requires approval!
ha_reload_themeswrite[WRITE] Reload themes in Home Assistant. MODIFIES system state - requires approval. Calls frontend.reload_themes service.
ha_remove_device_registry_entrydestructive[WRITE] Remove device from Device Registry. MODIFIES device registry - requires approval.
ha_remove_entity_registry_entrydestructive[WRITE] Remove entity from Entity Registry. MODIFIES entity registry - requires approval.
ha_rename_entitywrite[WRITE] Rename an entity_id in Home Assistant via Entity Registry. MODIFIES entity registry - requires approval. After renaming, you may need to reload automations/scripts that reference the entity.
ha_restartwrite[WRITE] FULL restart of Home Assistant. Completely restarts HA Core. Use when configuration changes require full restart (e.g., new dashboards, integrations). HA will be unavailable for 30-60 seconds. DISRUPTIVE - requires approval!
ha_restart_addonwrite[WRITE] Restart an add-on. MODIFIES system - requires approval.
ha_set_addon_optionswrite[WRITE] Set add-on configuration options. MODIFIES configuration - requires approval. Add-on may need restart.
ha_start_addonwrite[WRITE] Start an add-on. MODIFIES system - requires approval.
ha_stop_addonwrite[WRITE] Stop a running add-on. MODIFIES system - requires approval.
ha_uninstall_addondestructive[WRITE] Uninstall a Home Assistant add-on. DESTRUCTIVE - requires approval! Removes add-on and its data.
ha_uninstall_hacsdestructive[WRITE] Uninstall HACS (Home Assistant Community Store). Removes HACS directory, storage files, and restarts Home Assistant. DESTRUCTIVE - requires approval!
ha_update_addonwrite[WRITE] Update an add-on to latest version. MODIFIES system - requires approval. Update can take several minutes.
ha_update_areawrite[WRITE] Update area in Area Registry. MODIFIES area registry - requires approval.
ha_update_automationwrite[WRITE] Update existing automation in Home Assistant. MODIFIES configuration - requires approval. Provide a meaningful description of what changed and why (e.g.,
ha_update_device_registrywrite[WRITE] Update device in Device Registry (area_id, name_by_user, disabled_by, etc.). MODIFIES device registry - requires approval.
ha_update_entity_registrywrite[WRITE] Update entity in Entity Registry (name, area_id, disabled status, etc.). MODIFIES entity registry - requires approval.
ha_update_scriptwrite[WRITE] Update existing script in Home Assistant. MODIFIES configuration - requires approval. Provide a meaningful description of what changed and why (e.g.,
ha_update_themewrite[WRITE] Update an existing theme in Home Assistant. MODIFIES configuration - requires approval. After update, call ha_reload_themes or restart HA. Provide a meaningful description of what changed (e.g.,
ha_write_filewrite[WRITE] Write content to a file in Home Assistant. MODIFIES configuration - requires approval. Provide a meaningful description of what and why you are changing (e.g.,
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMInventory / provenance · inv.binary · CWE-1104
coolver-mcp-home-assistant-1.0.0.tgz
coolver-mcp-home-assistant-1.0.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
ha_delete_area, ha_delete_automation, ha_delete_dashboard, ha_delete_file, ha_delete_helper, ha_delete_script, ha_delete_theme, ha_delete_zone, ha_remove_device_registry_entry, ha_remove_entity_regist
Why it matters. 12 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
CHANGELOG.md:160
**Full access to Home Assistant registries with metadata and area assignments**

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6091a5835985full audit observations/trust-audit/mcp-server/coolver__home-assistant-vibecode.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086091a5835985CAUTIONB89first audit
06

Questions

What is the Home Assistant Vibecode MCP server?

Home Assistant MCP Server. Enable Cursor, VS Code, Claude Code or any MCP-enabled IDE to vibe-code and manage Home Assistant: create automations, design dashboards, tweak themes, modify configs and deploy changes to your HA instance using natural language 🏠🤖

What tools does Home Assistant Vibecode expose?

93 in total: 38 read-only, 43 that write, and 12 that can delete or overwrite (ha_delete_area, ha_delete_automation, ha_delete_dashboard, ha_delete_file, ha_delete_helper). Every one is listed on this page with its risk.

Is Home Assistant Vibecode safe to connect to an agent?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Home Assistant Vibecode need?

It reads HA_AGENT_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Home Assistant Vibecode run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @coolver/home-assistant-mcp at 3.2.31.

How current is this page?

The grade is for one exact copy of the source (6091a5835985), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement