Atlas / MCP servers / jango-blockchained / Advanced Home Assistant

Advanced Home AssistantCAUTION

mcp/jango-blockchained/advanced-home-assistant

MCP server that gives AI assistants control over your Home Assistant. Including 50+ tools over 3 transports. Batteries included 🔋

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
91 68r · 20w · 3d
Transport
—
License
Apache-2.0
Stars
57
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@jango-blockchained/advanced-homeassistant-mcp) [](https://github.com/jango-blockchained/advanced-homeassistant-mcp/releases) [](https://www.npmjs.com/package/@jango-blockchained/homeassistant-mcp) [](https://github.com/jango-blockchained/advanced-homeassistant-mcp/pkgs/container/advanced-homeassistant-mcp) [](https://github.com/jango-blockchained/advanced-homeassistant-mcp/actions) [](https://bun.sh) [](https://nodejs.org) [](LICENSE)

Talk to your house. Your AI assistant (Claude, GPT, Cursor, Copilot) — connected to Home Assistant through the Model Context Protocol. 50+ tools, three transports, one bunx command.
# ⚡ Fastest way to try it
bunx github:jango-blockchained/advanced-homeassistant-mcp

🚀 Quick Start

You need a Home Assistant instance and a long-lived access token (create one here).

Claude Desktop

Add to claude_desktop_config.json:

{
"mcpServers": {
"homeassistant-mcp": {
"command": "bunx",
"args": ["github:jango-blockchained/advanced-homeassistant-mcp"],
"env": {
"HASS_HOST": "http://your-ha-instance:8123",
"HASS_TOKEN": "your_long_lived_access_token"
}
}
}
}

**R

Read from source at commit d2f68b18429dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add homeassistant-mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env COOKIE_SECRET=${COOKIE_SECRET} --env CORS_CREDENTIALS=${CORS_CREDENTIALS} --env HASS_TOKEN=${HASS_TOKEN} -- npx -y @jango-blockchained/[email protected]
claude-desktop
{
  "mcpServers": {
    "homeassistant-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@jango-blockchained/[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "COOKIE_SECRET": "${COOKIE_SECRET}",
        "CORS_CREDENTIALS": "${CORS_CREDENTIALS}",
        "HASS_TOKEN": "${HASS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (91)

68 read · 20 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AutomationsreadList of all configured automations
CoversreadAll cover entities (blinds, curtains, garage doors)
FansreadAll fan entities and their states
HealthreadHealth check endpoints for monitoring server status
LocksreadAll lock entities and their states
MCPreadModel Context Protocol endpoints for tool execution
SSEreadServer-Sent Events endpoints for real-time updates
ScenesreadList of all configured scenes
SensorsreadAll sensor entities (temperature, humidity, etc.)
SwitchesreadAll switch entities
ToolsreadTool management endpoints for listing and configuring tools
actionreadWhat to do with the lights (e.g.,
activityreadWhat you want to do (e.g.,
addonwriteList Home Assistant add-ons or get info on a specific add-on
addon_modifydestructiveManage Home Assistant add-ons (install, uninstall, start, stop, restart)
alarmsreadList all alarm panels or get the state of a specific alarm panel.
alarms_activatereadArm in various modes (home, away, night, vacation, custom bypass), disarm, or trigger an alarm. Security-sensitive operations.
animation_controlreadList currently running background light animations.
animation_control_activatewriteStart, stop, or stop-all background light animations (endless loops).
automationreadList Home Assistant automations and their current state.
automation_activatereadFire a Home Assistant automation
automation_config_modifywriteManage Home Assistant automations
automation_modifywriteToggle (enable/disable) a Home Assistant automation. Does not fire the automation
claudereadClaude-specific prompt template for home automation control
climatereadList all climate devices (thermostats, AC) or get the state of a specific one.
climate_activatewriteSet HVAC mode, target temperature, or fan mode on climate devices.
climate_comfortreadOptimize climate control for comfort and efficiency
controlreadControl Home Assistant entities
control_activatereadControl Home Assistant entities (lights, climate, etc.)
control_lightsreadHelp with controlling lights in a room or area
coversreadList all covers (blinds, curtains, garage doors, shades) or get the state of one.
covers_activatewriteOpen, close, stop, toggle, or set the position/tilt of a cover.
customreadCustomizable prompt template for home automation control
dashboardreadList Home Assistant Lovelace dashboards or read a dashboard
dashboard_modifywriteReplace a Home Assistant Lovelace dashboard
device_namereadThe name or type of device having issues
energy_savingreadSuggestions for energy-saving automations
fansreadList all fans or get the state of a specific fan.
fans_activatewriteControl fans: turn on/off/toggle, set speed percentage, preset mode, oscillation, direction.
get_entity_statereadGet the current state of any Home Assistant entity. Works with all entity types: sensors, binary_sensors, switches, lights, climate, covers, etc. Returns state value, timestamps, and optionally all attributes.
get_historyreadRetrieve historical data for entities
get_sse_statsreadGet statistics about SSE connections
gpt4readGPT-4 specific prompt template for precise home automation control
historyreadGet entity history
light_animation_activatewriteExecute custom light animation sequences (e.g., police lights, alerts) on any RGB light.
light_scenario_activatewriteApply ambient lighting moods (Chill, Nightly, Focus, etc.) to a specific area or light.
light_showcase_activatewriteRun a choreographed light showcase that calls various moods and custom palettes to demonstrate system capabilities.
lightsreadList all lights or get the state of a specific light.
lights_activatereadTurn lights on (with optional brightness/color/effect) or off.
list_devicesreadList all Home Assistant devices
locksreadList all locks or get the state of a specific lock.
locks_activatereadLock, unlock, or open (unlatch) physical locks. Unlocking is a security-sensitive operation.
maintenancereadAnalyze Home Assistant health: find orphaned/unavailable devices, analyze light usage and energy consumption, run device health checks. All actions are read-only — no entities are removed or modified.
media_controlreadControl media players and entertainment systems
media_playersreadList all media players or get the state of a specific media player.
media_players_activatereadControl media players: playback, volume, source/sound mode selection, play media on TVs and speakers.
morning_routinewriteCreate a morning routine automation
notifywriteSend notification
notify_activatewriteSend notifications through Home Assistant
packagereadList HACS packages and custom components by category
package_modifydestructiveManage HACS packages (install, uninstall, update)
preferred_tempreadYour preferred temperature (e.g.,
render_templatereadEvaluate a Home Assistant Jinja2 template. Use this to query complex state information, perform calculations, format data, or test template expressions. The template is rendered server-side by Home Assistant and the result is returned as text.
roomreadThe room or area name (e.g.,
scenereadList Home Assistant scenes.
scene_activatereadActivate a Home Assistant scene
scene_creationwriteCreate a scene for a specific activity or mood
scene_namereadName for the scene (e.g.,
search_entitiesreadSearch Home Assistant entities with powerful filtering. Supports domain, device_class, state (exact or comparison like
security_setupwriteSet up security and monitoring
smart_scenariosreadDetect common smart home scenarios (nobody home, window/heating conflicts, energy-saving opportunities). Read-only analysis.
smart_scenarios_activatewriteApply smart home scenarios: turn off lights and adjust climate when nobody is home, or turn off heating when windows are open. Actuates devices and sends notifications.
stream_generatorreadGenerate a stream of data with configurable delay and count
subscribe_eventsreadSubscribe to Home Assistant events via SSE
switchesreadList all switches or get the state of a specific switch (smart plugs, relays, virtual switches).
switches_activatereadTurn switches on, off, or toggle.
system_inforeadGet basic information about this MCP server including version, transport, and connection status
test_toolreadA test tool
text_to_speechreadGenerate and play text-to-speech audio via Home Assistant. Provides voice feedback for commands with support for multiple languages and TTS providers.
todoreadList Home Assistant to-do lists or get items from a specific list.
todo_modifydestructiveAdd, update, or remove items in a Home Assistant to-do list.
tracereadAccess automation and script execution traces. List recent traces, get detailed trace data, or list trace contexts. Useful for debugging automation issues.
troubleshoot_devicereadHelp troubleshoot a device that
vacuum_schedulewriteSet up robot vacuum cleaning schedule
vacuumsreadList all robot vacuums or get the state of a specific vacuum.
vacuums_activatewriteControl robot vacuums: start/pause/stop, return to dock, spot cleaning, locate, fan speed, vendor-specific commands.
validation_demoreadDemonstrates parameter validation with Zod schemas
voice_command_ai_parser_activatereadParse voice commands using AI (Claude). Makes an outbound API call to api.anthropic.com (consumes API credits, sends transcript to a third party). Falls back gracefully if AI not available.
voice_command_executor_activatewriteExecute parsed voice commands through Home Assistant. Maps intents to service calls and controls devices.
voice_command_parserreadParse natural language voice transcriptions into structured Home Assistant commands. Extracts intent, entities, and parameters from voice input.
voice_control_setupreadRecommendations for voice control setup
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/hass/index.ts:22
logger.debug(`Token loaded: yes (${this.token.length} chars)`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
addon_modify, package_modify, todo_modify
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/ai/endpoints/ai-router.test.ts:4
import type { AIResponse, AIError } from "../../../src/ai/types/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/ai/endpoints/ai-router.test.ts:23
void mock.module("../../../src/ai/nlp/processor.js", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/ai/endpoints/ai-router.test.ts:38
import router from "../../../src/ai/endpoints/ai-router.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/ai/nlp/intent-classifier.test.ts:2
import { IntentClassifier } from '../../../src/ai/nlp/intent-classifier.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/api/index.test.ts:6
import type { Entity } from '../../src/types/hass.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.opencode/audit/00-summary.md:37
| **C14** | `docker-compose.yml` hardcodes personal IP `http://192.168.178.63:8123` — privacy leak                                                          | `docker-compose.yml`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.opencode/audit/01-structure-and-config.md:168
- Default HASS host: **`http://192.168.178.63:8123`** (C14 — personal IP leaked)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs-site/src/content/docs/configuration/environment.mdx:92
HASS_HOST=http://192.168.1.50:8123
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs-site/src/content/docs/deployment/http.mdx:23
The server prints `MCP Server listening on http://0.0.0.0:4000` (or whatever `PORT` you set). Hit `GET /health` to confirm:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs-site/src/content/docs/deployment/http.mdx:53
proxy_pass http://127.0.0.1:4000;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
docs-site/package.json
@astrojs/check, @astrojs/mdx, @astrojs/react, @astrojs/sitemap, @radix-ui/react-dialog, @radix-ui/react-dropdown-menu, @tailwindcss/vite, @types/react
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/node, @types/sanitize-html, @types/swagger-ui-express, @types/uuid, @types/ws, cors, dotenv, express
Why it matters. 40 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
.smithery/index.cjs
.smithery/index.cjs
Why it matters. 1128540 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
.smithery/shttp/module.js
.smithery/shttp/module.js
Why it matters. 1880948 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
.smithery/shttp/module.js.map
.smithery/shttp/module.js.map
Why it matters. 5647346 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs-site/src/content/docs/configuration/environment.mdx:75
A handful of legacy call sites read `process.env` directly (the rate limit, the speech flags). Those are documented inline. New code should import from `APP_CONFIG` so the Zod defaults apply consisten
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs-site/src/content/docs/guides/adding-a-tool.mdx:153
- **Don't read `process.env` in the tool.** Use the context or the typed `APP_CONFIG`. The Zod validation won't catch a typo.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha d2f68b18429dfull audit observations/trust-audit/mcp-server/jango-blockchained__advanced-home-assistant.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d2f68b18429dCAUTIONB89first audit
06

Questions

What is the Advanced Home Assistant MCP server?

MCP server that gives AI assistants control over your Home Assistant. Including 50+ tools over 3 transports. Batteries included 🔋

What tools does Advanced Home Assistant expose?

91 in total: 68 read-only, 20 that write, and 3 that can delete or overwrite (addon_modify, package_modify, todo_modify). Every one is listed on this page with its risk.

Is Advanced Home Assistant safe to connect to an agent?

With care. The audit graded it B (89/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Advanced Home Assistant need?

It reads ANTHROPIC_API_KEY, COOKIE_SECRET, CORS_CREDENTIALS, HASS_TOKEN, JWT_SECRET, OPENAI_API_KEY, TEST_HASS_TOKEN, TEST_INVALID_TOKEN, TEST_JWT_SECRET, TEST_TOKEN and TOKEN_MIN_LENGTH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (d2f68b18429d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement