Query and control a SimpliSafe alarm system from the shell with curl — read system state, sensors, locks, events and settings, and arm/disarm or lock/unlock. Use when the user asks about their SimpliSafe alarm, house sensors, door locks, or whether the system is armed. Requires a one-time browser login to mint a refresh token.
编程
Safe Device Control
试用Physical-device control safety gate — never blindly toggle cloud devices; check state, surface risk, require explicit go-ahead before risky actions.
它能做什么
Physical-device control safety gate — never blindly toggle cloud devices; check state, surface risk, require explicit go-ahead before risky actions.
技能文档
Safe Device Control
Core Rule
Never execute risky control actions on physical devices without explicit go-ahead from Hobo. Risky = anything that could lock a device offline, change persistent settings, require physical intervention to reverse, or trigger firmware/account-level locks.
Pre-Action Checklist (Before Any Risky Control Command)
- Read current state first — get full device state via the sensor endpoint
- Classify the action into one of the risk tiers below
- Surface the risk — tell Hobo what could go wrong
- Get explicit go-ahead for write-risky and write-irreversible actions
- Verify after — read state again, confirm intended change actually happened
Risk Tiers
Read-Only — no gate needed
- Get current state, list devices, read sensors, query API
Write-Low-Risk — execute, but verify state after
- Toggle Tapo plug on/off (state-verifiable via /plug/)
- Set fan_speed (queued, reversible, doesn't lock device)
- Set mode to a known preset (Auto/Strong/Sleep — reversible)
- Send learned IR code (reversible)
Write-Risky — require explicit go-ahead from Hobo
- Power toggle action on any cloud-controlled device (can trigger deep standby — see FP10 incident below)
- Factory reset, firmware update, account linking/unlinking
- Wipe learned IR codes, change device passwords
- First-time control of a device that hasn't been end-to-end-tested before
- Any action where the API returns
code: 0but device state didn't actually change (treat as suspicious)
Write-Irreversible — requires typed approval from Hobo
- Anything in AGENTS.md red lines (deleting files, configs, cron jobs)
- Anything destructive flagged in HEARTBEAT.md or LISTS.md
- Network/firewall changes, auth key rotations
Mistakes to Avoid (Lessons from FP10 Incident, 2026-07-17)
- Don't blindly toggle power on a cloud-controlled device. The Dreame FP10 toggle action (
siid=2, aiid=3) put the device into deep standby — went fromonline: True(with stale reads) toonline: False(no reads at all). Required physical button press on the unit to recover. code: 0from cloud APIs is not confirmation. The Dreame cloud returned success forset_propertieson power (siid=2, piid=1) when the device silently rejected it. The action toggle returned success and then bricked the connection. Cloud acceptance ≠ device execution.- Don't run untested control code on a real device. Test with
dry_run=true, against a known-good baseline, or against a non-critical device first. - Don't assume state. Always read current state before controlling. If state is ambiguous (e.g., device shows online but power state is stuck, or returns stale values like
fan_speed=8/10while reportingpower=2), stop and ask. - Don't chain control commands without per-step verification. Set one thing, verify it actually took effect, then proceed.
- The "soft off" model matters. Some devices (Dreame FP10 included) have a soft-off state (e.g., Sleep mode + fan_speed=1) that keeps cloud alive, vs a deep standby (physical button press) that disconnects. Confirming which state we're in should be the first read before any control action.
Concrete API Guards (Already Implemented)
POST /dreame//onrequires{"force": true}in body — refuses without it (HTTP 403 with reason). Hobo must explicitly type the confirmation.POST /dreame//off— soft-off only (Sleep + fan_speed=1). No deep standby path.POST /dreame//fan_speed— value is clamped 1-10 (FP10 supports 10 manual speeds). No gate, since it's reversible.- Future risky endpoints should follow the same
force=truepattern.
Recovery Procedures
- Dreame FP10 deep standby: physical power button press on the unit (~3s hold). After wake, fan_speed queued value should be honored.
- Tapo plug offline: unplug 10s, replug, wait for DHCP lease + WiFi reconnect.
- Broadlink RM4 Mini timeout: power cycle the unit (unplug/replug).
- Anything else: check the device's official app first to confirm cloud-side state before re-trying from our API.
When to Use This Skill
Use this skill BEFORE any device control action that is:
- A new control path (first time we're sending this command to this device)
- Anything in the Write-Risky tier
- An action that has previously failed or behaved unexpectedly
- Part of a chained sequence where one link failed
Routine actions already validated end-to-end (e.g., turning the plant-light on/off, sending a learned IR button) don't need to re-trigger this skill every time — they're pre-approved by their existing log of successful runs.
Sources
- Original incident:
memory/2026-07-17.md(21:11–21:49 SGT) - MiOT spec verified from: https://github.com/CodyJon/dreame-ap10-integration
- Force-guard implementation:
scripts/smart-home/app.py(dreame_onendpoint) - HEARTBEAT.md: "Device Control — Safety Gate" section (loaded at every wake)
相关技能
Sanitize logs, configs, prompts, stack traces, and skill content before they are shared publicly. Use when a user wants a local, low-risk pass to remove API...
Run and interpret a read-only OpenClaw security preflight on an authorized Linux VPS. Use when an operator asks to audit gateway exposure, authentication, RP...
安全处理本机 API 密钥、环境变量、密码、SSH、远程服务器和身份认证。任务涉及凭据读取、认证操作或远程主机连接时使用。限制秘密读取与输出,强制使用批准的 SSH 别名。
Runtime safety guard for OpenClaw multi-agent workflows. Blocks destructive tools (write, edit, exec, process, apply_patch) for controlled agents, forcing de...
Runtime interaction guard for Hermes/OpenClaw: a deterministic transition policy engine that keeps reading, browsing, and summarizing free while stripping co...