Switchr Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Switchr Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Node.js MCP (Model Context Protocol) server that exposes SwitchBot temperature sensors for monitoring via Claude Desktop or Home Assistant.
cd switchr-mcp
npm installSwitchBot API credentials are managed by @caseman72/switchr-api via .env.local. The file is searched in:
~/.config/switchr-api/.env.local~/.switchbot.env.localCreate a .env.local file with your SwitchBot credentials:
SWITCHBOT_TOKEN=your-switchbot-token
SWITCHBOT_SECRET=your-switchbot-secretVisit the SwitchBot Developer Portal to obtain your API credentials.
Copy config.example.json to config.json to customize server settings:
{
"server": {
"transport": "stdio",
"httpPort": 8001,
"httpHost": "127.0.0.1"
},
"devices": {
"refreshIntervalMinutes": 60
},
"monitoring": {
"enabled": false,
"logFile": "./switchr-mcp-requests.log"
}
}node src/index.jsThe HA custom component requires the MCP server to be exposed over HTTP/SSE. Use mcp-proxy to bridge the stdio server.
#### Install mcp-proxy
brew install mcp-proxy#### Start the proxy
# Binds to all interfaces so Docker can reach it
mcp-proxy --port 8082 --host 0.0.0.0 -- node /path/to/switchr-mcp/src/index.js cp -r custom_components/switchr_mcp ~/.home-assistant/custom_components/host.docker.internal (for Docker) or your Mac's IP8082#### Entities created
Meter, MeterPlus, WoIOSensor): one combined entity per device with temperature as the native value and humidity/battery as attributes.<name> Power (W), <name> Voltage (V), <name> Current (mA), <name> Energy (kWh), and switch.<name> (on/off control). The Energy entity integrates instantaneous power between polls and persists across HA restarts via RestoreEntity, so it can be used directly in the HA Energy dashboard with no Riemann helper.button.<name>_press — sends a momentary press (extend then retract). Suitable for pressMode Bots.#### Auto-start mcp-proxy with launchd
Create ~/Library/LaunchAgents/com.switchr.mcp-proxy.plist:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>com.switchr.mcp-proxy</string>
<key>ProgramArguments</key>
<array>
<string>/opt/homebrew/bin/mcp-proxy</string>
<string>--port</string>
<string>8082</string>
<string>--host</string>
<string>0.0.0.0</string>
<string>--</string>
<string>/opt/homebrew/bin/node</string>
<string>/path/to/switchr-mcp/src/index.js</string>
</array>
<key>WorkingDirectory</key>
<string>/path/to/switchr-mcp</string>
<key>RunAtLoad</key>
<true/>
<key>KeepAlive</key>
<true/>
<key>StandardOutPath</key>
<string>/tmp/switchr-mcp-proxy.log</string>
<key>StandardErrorPath</key>
<string>/tmp/switchr-mcp-proxy.err</string>
</dict>
</plist>Then load it:
launchctl load ~/Library/LaunchAgents/com.switchr.mcp-proxy.plistTo stop/unload:
launchctl unload ~/Library/LaunchAgents/com.switchr.mcp-proxy.plist#### Managing the service
# Check status
launchctl list | grep switchr
# View logs
tail -f /tmp/switchr-mcp-proxy.err
# Restart
launchctl unload ~/Library/LaunchAgents/com.switchr.mcp-proxy.plist
launchctl load ~/Library/LaunchAgents/com.switchr.mcp-proxy.plist
# Stop
launchctl unload ~/Library/LaunchAgents/com.switchr.mcp-proxy.plistAdd to ~/.claude/claude_desktop_config.json:
{
"mcpServers": {
"switchr": {
"command": "node",
"args": ["/path/to/switchr-mcp/src/index.js"],
"env": {}
}
}
}list_devicesList all discovered SwitchBot devices. Optionally filter to show only temperature sensors.
Parameters:
sensorsOnly (optional): If true, only return temperature sensors (Meter, MeterPlus, WoIOSensor)refresh (optional): Force refresh device list from SwitchBot APIget_device_statusGet detailed status of any SwitchBot device. Returns device-specific properties like power state, battery level, etc.
Parameters:
deviceId: Device ID or device nameget_temperatureGet temperature and humidity reading from a specific SwitchBot temperature sensor.
Parameters:
deviceId: Device ID or device name of the temperature sensorunit (optional): Temperature unit - F for Fahrenheit (default), C for CelsiusResponse includes:
temperature: Current temperature in requested unithumidity: Current humidity percentagebattery: Battery level percentageget_all_temperaturesGet temperature and humidity readings from all SwitchBot temperature sensors at once.
Parameters:
unit (optional): Temperature unit - F for Fahrenheit (default), C for Celsiusget_plug_statusGet power state and energy data from a SwitchBot Plug Mini. Use for UPS/energy monitoring.
Parameters:
deviceId: Device ID or device name of the plugResponse includes:
power: "on" or "off"voltage: Voltswatts: Instantaneous power draw (W)currentMilliamps: Current draw (mA)electricityOfDay: Today's on-time accumulator from the deviceget_all_plugsGet power and energy readings from all SwitchBot Plug Mini devices at once.
turn_on / turn_offTurn a SwitchBot Plug Mini (or a Bot in switch mode) on/off.
Parameters:
deviceId: Device ID or device namepress_botSend a momentary press to a SwitchBot Bot (finger simulator). The finger extends then retracts.
Parameters:
deviceId: Device ID or device name of the Botget_api_statusGet SwitchBot API rate limit status. Returns remaining calls, reset time, and cache info.
Response includes:
rate_limit.remaining: API calls remainingrate_limit.reset_by: When the rate limit resetscache.last_refresh: When devices were last refreshedcache.device_count: Total devices discoveredcache.sensor_count: Temperature sensors discoveredEnable request logging in config.json:
{
"monitoring": {
"enabled": true,
"logFile": "./switchr-mcp-requests.log"
}
}Logs are written in JSON Lines format with timestamps, tool names, parameters, and results.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.