just what i find

Is the window open?

I’m sure we’ve all been there - coat on, shoes on, just about to lock the door and - “did i leave the back window open?”

I wanted something which shows me, at a glance, which windows are open, or confirms they’re all closed. E-paper display showing a Home Assistant window-status dashboard with two windows open: Front bed and Study, updated at 18:06.

goals

  • low maintenance - dont need to charge it every week
  • automatically updates in a few seconds
  • our windows can be “closed” or “latched closed” (with a ventilation space around), so support both
  • easy to glance at - no complex dashboards
  • small and unobtrusive.

What i used

  • Home Assistant Yellow
  • SNZB-04P/PR1 sensors
  • 2.6" Hanshow Polaris Pro 280 Electronic Shelf Label
  • LilyGo T-Panel S3
  • OpenEPaperLink HA integration

Window sensors

I wanted sensors with long battery life. I have a Home Assistant Yellow at home, which has Zigbee support. I already have several Zigbee plugs around the house. Most permanently powered Zigbee devices act as “routers” so there’s a strong network around the house. I decided to buy Sonoff SNZB-04P:

Responsible disclosure: TRMNL MCP server leaks password fields to AI agents

TRMNL is an awesome open-source ePaper display that lets users show almost anything they want. Launched on Kickstarter, it’s now got thousands of plugins and users. I’ve published a few plugins myself. A few weeks ago, TRMNL added an MCP server. This lets you use a local coding agent to do most of the grunt work. I wrote about how to set that up in another post.

Secret disclosure

As soon as i’d set up the MCP server, i asked Claude to test it against a plugin i’d already built and deployed. The model called IntegrationsShowTool with no arguments. The response included:

Using multiple TRMNL MCP API keys in a single plugin repo

TRMNL is an awesome open-source ePaper display that lets users show almost anything they want. Launched on Kickstarter, it’s now got thousands of plugins and users. I’ve published a few plugins, including a realtime TfL bus stop arrival time board.

A few weeks ago, TRMNL added an MCP server. This lets you use a local coding agent to do most of the grunt work.

Install the MCP server through .mcp.json

Using Claude Code, i created a simple .mcp.json file which references the API key by environment variable. Place this in the root of your repo. As it contains no secrets, this is safe to commit:

Fix: Claude Code with op run responds "No deferred tool marker found in the resumed session"

To stop my API keys being sucked up by some random malware, I keep secrets in 1Password and inject them into commands at runtime with op run. That works for almost everything, but when using Claude Code, i started getting a confusing error message.

Injecting MCP API keys to Claude Code

Claude Code reads MCP server config from .mcp.json and expands ${VAR} references from the environment.

{
  "mcpServers": {
    "trmnl": {
      "type": "http",
      "url": "https://mcp-server.com/mcp?api_key=${MY_SECRET_MCP_API_KEY}"
    }
  }
}

The API key is in a file. .env.tpl:

Recipe: Veggie smoked beans

Ingredients

  • 1 tin baked beans
  • 1 small white onion
  • 1 clove garlic
  • 1 tbsp Hendersons Relish
  • splash of vegetable oil

Method

  1. finely chop the onion
  2. grate the garlic
  3. gently (low temperature) fry onion in the vegetable oil for 5-6 mins over a medium heat in the small (metal?) roasting tin you’ll use in the smoker
  4. Take off the heat and add the grated garlic
  5. Add the beans and hendersons
  6. Stir and put in the smoker (110-120c) for 60-90 minutes. Check after 60 mins to make sure not dried out. If it starts to get dry, add a splash of water. Stir.

Recipe: Spicy cheese quesadillas

ingredients

  • 20g cheddar
  • 20g light cream cheese
  • 1 tsp paprika
  • 1/2 tsp chilli flakes
  • 30g tinned sweetcorn, drained well
  • One of:
    • 1/2 tsp miso paste
    • 1 tsp soy sauce
    • 1 tsp Hendersons relish
  • 1/4 tsp garlic powder
  • 1/4 tsp onion powder
  • pinch white pepper
  • 1 small tortilla

Method

  1. Mix cream cheese & miso/soy/Henderson’s + spices into a paste
  2. Fold in sweetcorn and cheddar
  3. Spread in tortilla and fold in half
  4. Cook in pan, place baking parchment on top and plate on that to squash slightly

Recipe: Smoked Tempeh

Smoked tempeh is excellent for smoking as the dense, porous structure absorbs smoke like few other proteins.

Ingredients

  • 30ml soy sauce
  • 3 grams (about 1-2 cloves) minced garlic
  • 15 g sesame oil
  • 15ml rice vinegar - needed to penetrate
  • pinch of salt

Method

  1. Slice into planks or thick strips rather than cubes — more surface area, better bark formation, less risk of drying out.
  2. Steam or simmer the tempeh for 10-15 minutes first. This removes bitterness and opens the pores for better smoke and marinade absorption.
  3. Marinate for at least 30 minutes. This gives time for the marinade to to infuse.
  4. Smoke at 110-130°C for 45-60 minutes.
  5. Baste or re-glaze halfway through (or more often if you like) if using a sticky marinade.

Recipe: Smoked Roast Potatoes

Ingredients

  • as many New Potatoes as you think you’ll need
  • Vegetable oil
  • salt, pepper
  • and a smoker

Method

  1. Boil new potatoes until fork-tender (15-20 min) then drain
  2. smash them on a sheet tray to break them slightly. The fluffy bits go crispy.
  3. Coat them in oil/fat (e.g. drizzle in vegetable oil) and seasoning (salt, pepper)
  4. roast in the oven at 220°C for 20-25 minutes until the edges are crispy and golden.
  5. Transfer to the smoker at 110-130°C for 20-30 minutes to pick up smoke flavour. The already-crisped surfaces absorb smoke well. Going longer than 30 minutes risks drying them out or making the smoke flavour acrid.

Updated: using 1Password and direnv to store developer secrets

I previously wrote about how i’d implemented a combination of 1Password’s CLI and direnv to avoid storing passwords on disk. This works great, most of the time. The problem comes when i want to add a secret and i’m in the middle of a complex multi-agent task - because the environment is loaded once before Claude or Codex or whatever starts, adding or rotating credentials during a build (e.g. if the agent needs an API key to a new service, or accidentally exposes a secret to its context) is tricky. So i’ve evolved the system slightly.

All posts