One question every Home Assistant user should ask before installing a custom add-ons

One question every Home Assistant user should ask before installing a custom add-ons

Published Jul 25, 2026, 9:45 AM EDT Tim has been covering technology for almost 20 years, in that time spanning a broad range of topics from security to product reviews. He is especially focused on the Apple ecosystem, productivity, and consumer advice. Over the years Tim has written thousands of articles, reviews, and round-ups in addition to producing video content and original photography. A graduate of journalism, he found his footing as a freelancer with a laptop and loves how he is able to work from practically anywhere. Now a Senior Editor for iPhone, Mac, and Smart Home at How-To Geek, Tim still loves to write. He can also be found crafting round-ups and productivity posts for the Zapier blog. Earlier in his career Tim spent nearly a decade as a writer and eventually Apple section editor for MakeUseOf. Tim currently lives in Brisbane, Australia. Outside of work he loves to hike and work out, play video games, and spend quality time with his wonderful partner and two cats Inka and Roger. The rise of AI has been both a blessing and a curse for software development. On the one hand, experienced programmers can turbo-charge their productivity. On the other, vibe-coding means anyone can have a go—even if they have little experience. Before you add an integration or app to your Home Assistant smart home, ask yourself: is it vibe-coded and could it put my smart home at risk? Vibe-coded add-ons are risky business Everyone is a programmer now Vibe-coding is the practice of using large language models (LLMs) like ChatGPT and Claude to develop software with little understanding of the underlying framework. These tools absolutely have a valid role to play in the development world, and not all use of AI tools constitutes vibe coding. Not all developers are relying solely on “vibes.” I spoke to a friend who develops software for a living, and he explained the “garbage in, garbage out” nature of these tools. The code you receive is only as good as the instructions you provide, and the more knowledgeable you are on how a problem is best solved and the practices involved in doing so, the better you can guide the tool. Experienced developers are adept at spotting problems with this code and fixing issues as they arise. A lot of software depends on established shared libraries. Flaws that arise in these libraries can present knock-on problems with the projects that depend on them, and one of the biggest concerns with vibe-coded projects is the lack of agility in responding to these issues. Any software can be abandoned or neglected, but those odds are higher when its existence depends solely on a prompt. There are many valid reasons one might turn to vibe coding, particularly in low-stakes personal projects. Some examples include help with YAML for Home Assistant dashboards, designing cards, or simple ESPHome devices. But more people than ever are using vibe coding to expand Home Assistant with custom integrations and apps (previously known as add-ons). These add-ons have access to your smart home server, and many talk to remote services. The most concerning example I ever saw was a vibe-coded facial recognition system that unlocks a smart lock based on a smart doorbell feed. This is how you get projects that let anyone unlock your home with a printed photograph of your face. How to spot vibe-coded projects It’s easier said than done Home Assistant comes with a lot of integrations in its core release, and these are frequently reviewed by the team (with new ones added, and old ones removed depending on whether they pass the bar for quality). These are generally considered trustworthy since they must be actively maintained. But there’s a whole world of custom integrations out there that can be installed via the excellent Home Assistant Community Store (HACS). Some of my favorite integrations are custom elements that let me do things like display public transport departures on my dashboard or control my heating and cooling system. These are mostly added using custom GitHub repositories. Spotting vibe-coded projects can be difficult, but there are some telltale signs. Many GitHub repositories will include the LLM on the list of contributors; for example, “Claude” has become a lot more common. This doesn’t necessarily mean that the project was vibe coded, but that Claude was used in its production. Many project authors are forthcoming in their use of these tools when announcing their projects to the world. This is common on subreddits like r/HomeAssistant, but it can result in a deluge of downvotes. Another “red flag” that pops up a lot is a user introducing their tool in a post that was obviously written by AI. Sometimes, you’re essentially rolling the dice. Depending on what the component is doing, this might not be a big deal. For niche services, you might not have a choice. Open-source projects are at least transparent, so others can see exactly what’s going on. But that highlights another problem. Closed-source projects add another layer of doubt It’s all about the money, money, money The “vibe-coded economy” is one of the more troubling developments that Home Assistant has seen for a while. While the project’s community spirit is very much alive and well, there’s been a surge in people looking to make some money by cashing in on the platform’s popularity. Described by a colleague as a “side-hustle” trend, the rise of closed-source integrations that lock certain features behind paywalls feels at odds with the Home Assistant project. It’s not that developers don’t deserve to be paid for their work, but rather that some of these individuals were never developers in the first place. To keep it short: always be suspicious of Home Assistant expansions that require you to open your wallet. I’m not talking about Home Assistant Cloud or established open-source projects like Frigate and Scrypted that integrate paid elements. I’m specifically referring to smaller upstart projects that are destined for the dustbin of vibe-coded apps in a few months or years. Home Assistant Green Dimensions (exterior) 4.41"L x 4.41"W x 1.26"H Weight 12 Ounces Home Assistant Green is a pre-built hub directly from the Home Assistant team. It's a plug-and-play solution that comes with everything you need to set up Home Assistant in your home without needing to install the software yourself. For some, installing a vibe-coded app is worth the risk. That’s how some feel about useful additions like Upgrade Advisor for Home Assistant.

Original Source

Read the full article at Howtogeek →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.