- name
- pp-eero
- description
- Inspect an eero mesh network from the terminal with agent-friendly output for networks, nodes, connected devices, diagnostics, and speed tests.
- author
- Erik Rogne
- license
- Apache-2.0
- argument-hint
- <command> [args] | install cli|mcp
- allowed-tools
- Read Bash
- metadata
- {"openclaw":{"requires":{"bins":"[Truncated]"},"install":["[Truncated]"]}}
<!-- GENERATED FILE — DO NOT EDIT.
This file is a verbatim mirror of library/devices/eero/SKILL.md,
regenerated post-merge by tools/generate-skills/. Hand-edits here are
silently overwritten on the next regen. Edit the library/ source instead.
See the repository agent guide, section "Generated artifacts: registry.json, cli-skills/". -->
# Eero — Printing Press CLI
## Prerequisites: Install the CLI
This skill drives the `eero-pp-cli` binary. **You must verify the CLI is installed before invoking any command from this skill.** If it is missing, install it first:
1. Install via the Printing Press installer. It defaults binaries to `$HOME/.local/bin` on macOS/Linux and `%LOCALAPPDATA%\Programs\PrintingPress\bin` on Windows:
```bash
npx -y @mvanhorn/printing-press-library install eero --cli-only
```
2. Verify: `eero-pp-cli --version`
3. Ensure the reported install directory is on `$PATH` for the agent/runtime that will invoke this skill.
If the `npx` install fails (no Node, offline, etc.), fall back to a direct Go install (requires Go 1.26.5 or newer). This installs into `$GOPATH/bin` (default `$HOME/go/bin`), so add that directory to `$PATH` instead:
```bash
go install github.com/mvanhorn/printing-press-library/library/devices/eero/cmd/eero-pp-cli@latest
```
If `--version` reports "command not found" after install, the runtime cannot see the binary directory on `$PATH`. Do not proceed with skill commands until verification succeeds.
eero-pp-cli turns the unofficial eero account API into a small, read-first command surface for networks, nodes, connected devices, diagnostics, and speed tests. It supports browser-cookie login for local use and EERO_SESSION_TOKEN for non-interactive automation.
## When Not to Use This CLI
Do not activate this CLI for requests that require creating, updating, deleting, publishing, commenting, upvoting, inviting, ordering, sending messages, booking, purchasing, or changing remote state. This printed CLI exposes read-only commands for inspection, export, sync, and analysis.
## Unique Capabilities
These capabilities aren't available in any other tool for this API.
### Read-first network operations
- **`network`** — One agent-friendly read combines network status, speed summary, client count, node count, DNS, and feature settings.
_Use this first when diagnosing whether an eero network is healthy before drilling into a node or client._
```bash
eero-pp-cli network 550e8400-e29b-41d4-a716-446655440000 --agent
```
- **`eero list`** — List all eero nodes in a network with compact agent-friendly output.
_Use it to identify the node to inspect when coverage or topology is the problem._
```bash
eero-pp-cli eero list 550e8400-e29b-41d4-a716-446655440000 --agent
```
- **`device list`** — List connected client devices for a network, with filters and compact JSON for downstream automation.
_Use it to answer which clients are connected before investigating one device in detail._
```bash
eero-pp-cli device list 550e8400-e29b-41d4-a716-446655440000 --agent
```
- **`diagnostics`** — Fetch the latest diagnostic report for a network through the same authenticated CLI surface.
_Use it when the health snapshot shows a problem and you need the provider's latest diagnostic signal._
```bash
eero-pp-cli diagnostics 550e8400-e29b-41d4-a716-446655440000 --agent
```
- **`speed-test`** — Read the latest available speed-test results for a network as structured output.
_Use it to distinguish topology or client issues from an upstream throughput problem._
```bash
eero-pp-cli speed-test 550e8400-e29b-41d4-a716-446655440000 --agent
```
## Command Reference
**account** — Authenticated eero account summary
- `eero-pp-cli account` — Show the authenticated account and available networks.
**activity** — eero Plus network activity summary
- `eero-pp-cli activity <network_id>` — Show network activity insights when the account has eero Plus.
**device** — Connected client devices
- `eero-pp-cli device list` — List connected and recently seen client devices on a network.
- `eero-pp-cli device show` — Show one connected device by its resource ID.
**diagnostics** — Network diagnostics
- `eero-pp-cli diagnostics <network_id>` — Show the latest diagnostic report for a network.
**eero** — eero mesh nodes
- `eero-pp-cli eero list` — List the eero nodes in a network.
- `eero-pp-cli eero show` — Show one eero node by its resource ID.
**network** — eero network configuration and health
- `eero-pp-cli network <network_id>` — Show network health, speed summary, client count, node count, DNS, and feature settings.
**profiles** — Parental-control profiles
- `eero-pp-cli profiles list` — List profiles attached to a network.
- `eero-pp-cli profiles show` — Show one parental-control profile by its resource ID.
**speed_test** — Network speed-test results
- `eero-pp-cli speed-test <network_id>` — List the latest available speed-test results for a network.
### Finding the right command
When you know what you want to do but not which command does it, ask the CLI directly:
```bash
eero-pp-cli which "<capability in your own words>"
```
`which` resolves a natural-language capability query to the best matching command from this CLI's curated feature index. Exit code `0` means at least one match; exit code `2` means no confident match — fall back to `--help` or use a narrower query.
## Auth Setup
The eero service uses a session cookie rather than a conventional API key. Run `eero-pp-cli auth login --chrome` to harvest the eero session from Chrome, or set EERO_SESSION_TOKEN when an existing session token is already available. Never commit cookie files or tokens.
Run `eero-pp-cli doctor` to verify setup.
## Agent Mode
Add `--agent` to any command. Expands to: `--json --compact --no-input --no-color --yes`.
- **Pipeable** — JSON on stdout, errors on stderr
- **Filterable** — `--select` keeps a subset of fields. Dotted paths descend into nested structures; arrays traverse element-wise. Critical for keeping context small on verbose APIs:
```bash
eero-pp-cli account --agent --select id,name,status
```
- **Previewable** — `--dry-run` shows the request without sending
- **Offline-friendly** — sync/search commands can use the local SQLite store when available
- **Non-interactive** — never prompts, every input is a flag
- **Read-only** — do not use this CLI for create, update, delete, publish, comment, upvote, invite, order, send, or other mutating requests
### Response envelope
Commands that read from the local store or the API wrap output in a provenance envelope:
```json
{
"meta": {"source": "live" | "local", "synced_at": "...", "reason": "..."},
"results": <data>
}
```
Parse `.results` for data and `.meta.source` to know whether it's live or local. A human-readable `N results (live)` summary is printed to stderr only when stdout is a terminal AND no machine-format flag (`--json`, `--csv`, `--compact`, `--quiet`, `--plain`, `--select`) is set — piped/agent consumers and explicit-format runs get pure JSON on stdout.
## Paths and state
Agents should treat the CLI's path resolver as part of the runtime contract:
- Use `--home <dir>` for one invocation, or set `EERO_HOME=<dir>` to relocate all four path kinds under one root.
- Use per-kind env vars only when a specific kind must diverge: `EERO_CONFIG_DIR`, `EERO_DATA_DIR`, `EERO_STATE_DIR`, `EERO_CACHE_DIR`.
- Resolution order is per-kind env var, `--home`, `EERO_HOME`, XDG (`XDG_CONFIG_HOME`, `XDG_DATA_HOME`, `XDG_STATE_HOME`, `XDG_CACHE_HOME`), then platform defaults.
- `config` contains settings like `config.toml` and profiles. `data` contains `credentials.toml`, `data.db`, cookies, and auth sidecars. `state` contains persisted queries, jobs, and `teach.log`. `cache` contains regenerable HTTP/cache files.
- Stored secrets live in `credentials.toml` under the data dir. Existing legacy `config.toml` secrets are read for compatibility and leave `config.toml` on the first auth write.
- Run `eero-pp-cli doctor --fail-on warn` to surface path and credential-location warnings. `agent-context` exposes a schema v4 `paths` block for agents that need the resolved dirs.
- For MCP, pass relocation through the MCP host config. The MCP binary does not inherit CLI flags:
```json
{
"mcpServers": {
"eero": {
"command": "eero-pp-mcp",
"env": {
"EERO_HOME": "/srv/eero"
}
}
}
}
```
Fleet precedence: an inherited per-kind env var overrides an explicit `--home` for that kind. Use `EERO_HOME` or per-kind vars as durable fleet levers, and use `--home` only for a single invocation. Relocation is not reversible by unsetting env vars; move files manually before clearing `EERO_HOME`, or `doctor` will not find credentials left under the former root.
## Automatic learning
This CLI ships a self-capturing learning loop. The CLI does its own bookkeeping: every invocation is journaled locally, a failed flag followed by a corrected retry auto-derives a `flag_alias` candidate, and a `teach` on a query family without a playbook auto-synthesizes a `playbook_candidate` from the session's journal. Your job is judgment only: `recall` first, act on surfaced candidates, `teach` the final answer, `playbook amend` when you observe a correction. You never record failures by hand.
### Step 1: `recall` before any discovery
Before list/search/drill commands on a new user question, run:
```bash
eero-pp-cli recall "<user's question>" --agent
```
The response envelope:
```json
{
"query": "...",
"normalized": "<normalized form>",
"query_entities": ["..."],
"found": true | false,
"match_score": 0.0,
"results": [
{ "resource_id": "...", "resource_type": "...", "venue": "...",
"confidence": 2, "entity_match": "exact|partial|unknown",
"source": "taught|preseed|pattern", "warnings": ["..."] }
],
"mismatches": [ /* only when --debug-mismatches */ ],
"warnings": [ /* top-level */ ],
"candidates": [
{ "id": 12, "class": "flag_alias | playbook_candidate",
"summary": "...", "sightings": 3, "last_seen": "...",
"rationale": "...",
"next_action": ["<trial command>", "eero-pp-cli learnings confirm 12"] }
],
"playbook": {
"query_family": "...",
"playbook": {
"steps": [ { "cmd": "<command with {slot} substitution>", "purpose": "..." } ],
"entity_slots": ["$ENTITY"],
"expected_tool_calls": 3
},
"slots_resolved": { "$ENTITY": { "token": "<live token>", "canonical": "<canonical>" } },
"notes": "<workarounds + gotchas for this query family>"
},
"notes": "<duplicate surface for non-playbook callers>"
}
```
Empty-store short-circuit: if the store has no learnings, playbooks, or candidates yet (recall finds nothing and `learnings list` and `learnings candidates` are both empty), skip recall for the rest of this session instead of taxing every query; resume recall-first once something has been taught.
### Step 2: decision tree
Read `candidates`, `playbook`, `notes`, `results[0]`, and warnings in that order:
```
if Candidates present (warnings include "candidates_present"):
-> candidates are try-then-confirm, never facts. Follow each candidate's
two-step next_action verbatim: run the trial command first, then run
`learnings confirm <id>` only after the trial verified the behavior.
Reject a wrong candidate with `learnings reject <id>`.
-> NEVER re-teach something recall surfaced as a candidate; confirm or
reject that candidate instead of teaching a duplicate.
-> candidates ride alongside playbooks and resource hits, not instead of
them; continue with the branches below after acting on them.
if Playbook present:
-> READ Playbook.notes verbatim FIRST (workarounds + gotchas the CLI surface doesn't expose)
-> replay Playbook.steps in order, substituting Playbook.slots_resolved entries
for the entity slot tokens. If a step's slot is unresolved, fall back to
discovery for that step only.
-> the Playbook's expected_tool_calls is a budget; if you find yourself running
materially more, record the divergence via `eero-pp-cli playbook amend`
at end-of-session.
elif Notes present (no Playbook):
-> read Notes verbatim before any discovery step; they carry known gotchas
for this query family even when no structured choreography exists yet.
elif Found AND Results[0].EntityMatch == "exact" AND Results[0].Confidence >= 2:
-> skip discovery; fetch live data for Results[*].ResourceID in parallel
elif Found AND Results[0].EntityMatch == "partial":
-> candidate hint, NOT a hit; read the resource title to validate before trusting
elif (any row in Mismatches[] when --debug-mismatches was passed):
-> treat as cold start; the stored learning is for a different entity
(different canonical resolved from query_entities)
else: // Found == false, no playbook, no notes
-> cold start; run discovery normally; teach the answer afterward (Step 4).
If the family has no playbook yet, that teach auto-synthesizes a
playbook candidate from this session's journal - you do not need to
record one by hand.
```
Playbook and Notes are orthogonal to the per-resource path. A recall response can carry both a Playbook AND a `Results[]` hit - use both: the Playbook tells you which choreography to run; the resource hits short-circuit specific steps. Default to skipping `mismatches`; pass `--debug-mismatches` only when investigating cold-start surprises.
Candidate judgment details: `learnings confirm <id>` prints the candidate's full payload before materializing it - check that the printed payload matches the behavior you verified. `learnings reject <id>` tombstones the derivation signature so the same candidate does not resurface. The envelope carries only the few candidates worth acting on now; `eero-pp-cli learnings candidates` lists the full open set.
Graceful degradation: if `learnings confirm` is an unknown command, you are driving an older binary - ignore the candidates guidance and follow the rest of the protocol.
### Step 3: always read `warnings`
- `low_confidence`: row exists at `confidence<2`. Treat as a hint, not a skip-discovery hit.
- `resource_not_in_store`: the local store doesn't have the resource the learning points at. The match validator couldn't classify entities — direct-fetch and re-evaluate.
- `cross_alias_match` (per-result): the row was taught under a different alias and matched the live query's canonical via `entity_lookups` (e.g., a "USA" teach satisfying a "United States" recall). Trust the resource_id.
- `similar_shape_different_entity:<canonical>` (top-level): a structurally matching row exists but its canonical entity differs from the live query's. Treated as cold start; the warning carries the conflicting canonical as a hint, but the row is NOT promoted into Results.
- `ambiguous_alias` (top-level): a single query entity resolved to multiple canonicals (e.g., "Cards" → Arizona Cardinals + St. Louis Cardinals). Surface the ambiguity from context before committing to a resource.
- `candidates_present` (top-level): the envelope carries a `candidates` section. Handle it via the candidates branch in Step 2 before anything else.
- Top-level `no_learnings_for_query_family`: the table had no rows above the Jaccard floor. Pure cold start.
### Step 4: `teach &` after finalizing your response - always
Teaching is unconditional. After resolving a query the store could not answer, background-teach the final resource mapping - no call-count threshold, no judging whether it was "worth" learning. The teach is the anchor of the loop: it triggers playbook synthesis for a family without a playbook, and same-referent phrasings fold into one family so near-duplicate teaches do not fragment the store. Fire it after assembling your user-facing response but BEFORE emitting it, with a shell `&` so the call returns immediately:
```bash
eero-pp-cli teach --query "<user's question>" --resource-type <type> --resource <id1> --resource <id2>
# (append shell `&` to background it)
```
View on GitHub