ESP32AI.ME
PL
release candidate · hand tests unfinished
radbox · second system for core2

Every room is talking.
This cube lets you watch.

Phones, watches, earbuds, TVs, routers, doorbells — most of what surrounds you is broadcasting all day, to nobody in particular. RADBOX turns that traffic into something you can actually watch, on a cube that fits in your hand: how busy the room is, what changed when you walked in, and whether it really goes quiet when you think it should.

Install it in a minute See what it shows

Hardware
Core2 v1.3
Runs
On the cube
Languages
EN / PL
M5Stack Core2 z ekranem RADBOX

Pulse — signal weather. Nineteen results in the last scan: twelve Wi-Fi, seven BLE, three more than the scan before.

in the hand

Forty-four seconds, filmed by hand.

Filmed on the actual cube, not rendered. What you see on the screen is what the device draws.

what changed in this build

Six things you will notice first.

Pulse, redrawn

Pulse, redrawn

Static X and Y axes instead of a compass rose. No sweep line, no centre reticle. A white reference line follows the BMI270 as you turn the cube — it answers your hand, not a radio bearing.

Deep Scan

Deep Scan

The one moment RADBOX transmits: standard BLE scan requests, four seconds at most, and only on an explicit tap. Then passive again, with a ten-second cooldown you can watch.

A 110-rule signature pack

Public appearance values, service UUIDs, documented frame patterns and protocol clues — plus session-linking of rotating adverts across as many as 64 advertisers.

Touch that lands where you aim

Bigger Settings and A/B/C targets, a 14 px / 500 ms tap, horizontal swipe between instruments, swipe down for Settings and up to come back.

Zen breathes at zero

When nothing is visible the circle breathes at a steady rate — and freezes completely when your system asks for reduced motion.

Power that tells the truth

CHG, USB, LOW or BAT, or the instantaneous directional PMIC current in mA. No hour bands, no mAh, and no promise about how long it will last.

the field kit

Nine instruments, and nine places where each one stops.

Every job gets its own screen instead of another tile in a menu. The limit under each one is part of the description, not the small print.

01

Pulse

How many Wi-Fi and BLE results the last scan found, and how that number moved against the one before it.

An aggregate. Not devices, not positions.
Pulse — RADBOX screen
02

Signals

Where the visible access points sit across channels 1–13, scaled to whichever channel carries the most of them.

Not airtime. Not interference. Not a spectrum analyser.
Signals — RADBOX screen
03

Signal Hunt

Follow one temporary session alias and watch its signal strength move. CLOSER and FARTHER describe strength, never distance or direction.

An explicit session. Optional clicks. No bearing.
Signal Hunt — RADBOX screen
04

Signal Card

Keep one of at most four scene records on the cube. WHY gives a full screen to what the card is and where it stops.

No names. No MAC or BSSID. No export in this build.
Signal Card — RADBOX screen
05

Room Sweep

Take three scans for a baseline, walk the room, take three more. The difference is a reason to look closer.

Change in visible Wi-Fi and BLE. Not a camera detector.
Room Sweep — RADBOX screen
06

BLE type clues

Groups visible BLE signals into broad, confidence-labelled type clues — phone, watch, audio, computer, IoT, unknown.

A mix, not a map. Passive by default; Deep only on an explicit tap.
BLE type clues — RADBOX screen
07

Zen

The last count becomes a calmer scene. Zero gives you ZEN, and proves nothing about silence, health or safety.

Swipe will not leave it. Back, Settings or power off.
Zen — RADBOX screen
08

Settings

Five steps of brightness and volume, interface sounds, Zen audio, vibration, bounded motion, English or Polish. Stored on the cube.

Battery in four segments in the top bar, with a state label beside it.
Settings — RADBOX screen
09

About

The QR code points back at this page. RADBOX and the Core2 Foundation work are Apache-2.0; the separate screen-capture tool stays GPL-3.0-only.

Dependencies keep their own licences. No account, no cloud.
About — RADBOX screen
the newest instrument

BLE type clues.

RADBOX groups visible BLE signals into broad, confidence-labelled type clues. Six classes, a confidence level on every single one, and Unknown whenever the evidence simply is not there.

Six broad classes

Phone, Watch, Audio, Computer, IoT — and Unknown, which is a valid result rather than a failure to try harder.

110 documented rules

Public Appearance values, service UUIDs, documented frame patterns and protocol clues like Fast Pair, LE Audio, iBeacon, BTHome and Eddystone. All of it public, all of it written down.

A confidence level on every clue

Strong, Likely or Hint. Nothing arrives as a bare fact, because a class without a confidence level reads like one.

Passive by default. Deep only when you press it.

Normal scanning listens and transmits nothing. Press DEEP and the cube sends standard BLE scan requests for at most four seconds, then drops back to listening and shows a ten-second cooldown. It never connects, never pairs, never bonds and never opens GATT.

A mix, not a map

Signal strength places a mark on one of the rings and means relative strength. It never decides the type and never a position.

BLE type clues screen
Six classes, each with a count
BLE clues explanation screen
The screen that says where it reads from

What it never givesNo exact model, no owner, no MAC, no device name, no camera verdict and no location. None of that is read, inferred or kept.

Unknown is a valid result.In a real room the passive scan typed 0 of 14 and Deep typed 0 of 16 — with eleven manufacturer fields and five service fields present. Both the scanner and Deep worked exactly as built. Those adverts simply did not carry type evidence that qualifies under the current rules, so the honest answer was Unknown. This is what that looks like, and we would rather show it than a demo room picked to flatter the instrument.

what it knows

Curiosity without false certainty.

Observes

Counts of visible 2.4 GHz Wi-Fi access points, how they spread across channels 1–13, visible BLE advertisers, and the relative strength of one session alias.

Does not identify

A device type, a person, a camera or a bug. It is blind to cables, to sleeping devices, to 5 GHz-only devices, to cellular networks and to the rest of the spectrum.

Keeps

Your settings and at most four scene records. No names, no MAC or BSSID, no location, no account, no analytics, no cloud.

RADBOX shows change in the visible Wi-Fi and BLE layer.It can begin a room check. It does not replace a physical inspection or a specialist detector, and it never claims to have finished the job for you.

moves with you

Tilt it. Turn it. The field answers.

The BMI270 shifts the Pulse field by at most four pixels, and turning the cube changes the phase of its sweep. That is a response to your hand — not a compass, and not an RF bearing.

Tilt · −4 px
Tilt · −4 px
Neutral
Neutral
Turn · relative phase
Turn · relative phase

The marks are a bounded picture of an aggregate, not device positions. Proven on the host build; how it feels in the hand still waits for a verdict.

this exact hardware

One cube, one firmware, stated limits.

Not a launcher, not an app store, not a generic pentest bundle. One device tuned to the exact Core2 v1.3 — the same cube Open Radio runs on.

ESP32
D0WDQ6-V3240 MHz · everything computed on the cube
Display
320 × 240RGB565 · whole pixels only
Motion
BMI270tilt and relative turn
Power
AXP1924 segments · CHG / USB / LOW or instantaneous directional current in mA
Input
Touch + 3 zonesgestures and the marked capacitive circles
Radio
2.4 GHz + BLEpassive by default · Deep only on an explicit tap
Feedback
Speaker + hapticoptional, bounded cues
Microphone
Unusedno product input and no capture in this build
Where to buy the cube

Paid partnership · Botland is a partner of this project. Buy the cube anywhere you like, the system works the same.

where this is going

Ideas, not promises.

Nothing here has a date, and everything unbuilt carries the same label. It is published so you can see the direction, not so you can hold us to a calendar.

Next 0.1.xprove and sharpenexploring

  • wider BLE coverage: 32- and 128-bit service UUIDs, more permissive signature sources, conflict fixtures and better protocol clues
  • a visible TYPED n/total counter and coverage diagnostics — with no addresses, names or raw payloads
  • the full touch and gesture matrix, a sixty-minute soak and battery calibration
  • Geiger-style sound and haptics tuned to signal density and change, fully switchable off in Settings
  • another pixel-perfect pass on real RGB565, not on a smoothed mockup

0.2reasons to come backexploring

  • local, aggregate room before/after history and micro-charts, with no device identifiers
  • simple daily field missions instead of a vague quest: one action, one result, one explanation
  • Zen sessions and local streaks — no account, no cloud, no leaderboard
  • an optional card to show a friend: aggregates and confidence-labelled types only, plainly marked mix, not a map
  • a tested settings-preserving update and a recovery flow

0.3 Proone qualified module at a timeexploring

  • only modules that first pass the Foundation catalogue and bench
  • Port A v1 stays I²C-only; candidates include CO₂, temperature and humidity for Air/Quiet, or a light and flicker sensor for manual room inspection
  • a microphone could one day give a local envelope or bands with no PCM recorded — that needs separate approval and measurements
  • no promises today about UART, GPIO, SPI, Base stacking or any specific module

Toward 1.0the boring, necessary partexploring

  • formal clearance of the name and the final identity
  • a calibrated power profile, recovery and update
  • more languages beyond EN and PL
  • a stable public data contract and a complete set of exact-device evidence
Never, in any version
  • deauthentication or jamming
  • credential capture
  • spoofing or replay
  • covert recording
  • tracking people
  • exporting raw MAC or BSSID
  • a mandatory cloud, account or phone
how it was written

An AI agent wrote it. A person signed it off.

The RADBOX firmware was written by GPT-5.6-Sol running at its highest reasoning setting. Getting from an empty repository to this build took roughly 400 million tokens. What the agent did not decide: the limits of the hardware, the wording of every warning the device shows, and whether any of this goes out at all. Those belong to Tomasz Fiedoruk, and so does the answer for them.

Model
GPT-5.6-Solreasoning effort: xhigh
Tokens
≈400 millionempty repository → this build
Approval
Humanlimits, wording, release
release candidate · hand tests unfinished

Put the invisible layer in your hand.

This build is flashed and digest-verified on the exact Core2 v1.3, and the owner has authorised distributing it. Three things are still open, so you should hear them before you install: the hand tests and the soak on the device are unfinished, the runtime band is modelled rather than measured, and RADBOX is a working name that has not been cleared. There is no public repository.

Install it in a minute