Overview
- Skill Key
- diegofcornejo/totp
- Author
- diegofcornejo
- Source Repo
- openclaw/skills
- Version
- -
- Source Path
- skills/diegofcornejo/totp
- Latest Commit SHA
- 87f66886c2273d175ba883a835bb58f70fedeb9b
TOTP-based OTP verification for sensitive operations (env vars, gateway restarts, backup deletions, critical config changes). Uses otplib with window:2 (1 minute tolerance).
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
直接复制以下提示词,发送给你的 AI 助手即可完成安装。
请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 totp 技能。 若已安装,则直接安装 totp 技能。
# TOTP Verification Skill Secure OTP verification using TOTP (Time-based One-Time Password) for sensitive operations. ## Purpose Protect access to: - `.env` variables - `openclaw.json` configuration - Gateway restarts - Backup deletions - Critical configuration changes - External API key operations ## Setup 1. **Install dependencies:** ```bash npm install ``` 2. **Generate secret and QR:** ```bash npm run generate ``` Optionally pass service and account name: ```bash node scripts/generate-secret.js MyService myuser ``` 3. **Send the QR image** (`qr.png`) to the user, then delete it immediately: ```bash rm qr.png ``` 4. **Set TOTP_SECRET in `.env`:** ```env TOTP_SECRET=YOUR_BASE32_SECRET_HERE ``` 5. **Configure Google Authenticator/Authy** with the generated secret or QR. ## Usage When a sensitive operation is requested: 1. **Agent:** "Please provide your OTP" 2. **User:** Provides 6-digit code from authenticator app 3. **Agent:** Runs verification: ```bash TOTP_SECRET=$TOTP_SECRET node scripts/verify.js 123456 ``` 4. **If valid (exit 0):** Proceed with operation 5. **If invalid (exit 1):** Deny access ## Files - `scripts/generate-secret.js` - Generate new TOTP secret and QR - `scripts/verify.js` - Verify OTP tokens (window:2 = 1 minute tolerance) - `SKILL.md` - This documentation ## Security Notes - **Window:** 2 (1 minute tolerance) for time drift - **Algorithm:** SHA1 - **Digits:** 6 - **Period:** 30 seconds - **Secret:** Base32 encoded, stored in `.env` as `TOTP_SECRET` ## Integration This skill should be integrated into the agent's decision flow when: 1. User requests `.env` variables 2. User requests `openclaw.json` contents 3. User requests gateway restart 4. User requests backup deletion 5. Any operation marked as "critical"
human-pages-ai
Search and hire real humans for tasks — photography, delivery, research, and more
zseven-w
Reusable skill templates for OpenClaw AI agents. Templates for API integration, data processing, web scraping, CLI tools, and file processing.
capt-marbles
Attio CRM integration for managing companies, people, deals, notes, tasks, and custom objects. Use when working with Attio CRM data, searching contacts, managing sales pipelines, adding notes to records, creating tasks, or syncing prospect information.
capt-marbles
Web scraping and crawling with Firecrawl API. Fetch webpage content as markdown, take screenshots, extract structured data, search the web, and crawl documentation sites. Use when the user needs to scrape a URL, get current web info, capture a screenshot, extract specific data from pages, or crawl docs for a framework/library.
caqlayan
Tweet Processor Skill
carlosarturoleon
Connect to Windsor.ai MCP for natural language access to 325+ data sources including Facebook Ads, GA4, HubSpot, Shopify, and more.