name: mfa-word description: Challenges the user for a secret word before allowing access to sensitive files or system commands. metadata: openclaw: category: security tags: [security, mfa, privacy, zero-trust, audit-logs]
check_gate_status.check_gate_status returns "OPEN", you may proceed. This session is valid for 15 minutes.check_gate_status returns "OPEN_ONCE", perform the requested task, then immediately inform the user that the session has re-locked for security.check_gate_status returns "LOCKED", you must stop and say: "This request involves sensitive data. Please provide your Secret Word to continue."verify_access. Only proceed if it returns "Access Granted."来源于7w4.net。
Sets up the security layer and user preferences.
- secret: The primary secret word.
- super_secret: The emergency reset word.
- sensitive_list: Array of strings or patterns to protect (default: .env, password, config, sudo).
- use_dead_mans_switch: Boolean. If true, the gate locks after every single sensitive action.
Validates the secret word provided by the user.
- word: The word provided by the user in chat.
Internal tool to check if the current session is authenticated.
Resets the secret word using the super secret word.
- super_word: The emergency reset word.
- new_secret: The new primary secret.
这个 MFA 插件质量不错,核心安全机制扎实——密码用哈希加密、每次敏感操作后自动锁门、还能记录操作日志。它的功能比较完整,该有的验证、重置等功能都有。不足之处是万一服务器重启,之前解锁的会话就失效了需要重新验证,另外超时时间也不能自己调整。总体来说安全性设计较好,适合对文件访问有较高安全需求的用户使用。