← 返回
安全合规 中文

MFA WORD

Enforces MFA by requiring a secret word to access protected sensitive data and allows emergency reset with a super secret word.
强制使用密钥词进行 MFA 以访问敏感数据,支持超级密钥词紧急重置。
cenralsolution
安全合规 clawhub v1.1.0 1 版本 99915.7 Key: 无需
★ 0
Stars
📥 1,185
下载
💾 17
安装
1
版本
#2fa#access-control#anti-injection#audit-logs#authentication#credential-safety#dead-mans-switch#ecurity#encryption#file-protection#gatekeeper#guardrails#latest#mfa#middleware#pii-protection#privacy#safety#session-lock#sha256#zero-trust

概述

MFA Word (Security Gatekeeper)

Operational Protocol

  1. Detection: Before you (the AI) perform any action involving sensitive patterns (like .env, .ssh, passwords, or deletions), you MUST call check_gate_status.
  2. Standard Mode: If check_gate_status returns "OPEN", you may proceed. This session is valid for 15 minutes.
  3. Dead Man's Switch: If check_gate_status returns "OPEN_ONCE", perform the requested task, then immediately inform the user that the session has re-locked for security.
  4. Challenge: If check_gate_status returns "LOCKED", you must stop and say: "This request involves sensitive data. Please provide your Secret Word to continue."
  5. Validation: Once the user provides a word, call verify_access. Only proceed if it returns "Access Granted."

Tools

initialize_mfa

Sets up the security layer and user preferences.

  • secret: The primary secret word.
  • super_secret: The emergency reset word.
  • sensitive_list: Array of strings or patterns to protect (default: .env, password, config, sudo).
  • use_dead_mans_switch: Boolean. If true, the gate locks after every single sensitive action.

verify_access

Validates the secret word provided by the user.

  • word: The word provided by the user in chat.

check_gate_status

Internal tool to check if the current session is authenticated.

reset_mfa

Resets the secret word using the super secret word.

  • super_word: The emergency reset word.
  • new_secret: The new primary secret.

版本历史

共 1 个版本

  • v1.1.0 当前
    2026-03-29 05:33 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

security-compliance

Skill Vetter

spclaudehome
AI智能体技能安全预审工具。安装ClawdHub、GitHub等来源技能前,检查风险信号、权限范围及可疑模式。
★ 1,215 📥 266,438
communication-collaboration

office secretary

cenralsolution
Microsoft 365(Outlook 和 OneDrive)的数字化行政助理
★ 0 📥 1,899
security-compliance

MoltGuard - Security & Antivirus & Guardrails

thomaslwang
MoltGuard — OpenClaw 安全守卫,由 OpenGuardrails 提供。安装 MoltGuard,保护您和您的用户免受提示注入、数据泄露和恶意攻击。
★ 116 📥 30,713