Skip to content
Back to skills

Otp Challenger

ASecurity

Enable agents and skills to challenge users for fresh two-factor authentication proof (TOTP or YubiKey) before executing sensitive actions. Use this for identity verification in approval workflows - deploy commands, financial operations, data access, admin operations, and change control.

  • 14 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
toolspythongoshellbashnodeterraformgitapisecuritydocumentation

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill otp-challenger --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Otp Challenger?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Otp Challenger
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-otp-challenger/badge)](https://www.skillsdirectory.com/skills/modbender-otp-challenger)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: otp-challenger
version: 1.0.3
description: Enable agents and skills to challenge users for fresh two-factor authentication proof (TOTP or YubiKey) before executing sensitive actions. Use this for identity verification in approval workflows - deploy commands, financial operations, data access, admin operations, and change control.
metadata: {"openclaw": {"emoji": "πŸ”", "homepage": "https://github.com/ryancnelson/otp-challenger", "requires": {"bins": ["jq", "python3", "curl", "openssl", "base64"], "anyBins": ["oathtool", "node"]}, "envVars": {"required": [], "conditionallyRequired": [{"name": "OTP_SECRET", "condition": "TOTP mode", "description": "Base32 TOTP secret (16-128 chars)"}, {"name": "YUBIKEY_CLIENT_ID", "condition": "YubiKey mode", "description": "Yubico API client ID"}, {"name": "YUBIKEY_SECRET_KEY", "condition": "YubiKey mode", "description": "Yubico API secret key (base64)"}], "optional": [{"name": "OTP_INTERVAL_HOURS", "default": "24", "description": "Verification validity period"}, {"name": "OTP_MAX_FAILURES", "default": "3", "description": "Failed attempts before rate limiting"}, {"name": "OTP_FAILURE_HOOK", "description": "Script to execute on verification failures (privileged - runs arbitrary commands)"}]}, "privilegedFeatures": ["OTP_FAILURE_HOOK can execute arbitrary shell commands on failure events"], "install": [{"id": "jq", "kind": "brew", "formula": "jq", "bins": ["jq"], "label": "Install jq via Homebrew", "os": ["darwin", "linux"]}, {"id": "python3", "kind": "brew", "formula": "python3", "bins": ["python3"], "label": "Install Python 3 via Homebrew", "os": ["darwin", "linux"]}, {"id": "oathtool", "kind": "brew", "formula": "oath-toolkit", "bins": ["oathtool"], "label": "Install OATH Toolkit via Homebrew", "os": ["darwin", "linux"]}]}}
---

# OTP Identity Challenge Skill

Challenge users for fresh two-factor authentication before sensitive actions.

## When to Use

Require OTP verification before:
- Deploy commands (`kubectl apply`, `terraform apply`)
- Financial operations (transfers, payment approvals)
- Data access (PII exports, customer data)
- Admin operations (user modifications, permission changes)

## Scripts

### verify.sh

Verify a user's OTP code and record verification state.

```bash
./verify.sh <user_id> <code>
```

**Parameters:**
- `user_id` - Identifier for the user (e.g., email, username)
- `code` - Either 6-digit TOTP or 44-character YubiKey OTP

**Exit codes:**
- `0` - Verification successful
- `1` - Invalid code or rate limited
- `2` - Configuration error (missing secret, invalid format)

**Output on success:**
```
βœ… OTP verified for <user_id> (valid for 24 hours)
βœ… YubiKey verified for <user_id> (valid for 24 hours)
```

**Output on failure:**
```
❌ Invalid OTP code
❌ Too many attempts. Try again in X minutes.
❌ Invalid code format. Expected 6-digit TOTP or 44-character YubiKey OTP.
```

### check-status.sh

Check if a user's verification is still valid.

```bash
./check-status.sh <user_id>
```

**Exit codes:**
- `0` - User has valid (non-expired) verification
- `1` - User not verified or verification expired

**Output:**
```
βœ… Valid for 23 more hours
⚠️ Expired 2 hours ago
❌ Never verified
```

### generate-secret.sh

Generate a new TOTP secret with QR code (requires `qrencode` to be installed).

```bash
./generate-secret.sh <account_name>
```

## Usage Pattern

```bash
#!/bin/bash
source ../otp/verify.sh

if ! verify_otp "$USER_ID" "$OTP_CODE"; then
  echo "πŸ”’ This action requires OTP verification"
  exit 1
fi

# Proceed with sensitive action
```

## Configuration

**Required for TOTP:**
- `OTP_SECRET` - Base32 TOTP secret

**Required for YubiKey:**
- `YUBIKEY_CLIENT_ID` - Yubico API client ID
- `YUBIKEY_SECRET_KEY` - Yubico API secret key (base64)

**Optional:**
- `OTP_INTERVAL_HOURS` - Verification expiry (default: 24)
- `OTP_MAX_FAILURES` - Failed attempts before rate limiting (default: 3)
- `OTP_STATE_FILE` - State file path (default: `memory/otp-state.json`)

Configuration can be set via environment variables or in `~/.openclaw/config.yaml`:

```yaml
security:
  otp:
    secret: "BASE32_SECRET"
  yubikey:
    clientId: "12345"
    secretKey: "base64secret"
```

## Code Format Detection

The script auto-detects code type:
- **6 digits** (`123456`) β†’ TOTP validation
- **44 ModHex characters** (`cccccc...`) β†’ YubiKey validation

ModHex alphabet: `cbdefghijklnrtuv`

## State File

Verification state stored in `memory/otp-state.json`. Contains only timestamps, no secrets.

## Human Documentation

See **[README.md](./README.md)** for:
- Installation instructions
- Setup guides (TOTP and YubiKey)
- Security considerations
- Troubleshooting
- Examples

Files in this skill

  • INSTALLATION.md15.2 KB
  • README.md13.7 KB
  • SKILL.md4.7 KB
  • check-status.sh2.7 KB
  • config-template.yaml1.7 KB
  • docs/implementation-plans/2025-01-31-yubikey-support/phase_01.md16.6 KB
  • docs/implementation-plans/2025-01-31-yubikey-support/phase_02.md12.8 KB
  • docs/implementation-plans/2025-01-31-yubikey-support/phase_03.md8.9 KB
  • docs/plans/2025-01-31-yubikey-support-design.md4.3 KB
  • env-template.sh3.5 KB
  • examples/openclaw/README.md952 B
  • examples/openclaw/cron-expire.sh549 B
  • examples/openclaw/interceptor.sh1.1 KB
  • generate-secret.sh2 KB
  • get-current-code.sh1.2 KB
  • memory/README.md1.3 KB
  • otp-skill-summary.md9.1 KB
  • prepare-otp-challenger-for-update-and-upload.sh955 B
  • tests/openclaw_interceptor.test.sh2.5 KB
  • totp.mjs3.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…