QR Password for Openclaw

An air-gapped credential bridge that facilitates bidirectional secret transfer using QR codes as an optical channel.

lifehackjohn
v1.0.0
Feb 16, 2026
0
1.7k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install qr-password

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install qr-password using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is QR Password?

QR Password is a specialized security tool designed for Openclaw Skills users who need to bridge the gap between networked and isolated environments. By utilizing QR codes as an optical data channel, it ensures that sensitive credentials never touch a network interface during transfer. This skill is built with a security-first architecture, focusing on ephemeral data handling and automated cleanup to prevent secret leakage in logs or local storage.

Whether you are migrating passwords from a digital vault to a secure offline hardware wallet or scanning credentials from a printed code into a local application, this skill provides the necessary scripts and safeguards. It is a critical addition to the Openclaw Skills library for developers and security professionals managing high-security infrastructure.

QR Password Use Cases

  • Transferring login credentials from a networked workstation to an air-gapped server.
  • Reading credential QR codes via camera to quickly populate local configuration files.
  • Generating temporary optical bridges for vault-to-device credential migration.
  • Sharing sensitive secrets in physically secure environments without utilizing USB or Bluetooth.

How QR Password Works

  1. The outbound workflow takes a JSON object containing a username, password, and domain and generates a QR code image.
  2. This image is displayed via a canvas interface for the user to scan with an external device.
  3. A security timer automatically hides the canvas and deletes the ephemeral image file after 30 seconds.
  4. For inbound transfers, the skill captures an image using a camera node or accepts a user-provided file.
  5. The decoding script processes the image to extract the structured credential data for immediate use without saving it to disk.
  6. All logs are automatically redacted to ensure the Openclaw Skills memory remains clean and secure.

QR Password Setup

To get started with this skill, install the necessary Python dependencies for image processing and QR generation:

python3 -m pip install --user qrcode Pillow opencv-python-headless

Ensure that the scripts located in the scripts/ directory have execute permissions and that your environment supports camera access if using the inbound mode.

QR Password Data Schema & Taxonomy

The skill utilizes a standard JSON format for all credential operations to ensure compatibility between the generator and the reader:

Field Type Description
username String The account identifier or email address.
password String The sensitive secret key (redacted in logs).
domain String The target service or hardware identifier.

All temporary images are stored in /tmp/ and are purged immediately after the 30-second display window or successful decode.

QR Password Advanced Features

  • Offline Generator: Includes a standalone HTML/JS tool for air-gapped devices to generate QR codes without any dependencies.
  • Ephemeral Canvas: Automated 30-second visual display lifecycle to minimize shoulder-surfing risks.
  • Auto-Redaction: Deep integration with the agent's output stream to ensure passwords are never printed in plain text.
  • Multi-Platform Support: Compatible with any device capable of running Python 3 and displaying a standard PNG file.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*