Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
HATCHA — CAPTCHAはあなたが人間であることを証明します。HATCHAはあなたが人間でないことを証明します。 | Kitploit
ツール/GitHubGitHub/mondaycom/hatcha
なりすましツールウェブセキュリティ認証アンチボットCAPTCHAバイパスAIセキュリティ
GitHubmondaycom/hatcha

HATCHA

CAPTCHAはあなたが人間であることを証明します。HATCHAはあなたが人間でないことを証明します。

リポジトリを見る
992216ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
ウェブサイト

HATCHA

CAPTCHAは人間であることを証明します。HATCHAは人間でないことを証明します。

npm License CI


HATCHA modal in action

HATCHA(Hyperfast Agent Test for Computational Heuristic Assessment)は、AIエージェントには簡単だが人間には困難なチャレンジ(大きな数の掛け算、文字列の反転、バイナリデコードなど)の背後にアクセスをゲートするリバースCAPTCHAです。

  • サーバーサイド検証 — 回答がクライアントに到達することはありません。HMAC署名されたトークン、ステートレス、データベース不要。
  • 5つの組み込みチャレンジタイプ — 算術、文字列反転、文字カウント、並べ替え、バイナリデコード。
  • 拡張可能 — 実行時にカスタムチャレンジジェネレーターを登録可能。
  • テーマ対応 — CSSカスタムプロパティによるダーク、ライト、自動モード。
  • フレームワークアダプター — Next.js App RouterとExpressミドルウェアを標準装備。

Quickstart (Next.js)

1. インストール

npm install @mondaycom/hatcha-react @mondaycom/hatcha-server

2. APIルートを追加

// app/api/hatcha/[...hatcha]/route.ts
import { createHatchaHandler } from "@mondaycom/hatcha-server/nextjs";

const handler = createHatchaHandler({
  secret: process.env.HATCHA_SECRET!,
});

export const GET = handler;
export const POST = handler;

3. レイアウトをラップ

// app/layout.tsx
import { HatchaProvider } from "@mondaycom/hatcha-react";
import "@mondaycom/hatcha-react/styles.css";

export default function RootLayout({ children }) {
  return (
    <html lang="en">
      <body>
        <HatchaProvider>{children}</HatchaProvider>
      </body>
    </html>
  );
}

4. 検証をトリガー

"use client";
import { useHatcha } from "@mondaycom/hatcha-react";

function AgentModeButton() {
  const { requestVerification } = useHatcha();

  return (
    <button
      onClick={() =>
        requestVerification((token) => {
          console.log("Agent verified!", token);
        })
      }
    >
      Enter Agent Mode
    </button>
  );
}

5. シークレットを設定

# .env.local
HATCHA_SECRET=your-random-secret-here

仕組み

Client                            Server
  │                                 │
  │  GET /api/hatcha/challenge      │
  │────────────────────────────────►│
  │                                 │  Generate challenge
  │                                 │  Hash answer
  │                                 │  HMAC-sign { hash, expiry }
  │  { challenge (no answer), token }
  │◄────────────────────────────────│
  │                                 │
  │  Agent solves the challenge     │
  │                                 │
  │  POST /api/hatcha/verify        │
  │  { answer, token }              │
  │────────────────────────────────►│
  │                                 │  Verify HMAC signature
  │                                 │  Check expiry
  │                                 │  Compare answer hash
  │  { success, verificationToken } │
  │◄────────────────────────────────│

回答がクライアントに到達することはありません。署名されたトークンは不透明で、ハッシュ化された回答と有効期限のみを含みます。検証はステートレスであり、データベースは不要です。

チャレンジタイプ

タイプアイコン内容制限時間
math×5桁×5桁の掛け算30秒
string↔60~80文字のランダム文字列の反転30秒
count#約250文字の中で特定の文字をカウント30秒
sort⇅15個の数値を並べ替え、k番目に小さい値を返す30秒
binary01バイナリオクテットをASCIIにデコード30秒

カスタムチャレンジ

import { registerChallenge } from "@mondaycom/hatcha-server";

registerChallenge({
  type: "hex",
  generate() {
    const n = Math.floor(Math.random() * 0xffffff);
    return {
      display: {
        type: "hex",
        icon: "0x",
        title: "Hex Decode",
        description: "Convert this hex number to decimal.",
        prompt: `0x${n.toString(16).toUpperCase()}`,
        timeLimit: 30,
        answer: String(n),
      },
      answer: String(n),
    };
  },
});

テーマ

HATCHAは--hatcha-*スコープのCSSカスタムプロパティを使用しています。任意の親要素で上書きできます。

[data-hatcha-theme] {
  --hatcha-accent: #3b82f6;
  --hatcha-accent-light: #60a5fa;
  --hatcha-bg: #060b18;
  --hatcha-fg: #e4eaf6;
  --hatcha-success: #22c55e;
  --hatcha-danger: #ef4444;
}

<HatchaProvider>または<Hatcha>にtheme="dark"、theme="light"、theme="auto"を渡します。

Express

import express from "express";
import { hatchaRouter } from "@mondaycom/hatcha-server/express";

const app = express();
app.use(express.json());
app.use("/api/hatcha", hatchaRouter({ secret: process.env.HATCHA_SECRET! }));

app.listen(3000);

パッケージ

パッケージ説明
@mondaycom/hatcha-coreチャレンジ生成と暗号検証
@mondaycom/hatcha-reactReactコンポーネント、プロバイダー、スタイル
@mondaycom/hatcha-serverNext.jsおよびExpressサーバーハンドラー

開発

git clone https://github.com/mondaycom/HATCHA.git
cd HATCHA
pnpm install
pnpm build
cd examples/nextjs-app
pnpm dev

貢献

コントリビューションを歓迎します!セットアップ手順とガイドラインについてはCONTRIBUTING.mdを参照してください。

ライセンス

MIT

ツールをダウンロード