skills/melonask/altcha-skills/altcha/Gen Agent Trust Hub

altcha

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional documentation for the altcha Rust library, offering patterns for server and frontend integration.
  • [SAFE]: External resource references target well-known and trusted services, such as the altcha-org GitHub repository and the jsdelivr CDN for the frontend widget.
  • [SAFE]: The documentation explicitly warns against hardcoding secrets, recommending the use of environment variables and .env files for managing HMAC keys.
  • [SAFE]: The skill addresses common security pitfalls, providing specific remediation logic for replay attacks (via Redis or in-memory caching) and form-field tampering (via HMAC hashes).
  • [SAFE]: A known-issues.md file is included, which demonstrates a high level of transparency by documenting API discrepancies and providing corrected code examples for the developer.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 04:31 PM
Security Audit — agent-trust-hub — altcha