Agent skill

Turnstile Spin

by swyxio in swyxio/skills

Add or repair Cloudflare Turnstile on an existing web form by creating or reusing a widget, embedding it, wiring mandatory server-side Siteverify in the existing backend, and validating the result.

MITAuto-check passedAI & LLM Engineering

Install Turnstile Spin

skills CLI
$ npx skills add swyxio/skills --skill turnstile-spin -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install swyxio/skills turnstile-spin --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/swyxio/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/turnstile-spin .claude/skills/turnstile-spin && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
turnstile-spin
GitHub stars
176
Token cost
~987 tokens
SKILL.md length
451 words
Files
12 (incl. scripts, references)
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Add or repair Cloudflare Turnstile on an existing web form by creating or reusing a widget, embedding it, wiring mandatory server-side Siteverify in the existing backend, and validating the result.

  • Works in 5 steps: Run scripts/auth-probe.sh to resolve an… → If several accounts are available and… → For a new widget, use the current… → …
  • The user explicitly asks to add Turnstile
  • SKILL.md covers Resolve the integration, Create or reuse the widget, Gate the existing handler and Migrate another CAPTCHA…, plus 1 more section
  • Runs Shell scripts from its folder; calls wrangler; needs TURNSTILE_SECRET

What it does

Turnstile Spin is an agent skill from swyxio/skills. Add or repair Cloudflare Turnstile on an existing web form by creating or reusing a widget, embedding it, wiring mandatory server-side Siteverify in the existing backend, and validating the result. Use when the user explicitly asks to add Turnstile, replace reCAPTCHA or hCaptcha with Turnstile, protect a form from bots, or fix a Turnstile integration. Do not trigger for unrelated Cloudflare or general form work.

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts and reference files (for example `references/astro.md`, `references/hugo.md` and `references/nextjs-app.md`).

It sits in AI & LLM Engineering, covering Backend development and Embeddings. It works with Cloudflare. The repository describes itself as: Agent skills for Claude Code and other AI agents. The licence is MIT.

When your agent uses it

  • The user explicitly asks to add Turnstile
  • Replace reCAPTCHA
  • HCaptcha with Turnstile
  • Protect a form from bots

Example prompts

  • “/turnstile-spin”

Requirements

  • A Bash shell
  • A credential in TURNSTILE_SECRET

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run scripts/auth-probe.sh to resolve an account and the required Turnstile
  2. If several accounts are available and the project does not resolve one, ask
  3. For a new widget, use the current wrangler turnstile widget create command
  4. Register only the intended hostnames. Include local hostnames only when local
  5. Put the returned secret directly into the user's existing secret store as

What it can do on your machine

Read from SKILL.md and the folder at commit 038ef34. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • wrangler

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TURNSTILE_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Turnstile Spin loads about 987 tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 451 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~987
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from swyxio/skills at commit 038ef34, republished under its MIT licence (© swyxio). 451 words, ~987 tokens.

Download SKILL.mdSave it as .claude/skills/turnstile-spin/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
turnstile-spin
description
Add or repair Cloudflare Turnstile on an existing web form by creating or reusing a widget, embedding it, wiring mandatory server-side Siteverify in the existing backend, and validating the result. Use when the user explicitly asks to add Turnstile, replace reCAPTCHA or hCaptcha with Turnstile, protect a form from bots, or fix a Turnstile integration. Do not trigger for unrelated Cloudflare or general form work.

Turnstile Spin

Integrate Turnstile into the user's existing frontend and backend. Do not create a new backend, proxy Worker, or other infrastructure merely to host Siteverify. Current canonical guidance lives at Cloudflare Turnstile Spin.

Resolve the integration

Inspect the project before asking questions:

  • identify the frontend framework and forms that need protection;
  • locate the existing server-side submit handler;
  • detect an existing Turnstile, reCAPTCHA, or hCaptcha integration; and
  • resolve the production hostnames from project configuration when possible.

If no server-side handler exists, report that Turnstile cannot be completed securely in the current architecture and stop. Siteverify is mandatory and must run on the server.

Show the proposed forms and hostnames when a material choice remains. Do not broaden the task into form persistence, email delivery, payment, OAuth, styling, or framework migration.

Create or reuse the widget

  1. Run scripts/auth-probe.sh to resolve an account and the required Turnstile permission. Prefer credentials already available to the user's environment; never print a token or commit it.
  2. If several accounts are available and the project does not resolve one, ask the user to select the account.
  3. For a new widget, use the current wrangler turnstile widget create command when installed; otherwise use scripts/widget-create.sh.
  4. Register only the intended hostnames. Include local hostnames only when local development requires them, and validate the production hostname returned by Siteverify in production.
  5. Put the returned secret directly into the user's existing secret store as TURNSTILE_SECRET. Never inline it or save an extra copy.

For an existing sitekey, use scripts/fetch-secret.sh when authorized and keep the current widget. Verify its domains and pre-clearance mode. Do not recreate a widget merely to recover its secret, because that changes the sitekey used by deployed pages.

Show full SKILL.md (166 more words)Show less

Gate the existing handler

Embed the widget using the framework-specific reference:

Send the resulting token to the existing backend and call the canonical Siteverify endpoint there. Continue the original handler only when success === true. Validate the returned hostname and any expected action or customer data. Tokens expire and are single-use; never rely on client-side success alone.

Preserve the original submit behavior. Turnstile gates the handler; it does not replace it.

Migrate another CAPTCHA carefully

Replace the provider script, widget/sitekey, response field, server verification endpoint, and secret together. Preserve intentional action names. Do not automatically translate reCAPTCHA v3 score thresholds or reCAPTCHA Enterprise policy; surface those semantic differences before editing.

Validate

Run scripts/validate.sh and the project's focused tests. Verify the chosen forms contain the widget, the token reaches the backend, valid Siteverify output allows the original handler, invalid or missing tokens are rejected, and the secret is bound to the intended environment. Report provider setup, local code, and live behavior separately.

© swyxio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (scripts, references) in turnstile-spin of swyxio/skills.

  • SKILL.md
  • references/astro.md
  • references/hugo.md
  • references/nextjs-app.md
  • references/nextjs-pages.md
  • references/sveltekit.md
  • references/vanilla-html.md
  • scripts/auth-probe.sh
  • scripts/fetch-secret.sh
  • scripts/validate.sh
  • scripts/widget-create.sh
  • tests/validation.md

Open the folder on GitHubat commit 038ef34

Compare with similar skills

Turnstile Spin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Turnstile Spin compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Turnstile Spin this skillswyxio/skills176—~987Automated safety check: PassMIT
AI SDK Developmenttrypostit/trypost6921 repos~3.5kAutomated safety check: PassMIT
Gscore Plugin DevelopmentGenshin-bots/gsuid_core356—~3.1kAutomated safety check: PassGPL-3.0
Spring AI Integrationrrezartprebreza/spring-boot-skills301—~2.5kAutomated safety check: PassMIT
Sentry Instrumentgetsentry/sentry-for-ai268—~3.2kAutomated safety check: PassApache-2.0
AWS SDK Java V2 Bedrockgiuseppe-trisciuoglio/developer-kit357—~3.2kAutomated safety check: NotesMIT

Similar skills

  • AI SDK Development

    trypostit/trypost

    TRIGGER when working with ai-sdk which is Laravel official first-party AI SDK.

    692 GitHub starsUsed in 1 repo~3.5k tokens
    AI & LLM EngineeringAuto-check passed
  • Gscore Plugin Development

    Genshin-bots/gsuid_core

    当用户要求"帮我写一个 GsCore 插件"、"给这个插件加功能"、"改造触发器支持 AI"、 "怎么用 toai"、"注册 aitools"、"写一个游戏查询插件"、"插件帮助怎么注册"、 "能力代理/代理画像"、"怎么为触发器添加AI功能"、"几个触发器的差别在哪"、"数据库和配置项怎么添加" "如何把数据库表挂到网页控制台"、"PIL/pytakumi/playwright…

    356 GitHub stars~3.1k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Spring AI Integration

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when integrating LLMs, chat clients, embeddings, RAG pipelines, or AI agents into Spring Boot.

    301 GitHub stars~2.5k tokensUpdated 19 days ago
    AI & LLM EngineeringAuto-check passed
  • Sentry Instrument

    getsentry/sentry-for-ai

    Official

    Instrument an application with Sentry — detect the platform, install and initialize the SDK if needed, and wire up any signal — error monitoring, tracing/performance, logging, metrics, profiling…

    268 GitHub stars~3.2k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • AWS SDK Java V2 Bedrock

    giuseppe-trisciuoglio/developer-kit

    Provides Amazon Bedrock patterns using AWS SDK for Java 2.x.

    357 GitHub stars~3.2k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check: notes
  • Cookbook Aiml

    databricks-solutions/databricks-apps-cookbook

    Invoke ML models, run vector search, and connect to MCP servers from Databricks Apps.

    183 GitHub stars~1.7k tokensUpdated 6 days ago
    AI & LLM EngineeringAuto-check passed

More from swyxio/skills

All 89 skills in this repo
  • Programmatic Agents

    swyxio/skills

    Run a selected coding-agent CLI programmatically, with latency, error, usage, cost, and trace logging.

    176 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Design, implement, audit, or refresh protected username and handle namespaces for public products.

    176 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • New Mac Setup

    swyxio/skills

    Fully automated new Mac setup for fullstack web developers and AI engineers.

    176 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Youtube API

    swyxio/skills

    Manage YouTube videos programmatically via the YouTube Data API v3 — upload video files, upload custom thumbnails, update video metadata (titles, descriptions, tags), and query video/channel info…

    176 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Batch YouTube Studio upload workflow for videos sourced from Airtable, Google Drive, Loom, YouTube, or local files.

    176 GitHub stars~1.5k tokensUpdated today
    Auto-check: warnings
  • Reconstruct and visually analyze paired agent, game, or policy trajectories to determine whether changed actions produced their intended effects.

    176 GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Works with

Questions about Turnstile Spin

What does Turnstile Spin do?

Add or repair Cloudflare Turnstile on an existing web form by creating or reusing a widget, embedding it, wiring mandatory server-side Siteverify in the existing backend, and validating the result. Turnstile Spin is an agent skill from swyxio/skills. Add or repair Cloudflare Turnstile on an existing web form by creating or reusing a widget, embedding it, wiring mandatory server-side Siteverify in the existing backend, and validating the result.

When should I use Turnstile Spin?

Turnstile Spin fits situations like: the user explicitly asks to add Turnstile; replace reCAPTCHA; HCaptcha with Turnstile; protect a form from bots.

How do I install Turnstile Spin in Claude Code?

Run `npx skills add swyxio/skills --skill turnstile-spin -a claude-code`. Or copy the skill folder (turnstile-spin in swyxio/skills) into .claude/skills/turnstile-spin in your project. Claude Code loads it when a task matches its description.

How do I install Turnstile Spin in Codex?

Run `npx skills add swyxio/skills --skill turnstile-spin -a codex`. Or copy the skill folder (turnstile-spin in swyxio/skills) into .agents/skills/turnstile-spin in your project. Codex loads it when a task matches its description.

Can I use Turnstile Spin in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add swyxio/skills --skill turnstile-spin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/turnstile-spin, .gemini/skills/turnstile-spin, .github/skills/turnstile-spin and .opencode/skills/turnstile-spin in your project.

What does Turnstile Spin need to run?

Going by SKILL.md and its folder, Turnstile Spin needs a shell for the scripts in its folder, the command-line tools its instructions call (wrangler) and credentials named TURNSTILE_SECRET. Our summary lists: A Bash shell; A credential in TURNSTILE_SECRET.

Does Turnstile Spin access the network?

SKILL.md names 1 domain. As links in the text: developers.cloudflare.com. This is read from the text; nothing was executed.

Is Turnstile Spin safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Turnstile Spin use?

Turnstile Spin is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Turnstile Spin use?

About 987 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.7k tokens, read only when the agent opens those files.

What are the alternatives to Turnstile Spin?

Skills that share tags, products or a category with Turnstile Spin: AI SDK Development (trypostit/trypost, 692 stars), Gscore Plugin Development (Genshin-bots/gsuid_core, 356 stars), Spring AI Integration (rrezartprebreza/spring-boot-skills, 301 stars) and Sentry Instrument (getsentry/sentry-for-ai, 268 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Turnstile Spin?

swyxio (a GitHub user) maintains it in swyxio/skills, which has 176 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 5, 2026.

Source: swyxio/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.