Agent skill

Turnstile Spin

by try-works in try-works/role-model

Set up Cloudflare Turnstile end-to-end in a project — scan the codebase, create the widget via the Cloudflare API, deploy the managed siteverify Worker, write the frontend snippets, validate, and…

Custom licenceAuto-check passedFrontend & Design

Install Turnstile Spin

skills CLI
$ npx skills add try-works/role-model --skill turnstile-spin -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install try-works/role-model turnstile-spin --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/try-works/role-model.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/turnstile-spin .claude/skills/turnstile-spin && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
turnstile-spin
GitHub stars
118
Token cost
~3.8k tokens
SKILL.md length
1,884 words
Files
36 (incl. scripts, references)
Skills in repo
19
Repo updated
First seen
Licence
Custom licence

At a glance

Set up Cloudflare Turnstile end-to-end in a project — scan the codebase, create the widget via the Cloudflare API, deploy the managed siteverify Worker, write the frontend snippets, validate, and…

  • Works in 12 steps: Brief acknowledge. One sentence: "I'll… → Wrangler check. npx wrangler --version.… → Auth + scope probe (FIRST irreversible… → …
  • Tasks that involve End-to-end testing
  • SKILL.md covers When to load this skill, Conversation flow, Migrating from another CAPTCHA and Edge cases, plus 2 more sections
  • Runs Shell scripts from its folder; calls npx, npm and wrangler; reaches google.com and js.hcaptcha.com; needs WIDGET_SECRET and TURNSTILE_SECRET_KEY

What it does

Turnstile Spin is an agent skill from try-works/role-model. Set up Cloudflare Turnstile end-to-end in a project — scan the codebase, create the widget via the Cloudflare API, deploy the managed siteverify Worker, write the frontend snippets, validate, and persist the skill. Load this when a user asks to add Turnstile, set up CAPTCHA, protect a form from bots, or fix a Turnstile integration. Mirrors developers.cloudflare.com/turnstile/spin.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 39 other files, including scripts and reference files (for example `README.md`, `references/astro.md` and `references/hugo.md`).

It sits in Frontend & Design, covering End-to-end testing. It works with Cloudflare, Cloudflare Workers and npm. The repository describes itself as: role-model is a protocol for assigning the right model for the right job. Use local and cloud AI together, or route between several cloud providers.

When your agent uses it

  • Tasks that involve End-to-end testing

Example prompts

  • “/turnstile-spin”

Requirements

  • Node.js
  • A Bash shell
  • A credential in CLOUDFLARE_API_TOKEN
  • A credential in WIDGET_SECRET

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. Brief acknowledge. One sentence: "I'll run Turnstile setup end to end. That's: check auth, scan the codebase, create the widget, deploy…
  2. Wrangler check. npx wrangler --version. If missing, ask once: "Install wrangler with npm install --save-dev wrangler (Node project) or npm…
  3. Auth + scope probe (FIRST irreversible action). Run scripts/auth-probe.sh. Branch on status
  4. Account selection. If auth-probe.sh returned ok after a multiple_accounts round-trip, this is already done. Otherwise the script picked…
  5. Domain. Always include localhost and 127.0.0.1. For production, scan package.json homepage, wrangler.toml, README.md, AGENTS.md, git…
  6. Codebase scan. Detect framework + insertion candidates silently.
  7. Insertion plan. Show the candidate list with [recommended] / [skip by default] markers; ask the user to confirm (numbers, "all"…
  8. Widget creation. Run scripts/widget-create.sh --account-id --name --domains --mode managed. Report the sitekey. The secret stays in env…
  9. Worker deploy. Run scripts/worker-deploy.sh --name turnstile-siteverify- with WIDGET_SECRET exported. Report the Worker URL on status: ok…
  10. Frontend edits. State the contract: "I'll add the widget + gate the existing submit handler on success === true. The existing handler…
  11. Validation. Run scripts/validate.sh. Report each check as it passes. If any fails, surface the error and stop. [wait for user if anything…
  12. Persist skill. Ask: "Save the Spin skill to .claude/skills/turnstile-spin/SKILL.md so I can reuse it on follow-up tasks?" Default yes…

What it can do on your machine

Read from SKILL.md and the folder at commit de1c04a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • npx
    • npm
    • wrangler
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • google.com
    • js.hcaptcha.com
    • hcaptcha.com
    • challenges.cloudflare.com

    Also links to:

    • developers.cloudflare.com
    • dash.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • WIDGET_SECRET
    • TURNSTILE_SECRET_KEY
    • CLOUDFLARE_API_TOKEN
    • RECAPTCHA_SECRET
    • HCAPTCHA_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Turnstile Spin loads about 3.8k tokens when it runs, and up to ~7k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 1,884 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,884 words (~3,760 tokens).

“Turns the prompt "set up Turnstile" into a working end-to-end integration: a widget, a deployed managed siteverify Worker, frontend snippets at every chosen insertion point, and a real validation pass before reporting success.”

— opening of SKILL.md by try-works, Custom licence
name
turnstile-spin
references
vanilla-html, nextjs-app, nextjs-pages, astro, sveltekit, hugo

Read the full SKILL.md on GitHub

Files

SKILL.md and 35 other files (scripts, references) in .agents/skills/turnstile-spin of try-works/role-model.

  • SKILL.md
  • README.md
  • references/astro.md
  • references/hugo.md
  • references/nextjs-app.md
  • references/nextjs-pages.md
  • references/sveltekit.md
  • references/vanilla-html.md
  • scripts/auth-probe.sh
  • scripts/fetch-secret.sh
  • scripts/persist-skill.sh
  • scripts/validate.sh
  • scripts/widget-create.sh
  • scripts/worker-deploy.sh
  • templates/worker/.gitignore
  • templates/worker/LICENSE
  • templates/worker/README.md
  • … and 19 more

Open the folder on GitHubat commit de1c04a

Compare with similar skills

Turnstile Spin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Turnstile Spin compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Turnstile Spin this skilltry-works/role-model118—~3.8kAutomated safety check: PassCustom licence
Cloudflare Pagessickn33/agentic-awesome-skills47k2 repos~2.4kAutomated safety check: PassMIT
Deploy Agentsundial-org/awesome-openclaw-skills663—~1.6kAutomated safety check: PassNone
Bun Cloudflare Workerssecondsky/claude-skills227—~2.3kAutomated safety check: PassMIT
Kumo Designelliothux/open-compute1.8k—~1.6kAutomated safety check: PassApache-2.0
Test Fumadocs Wranglerclabernetes/clabernetes143—~569Automated safety check: PassBSD-3-Clause

Similar skills

  • Cloudflare Pages

    sickn33/agentic-awesome-skills

    Deploy static sites and full-stack apps on Cloudflare Pages with previews, functions, and custom domains.

    47k GitHub starsUsed in 2 repos~2.4k tokens
    DevOps & CloudAuto-check passed
  • Deploy Agent

    sundial-org/awesome-openclaw-skills

    Multi-step deployment agent for full-stack apps. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~1.6k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Bun Cloudflare Workers

    secondsky/claude-skills

    This skill should be used when the user asks about "Cloudflare Workers with Bun", "deploying Bun to Workers", "wrangler with Bun", "edge deployment", "Bun to Cloudflare", or building and deploying…

    227 GitHub stars~2.3k tokensUpdated 11 days ago
    DevOps & CloudAuto-check passed
  • Kumo Design

    elliothux/open-compute

    Cloudflare product design guidance. An agent skill from elliothux/open-compute.

    1.8k GitHub stars~1.6k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Test Fumadocs Wrangler

    clabernetes/clabernetes

    Builds and validates the Fumadocs React Router static site through Wrangler with headless browser checks.

    143 GitHub stars~569 tokensUpdated 4 days ago
    Productivity & AutomationAuto-check passed
  • Deploy

    cyanfish-x/tellux

    Deploy tellux examples/docs sites via project scripts — one local command (pnpm run deploy) rclone-syncs to the self-hosted site then Wrangler Direct Uploads to Cloudflare Pages.

    207 GitHub stars~1.1k tokensUpdated 18 days ago
    Game DevelopmentAuto-check: notes

More from try-works/role-model

All 19 skills in this repo
  • E2E Testing Patterns

    try-works/role-model

    Master end-to-end testing with Playwright and Cypress to build reliable test suites that catch bugs, improve confidence, and enable fast deployment.

    118 GitHub starsUsed in 14 repos~990 tokens
    Auto-check passed
  • UI Design System

    try-works/role-model

    React UI component systems with TailwindCSS + Radix + shadcn/ui.

    118 GitHub stars~5k tokensUpdated 2 days ago
    Auto-check passed
  • Swiss Design

    try-works/role-model

    Apply a Swiss International Style design system using Tailwind CSS.

    118 GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Contributing

    try-works/role-model

    A skill your agent uses when contributing to the Cloudflare Docs repository — writing or editing documentation pages, choosing content types or components, adding changelog entries, reviewing docs…

    118 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Effect V3 To V4

    try-works/role-model

    A skill your agent uses when migrating a codebase from Effect v3 to Effect v4, upgrading effect or any @effect/ package across the v3/v4 boundary.

    118 GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Eli5

    try-works/role-model

    Transform technical jargon into clear explanations using before/after comparisons, metaphors, and practical context

    118 GitHub starsUsed in 1 repo~7.1k tokens
    Auto-check passed

Questions about Turnstile Spin

What does Turnstile Spin do?

Set up Cloudflare Turnstile end-to-end in a project — scan the codebase, create the widget via the Cloudflare API, deploy the managed siteverify Worker, write the frontend snippets, validate, and…. Turnstile Spin is an agent skill from try-works/role-model. Set up Cloudflare Turnstile end-to-end in a project — scan the codebase, create the widget via the Cloudflare API, deploy the managed siteverify Worker, write the frontend snippets, validate, and persist the skill.

When should I use Turnstile Spin?

Turnstile Spin fits situations like: tasks that involve End-to-end testing.

How do I install Turnstile Spin in Claude Code?

Run `npx skills add try-works/role-model --skill turnstile-spin -a claude-code`. Or copy the skill folder (.agents/skills/turnstile-spin in try-works/role-model) into .claude/skills/turnstile-spin in your project. Claude Code loads it when a task matches its description.

How do I install Turnstile Spin in Codex?

Run `npx skills add try-works/role-model --skill turnstile-spin -a codex`. Or copy the skill folder (.agents/skills/turnstile-spin in try-works/role-model) into .agents/skills/turnstile-spin in your project. Codex loads it when a task matches its description.

Can I use Turnstile Spin in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add try-works/role-model --skill turnstile-spin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/turnstile-spin, .gemini/skills/turnstile-spin, .github/skills/turnstile-spin and .opencode/skills/turnstile-spin in your project.

What does Turnstile Spin need to run?

Going by SKILL.md and its folder, Turnstile Spin needs a shell for the scripts in its folder, the command-line tools its instructions call (npx, npm, wrangler and curl) and credentials named WIDGET_SECRET, TURNSTILE_SECRET_KEY, CLOUDFLARE_API_TOKEN and RECAPTCHA_SECRET. Our summary lists: Node.js; A Bash shell; A credential in CLOUDFLARE_API_TOKEN; A credential in WIDGET_SECRET.

Does Turnstile Spin access the network?

SKILL.md names 6 domains. In commands or code: google.com, js.hcaptcha.com, hcaptcha.com and challenges.cloudflare.com; the agent is likely to contact these when it follows the instructions. As links in the text: developers.cloudflare.com and dash.cloudflare.com. This is read from the text; nothing was executed.

Is Turnstile Spin safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Turnstile Spin use?

Turnstile Spin has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Turnstile Spin use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.

What are the alternatives to Turnstile Spin?

Skills that share tags, products or a category with Turnstile Spin: Cloudflare Pages (sickn33/agentic-awesome-skills, 47k stars), Deploy Agent (sundial-org/awesome-openclaw-skills, 663 stars), Bun Cloudflare Workers (secondsky/claude-skills, 227 stars) and Kumo Design (elliothux/open-compute, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Turnstile Spin?

try-works (a GitHub user) maintains it in try-works/role-model, which has 118 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.

Source: try-works/role-model on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.