All skills
cloudflare avatar

/turnstile-spin

@41e0d19 official
by cloudflarecloudflare/skills3k stars
298

Set up, repair, or migrate to Cloudflare Turnstile bot verification in an existing frontend and backend, including server-side Siteverify.

Use this Skill: https://skilld.dev/gh/cloudflare/skills/turnstile-spin

This session only. Nothing lands on disk.

README.md

≈946 tokens on demand. Your agent reads this file only when SKILL.md points to it.

turnstile-spin (skill)

End-to-end setup skill for Cloudflare Turnstile. Loads when an agent is asked to add Turnstile, set up CAPTCHA, or protect a form from bots.

SKILL.md is the canonical machine-readable behavior. The hosted prompt at developers.cloudflare.com/turnstile/spin/prompt.md packages the same behavior for agents that do not have this bundle installed. Product requirements come from the Turnstile documentation.

Layout

File Purpose
SKILL.md Main wizard instructions for the agent
scripts/auth-probe.sh Probes the customer's Cloudflare API token for Turnstile scope
scripts/widget-create.sh Creates the Turnstile widget via the Cloudflare API
scripts/validate.sh Dummy-siteverify + hostname check at the end of the wizard
scripts/persist-skill.sh Installs the canonical skill bundle into the user's repo
references/vanilla-html.md Code snippet for static / vanilla HTML projects
references/nextjs-app.md Code snippet for Next.js App Router projects
references/nextjs-pages.md Code snippet for Next.js Pages Router projects
references/astro.md Code snippet for Astro projects
references/sveltekit.md Code snippet for SvelteKit projects
references/hugo.md Code snippet for Hugo projects
tests/validation.md Validation cases matching the assertions in the PRD

How agents load it

Agents that load skill bundles from github.com/cloudflare/skills will pick this up automatically. For agents that load skills out of a local directory, clone the bundle once and symlink it:

git clone https://github.com/cloudflare/skills ~/.config/cloudflare-skills
ln -s ~/.config/cloudflare-skills/skills/turnstile-spin ~/.claude/skills/turnstile-spin

If cloning is not an option, the hosted single-file prompt is a read-only fallback:

mkdir -p .claude/skills/turnstile-spin && \
  curl -sSL https://developers.cloudflare.com/turnstile/spin/prompt.md \
  -o .claude/skills/turnstile-spin/SKILL.md

The single-file install does not include scripts/ or references/; the hosted prompt fetches those on demand with fetch_spin_script. scripts/persist-skill.sh requires the cloned bundle above and cannot be used from a single-file install. For other agents, see the table in SKILL.md.

Keep the hosted prompt in sync

Any behavioral change to SKILL.md must also be applied to public/turnstile/spin/prompt.md in the cloudflare-docs repository. The hosted file adds bootstrap instructions, but its wizard, security boundaries, recovery flow, and validation requirements must match this skill.

Related

Source: SKILL.md on GitHub

No alerts25d3 checks · Risk SAFE
  • Gen Agent Trust Hub25d

    This skill facilitates the end-to-end setup of Cloudflare Turnstile and includes security considerations such as the retrieval of configuration from external sources and the scanning of repository files for project identification. These actions are performed using robust security practices, including isolated command execution and sensitive data handling. See the detailed analysis for context.

  • Socket25d

    No alerts

  • Snyk25d

    Risk: LOW · No issues

Signed by skilld at 41e0d19. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 10 hours ago.

Activeupdated 11 hours ago
  • turnstile
  • cloudflare
  • captcha
  • bot-protection
  • workers
  • form-validation
  • siteverify
  • javascript

README badge

README badge for cloudflare/skills/turnstile-spin

Sets up Cloudflare Turnstile end-to-end: creates the widget via API, deploys a siteverify Worker, wires frontend snippets, and validates the integration. Targets projects using vanilla HTML, Next.js, Astro, SvelteKit, or Hugo and includes migration paths from reCAPTCHA or hCaptcha.

Generated from the current SKILL.md.

Does this skill work with my framework?
Yes. The skill has templates for vanilla HTML, Next.js (app and pages), Astro, SvelteKit, and Hugo. It detects your framework during the codebase scan and adapts the frontend edits accordingly.
Will this overwrite my existing form code?
No. The skill gates your existing submit handler on Turnstile validation success but leaves the handler logic unchanged. It only adds the token fetch and Worker call before your code runs.
What if I already have a Turnstile widget set up?
The skill can wire siteverify to your existing sitekey without recreating the widget. Provide your sitekey and the skill will fetch its secret, deploy the Worker, and integrate validation into your form.
Can this skill migrate from reCAPTCHA or hCaptcha?
Yes. If the skill detects reCAPTCHA or hCaptcha during codebase scan, it will present a migration plan that swaps the script tag, updates the widget class and data attributes, and routes validation through the deployed Worker.
Does the Turnstile secret stay secure?
Yes. The secret is never written to disk. It's passed via stdin directly to `wrangler secret put` and stored as a Worker environment variable.

Generated from the current SKILL.md. These answers refresh after source changes.