Protect public forms with CAPTCHA
SkillSecurityform-captcha is a skill that guides an AI agent through reviewing public HTML forms, such as logins, signups, contact pages, and comments, for bot and abuse protection. It checks whether each publicly reachable form has CAPTCHA, honeypot fields, or rate limiting, and explains how to add protections like Cloudflare Turnstile or reCAPTCHA v3.
Available today. Use it from your connected AI after setup.
No other account needed.
Have an agent that supports loading skills.
Then ask your AI: use the Protect public forms with CAPTCHA skill
What your AI can do with it
- Finds every publicly reachable form on a site, including login, signup, contact, and comme
- Verifies each form has CAPTCHA, honeypot fields, or rate limiting
- Explains how to add Cloudflare Turnstile or reCAPTCHA v3 to a form
- Stresses validating CAPTCHA tokens server-side, since client-side checks can be bypassed
Getting started
- Have an agent that supports loading skills.
- Add the form-captcha skill to the agent's available skills.
- Point the agent at a site or set of HTML forms to review.
- Ask it to check the public forms for CAPTCHA, honeypot fields, or rate limiting.
What this skill tells your AI
The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/form-captcha/SKILL.md and read by ahel’s review.
An unprotected registration form can create thousands of spam accounts per minute; an unprotected login form enables credential stuffing attacks that test millions of username/password combinations from data breaches.
Quick Reference
- Public forms (contact, registration, login, password reset, comment) without CAPTCHA are targets for automated abuse
- Prefer invisible/automated solutions (Cloudflare Turnstile, Google reCAPTCHA v3, hCaptcha) over interactive challenges that harm UX
- Always validate CAPTCHA tokens server-side — client-side validation is bypassable
- Rate limiting is complementary to CAPTCHA but not a substitute — bots can solve rate limits with distributed attacks
- Honeypot fields (hidden inputs that users never fill but bots do) are a lightweight CAPTCHA alternative for low-risk forms
Check
Identify all public-facing forms (contact, registration, login, password reset, newsletter, comment). Check whether each has CAPTCHA, honeypot fields, or server-side rate limiting. Verify any CAPTCHA tokens are validated server-side.
Fix
Integrate a CAPTCHA service (Cloudflare Turnstile, hCaptcha, or Google reCAPTCHA v3) on all public forms. Validate the CAPTCHA response token on your server before processing the form submission. Add rate limiting as a defense-in-depth measure.
Explain
Explain what credential stuffing and spam bot attacks are, how CAPTCHA protects public forms, the trade-offs between different CAPTCHA approaches (v2 checkbox, v3 invisible, Turnstile), and why server-side validation is required.
Code Review
Review server config, headers, forms, and integration points related to Protect public forms with CAPTCHA. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/form-captcha
Signals
- GitHub stars
- 74k
- Forks
- 7k
- Last commit
- Aug 2026
Questions
- Which forms does it review?
- Publicly reachable HTML forms that require no authentication to reach, such as login, signup, contact, and comment forms.
- Does it add protections or just check for them?
- It verifies existing protections and explains how to add services like Cloudflare Turnstile or reCAPTCHA v3.
- Why does it insist on server-side validation?
- Client-side CAPTCHA checks can be bypassed, so tokens must be validated server-side.
Advanced
- Item type
- skill
- Key
form-captcha- Source
- github.com/thedaviddias/front-end-checklist