I'm unsure how a CAPTCHA would provide any guard against CSRF. CSRF occurs when a user authenticates with a secure site, and then visits a malicious site that then submits requests to the secure site via forms, images, AJAX that leverage that authenticated connection.
CAPTCHA only ensures that someone is a human being, typically for ensuring that a commenter or a new registrant is a person, and not a bot. I would never rely on CAPTCHAs for any sort of security, as bots are now better than humans at reading some of them.