strava

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s functionality matches Strava usage, but it relies on a curl-piped installer from a personal GitHub repo and forwards Strava API credentials to a non-official CLI. Without verifiable provenance, this is disproportionate install and credential risk for the stated purpose.

Confidence: 84%Severity: 86%
Audit Metadata
Analyzed At
Mar 21, 2026, 03:18 PM
Package URL
pkg:socket/skills-sh/eddmann%2Fstrava-cli%2Fstrava%2F@39c9b912407c5e4f55a402469a64b479d7342443