strava
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s functionality matches Strava usage, but it relies on a curl-piped installer from a personal GitHub repo and forwards Strava API credentials to a non-official CLI. Without verifiable provenance, this is disproportionate install and credential risk for the stated purpose.
Confidence: 84%Severity: 86%
Audit Metadata