This is a coherent OAuth settings skill, but it asks OpenClaw to reuse sensitive login credentials from other tools and persists them broadly enough to deserve manual review.
Review before installing. Use provider API keys unless you intentionally want OpenClaw to reuse Claude/OpenAI subscription credentials, avoid the Claude auto-detect flow unless you understand the account and policy implications, and verify/remove stored profiles and secrets in ~/.openclaw after setup. Static scan was clean and VirusTotal was pending, so the Review verdict is based on artifact-backed credential-handling scope, not malware telemetry.