Openclaw Strava Plugin
Security checks across malware telemetry and agentic risk
Overview
This appears to be a normal Strava integration that uses Strava OAuth and Strava API calls, with no unrelated credential requests or unexpected external services visible.
Before installing, understand that this plugin will let OpenClaw read your Strava activity data, including private activity data if you approve the activity:read_all scope. The visible code only talks to Strava and your OpenClaw gateway, and the Strava credentials it asks for are appropriate. Confidence is medium because part of src/tools.ts and a few small files were omitted/truncated in the provided artifact; a full untruncated source review would increase confidence.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
VirusTotal engine telemetry is currently stale for this artifact.
