notebooklm-second-brain

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is a coherent, self-consistent skill specification for a NotebookLM-based retrieval policy. It aligns its described capabilities (routing queries through NotebookLM, maintaining notebooks.json, post-build synchronization) with its stated purpose of keeping context lean and using notebook-backed knowledge first. There are no evident malicious data exfiltration or credential-harvesting patterns; the workflow appears to operate within local config and a sanctioned CLI. Caution is advised to ensure credentials used by the nlm CLI (via login and tokens) are protected and that the bootstrap process and hooks are trusted in the CI/CD environment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 08:33 PM
Package URL
pkg:socket/skills-sh/cleanexpo%2Fnodejs-starter-v1%2Fnotebooklm-second-brain%2F@e85e4d9c0148b6785a76a3467799ce7cc1f37461