notebooklm-second-brain
Warn
Audited by Socket on Apr 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but its actual trust model is weak. It routes project data and browser-derived auth through an unofficial third-party CLI that uses cookie extraction, and it adds automatic remote syncing of build metadata; this is more exposure than a simple retrieval policy needs.
Confidence: 86%Severity: 72%
Audit Metadata