notebooklm

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is largely aligned with its stated NotebookLM automation purpose and routes activity to official Google endpoints, but it carries medium risk due to persistent browser auth, file-upload capability, and reliance on Patchright, a third-party stealth browser automation package outside Google's trust boundary. This looks more suspicious than malicious: coherent functionality with a broader-than-minimal execution footprint.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 14, 2026, 09:34 AM
Package URL
pkg:socket/skills-sh/hugokick%2Fnotebooklm_upgraded-skill%2Fnotebooklm%2F@cdbda48c15605fdeca5ad11f1053da46e32bc6b6