nlm-skill

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely coherent and uses verifiable package-manager distribution, but it wraps undocumented NotebookLM APIs, handles raw Google session cookies, and includes transitive skill-installation plus public sharing/invite actions. This is not confirmed malicious, but it has meaningful trust and credential-handling risk beyond a normal documentation-only skill.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Mar 29, 2026, 04:16 PM
Package URL
pkg:socket/skills-sh/jst-well-dan%2Fskill-box%2Fnlm-skill%2F@b3263cc5cdf1d8988d32048dbe2c520b0b494189