nlm-skill
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is largely coherent and uses verifiable package-manager distribution, but it wraps undocumented NotebookLM APIs, handles raw Google session cookies, and includes transitive skill-installation plus public sharing/invite actions. This is not confirmed malicious, but it has meaningful trust and credential-handling risk beyond a normal documentation-only skill.
Confidence: 88%Severity: 64%
Audit Metadata