notebooklm

Fail

Audited by Socket on Mar 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent, but its footprint is broader than a simple NotebookLM helper: it uses browser automation against the web UI instead of the official API, installs a third-party stealth browser stack, and persists Google session state locally. Data flow appears to stay with Google, so this is not confirmed malware, but the install trust and credential-handling model create meaningful security risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 16, 2026, 06:53 AM
Package URL
pkg:socket/skills-sh/langbaseinc%2Fagent-skills%2Fnotebooklm%2F@c9dca3429dc0693e54dba2cce262b6de9de67a4b