notebooklm

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill matches its claimed functionality and does not contain explicit indicators of malware (no suspicious domains, no backdoor commands, no obvious obfuscation). The main security issues are supply-chain and operational: automatic, unpinned installation of dependencies and Chromium (download-and-execute) without integrity verification, and persistent local storage of authentication artifacts in plaintext. These increase attack surface and warrant mitigation (pinning, integrity checks, user prompts, protected storage). The package is not confirmed malicious but is moderately risky from a supply-chain perspective and should be reviewed and hardened before use in sensitive environments.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:09 PM
Package URL
pkg:socket/skills-sh/poletron%2Fcustom-rules%2Fnotebooklm%2F@3942434d7369a7f5dfff660f390d25d2ed5b2b4c