notebooklm

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s overall purpose is coherent, but it uses persistent browser-session automation for a Google service from a personal publisher rather than an official API flow. Data appears to go to the intended Google service, so this is not confirmed malware, but the auth model, bulk account actions, and local retention of session/artifact data make it medium risk.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:01 PM
Package URL
pkg:socket/skills-sh/sanjay3290%2Fnotebooklm-skill%2Fnotebooklm%2F@62e2c9b4b48b56649a55f9fe751dac5b1c200c0c