notebooklm

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the provided skill is only a loader stub, so its real behavior is not reviewable here. The main risk is transitive trust and unpinned GitHub source installation from a personal account; there is not enough evidence in the stub alone to call it malicious, but it should not be treated as benign without reviewing the external repo contents.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 5, 2026, 09:07 AM
Package URL
pkg:socket/skills-sh/stevengonsalvez%2Fagents-in-a-box%2Fnotebooklm%2F@1ec14ab68d2729099693988b1048306f7041f968