notebooklm
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, prompt injections, or unauthorized exfiltration attempts were found in the skill's instructions or implementation.
- [COMMAND_EXECUTION]: The tool includes a feature to execute a user-defined command for session refresh. This functionality is intended for automation and includes security hardening such as shell execution prevention by default. The agent instructions also use standard commands to fetch and install the tool from its official repository.
- [EXTERNAL_DOWNLOADS]: The skill makes network requests to trusted Google API endpoints and GitHub for version checks and installation. These operations are strictly limited to domains required for the skill's intended purpose.
- [CREDENTIALS_UNSAFE]: The tool manages sensitive Google session cookies but implements proactive safeguards, including owner-only file permissions (0o600) and a comprehensive redaction system to prevent accidental exposure of tokens in logs and error messages.
Audit Metadata