notebooklm

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities mostly match its NotebookLM automation purpose, but it relies on an unofficial third-party CLI, handles sensitive Google session/auth state, and instructs transitive skill installation. This is not clearly malicious, yet the trust and credential-routing model is broader than ideal for a Google integration.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/teng-lin%2Fnotebooklm-py%2Fnotebooklm%2F@b31ec577f8180fff12e932bceeec240744661149