notebooklm-mcp

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for NotebookLM access, but its actual footprint is high-trust and disproportionate because it depends on an unofficial third-party client that authenticates by ingesting full Google session cookies. Pinned PyPI distribution and provenance reduce supply-chain concern, but credential sensitivity, browser-cookie extraction, and third-party session handling keep overall risk elevated.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Sep 14, 2026, 06:33 PM
Package URL
pkg:socket/skills-sh/afonsoft%2Fskills%2Fnotebooklm-mcp%2F@046b2c060cf62b4d468b74a9353c28a8554c07c61769922f6d16201f1472cc60
Security Audit — socket — notebooklm-mcp