notebooklm

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent—querying NotebookLM via browser automation—but the trust model is weaker than it should be: it stores persistent Google session state locally, depends on third-party 'undetected' browser automation, and documents a transitive install path through an unrelated skills repo. Data flows go to official Google endpoints rather than obvious exfiltration hosts, so this is not confirmed malware, but it is a medium-high risk skill due to supply-chain and credential/session-handling concerns.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
May 4, 2026, 12:43 PM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-skills%2Fnotebooklm%2F@4871dfcefce58e0e92e81b1e3e9dabc475b0dc90