notebooklm-mcp-cli

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill employs browser cookie extraction via nlm login to authenticate with Google services. This involves accessing sensitive session data stored on the local filesystem, which is required for its undocumented API interactions.
  • [EXTERNAL_DOWNLOADS]: The nlm skill install command facilitates the download and installation of additional content and logic from remote repositories, which may not be subject to the same review as the core tool.
  • [COMMAND_EXECUTION]: The tool automatically modifies system-level configuration files for various AI assistants (e.g., Claude Desktop, Cursor, Gemini) using the nlm setup command suite to integrate the MCP server.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of processing external data.
  • Ingestion points: Ingests untrusted data from arbitrary URLs, local PDF/text files, and Google Drive documents via the nlm source add command.
  • Boundary markers: No evidence of delimiters or protective instructions (e.g., "ignore embedded instructions") is provided when interpolating external source content into the NotebookLM context.
  • Capability inventory: Includes network operations for API access, local file system writes for downloading generated artifacts, and modification of third-party application configuration files.
  • Sanitization: The skill lacks explicit sanitization or filtering for the content it ingests from external sources before processing it through the AI model.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 10:04 AM
Security Audit — agent-trust-hub — notebooklm-mcp-cli