anything-to-notebooklm

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated NotebookLM workflow, but its core trust model depends on `notebooklm-py`, an unofficial third-party CLI that explicitly uses undocumented Google APIs. Data uploads to NotebookLM are expected for this purpose, yet credential/session handling and all content routing occur through non-official tooling. No clear malware or hidden exfiltration is shown, but install trust and credential forwarding are only partially justified, and sharing features add real-world action risk.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Apr 1, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/azuma520%2Fyoutube-to-notebooklm%2Fanything-to-notebooklm%2F@a93f7a53711de3ae20a7490911330490afb41be5