nlm-skill

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access attempts were detected in the skill instructions or referenced documentation.
  • [COMMAND_EXECUTION]: The skill uses the bash tool to execute nlm CLI commands. This is the intended primary function of the skill for programmatically managing NotebookLM workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of content from external and potentially untrusted sources such as URLs, YouTube videos, and web research results. This creates a standard surface for indirect prompt injection, an inherent risk in retrieval-augmented generation (RAG) tools.
  • Ingestion points: nlm source add (URLs, text, Drive docs) and nlm research start (web and Drive search).
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the agent when processing external source content.
  • Capability inventory: The skill utilizes bash for CLI interaction, file operations for downloading generated artifacts (e.g., PDFs, MP3s), and network operations for interacting with Google services.
  • Sanitization: No specific content sanitization or validation steps are described for the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 07:53 AM
Security Audit — agent-trust-hub — nlm-skill