notebooklm-researcher
Warn
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing 'notebooklm-mcp-cli' via pipx, which is an external dependency from a source not identified as a trusted vendor.
- [COMMAND_EXECUTION]: Relies on the nlm CLI for its operations, including commands like 'nlm login' that extract browser cookies for authentication, posing a risk of session data exposure.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing content from external URLs and YouTube.
- [INGESTION_POINTS]: Sources added through 'nlm source add' commands.
- [BOUNDARY_MARKERS]: No delimiters or warnings are used to isolate external data from instructions.
- [CAPABILITY_INVENTORY]: Includes bash command execution (nlm CLI), network access, and file downloading.
- [SANITIZATION]: No sanitization or validation of the ingested external content is mentioned.
- [COMMAND_EXECUTION]: Uses dynamic context injection via '!cat' commands in the SKILL.md file to load the contents of local protocols and configuration files into the prompt context at load time.
Audit Metadata