notebooklm-researcher

Warn

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing 'notebooklm-mcp-cli' via pipx, which is an external dependency from a source not identified as a trusted vendor.
  • [COMMAND_EXECUTION]: Relies on the nlm CLI for its operations, including commands like 'nlm login' that extract browser cookies for authentication, posing a risk of session data exposure.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing content from external URLs and YouTube.
  • [INGESTION_POINTS]: Sources added through 'nlm source add' commands.
  • [BOUNDARY_MARKERS]: No delimiters or warnings are used to isolate external data from instructions.
  • [CAPABILITY_INVENTORY]: Includes bash command execution (nlm CLI), network access, and file downloading.
  • [SANITIZATION]: No sanitization or validation of the ingested external content is mentioned.
  • [COMMAND_EXECUTION]: Uses dynamic context injection via '!cat' commands in the SKILL.md file to load the contents of local protocols and configuration files into the prompt context at load time.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — notebooklm-researcher