notebooklm
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements a behavioral instruction injection in
scripts/ask_question.py. TheFOLLOW_UP_REMINDERconstant appends a directive to tool outputs using high-priority language ("EXTREMELY IMPORTANT") designed to override the agent's default completion logic and force a recursive research loop. - [INDIRECT_PROMPT_INJECTION]: The skill possess an indirect prompt injection attack surface by processing data from external sources.
- Ingestion points: Retrieval of synthesized answers and document excerpts from the Google NotebookLM web interface in
scripts/ask_question.py. - Boundary markers: The skill does not wrap external content in delimiters or provide "ignore embedded instructions" warnings before passing the data to the agent.
- Capability inventory: The skill can execute subprocesses (
scripts/run.py), perform local file writes for library management (scripts/notebook_manager.py), and conduct network operations via browser automation. - Sanitization: Content retrieved from NotebookLM is returned to the agent without filtering or escaping of potential instructions embedded in the processed documents.
- [EXTERNAL_DOWNLOADS]: During initialization, the skill automatically fetches and installs external resources.
scripts/setup_environment.pyandscripts/__init__.pyutilizepipto install Python dependencies and thepatchrightlibrary to download Google Chrome or Chromium binaries into a local virtual environment. - [COMMAND_EXECUTION]: The skill relies on the
subprocessmodule to manage its local environment. Thescripts/run.pyscript dynamically constructs and executes shell commands to launch other skill scripts within the isolated Python virtual environment.
Audit Metadata