notebooklm

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a behavioral instruction injection in scripts/ask_question.py. The FOLLOW_UP_REMINDER constant appends a directive to tool outputs using high-priority language ("EXTREMELY IMPORTANT") designed to override the agent's default completion logic and force a recursive research loop.
  • [INDIRECT_PROMPT_INJECTION]: The skill possess an indirect prompt injection attack surface by processing data from external sources.
  • Ingestion points: Retrieval of synthesized answers and document excerpts from the Google NotebookLM web interface in scripts/ask_question.py.
  • Boundary markers: The skill does not wrap external content in delimiters or provide "ignore embedded instructions" warnings before passing the data to the agent.
  • Capability inventory: The skill can execute subprocesses (scripts/run.py), perform local file writes for library management (scripts/notebook_manager.py), and conduct network operations via browser automation.
  • Sanitization: Content retrieved from NotebookLM is returned to the agent without filtering or escaping of potential instructions embedded in the processed documents.
  • [EXTERNAL_DOWNLOADS]: During initialization, the skill automatically fetches and installs external resources. scripts/setup_environment.py and scripts/__init__.py utilize pip to install Python dependencies and the patchright library to download Google Chrome or Chromium binaries into a local virtual environment.
  • [COMMAND_EXECUTION]: The skill relies on the subprocess module to manage its local environment. The scripts/run.py script dynamically constructs and executes shell commands to launch other skill scripts within the isolated Python virtual environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — notebooklm