notebooklm

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The scripts/run.py script serves as a wrapper that takes a filename as a command-line argument and executes it as a Python script using the local virtual environment. This pattern allows the agent to dynamically execute any code present in the scripts/ directory.\n- [COMMAND_EXECUTION]: Multiple scripts, including scripts/run.py, scripts/setup_environment.py, and scripts/__init__.py, utilize subprocess.run to manage the execution environment, install Python packages, and invoke the Patchright browser installation tool.\n- [EXTERNAL_DOWNLOADS]: The skill downloads the patchright library from PyPI and subsequently uses it to download the Google Chrome browser binary during its initialization process. While these are necessary for the skill's browser automation features, they involve downloading and executing external binaries and code.\n- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest answers from external Google NotebookLM sources. In scripts/ask_question.py, the grounded response text is extracted from the DOM and returned directly to the agent's context without sanitization or boundary markers (e.g., XML tags or clear delimiters). This represents an ingestion point where malicious content within a notebook could influence the agent's logic.\n- [DATA_EXPOSURE]: The skill manages authentication by capturing Google session cookies and storing them in data/browser_state/state.json. While this is a common requirement for persistent automation, the presence of sensitive session data in the skill's data directory is a notable security consideration.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — notebooklm