notebooklm
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
scripts/run.pyscript serves as a wrapper that takes a filename as a command-line argument and executes it as a Python script using the local virtual environment. This pattern allows the agent to dynamically execute any code present in thescripts/directory.\n- [COMMAND_EXECUTION]: Multiple scripts, includingscripts/run.py,scripts/setup_environment.py, andscripts/__init__.py, utilizesubprocess.runto manage the execution environment, install Python packages, and invoke the Patchright browser installation tool.\n- [EXTERNAL_DOWNLOADS]: The skill downloads thepatchrightlibrary from PyPI and subsequently uses it to download the Google Chrome browser binary during its initialization process. While these are necessary for the skill's browser automation features, they involve downloading and executing external binaries and code.\n- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest answers from external Google NotebookLM sources. Inscripts/ask_question.py, the grounded response text is extracted from the DOM and returned directly to the agent's context without sanitization or boundary markers (e.g., XML tags or clear delimiters). This represents an ingestion point where malicious content within a notebook could influence the agent's logic.\n- [DATA_EXPOSURE]: The skill manages authentication by capturing Google session cookies and storing them indata/browser_state/state.json. While this is a common requirement for persistent automation, the presence of sensitive session data in the skill's data directory is a notable security consideration.
Audit Metadata