cli-anything-notebooklm

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external notebook data through the chat, source, and artifact command groups. Maliciously crafted content within a notebook's sources or chat history could potentially influence the agent's behavior during processing.
  • Ingestion points: Data retrieved via chat, source, and artifact commands defined in SKILL.md.
  • Boundary markers: None provided to distinguish between notebook content and agent instructions.
  • Capability inventory: Shell command execution via the cli-anything-notebooklm harness.
  • Sanitization: No sanitization or filtering of notebook content is documented.
  • [EXTERNAL_DOWNLOADS]: The installation process requires downloading the notebooklm-py package from PyPI and browser binaries for the Playwright framework.
  • Evidence: python3 -m pip install --user 'notebooklm-py[browser]' and python3 -m playwright install chromium found in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:57 PM
Security Audit — agent-trust-hub — cli-anything-notebooklm