cli-anything-notebooklm
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external notebook data through the
chat,source, andartifactcommand groups. Maliciously crafted content within a notebook's sources or chat history could potentially influence the agent's behavior during processing. - Ingestion points: Data retrieved via
chat,source, andartifactcommands defined inSKILL.md. - Boundary markers: None provided to distinguish between notebook content and agent instructions.
- Capability inventory: Shell command execution via the
cli-anything-notebooklmharness. - Sanitization: No sanitization or filtering of notebook content is documented.
- [EXTERNAL_DOWNLOADS]: The installation process requires downloading the
notebooklm-pypackage from PyPI and browser binaries for the Playwright framework. - Evidence:
python3 -m pip install --user 'notebooklm-py[browser]'andpython3 -m playwright install chromiumfound inSKILL.md.
Audit Metadata