nlm-skill

Pass

Audited by Gen Agent Trust Hub on Oct 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted external data by ingesting content from URLs, YouTube, and Google Drive into the Gemini Notebook environment. This surface is mitigated by explicit instructions for the agent to use grounding anchors in all generation prompts.
  • Ingestion points: Sources are added via the source_add tool and CLI commands documented in SKILL.md and references/workflows.md.
  • Boundary markers: The references/studio-prompting-guide.md defines a mandatory grounding anchor for every prompt: "Use only uploaded sources. Do not invent statistics, quotes, or examples not in the sources."
  • Capability inventory: The skill utilizes CLI command execution (nlm), file downloads to a restricted directory (NOTEBOOKLM_DOWNLOAD_DIR), and authenticated network requests to Google services.
  • Sanitization: Relies on instructional grounding and user confirmation gates for critical operations.
  • [COMMAND_EXECUTION]: The skill's primary function is to provide an interface for the nlm CLI, which executes shell commands to perform notebook operations. This is the intended behavior of the skill.
  • [EXTERNAL_DOWNLOADS]: The skill guides the user to install the notebooklm-mcp-cli package via uv. This tool is maintained by the skill author and is necessary for the skill's operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 7, 2026, 12:21 AM