nlm-skill
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted external data by ingesting content from URLs, YouTube, and Google Drive into the Gemini Notebook environment. This surface is mitigated by explicit instructions for the agent to use grounding anchors in all generation prompts.
- Ingestion points: Sources are added via the
source_addtool and CLI commands documented inSKILL.mdandreferences/workflows.md. - Boundary markers: The
references/studio-prompting-guide.mddefines a mandatory grounding anchor for every prompt: "Use only uploaded sources. Do not invent statistics, quotes, or examples not in the sources." - Capability inventory: The skill utilizes CLI command execution (
nlm), file downloads to a restricted directory (NOTEBOOKLM_DOWNLOAD_DIR), and authenticated network requests to Google services. - Sanitization: Relies on instructional grounding and user confirmation gates for critical operations.
- [COMMAND_EXECUTION]: The skill's primary function is to provide an interface for the
nlmCLI, which executes shell commands to perform notebook operations. This is the intended behavior of the skill. - [EXTERNAL_DOWNLOADS]: The skill guides the user to install the
notebooklm-mcp-clipackage viauv. This tool is maintained by the skill author and is necessary for the skill's operation.
Audit Metadata