notebooklm

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a NotebookLM automation skill, but its trust model is weak: the skill requires an unverifiable external CLI as the core control plane and routes Google authentication through it. The capabilities are broadly aligned with the purpose, yet the missing provenance for the binary and its handling of OAuth materially raise supply-chain and credential-forwarding risk.

Confidence: 84%Severity: 83%
Audit Metadata
Analyzed At
Apr 19, 2026, 02:58 AM
Package URL
pkg:socket/skills-sh/jmagar%2Fclaude-homelab%2Fnotebooklm%2F@751d87778c06f6a4bb1d67ed67aec3fa90aa5ad8
Security Audit — socket — notebooklm