notebooklm-skill

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and uses mostly legitimate install channels, but it depends on an unofficial third-party client that handles Google authenticated session state and exposes sharing actions. No clear credential-harvesting endpoint or overt malware behavior is shown, yet the combination of undocumented API use, session file handling, and external sharing makes this a medium-risk automation skill rather than benign.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 03:34 AM
Package URL
pkg:socket/skills-sh/julianobarbosa%2Fclaude-code-skills%2Fnotebooklm-skill%2F@76babd61f58c3aeec08f96bf701f60c65cbc3d33
Security Audit — socket — notebooklm-skill