notebooklm

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose aligns with querying NotebookLM, and data appears to go to official Google endpoints, which argues against malicious intent. However, the skill depends on an unverifiable local wrapper that auto-installs dependencies, uses browser automation for Google auth, and stores persistent browser session data; these are proportionate to the task but elevate security risk due to opaque install behavior and sensitive local credential state.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 03:29 AM
Package URL
pkg:socket/skills-sh/leegonzales%2Faiskills%2Fnotebooklm%2F@4f5d9717c0315b8c553f332eda988c4aa5b7f949