cc-notebooklm
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the notebooklm-mcp-cli package from the Python Package Index using uv or pip. This is a standard dependency required for the integration and does not involve suspicious download sources.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from NotebookLM into the agent context, creating a potential attack surface for indirect prompt injection. 1. Ingestion points: NotebookLM notebooks accessed via the notebooklm-mcp-cli tool. 2. Boundary markers: None are specified in the instructions to prevent the agent from following instructions embedded in the notes. 3. Capability inventory: The skill operates within Claude Code, which has capabilities including shell command execution and file system access. 4. Sanitization: No explicit sanitization or filtering of the notebook content is mentioned.
Audit Metadata