codex-notebooklm

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its purpose, and the package install path is relatively trustworthy via PyPI with provenance. However, it relies on an unofficial third-party CLI using internal APIs and forwards user authentication to that tool, which is a meaningful trust and account-security concern even without clear evidence of malicious exfiltration.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 03:52 AM
Package URL
pkg:socket/skills-sh/mathruffian-dot%2Fcodex-lazy-packs%2Fcodex-notebooklm%2F@866ee3a0490816eb2de80ee15ba503d779f72e5d6c727399115fc79224c18131
Security Audit — socket — codex-notebooklm