notebooklm
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
subprocess.runinscripts/run.py,scripts/setup_environment.py, andscripts/__init__.pyto automate environment setup, install dependencies, and wrap script execution. These calls are used for the primary purpose of managing the skill's internal infrastructure and isolated virtual environment. - [EXTERNAL_DOWNLOADS]: During initial setup, the skill downloads required Python packages from official registries and browser binaries (Chrome/Chromium) through the
patchrightautomation library. - [PROMPT_INJECTION]: The skill implements a 'Follow-Up Protocol' by appending instructions to the end of answers in
scripts/ask_question.py. This directs the AI agent to evaluate the completeness of the information and perform additional queries if gaps exist, acting as a control-flow mechanism for the research process. - Ingestion points: External text retrieved from the NotebookLM web interface (scripts/ask_question.py).
- Boundary markers: Not present for the ingested text.
- Capability inventory: Subprocess execution for script wrapping and dependency management (scripts/run.py, scripts/setup_environment.py).
- Sanitization: None detected for the retrieved answers before they are returned to the agent context.
Audit Metadata