notebooklm
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly consistent with NotebookLM automation, but it depends on an unofficial third-party library, stores reusable Google session state locally, and supports headless cookie refresh for persistent agent access. No clear evidence of credential theft or attacker-controlled exfiltration endpoints, so this is not malicious, but the auth persistence and third-party trust model make it medium risk.
Confidence: 84%Severity: 56%
Audit Metadata