notebooklm

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s functionality mostly matches its stated NotebookLM purpose, and the install path is a standard PyPI package with public provenance rather than an obvious malware delivery chain. However, it depends on a third-party CLI outside the publisher’s org, uses browser-session auth against undocumented Google APIs, and combines untrusted content ingestion with Bash/Write permissions and external sharing/export actions. This is better classified as a high-trust integration with notable security exposure, not confirmed malware.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
May 1, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/yonatangross%2Forchestkit%2Fnotebooklm%2F@58d4e4a2376a40e80f18818d18cdc77a465fc93b