Back to skill

Security audit

Notebooklm

Security checks for vulnerabilities and agentic risk

Overview

This NotebookLM helper is mostly coherent, but it asks users to install an unpinned unofficial package and upload local content to Google/NotebookLM without enough scoping or privacy warnings.

Install only in a dedicated virtual environment, review and pin the notebooklm-py and browser dependencies, and treat NotebookLM uploads as external data sharing with Google/NotebookLM. Do not let an agent delete notebooks or upload private, regulated, or secret material unless you explicitly approve the exact files, URLs, and notebook actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/notebooklm-quickstart.py:19
Finding

Unpinned and Unverified Installation of an Unofficial Executable Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. The description claims a feature-rich NotebookLM skill capable of generating multiple content types and managing documents/knowledge workflows. However, the actual code chunk does not perform any of those tasks; it only prints a simple example message and includes comments indicating future work. This is a materially different primary purpose from the declared functionality, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly instructs use of shell commands and external tooling, but it declares no explicit tool scope or permissions boundary. In an agent environment, that increases the chance the skill will be invoked with broader shell capability than intended, enabling command execution, package installation, browser automation, and local file access without clear restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented delete command can permanently remove notebooks, but the skill provides no warning about data loss or need for confirmation. In an automated or agent-driven context, destructive commands without safeguards increase the risk of accidental deletion of user content and loss of work.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages uploading local files, URLs, audio, video, and research material to an external third-party service without prominently warning that potentially sensitive data will leave the local environment. In agent use, this can lead to unintentional exfiltration of confidential documents, internal URLs, or regulated data under the guise of normal content-processing workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code uses Chinese-only natural-language descriptions, help text, and status messages in the module docstring, argument help, and printed output. The file provides no user opt-in, locale selection, or justification for a Chinese-only interface, which is a natural-language locale policy concern under the stated rules.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/notebooklm-batch-download.py (reported line 14)May include surrounding context.

python
def get_notebook_metadata():
    """获取笔记本元数据"""
    result = subprocess.run(
        ["notebooklm", "metadata", "--json"],
        capture_output=True,
        text=True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/notebooklm-batch-download.py (reported line 43)May include surrounding context.

python
for artifact_type, ext, folder in artifact_types:
        try:
            output_path = os.path.join(output_dir, f"{folder}.{ext}")
            result = subprocess.run(
                ["notebooklm", "download", artifact_type, output_path],
                capture_output=True,
                text=True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/notebooklm-batch-download.py (reported line 61)May include surrounding context.

python
for fmt in ["json", "markdown"]:
            try:
                output_path = os.path.join(output_dir, f"{artifact_type}.{fmt}")
                result = subprocess.run(
                    ["notebooklm", "download", artifact_type, "--format", fmt, output_path],
                    capture_output=True,
                    text=True

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's docstrings, prompts, and status messages are all written in Chinese, including the title, installation prompt, and command descriptions. This imposes a specific language on all users without opt-in or any documented justification that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/notebooklm-quickstart.py (reported line 14)May include surrounding context.

python
def check_installation():
    """检查 notebooklm-py 是否已安装"""
    try:
        subprocess.run(["notebooklm", "--version"], capture_output=True, check=True)
        return True
    except (subprocess.CalledProcessError, FileNotFoundError):
        return False

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/notebooklm-quickstart.py (reported line 22)May include surrounding context.

python
def install_notebooklm():
    """安装 notebooklm-py"""
    print("📦 安装 notebooklm-py...")
    subprocess.run([sys.executable, "-m", "pip", "install", "notebooklm-py"], check=True)
    subprocess.run([sys.executable, "-m", "pip", "install", "notebooklm-py[browser]"], check=True)
    print("✅ 安装完成")
    print("⚠️  首次使用需要运行: notebooklm login")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/notebooklm-quickstart.py (reported line 23)May include surrounding context.

python
"""安装 notebooklm-py"""
    print("📦 安装 notebooklm-py...")
    subprocess.run([sys.executable, "-m", "pip", "install", "notebooklm-py"], check=True)
    subprocess.run([sys.executable, "-m", "pip", "install", "notebooklm-py[browser]"], check=True)
    print("✅ 安装完成")
    print("⚠️  首次使用需要运行: notebooklm login")

Static analysis

No suspicious patterns detected.