T08 · Insecure Dependencies
- Location
scripts/notebooklm-quickstart.py:19- Finding
Unpinned and Unverified Installation of an Unofficial Executable Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This NotebookLM helper is mostly coherent, but it asks users to install an unpinned unofficial package and upload local content to Google/NotebookLM without enough scoping or privacy warnings.
Install only in a dedicated virtual environment, review and pin the notebooklm-py and browser dependencies, and treat NotebookLM uploads as external data sharing with Google/NotebookLM. Do not let an agent delete notebooks or upload private, regulated, or secret material unless you explicitly approve the exact files, URLs, and notebook actions.
scripts/notebooklm-quickstart.py:19Unpinned and Unverified Installation of an Unofficial Executable Dependency
There is a clear description-behavior mismatch. The description claims a feature-rich NotebookLM skill capable of generating multiple content types and managing documents/knowledge workflows. However, the actual code chunk does not perform any of those tasks; it only prints a simple example message and includes comments indicating future work. This is a materially different primary purpose from the declared functionality, so it should be flagged as a mismatch.
The skill clearly instructs use of shell commands and external tooling, but it declares no explicit tool scope or permissions boundary. In an agent environment, that increases the chance the skill will be invoked with broader shell capability than intended, enabling command execution, package installation, browser automation, and local file access without clear restriction.
The documented delete command can permanently remove notebooks, but the skill provides no warning about data loss or need for confirmation. In an automated or agent-driven context, destructive commands without safeguards increase the risk of accidental deletion of user content and loss of work.
The skill encourages uploading local files, URLs, audio, video, and research material to an external third-party service without prominently warning that potentially sensitive data will leave the local environment. In agent use, this can lead to unintentional exfiltration of confidential documents, internal URLs, or regulated data under the guise of normal content-processing workflows.
This code uses Chinese-only natural-language descriptions, help text, and status messages in the module docstring, argument help, and printed output. The file provides no user opt-in, locale selection, or justification for a Chinese-only interface, which is a natural-language locale policy concern under the stated rules.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def get_notebook_metadata():
"""获取笔记本元数据"""
result = subprocess.run(
["notebooklm", "metadata", "--json"],
capture_output=True,
text=True
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
for artifact_type, ext, folder in artifact_types:
try:
output_path = os.path.join(output_dir, f"{folder}.{ext}")
result = subprocess.run(
["notebooklm", "download", artifact_type, output_path],
capture_output=True,
text=True
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
for fmt in ["json", "markdown"]:
try:
output_path = os.path.join(output_dir, f"{artifact_type}.{fmt}")
result = subprocess.run(
["notebooklm", "download", artifact_type, "--format", fmt, output_path],
capture_output=True,
text=True
The script's docstrings, prompts, and status messages are all written in Chinese, including the title, installation prompt, and command descriptions. This imposes a specific language on all users without opt-in or any documented justification that the skill is intended only for a Chinese-speaking or region-specific audience.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def check_installation():
"""检查 notebooklm-py 是否已安装"""
try:
subprocess.run(["notebooklm", "--version"], capture_output=True, check=True)
return True
except (subprocess.CalledProcessError, FileNotFoundError):
return False
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def install_notebooklm():
"""安装 notebooklm-py"""
print("📦 安装 notebooklm-py...")
subprocess.run([sys.executable, "-m", "pip", "install", "notebooklm-py"], check=True)
subprocess.run([sys.executable, "-m", "pip", "install", "notebooklm-py[browser]"], check=True)
print("✅ 安装完成")
print("⚠️ 首次使用需要运行: notebooklm login")
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""安装 notebooklm-py"""
print("📦 安装 notebooklm-py...")
subprocess.run([sys.executable, "-m", "pip", "install", "notebooklm-py"], check=True)
subprocess.run([sys.executable, "-m", "pip", "install", "notebooklm-py[browser]"], check=True)
print("✅ 安装完成")
print("⚠️ 首次使用需要运行: notebooklm login")
No suspicious patterns detected.