Back to skill

Security audit

Notebooklm Content

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed NotebookLM browser-automation skill, but users should be careful because it can act in a logged-in Chrome tab and send sources to Google NotebookLM.

Install only if you trust the Browser Relay extension and are comfortable using Google NotebookLM for the material involved. Enable the relay only on the intended NotebookLM tab, keep the gateway token private, avoid sensitive or regulated sources unless approved, and review NotebookLM sharing settings before sending any returned link.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough to trigger on many ordinary content-generation requests, which increases the chance the agent invokes browser automation and third-party service access when the user did not explicitly ask for NotebookLM. Because this skill can open a logged-in browser session and upload or process user-provided content, over-broad routing raises the risk of unintended data handling and external transmission.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Instructing the agent to return a shareable NotebookLM URL without any privacy warning can expose generated notebooks or embedded source material to unintended recipients. Share links can turn a private browser-automation workflow into a data disclosure event, especially if the notebook contains sensitive text, uploaded files, or proprietary URLs.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The workflow tells users to add URLs, text, and files into NotebookLM but does not disclose that this sends data to Google's service via a logged-in browser session. This omission is dangerous because users may provide confidential, regulated, or proprietary material without informed consent about third-party processing, retention, and sharing implications.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.