Back to skill

Security audit

Qa Notebooklm Api

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward NotebookLM CLI guide; it uses an authenticated cloud service and can download generated files, but those behaviors match its stated purpose.

Install only if you intend to use the notebooklm CLI with a NotebookLM account. Treat sources, pasted text, URLs, and questions as content sent to a cloud service, and avoid uploading confidential or regulated material unless you are authorized. Check where downloaded artifacts are saved and review the third-party CLI before authenticating.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The markdown instructs users to add sources and ask questions through the `notebooklm` CLI, which implies sending user-provided content and prompts to a remote service. There is no privacy or data-handling warning in the skill description to alert users that notebook content may leave the local system.

Missing User Warnings

Low
Confidence
87% confidence
Finding
The skill documents `notebooklm download` commands for slide decks, quizzes, and flashcards, which affect the local filesystem. The markdown provides no explicit notice that these commands create local output files or may overwrite/download content onto the user's machine.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
The example `Summarize this content in Chinese` directs a specific language output without documenting that language selection should come from user preference. This can conflict with organizational language/locale policies when the skill is otherwise general-purpose.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.