Back to skill

Security audit

NotebookLM Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly documents NotebookLM automation, but it needs Review because it tells users to handle browser cookies and weaken Codex sandbox protections without enough warning.

Install only if you are comfortable with a NotebookLM automation guide that may access your Google/NotebookLM session. Do not paste raw cookie headers into chats or logs, avoid danger-full-access unless you fully trust the command and environment, review public-sharing effects before enabling links, and treat skill install/update/uninstall commands as separate administrative changes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/troubleshooting.md:119
Finding

Unsafe Recommendation to Disable Codex Sandbox Isolation

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md:119-127
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: High

Vulnerable Code Snippet:

toml
[sandbox_workspace_write]
network_access = true

Or run with full network access:

bash
codex exec --sandbox danger-full-access "nlm notebook list"

Technical Analysis

The troubleshooting guide recommends --sandbox danger-full-access when network access is unavailable. This mode removes sandbox restrictions instead of granting only the network capability required by the NotebookLM operation.

The command executed inside the unrestricted environment is resolved from the user's local executable search path. If the nlm executable or one of its dependencies has been replaced, compromised, or shadowed by an attacker-controlled executable, it can operate with the invoking user's full host permissions. The sandbox bypass therefore expands a network troubleshooting action into unrestricted filesystem, process, credential, and network access.

The preceding network_access = true configuration is the narrower option, while the unrestricted fallback violates least-privilege principles.

Attack Path

  1. An attacker compromises the installed nlm package, one of its runtime dependencies, or places a malicious executable named nlm earlier in the user's PATH.
  2. The user encounters the documented sandbox network error.
  3. Following the troubleshooting guide, the user executes: codex exec --sandbox danger-full-access "nlm notebook list".
  4. Codex launches the attacker-controlled or compromised executable without normal sandbox isolation.
  5. The executable reads or modifies files accessible to the user, accesses local credentials and browser data, communicates with external systems, or launches additional processes.

Impact Assessment

Exploitation can provide access equivalen ...[truncated 399 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the --sandbox danger-full-access recommendation.
  2. Retain sandbox isolation and enable only the required outbound network capability, such as the documented network_access = true setting.
  3. Restrict outbound access to NotebookLM and required Google authentication endpoints where the execution environment supports destination allowlisting.
  4. Instruct users to verify the resolved executable before use, for example with command -v nlm, and to install it only from a trusted, pinned source.
  5. If unrestricted execution is unavoidable, clearly explain the affected security boundary and require explicit user approval after displaying the executable path and risks.

T09 · Insecure Skill Coding Practices

Warning
Location
references/troubleshooting.md:55
Finding

Overbroad and Forceful Termination of Browser Processes

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md:55-67
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code Snippet:

bash
pkill -f "Chrome\|Brave\|Arc\|Edge"
# Wait a moment, then retry
nlm login
bash
lsof -i :9222
# Kill the process using the port
kill -9 <PID>

Technical Analysis

pkill -f matches against complete process command lines and terminates every user-accessible process containing any listed browser name. It does not verify that a process belongs to the NotebookLM authentication session or is using the relevant debugging port. Consequently, unrelated browser sessions and auxiliary processes can be terminated.

The guide also recommends unconditional SIGKILL through kill -9. SIGKILL prevents applications from performing graceful shutdown, persisting pending state, releasing resources normally, or completing profile database writes. It should be a last resort after the exact process has been identified and a normal termination attempt has failed.

Attack Path

  1. A user has unrelated Chrome, Brave, Arc, or Edge sessions running, potentially containing unsaved work.
  2. NotebookLM login fails to launch or encounters a debugging-port conflict.
  3. The user follows the guide and executes the broad pkill -f command.
  4. All matching processes that the user can signal are terminated, including sessions unrelated to nlm.
  5. Alternatively, the user identifies a process associated with port 9222 and immediately sends SIGKILL without validating ownership or attempting graceful shutdown.
  6. Active work may be lost, and browser profile or session state may be left inconsistent.

Impact Assessment

The commands operate with the invoking user's process-control privileges. They can disrupt all matching browser processes owned by that user, cause loss of unsaved work, interrupt authenticated se ...[truncated 239 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the broad pkill -f instruction.
  2. Identify only the process listening on the relevant debugging port, using a command that reports the PID, owner, and executable.
  3. Display the identified process to the user and request confirmation before terminating it.
  4. Verify that the process belongs to the current user and was created for the nlm authentication workflow.
  5. Attempt graceful termination with kill <PID> or the application's normal shutdown mechanism first.
  6. Wait for a bounded period and use kill -9 only if the verified process remains unresponsive.
  7. Prefer selecting another available debugging port instead of terminating an unrelated process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
Findings (17)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs saving raw cookie headers via MCP without a strong warning that these are bearer-style credentials. Exposing or mishandling cookie headers can allow session hijacking and unauthorized access to the user's Google/NotebookLM account.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
98% confidence
Finding

The text explicitly tells the user to extract cookies from Chrome DevTools and pass them to a tool, which matches credential-harvesting/session-token handling behavior. Even as a fallback auth method, this is dangerous because copied browser cookies can be stolen, logged, or reused to impersonate the user.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

e notebook → nlm notebook delete --confirm

text

## Command Categories

### 1. Authentication

#### MCP Authentication

If using MCP tools and encountering authentication errors:

```bash
# Run the CLI authentication (works for both CLI and MCP)
nlm login

# Then reload tokens in MCP
mcp__notebooklm-mcp__refresh_auth()

Or manually save cookies via MCP (fallback):

python
# Extract cookies from Chrome DevTools and save
mcp__notebooklm-mcp__save_auth_tokens(cookies="<cookie_header>")
text

#### CLI Authentication

```bash
nlm login                           # Launch browser, extract cookies (primary method)
nlm login --check                   # Validate current session
nlm login --profile work            # Use named profile for multiple accounts
nlm login --provider openclaw --cdp-url http://127.0.0.1:18800  # External CDP provider
nlm login switch <profile>          # Switch the default profile
nlm login profile list              # List all profiles with email address

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 426)May include surrounding context.

md
**REPL Commands**:
- `/sources` - List available sources
- `/clear` - Reset conversation context
- `/help` - Show commands
- `/exit` - Exit REPL

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/command_reference.md (reported line 739)May include surrounding context.

md
**REPL Commands**:
- `/sources` - List available sources
- `/clear` - Reset conversation context
- `/help` - Show commands
- `/exit` - Exit REPL

Self-Modification

High
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill documents commands to update/install skills, which enables modification of the assistant's own capabilities or prompt surface. Self-modification is dangerous because it can introduce unreviewed instructions or overwrite trusted behavior through routine use of a seemingly unrelated skill.

Content

Scanner excerpt · SKILL.md (reported line 518)May include surrounding context.

nlm skill uninstall # Uninstall skill

text

**Verb-first aliases**: `nlm update skill`, `nlm list skills`, `nlm install skill`

## Output Formats

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Directing users to modify ~/.codex/config.toml changes agent/runtime configuration in the user's local environment, which can persist beyond the immediate troubleshooting session. In this context the specific setting enables network access, so the instruction affects security posture and could normalize unsafe configuration changes without sufficient warning.

Content

Scanner excerpt · references/troubleshooting.md (reported line 119)May include surrounding context.

Solution for OpenAI Codex:

Add to ~/.codex/config.toml:

toml
[sandbox_workspace_write]
network_access = true

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
98% confidence
Finding

The example codex exec --sandbox danger-full-access explicitly tells users to bypass sandbox restrictions and run with maximal access. Even as troubleshooting advice, this is dangerous because it encourages operating outside normal containment boundaries, which can magnify the impact of mistakes or malicious downstream actions.

Content

Scanner excerpt · references/troubleshooting.md (reported line 127)May include surrounding context.

Or run with full network access:

bash
codex exec --sandbox danger-full-access "nlm notebook list"

Solution for Docker/Containers:

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/workflows.md (reported line 176)May include surrounding context.

In REPL:

Type questions naturally

/sources - see available sources

/clear - reset conversation

/exit - exit REPL

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description includes a catch-all trigger phrase ('any NotebookLM-related automation task'), which is broader than precise activation criteria. Over-broad triggering can cause the skill to activate in contexts the user did not intend, increasing the chance that risky instructions in the skill influence unrelated workflows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes self-management commands for installing, updating, and uninstalling AI assistant skills, which expands its scope beyond NotebookLM usage into modifying the assistant environment. That increases attack surface because a user invoking this skill for NotebookLM help could be guided into changing agent capabilities or pulling updated skill content from external sources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown reference documents nlm share public as enabling public link sharing by default, but it does not include an explicit warning that the notebook may become accessible via a public link and could expose user content. Because this behavior can affect user privacy and data exposure, the skill description should disclose that impact clearly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The troubleshooting guide recommends broad process-termination commands such as pkill -f and kill -9 without warning that they may kill unrelated browser processes or force-stop applications in a way that can cause data loss. In an agent skill context, users may copy-paste these commands directly, increasing the chance of unintended disruption on the host system.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/troubleshooting.md (reported line 82)May include surrounding context.

nlm login profile list

text

2. **Create a new profile:**
```bash
nlm login --profile work

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide instructs users to enable network access in sandboxed environments and even suggests danger-full-access execution without any caution about reduced isolation, data exposure, or broader system risk. In a security-sensitive agent environment, this meaningfully weakens protections and could expose local files, credentials, or external services if followed blindly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow explicitly enables public notebook sharing but does not warn that a public link may expose notebook contents, sources, notes, and generated artifacts to unintended parties. In a skill centered on programmatic NotebookLM operations, users may follow the sequence verbatim, so omission of privacy guidance materially increases the risk of accidental data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The nlm share invite section explains how to invite collaborators, including granting editor access, but it does not explicitly warn that this shares notebook contents with another person and may permit modifications. For markdown guidance covering sharing behavior, users should be alerted to the access and integrity implications.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 201)May include surrounding context.

nlm source add --drive --type pdf # for PDF

text

3. **Check permissions:**
Ensure your Google account has access to the Drive document.

4. **Large documents timeout:**

Static analysis

No suspicious patterns detected.