nlm

Security checks across malware telemetry and agentic risk

Overview

This is a coherent NotebookLM command-line helper, but users should be careful with sharing, uploads, browser-session auth, and MCP setup.

Install only if you trust the external `notebooklm-mcp-cli` package and the Google/NotebookLM account session it will use. Before uploading local files, pasted text, URLs, or Drive sources, confirm the content is appropriate for NotebookLM. Before enabling public links, inviting editors, deleting sources, or adding MCP access for other agents, verify the active profile and notebook sharing state.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill exposes commands to make notebooks public and invite collaborators but provides no warning that these actions can disclose private notebook contents or broaden access. In a CLI skill intended for automation, users may copy commands verbatim, increasing the chance of accidental oversharing or unauthorized data exposure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal