notebooklm-cli
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle describes a CLI tool (`nlm`) for Google NotebookLM. The primary reason for classification as 'suspicious' is the explicit instruction for the `nlm login` command to 'Launch Chrome, navigate to NotebookLM, and extract session cookies' as detailed in `SKILL.md` and `references/commands.md`. While this is presented as a legitimate authentication mechanism for the tool, the act of programmatically extracting session cookies is a high-risk capability that could be leveraged for credential theft if the underlying `nlm` tool were compromised or misused. There is no clear evidence of intentional harmful behavior or prompt injection against the agent beyond the stated purpose, but the sensitive nature of cookie extraction warrants a 'suspicious' classification.
