Atlas / MCP servers / alfredang / NotebookLM

NotebookLMSAFE

mcp/alfredang/notebooklm-6

Bridge Google NotebookLM with Claude via MCP. Full programmatic access to create notebooks, manage sources, and generate AI-powered content — podcasts, videos, slides, mind maps, quizzes, flashcards, and reports — all through natural language.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
15 12r · 3w · 0d
Transport
—
License
—
Stars
57
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful MCP (Model Context Protocol) server that brings Google NotebookLM into Claude Desktop and Claude Code.

Features

  • Research: List and create notebooks
  • Content: Add URLs, text, and files as sources
  • Generation: Create Podcasts, Videos, Slides, Mind Maps, Infographics, Quizzes, Flashcards, and Reports
  • Natural Interaction: Chat directly with your sources using Claude's reasoning

Prerequisites

1. Install uv (Python Package Manager)

macOS / Linux

# Using curl
curl -LsSf https://astral.sh/uv/install.sh | sh

# Or with Homebrew (macOS)
brew install uv

Default install location: ~/.local/bin/uv

Windows

# Using PowerShell
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

# Or with Scoop
scoop install uv

# Or with winget
winget install --id=astral-sh.uv -e

Default install location: %USERPROFILE%\.local\bin\uv.exe

Verify installation:

uv --version

2. Clone and Install Dependencies

# Clone the repository
git clone https://github.com/alfredang/notebooklm-mcp.git

# Navigate to the project folder
cd notebooklm-mcp

# Install dependencies (includes notebooklm-py and fastmcp)
uv sync

This will:

  • Create a .venv virtual environment
  • Install notebooklm-py (Python client for NotebookLM API)
  • Install fastmcp (MCP server framework)
Note: These dependencies are required for both Claude Desktop and Claude Code.

Step 1: Authenticate with NotebookLM

NotebookLM uses browser-based authentication. You must login once to save your session cookies.

cd notebooklm-mcp
uv run notebooklm login

What happens:

  1. A browser window will open automatically
  2. Log in to your Google account
  3. Navigate to NotebookLM if not redirected automatically

4.

Read from source at commit 8cadb0226496OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add notebooklm-assistant -- uvx notebooklm-assistant
claude-desktop
{
  "mcpServers": {
    "notebooklm-assistant": {
      "command": "uvx",
      "args": [
        "notebooklm-assistant"
      ]
    }
  }
}
03

Exposed tools (15)

12 read · 3 write · 0 destructive.

ToolRiskDescription
add_source_textwriteAdd raw text as a source to a notebook.
add_source_urlwriteAdd a website URL as a source to a notebook.
ask_notebookreadAsk a question based on the sources in a specific notebook.
create_notebookwriteCreate a new notebook with the given title.
generate_audio_overviewread
generate_data_tableread
generate_flashcardsread
generate_infographicread
generate_mind_mapread
generate_quizread
generate_slide_deckread
generate_summary_reportread
generate_video_overviewread
get_notebook_summaryreadGet the summary and key insights of a notebook.
list_notebooksreadList all notebooks in your NotebookLM account.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:440
1. Open System Properties → Environment Variables
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
README.md:424
Add to your shell profile (`~/.zshrc` or `~/.bashrc`):
Why it matters. instructs the agent to persist itself in the user's environment
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
README.md:439
Add to your PATH:
Why it matters. instructs the agent to persist itself in the user's environment
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:23
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 8cadb0226496full audit observations/trust-audit/mcp-server/alfredang__notebooklm-6.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-088cadb0226496SAFEB89first audit
06

Questions

What is the NotebookLM MCP server?

Bridge Google NotebookLM with Claude via MCP. Full programmatic access to create notebooks, manage sources, and generate AI-powered content — podcasts, videos, slides, mind maps, quizzes, flashcards, and reports — all through natural language.

What tools does NotebookLM expose?

15 in total: 12 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is NotebookLM safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does NotebookLM need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (8cadb0226496), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement