Atlas / MCP servers / pantheon-security / NotebookLM Secure

NotebookLM SecureBLOCK

mcp/pantheon-security/notebooklm-secure

Secure NotebookLM MCP Server - Query Google NotebookLM from Claude/AI agents with 17 security hardening layers

Verdict
BLOCK
Grade
F
Trust score
40 /100
Exposed tools
58 40r · 12w · 6d
Transport
stdio
License
MIT
Stars
85
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🏆 The World's Most Advanced NotebookLM MCP Server

Zero-hallucination answers • Gemini Deep Research • 17 Security Layers • Enterprise Compliance

[](https://www.npmjs.com/package/@pan-sec/notebooklm-mcp) [](https://calver.org/) [](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io/) [](#cross-platform-support) [](./SECURITY.md) [](./SECURITY.md#post-quantum-encryption) [](#-gemini-deep-research-v180) [](#-document-api-v190) [](#programmatic-notebook-creation-v170) [](./docs/COMPLIANCE-SPEC.md) [](./tests/)

What's New 2026 • Deep Research • Document API • Create Notebooks • Security • Install

The only NotebookLM MCP with enterprise-grade security, post-quantum encryption, and full Gemini API integration. Security-hardened fork of [PleasePrompto/notebooklm-mcp](https://github.com/PleasePrompto/n
Read from source at commit a6c413f8a8e7OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add notebooklm-mcp -- npx -y @pan-sec/[email protected]
03

Exposed tools (58)

40 read · 12 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_notebookwriteAdd a NotebookLM notebook to the local library after explicit user confirmation.
add_sourcewriteAdd a source to an existing NotebookLM notebook. If neither \
batch_create_notebookswriteCreate multiple NotebookLM notebooks in one operation. ## What This Tool Does - Creates up to 10 notebooks in a single batch operation - Reports progress for each notebook - Optionally continues on error or stops on first failure - Auto-adds created notebooks to your library ## Example Usage \
cleanup_datadestructivePreview or delete NotebookLM MCP data across known install, browser, cache, log, backup, and trash locations.
close_sessionreadClose a specific session by session ID. Ask before closing if the user might still need it.
collect_audit_evidencereadCollect evidence package for compliance audits. Creates a verifiable package with checksums.
compliance_dashboardreadGet comprehensive compliance dashboard with GDPR, SOC2, and CSSF status. Shows overall compliance score, health status, and key metrics.
compliance_scorereadGet current compliance score (0-100) for each regulation and overall. Includes detailed breakdown by category.
configure_webhookwriteAdd or update a webhook endpoint for event notifications.\n\n
deep_researchreadPerform deep research using Gemini
download_audioreadDownload the generated audio overview file. ## Requirements - Audio must be in
export_user_datareadExport all user data in machine-readable format (GDPR Article 20 - Right to Data Portability).
generate_audio_overviewreadGenerate an AI-powered audio overview (podcast-style) for a notebook. ## What This Tool Does - Triggers NotebookLM
generate_compliance_reportreadGenerate a compliance audit report. Supports multiple report types and formats.
get_audio_statusreadCheck the audio overview generation status for a notebook. ## Returns - status:
get_consent_statusreadGet current consent status for all data processing purposes.
get_data_tablereadExtract the generated Data Table content from a notebook. ## What This Tool Does - Navigates to the notebook
get_healthreadGet server health status including authentication state, active sessions, and configuration.
get_incident_statusreadGet status of security incidents including open, investigating, and resolved counts.
get_library_statsreadGet statistics about your notebook library (total notebooks, usage, etc.)
get_notebookreadGet detailed information about a specific notebook by ID
get_notebook_chat_historyreadExtract conversation history from a NotebookLM notebook
get_policyreadGet detailed information about a specific compliance policy.
get_project_inforeadGet current project context and library location.\n\n
get_query_historyreadRetrieve past NotebookLM queries and answers for reviewing research sessions. Use this tool to: - Review past research conversations - Find specific information from previous queries - Track which notebooks and sessions you
get_quotareadGet current quota status including license tier, usage, and limits.\n\n
get_research_statusreadCheck the status of a background deep research task. Use this when you started deep_research with wait_for_completion=false. ## Returns - status: pending | running | completed | failed - answer: The research result (if completed) - error: Error message (if failed)
get_video_statusreadCheck the Video Overview generation status for a notebook. ## Returns - status:
grant_consentreadGrant consent for a specific data processing purpose.
list_evidence_packagesreadList all saved evidence packages with their metadata.
list_notebooksreadList all library notebooks with metadata (name, topics, use cases, URL).
list_policiesreadList all compliance policies with their status and review dates.
list_sessionsreadList all active sessions with stats (age, message count, last activity).
list_sourcesreadList sources in a notebook. Provide notebook_id or notebook_url; if neither is provided,
list_webhooksreadList all configured webhooks with their status and statistics.\n\n
notebooklm.auth-repairreadTroubleshooting guide for authentication issues.
notebooklm.auth-setupreadGuide for initial Google authentication setup for NotebookLM access.
notebooklm.quick-startwriteQuick start guide for NotebookLM MCP.
notebooklm.security-overviewreadOverview of security features in this hardened MCP server.
query_documentreadAsk questions about an uploaded document. ## What This Does - Queries a document previously uploaded with upload_document - Uses Gemini
remove_notebookdestructiveDangerous — requires explicit user confirmation. ## Confirmation Workflow 1) User requests removal (
remove_sourcedestructiveRemove a source from a NotebookLM notebook. If neither \
remove_webhookdestructiveRemove a configured webhook by ID.
report_security_incidentreadReport a security incident for investigation and tracking.
request_data_erasurereadRequest erasure of personal data (GDPR Article 17 - Right to Erasure). Creates an erasure request for review.
reset_sessiondestructiveReset a session
revoke_consentdestructiveRevoke previously granted consent for a data processing purpose.
run_health_checkwriteRun a comprehensive health check of all compliance components.
search_notebooksreadSearch library by query (name, description, topics, tags).
select_notebookwriteSet a notebook as the active default (used when ask_question has no notebook_id). ## When To Use - User switches context:
set_quota_tierwriteManually set your NotebookLM license tier.\n\n
submit_dsarwriteSubmit a Data Subject Access Request (GDPR Article 15-17, 20). Initiates the DSAR workflow.
test_webhookwriteSend a test event to a webhook to verify it
update_notebookwriteUpdate notebook metadata based on user intent. ## Pattern 1) Identify target notebook and fields (topics, description, use_cases, tags, url) 2) Propose the exact change back to the user 3) After explicit confirmation, call this tool ## Examples - User:
upload_documentwriteUpload a document (PDF, text, etc.) to Gemini for querying. > **⚠️ REQUIRES GEMINI_API_KEY** - For adding documents to NotebookLM notebooks (no API key), use create_notebook or add_source instead. ## What This Does - Uploads a local file to Gemini
verify_audit_log_integrityreadVerify the integrity of compliance audit logs using hash chain verification.
verify_evidence_integrityreadVerify the integrity of an evidence package using cryptographic checksums.
xreadx
04

Trust audit

BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/utils/secrets-scanner.ts:197
pattern: /-----BEGIN RSA PRIVATE KEY-----[\s\S]*?-----END RSA PRIVATE KEY-----/g,
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/utils/secrets-scanner.ts:203
pattern: /-----BEGIN EC PRIVATE KEY-----[\s\S]*?-----END EC PRIVATE KEY-----/g,
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/utils/secrets-scanner.ts:209
pattern: /-----BEGIN PRIVATE KEY-----[\s\S]*?-----END PRIVATE KEY-----/g,
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/utils/secrets-scanner.ts:309
pattern: /-----BEGIN OPENSSH PRIVATE KEY-----[\s\S]*?-----END OPENSSH PRIVATE KEY-----/g,
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/tools/handlers/notebook-creation.ts:522
".netrc",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/utils/security.ts:397
".netrc",
Why it matters. touches a credential store
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/SECURITY_IMPLEMENTATION_PLAN.md:241
/ignore\s+(all\s+)?(previous|prior|above)\s+(instructions?|prompts?)/i,
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/SECURITY_IMPLEMENTATION_PLAN.md:244
/forget\s+(everything|all|your)\s+(you|instructions)/i,
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/mcp-auth.ts:627
console.log(`  Token hash file: ${tokenFilePath}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/mcp-auth.ts:645
console.log(`  ║  New Token: ${newToken.padEnd(55)}║`);
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/secrets-scanner.test.ts:129
const text = "ANTHROPIC_KEY=sk-ant-ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnop";
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/secrets-scanner.test.ts:176
const text = "DATABASE_URL=postgres://user:password123@localhost:5432/mydb";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/secrets-scanner.test.ts:45
const text = 'const apiKey = "AIzaSyDaGmWKa4JsXZ-HjGw7ISLn_3namBGewQe"';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/secrets-scanner.test.ts:104
const text = 'stripe.api_key = "sk_test_4eC39HqLyjWDarjtT1zdp7dc"';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/secrets-scanner.test.ts:340
const text = 'api_key = "abcdefghijklmnop1234"';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/secrets-scanner.test.ts:356
const text = 'api_key = "abcdefghijklmnop1234"';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/webhook-secret-handling.test.ts:18
const SECRET = "s3cr3t-hmac-value-do-not-persist"; // pragma: allowlist secret
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/secrets-scanner.test.ts:63
const text = "token: ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/secrets-scanner.test.ts:72
"ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij",
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/secrets-scanner.test.ts:73
"gho_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij",
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/secrets-scanner.test.ts:75
"ghs_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij",
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/secrets-scanner.test.ts:76
"ghr_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/secrets-scanner.test.ts:138
const text = `-----BEGIN RSA PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
tests/secrets-scanner.test.ts:88
const text = "SLACK_TOKEN=xoxb-1234567890-1234567890-AbCdEfGhIjKlMnOpQrStUvWx";
MEDIUMHard-coded secrets · secret.stripe · CWE-798, CWE-321
tests/secrets-scanner.test.ts:111
const text = 'STRIPE_KEY=pk_live_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefg';

Gates applied: critical_finding, instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha a6c413f8a8e7full audit observations/trust-audit/mcp-server/pantheon-security__notebooklm-secure.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07a6c413f8a8e7BLOCKF40first audit
06

Questions

What is the NotebookLM Secure MCP server?

Secure NotebookLM MCP Server - Query Google NotebookLM from Claude/AI agents with 17 security hardening layers

What tools does NotebookLM Secure expose?

58 in total: 40 read-only, 12 that write, and 6 that can delete or overwrite (cleanup_data, remove_notebook, remove_source, remove_webhook, reset_session). Every one is listed on this page with its risk.

Is NotebookLM Secure safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (40/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does NotebookLM Secure need?

It reads GEMINI_API_KEY, LOGIN_PASSWORD, NLMCP_AUDIT_CHECKPOINT_KEY, NLMCP_AUTH_DISABLED, NLMCP_AUTH_ENABLED, NLMCP_AUTH_LOCKOUT_MS, NLMCP_AUTH_MAX_FAILED, NLMCP_AUTH_READONLY_TOKEN, NLMCP_AUTH_ROTATION_INTERVAL_HOURS, NLMCP_AUTH_TOKEN, NLMCP_AUTH_TOKEN_FILE and NLMCP_ENCRYPTION_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does NotebookLM Secure run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @pan-sec/notebooklm-mcp at 2026.5.0.

How current is this page?

The grade is for one exact copy of the source (a6c413f8a8e7), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement