NotebookLM SecureBLOCK
Secure NotebookLM MCP Server - Query Google NotebookLM from Claude/AI agents with 17 security hardening layers
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
🏆 The World's Most Advanced NotebookLM MCP Server
Zero-hallucination answers • Gemini Deep Research • 17 Security Layers • Enterprise Compliance
[](https://www.npmjs.com/package/@pan-sec/notebooklm-mcp) [](https://calver.org/) [](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io/) [](#cross-platform-support) [](./SECURITY.md) [](./SECURITY.md#post-quantum-encryption) [](#-gemini-deep-research-v180) [](#-document-api-v190) [](#programmatic-notebook-creation-v170) [](./docs/COMPLIANCE-SPEC.md) [](./tests/)
What's New 2026 • Deep Research • Document API • Create Notebooks • Security • Install
The only NotebookLM MCP with enterprise-grade security, post-quantum encryption, and full Gemini API integration. Security-hardened fork of [PleasePrompto/notebooklm-mcp](https://github.com/PleasePrompto/n
a6c413f8a8e7OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add notebooklm-mcp -- npx -y @pan-sec/[email protected]
Exposed tools (58)
40 read · 12 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_notebook | write | Add a NotebookLM notebook to the local library after explicit user confirmation. |
add_source | write | Add a source to an existing NotebookLM notebook. If neither \ |
batch_create_notebooks | write | Create multiple NotebookLM notebooks in one operation. ## What This Tool Does - Creates up to 10 notebooks in a single batch operation - Reports progress for each notebook - Optionally continues on error or stops on first failure - Auto-adds created notebooks to your library ## Example Usage \ |
cleanup_data | destructive | Preview or delete NotebookLM MCP data across known install, browser, cache, log, backup, and trash locations. |
close_session | read | Close a specific session by session ID. Ask before closing if the user might still need it. |
collect_audit_evidence | read | Collect evidence package for compliance audits. Creates a verifiable package with checksums. |
compliance_dashboard | read | Get comprehensive compliance dashboard with GDPR, SOC2, and CSSF status. Shows overall compliance score, health status, and key metrics. |
compliance_score | read | Get current compliance score (0-100) for each regulation and overall. Includes detailed breakdown by category. |
configure_webhook | write | Add or update a webhook endpoint for event notifications.\n\n |
deep_research | read | Perform deep research using Gemini |
download_audio | read | Download the generated audio overview file. ## Requirements - Audio must be in |
export_user_data | read | Export all user data in machine-readable format (GDPR Article 20 - Right to Data Portability). |
generate_audio_overview | read | Generate an AI-powered audio overview (podcast-style) for a notebook. ## What This Tool Does - Triggers NotebookLM |
generate_compliance_report | read | Generate a compliance audit report. Supports multiple report types and formats. |
get_audio_status | read | Check the audio overview generation status for a notebook. ## Returns - status: |
get_consent_status | read | Get current consent status for all data processing purposes. |
get_data_table | read | Extract the generated Data Table content from a notebook. ## What This Tool Does - Navigates to the notebook |
get_health | read | Get server health status including authentication state, active sessions, and configuration. |
get_incident_status | read | Get status of security incidents including open, investigating, and resolved counts. |
get_library_stats | read | Get statistics about your notebook library (total notebooks, usage, etc.) |
get_notebook | read | Get detailed information about a specific notebook by ID |
get_notebook_chat_history | read | Extract conversation history from a NotebookLM notebook |
get_policy | read | Get detailed information about a specific compliance policy. |
get_project_info | read | Get current project context and library location.\n\n |
get_query_history | read | Retrieve past NotebookLM queries and answers for reviewing research sessions. Use this tool to: - Review past research conversations - Find specific information from previous queries - Track which notebooks and sessions you |
get_quota | read | Get current quota status including license tier, usage, and limits.\n\n |
get_research_status | read | Check the status of a background deep research task. Use this when you started deep_research with wait_for_completion=false. ## Returns - status: pending | running | completed | failed - answer: The research result (if completed) - error: Error message (if failed) |
get_video_status | read | Check the Video Overview generation status for a notebook. ## Returns - status: |
grant_consent | read | Grant consent for a specific data processing purpose. |
list_evidence_packages | read | List all saved evidence packages with their metadata. |
list_notebooks | read | List all library notebooks with metadata (name, topics, use cases, URL). |
list_policies | read | List all compliance policies with their status and review dates. |
list_sessions | read | List all active sessions with stats (age, message count, last activity). |
list_sources | read | List sources in a notebook. Provide notebook_id or notebook_url; if neither is provided, |
list_webhooks | read | List all configured webhooks with their status and statistics.\n\n |
notebooklm.auth-repair | read | Troubleshooting guide for authentication issues. |
notebooklm.auth-setup | read | Guide for initial Google authentication setup for NotebookLM access. |
notebooklm.quick-start | write | Quick start guide for NotebookLM MCP. |
notebooklm.security-overview | read | Overview of security features in this hardened MCP server. |
query_document | read | Ask questions about an uploaded document. ## What This Does - Queries a document previously uploaded with upload_document - Uses Gemini |
remove_notebook | destructive | Dangerous — requires explicit user confirmation. ## Confirmation Workflow 1) User requests removal ( |
remove_source | destructive | Remove a source from a NotebookLM notebook. If neither \ |
remove_webhook | destructive | Remove a configured webhook by ID. |
report_security_incident | read | Report a security incident for investigation and tracking. |
request_data_erasure | read | Request erasure of personal data (GDPR Article 17 - Right to Erasure). Creates an erasure request for review. |
reset_session | destructive | Reset a session |
revoke_consent | destructive | Revoke previously granted consent for a data processing purpose. |
run_health_check | write | Run a comprehensive health check of all compliance components. |
search_notebooks | read | Search library by query (name, description, topics, tags). |
select_notebook | write | Set a notebook as the active default (used when ask_question has no notebook_id). ## When To Use - User switches context: |
set_quota_tier | write | Manually set your NotebookLM license tier.\n\n |
submit_dsar | write | Submit a Data Subject Access Request (GDPR Article 15-17, 20). Initiates the DSAR workflow. |
test_webhook | write | Send a test event to a webhook to verify it |
update_notebook | write | Update notebook metadata based on user intent. ## Pattern 1) Identify target notebook and fields (topics, description, use_cases, tags, url) 2) Propose the exact change back to the user 3) After explicit confirmation, call this tool ## Examples - User: |
upload_document | write | Upload a document (PDF, text, etc.) to Gemini for querying. > **⚠️ REQUIRES GEMINI_API_KEY** - For adding documents to NotebookLM notebooks (no API key), use create_notebook or add_source instead. ## What This Does - Uploads a local file to Gemini |
verify_audit_log_integrity | read | Verify the integrity of compliance audit logs using hash chain verification. |
verify_evidence_integrity | read | Verify the integrity of an evidence package using cryptographic checksums. |
x | read | x |
Trust audit
BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
pattern: /-----BEGIN RSA PRIVATE KEY-----[\s\S]*?-----END RSA PRIVATE KEY-----/g,
pattern: /-----BEGIN EC PRIVATE KEY-----[\s\S]*?-----END EC PRIVATE KEY-----/g,
pattern: /-----BEGIN PRIVATE KEY-----[\s\S]*?-----END PRIVATE KEY-----/g,
pattern: /-----BEGIN OPENSSH PRIVATE KEY-----[\s\S]*?-----END OPENSSH PRIVATE KEY-----/g,
".netrc",
".netrc",
/ignore\s+(all\s+)?(previous|prior|above)\s+(instructions?|prompts?)/i,
/forget\s+(everything|all|your)\s+(you|instructions)/i,
console.log(` Token hash file: ${tokenFilePath}`);console.log(` ║ New Token: ${newToken.padEnd(55)}║`);const text = "ANTHROPIC_KEY=sk-ant-ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnop";
const text = "DATABASE_URL=postgres://user:password123@localhost:5432/mydb";
const text = 'const apiKey = "AIzaSyDaGmWKa4JsXZ-HjGw7ISLn_3namBGewQe"';
const text = 'stripe.api_key = "sk_test_4eC39HqLyjWDarjtT1zdp7dc"';
const text = 'api_key = "abcdefghijklmnop1234"';
const text = 'api_key = "abcdefghijklmnop1234"';
const SECRET = "s3cr3t-hmac-value-do-not-persist"; // pragma: allowlist secret
const text = "token: ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij";
"ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij",
"gho_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij",
"ghs_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij",
"ghr_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij",
const text = `-----BEGIN RSA PRIVATE KEY-----
const text = "SLACK_TOKEN=xoxb-1234567890-1234567890-AbCdEfGhIjKlMnOpQrStUvWx";
const text = 'STRIPE_KEY=pk_live_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefg';
Gates applied: critical_finding, instruction_override, no_behavioural_pass.
a6c413f8a8e7full audit observations/trust-audit/mcp-server/pantheon-security__notebooklm-secure.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a6c413f8a8e7 | BLOCK | F | 40 | first audit |
Questions
What is the NotebookLM Secure MCP server?
Secure NotebookLM MCP Server - Query Google NotebookLM from Claude/AI agents with 17 security hardening layers
What tools does NotebookLM Secure expose?
58 in total: 40 read-only, 12 that write, and 6 that can delete or overwrite (cleanup_data, remove_notebook, remove_source, remove_webhook, reset_session). Every one is listed on this page with its risk.
Is NotebookLM Secure safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (40/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does NotebookLM Secure need?
It reads GEMINI_API_KEY, LOGIN_PASSWORD, NLMCP_AUDIT_CHECKPOINT_KEY, NLMCP_AUTH_DISABLED, NLMCP_AUTH_ENABLED, NLMCP_AUTH_LOCKOUT_MS, NLMCP_AUTH_MAX_FAILED, NLMCP_AUTH_READONLY_TOKEN, NLMCP_AUTH_ROTATION_INTERVAL_HOURS, NLMCP_AUTH_TOKEN, NLMCP_AUTH_TOKEN_FILE and NLMCP_ENCRYPTION_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does NotebookLM Secure run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @pan-sec/notebooklm-mcp at 2026.5.0.
How current is this page?
The grade is for one exact copy of the source (a6c413f8a8e7), read on 2026-10-07. The repository is watched and re-audited when it changes.