Atlas / MCP servers / roomi-fields / NotebookLM

NotebookLMBLOCK

mcp/roomi-fields/notebooklm-3

Google NotebookLM over MCP + a local HTTP REST API. Citation-backed Q&A, audio/video/content generation, multi-account rotation. For Claude Code, Codex, Cursor, n8n, Zapier, Make.

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
54 38r · 9w · 7d
Transport
stdio
License
MIT
Stars
188
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Automate Google NotebookLM at scale. 33-endpoint HTTP REST API for n8n / Zapier / Make / curl, plus an MCP server for Claude Code / Cursor / Codex. Citation-backed Q&A, full Studio generation (audio · video · infographic · report · presentation · data table), multi-account rotation with auto-reauth across personal and Google Workspace accounts.

v3.2.0 — generated content can finally be deleted (content_delete): the endpoint had been declared and called by nothing since v3, so notebooks accumulated every draft ever asked for. Builds on 3.1.x, where generated content stopped coming back in the wrong language — the interface locale was overriding the language argument on both transports, silently, while reporting success. Also: reading a source's full indexed text (source_read, paginated), working source labels, and RPC refusals reported as refusals instead of as a rotated endpoint id. Built on a dual transport — the internal batchexecute RPC API (10-100× faster than scraping, immune to UI rebrands) with the Playwright browser as an automatic fallback, both shipped permanently. Batch-tested on overnight runs of 1 000+ questions. See the changelog. Compare with `PleasePrompto/notebooklm-mcp` for when this project is the right pick (REST API, full Studio, auto-reauth).
Note (July 2026): Google rebranded NotebookLM to Gemini Notebook. It is the same product, existing links redirect, and this project drives the same underlying service — the browser path was updated for the new DOM in v2.3.0 and the RPC path in v3.0.0. Package and repository keep the notebooklm name.

[](https://github.com/roomi-fields/notebooklm-mcp/actions/workflows/ci.yml) [![npm version](https://badge.fury.io/js/%40roomi-field

Read from source at commit 28ef8087e99cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add notebooklm-mcp -- npx -y @roomi-fields/[email protected]
03

Exposed tools (54)

38 read · 9 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
OriginalreadKeep this
TestreadTest notebook
add_notebookwrite🔌 [PROXY] Add notebook to library via HTTP server
add_sourcewrite🔌 [PROXY] Add source/document to notebook via HTTP server
ask_questionreadAsk a question to NotebookLM
auto_discover_notebookread🔌 [PROXY] Auto-discover notebook metadata via HTTP server
batch_to_vaultwriteRun a list of questions against a notebook and persist each answer to disk as
cleanup_dataread🔌 [PROXY] Cleanup server data via HTTP server
close_sessionread🔌 [PROXY] Close session via HTTP server
complex_toolreadA complex tool
convert_note_to_sourcereadConvert a note to a source document in NotebookLM.\n\n
create_notewriteCreate a note in the NotebookLM Studio panel.\n\n
create_notebookwriteCreate a notebook
de_authdestructive🔌 [PROXY] Logout (clear credentials) via HTTP server
delete_contentdestructiveDelete a generated Studio artifact (audio overview, video, report, infographic,
delete_notebooks_from_nblmdestructiveDelete one or more notebooks directly from NotebookLM (UI-level deletion,
delete_sourcedestructiveDelete a source from the current NotebookLM notebook.\n\n
download_audioread🔌 [PROXY] Download generated audio file via HTTP server
download_contentreadDownload or export generated content from NotebookLM.\n\n
generate_audioread🔌 [PROXY] Generate audio overview (podcast) via HTTP server
generate_contentread🔌 [PROXY] Generate content via HTTP server.\n
generate_mind_mapwriteGenerate and save a mind map from a notebook’s sources. RPC-backed (no browser).
generate_study_aidreadGenerate a study aid from a notebook’s sources: flashcards or a quiz.
get_healthreadGet server health
get_library_statsread🔌 [PROXY] Get library statistics via HTTP server
get_notereadRetrieve the full title and text content of a specific note in the NotebookLM Studio panel.
get_notebookread🔌 [PROXY] Get notebook details by ID via HTTP server
list_contentread🔌 [PROXY] List sources and generated content via HTTP server
list_notebooksreadList all notebooks
list_notebooks_from_nblmread🔌 [PROXY] Scrape NotebookLM homepage to get real notebook list via HTTP server
list_notesreadList all user notes in the NotebookLM Studio panel. Returns note titles, IDs, and timestamps (e.g. details).
list_sessionsread🔌 [PROXY] List active sessions via HTTP server
list_sourcesreadList the sources of a NotebookLM notebook, with their IDs and titles.\n\n
manage_labelsdestructiveManage a notebook’s source labels (RPC-backed): list them, create one, or delete some.
my-test-notebookreadThree word name test. Works correctly.
n8n-workflow-guideread...
notebookreadSingle word name test. Works correctly.
re_authread🔌 [PROXY] Re-authenticate with different account via HTTP server
read_sourcereadRead a source’s full indexed content — the exact text NotebookLM reasons over,
remove_notebookdestructive🔌 [PROXY] Remove notebook from library via HTTP server
requiredreadAll required. Second.
research_sourcesreadDiscover web sources for a notebook via NotebookLM Fast Research. RPC-backed.
reset_sessiondestructive🔌 [PROXY] Reset session history via HTTP server
retry-testreadThis notebook was discovered after retry. Success on second attempt.
save_chat_to_notewriteSave the current NotebookLM chat/discussion to a note.\n\n
search_notebooksread🔌 [PROXY] Search notebooks via HTTP server
select_notebookwrite🔌 [PROXY] Set active notebook via HTTP server
setup_authread🔌 [PROXY] Setup Google authentication via HTTP server.\n
share_notebookreadRead a notebook’s sharing status, or toggle its public link.
test-namereadTest description. Second sentence.
test-notebookreadThis is a test notebook. It contains test data.
too-many-words-in-namereadTest description. Second sentence.
update_notebookwrite🔌 [PROXY] Update notebook metadata via HTTP server
valid-namereadShort description. Second sentence.
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (9 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (22)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/content/content-manager.ts:2496
deletedSourceName = await sourceElement.$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/content/content-manager.ts:2634
const nameText = await el.$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/content/content-manager.ts:3846
const titleText = await el.$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/content/content-manager.ts:4340
const innerContent = await noteElement.$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
tests/e2e/archive/E2E-TEST-REPORT.md:1
# NotebookLM MCP HTTP Server - E2E Test Report
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
deployment/docs/02-CONFIGURATION.md:142
$env:API_KEY="my-super-secure-secret-token"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
de_auth, delete_content, delete_notebooks_from_nblm, delete_source, manage_labels, remove_notebook, reset_session
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
website/static/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/__tests__/security.test.ts:158
'/root/.ssh/id_rsa',
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/security.test.ts:156
'/app/data/../../../etc/passwd',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/security.test.ts:157
'../../../etc/passwd',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/security.test.ts:159
'/app/data/../../etc/shadow',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/vault-writer.test.ts:107
expect(() => resolveVaultDir('../../etc')).toThrow(/escape/i);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/browser-modules.test.ts:24
import { CONFIG } from '../../src/config.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
deployment/docs/04-N8N-INTEGRATION.md:45
curl http://192.168.1.52:3000/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
deployment/docs/04-N8N-INTEGRATION.md:55
- **URL:** `http://192.168.1.52:3000/ask`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
deployment/docs/04-N8N-INTEGRATION.md:87
- URL: `http://192.168.1.52:3000/ask`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
deployment/docs/04-N8N-INTEGRATION.md:135
- URL: `http://192.168.1.52:3000/ask`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
deployment/docs/04-N8N-INTEGRATION.md:170
- URL: `http://192.168.1.52:3000/ask`
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, cors, dotenv, env-paths, express, globby, otplib, patchright
Why it matters. 27 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
website/package.json
@mdx-js/react, clsx, prism-react-renderer, react, react-dom, @types/react, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:252
The server descriptor read `process.env.npm_package_version`, which is only set
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 28ef8087e99cfull audit observations/trust-audit/mcp-server/roomi-fields__notebooklm-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0728ef8087e99cBLOCKF56first audit
06

Questions

What is the NotebookLM MCP server?

Google NotebookLM over MCP + a local HTTP REST API. Citation-backed Q&A, audio/video/content generation, multi-account rotation. For Claude Code, Codex, Cursor, n8n, Zapier, Make.

What tools does NotebookLM expose?

54 in total: 38 read-only, 9 that write, and 7 that can delete or overwrite (de_auth, delete_content, delete_notebooks_from_nblm, delete_source, manage_labels). Every one is listed on this page with its risk.

Is NotebookLM safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does NotebookLM need?

It reads GH_TOKEN, GITHUB_TOKEN, LOGIN_PASSWORD and NBLM_ENCRYPTION_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does NotebookLM run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as website at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (28ef8087e99c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement