Back to Home
Pantheon-Security icon

notebooklm-mcp-secure

Verified Safe

by Pantheon-Security

Overview

Provides programmatic access and management of NotebookLM and Google Gemini for AI agents, offering deep research capabilities, document analysis, and comprehensive compliance and security features.

Installation

Run Command
npx @pan-sec/notebooklm-mcp@latest

Environment Variables

  • GEMINI_API_KEY
  • NLMCP_AUTH_TOKEN
  • NLMCP_ENCRYPTION_ENABLED
  • NLMCP_AUTH_ENABLED
  • NLMCP_CERT_PINNING
  • NLMCP_AUDIT_ENABLED
  • NLMCP_COMPLIANCE_LOGGING
  • NLMCP_HEALTH_MONITORING
  • NLMCP_ALERTS_ENABLED
  • NLMCP_ALERTS_WEBHOOK_URL
  • NLMCP_SIEM_ENABLED
  • NLMCP_BREACH_DETECTION
  • NLMCP_SECRETS_MIN_SEVERITY
  • NLMCP_SESSION_MAX_LIFETIME
  • NLMCP_USE_POST_QUANTUM
  • NOTEBOOKLM_PROFILE
  • NLMCP_WEBHOOK_URL

Security Notes

The server demonstrates an exceptionally strong focus on security and compliance, implementing a wide array of features including post-quantum encryption, certificate pinning, input/output validation (e.g., prompt injection, suspicious URLs), secure session management, tamper-evident audit logging, secrets scanning, breach detection, incident management, data retention, and secure data erasure with wiping. Input validation for URLs and session IDs helps mitigate common injection risks. The extensive compliance framework for GDPR, SOC2, and CSSF is well-integrated. The main security consideration is the reliance on browser automation (Patchright/Chromium) for NotebookLM interactions, which, while handled with robust isolation and stealth measures, introduces an inherent attack surface compared to pure API-based interactions. No 'eval' or obfuscation was found, and no hardcoded secrets were identified.

Similar Servers

Stats

Interest Score39
Security Score9
Cost ClassHigh
Avg Tokens15000
Stars8
Forks3
Last Update2026-01-15

Tags

AILLMNotebookLMGeminiMCPSecurityComplianceAutomationBrowser Automation