notebooklm-mcp-secure
Verified Safeby Pantheon-Security
Overview
Provides programmatic access and management of NotebookLM and Google Gemini for AI agents, offering deep research capabilities, document analysis, and comprehensive compliance and security features.
Installation
npx @pan-sec/notebooklm-mcp@latestEnvironment Variables
- GEMINI_API_KEY
- NLMCP_AUTH_TOKEN
- NLMCP_ENCRYPTION_ENABLED
- NLMCP_AUTH_ENABLED
- NLMCP_CERT_PINNING
- NLMCP_AUDIT_ENABLED
- NLMCP_COMPLIANCE_LOGGING
- NLMCP_HEALTH_MONITORING
- NLMCP_ALERTS_ENABLED
- NLMCP_ALERTS_WEBHOOK_URL
- NLMCP_SIEM_ENABLED
- NLMCP_BREACH_DETECTION
- NLMCP_SECRETS_MIN_SEVERITY
- NLMCP_SESSION_MAX_LIFETIME
- NLMCP_USE_POST_QUANTUM
- NOTEBOOKLM_PROFILE
- NLMCP_WEBHOOK_URL
Security Notes
The server demonstrates an exceptionally strong focus on security and compliance, implementing a wide array of features including post-quantum encryption, certificate pinning, input/output validation (e.g., prompt injection, suspicious URLs), secure session management, tamper-evident audit logging, secrets scanning, breach detection, incident management, data retention, and secure data erasure with wiping. Input validation for URLs and session IDs helps mitigate common injection risks. The extensive compliance framework for GDPR, SOC2, and CSSF is well-integrated. The main security consideration is the reliance on browser automation (Patchright/Chromium) for NotebookLM interactions, which, while handled with robust isolation and stealth measures, introduces an inherent attack surface compared to pure API-based interactions. No 'eval' or obfuscation was found, and no hardcoded secrets were identified.
Similar Servers
hyper-mcp
A fast, secure Model Context Protocol (MCP) server that extends its capabilities through WebAssembly plugins, enabling AI agents to access tools, resources, and prompts.
toolhive-studio
ToolHive is a desktop application (Electron UI) for discovering, deploying, and managing Model Context Protocol (MCP) servers in isolated containers, and connecting them to AI agents and clients.
webscraping-ai-mcp-server
Integrates with WebScraping.AI to provide LLM-powered web data extraction, including question answering, structured data extraction, and HTML/text retrieval, with advanced features like JavaScript rendering and proxy management.
MCP-Security-Framework
Automated security assessment and vulnerability detection for Model Context Protocol (MCP) servers.