live · scanning repos
Scanrepo
github.com
github.com / PleasePrompto

PleasePrompto/notebooklm-mcp

TypeScript·50 files·commit 50b3e7f·scanned 4d ago·cached ✓
25/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.

score capped at 253,299 stars — findings likely legitimate code patterns

verdict accurate?
Crypto/Web3 project
CLI tool detected
threat-state: lowlive

FINDINGS ░▒▓

criticalSuspicious code is reachable from an entry pointFlagged files are imported by the application's entry path: src/auth/auth-manager.ts, src/notebooklm/selectors.ts, src/resources/resource-handlers.ts. This means the suspicious code can execute when the app runs.+8
warningCluster of suspicious files reachable from entry8 flagged files form a connected cluster that is reachable from an entry point, suggesting coordinated malicious behavior rather than isolated false positives.+5
warningHigh-entropy string literalsFound 6 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/auth/auth-manager.ts+3
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/notebooklm/selectors.ts+3
warningHigh-entropy string literalsFound 4 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/resources/resource-handlers.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/tools/handlers.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/utils/stealth-utils.ts+3

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

41 files scanned @ 50b3e7f | 8/20/2026 | heuristic scan — always review manually

risk by category
code execution13
network & exfiltration0
file system access0
obfuscation15
supply chain0
owasp / injection0
telemetry
files 41/50rules hit 7engine v5commit 50b3e7f

github

PleasePrompto/notebooklm-mcp

MCP server for NotebookLM - Let your AI agents (Claude Code, Codex) research documentation directly with grounded, citation-backed answers from Gemini. Persistent auth, library management, cross-client sharing. Zero hallucinations, just your knowledge base.

TypeScript
3299
467
312d
50 files
41 scanned(82%)
50b3e7f

architecture░▒▓

entry (1) flagged (8) pkg (12)
49 nodes · 119 edgesscroll to zoom · click node to jump to finding