ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      crabsticksalad

      Safety Report

      Open Notebook Skill

      @crabsticksalad

      Access and manage a self-hosted Open Notebook research system (NotebookLM alternative). Create notebooks, add sources (text/URL/file), cross-notebook search,...

      52Downloads
      0Installs
      0Stars
      5Versions
      File Management6,712Search & Retrieval5,443Notes & Knowledge2,526

      Security Analysis

      high confidence
      Suspicious0.04 risk

      This skill is mostly coherent, but its provided bridge code does not fully enforce the notebook access controls it promises, which could expose private notes in shared or restricted setups.

      Jun 15, 20264 files5 concerns
      Purpose & Capabilityconcern

      The skill's purpose is clear: connect an agent to a self-hosted Open Notebook system for saving, searching, chatting with, and managing research notes. However, private note access plus destructive notebook/source deletion are high-impact capabilities, and the sample bridge leaves cross-notebook list/search paths broader than the documented per-notebook controls.

      Instruction Scopeconcern

      The SKILL frontmatter says to use it only for explicit saved-content requests, but the README says the agent uses it automatically for broad research or notes prompts. That ambiguity matters because activation can retrieve persisted private notebook data.

      Install Mechanismnote

      Install/setup is disclosed and local: it requires a self-hosted Open Notebook deployment, a local FastAPI bridge on 127.0.0.1:5077, an agent API key, and a user systemd service. No hidden installer or obfuscated package behavior was found.

      Credentialsconcern

      Loopback-only network access and an API key are proportionate for this integration, but the documented security model depends on per-notebook allowlists that are not consistently applied by the included bridge example.

      Persistence & Privilegeconcern

      The bridge is intended to run persistently and logs calls, which is disclosed. The skill also exposes irreversible delete commands without an interactive confirmation step, so users should treat it as a privileged notebook-management tool, not only a search/RAG helper.

      Guidance

      Install only if you control the Open Notebook deployment and are comfortable giving the agent notebook-management authority. Before using per-notebook restrictions, fix or verify bridge-side enforcement for notebook listing and cross-notebook search, and require explicit user confirmation before delete-source or delete-notebook operations.

      Latest Release

      v1.3.0

      Security audit fixes v2: source ownership enforcement on get-source/delete-source (prevents cross-notebook access), stripped agent count from health endpoint, irreversible operation warnings on delete commands.

      More by @crabsticksalad

      Fitbit Tracker

      2 stars

      Youcom Search

      0 stars

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Published by @crabsticksalad on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]