This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+5 more
Affected surfaces
Summary
AI summarySession‑scoped OTP cooldowns close an abuse vector and usage alerts warn owners before billing caps hit.
Full changelog
What's New in v2026.1.7
Features - MCP Protocol UX Enhancements
Tool Enhancements (43 tools)
- 🎨 Icons - All tools now have SVG icons for visual identification
- 📝 Titles - Human-friendly display names (e.g., "Ask NotebookLM" instead of "ask_question")
- 🏷️ Behavior Annotations - Hints for client decision-making:
readOnlyHint- Tool only reads datadestructiveHint- Tool can delete dataidempotentHint- Safe to call repeatedlyopenWorldHint- Interacts with external services
- ⏱️ Task Support -
deep_researchdeclarestaskSupport: "optional"for long-running operations
Resource Enhancements
- 🎨 Icons for library, notebooks, and metadata resources
- 📝 Human-friendly titles
- 🏷️ Annotations with
audience,priority, andlastModified
New Prompts
notebooklm.auth-setup- Initial authentication guidenotebooklm.auth-repair- Troubleshooting guidenotebooklm.quick-start- Getting started guidenotebooklm.security-overview- Security features documentation
Dependencies Updated
@modelcontextprotocol/sdk→ 1.25.3@google/genai→ 1.38.0patchright→ 1.57.0tsx→ 4.21.0
Security
- Fixed 3 npm audit vulnerabilities (body-parser, hono, qs)
Full Changelog
https://github.com/Pantheon-Security/notebooklm-mcp-secure/compare/v2026.1.6...v2026.1.7
Security Fixes
- Authflow cooldowns now session-scoped — closes abuse vector where users changed phone/email mid-flow to reset OTP cooldowns
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Pantheon-Security/notebooklm-mcp-secure
Security-hardened NotebookLM MCP with post-quantum encryption (ML-KEM-768), GDPR/SOC2/CSSF compliance, and 14 security layers. Query Google's Gemini-grounded research from Claude and AI agents.
Related context
Beta — feedback welcome: [email protected]