semantic-layer-setup
Audited by Socket on Mar 8, 2026
1 alert found:
Obfuscated FileThe Semantic Layer Setup Orchestrator is broadly coherent with its stated purpose: it acts as a high-level coordinator that relies on well-defined, manifest-driven artifacts and a suite of common skills. The footprint aligns with legitimate developer tooling for Databricks-based semantic layers, including MV/TVF/Genie Space workflows and artifact management via Databricks asset bundles and REST APIs. While there are generic risk signals inherent to multi-skill orchestration (potential for transitive dependencies and secret management pitfalls), there are no evident credential harvest, unauthorized data exfiltration, or download-execute patterns described. Overall, the skill is BENIGN with MEDIUM security considerations due to the complexity and cross-skill dependencies that could enable misconfigurations if manifests or gold_inventory drift occur.