dotnet-semantic-kernel

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is a coherent, purpose-aligned guide for building Semantic Kernel-based .NET applications with plugins, prompts, memory, vector stores, and agent-based orchestration. Its footprint is proportional to its stated goal and relies on official package ecosystems and environment/config-based credentials. Security risks are modest and primarily relate to data touching external AI/vector store services and proper handling of credentials/logging. No evident malicious data flows or credential exfiltration patterns are described. Overall, this appears BENIGN with MEDIUM securityRisk due to data-in-transit to external services and potential logging exposure. Implementers should enforce minimal data exposure in logs, use secure configuration, and review data governance for embeddings and prompts.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 03:45 PM
Package URL
pkg:socket/skills-sh/wshaddix%2Fdotnet-skills%2Fdotnet-semantic-kernel%2F@6457ef7cb86c1c27defc3bdbe515fdfcd6b708b4