dotnet-semantic-kernel
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe skill is a coherent, purpose-aligned guide for building Semantic Kernel-based .NET applications with plugins, prompts, memory, vector stores, and agent-based orchestration. Its footprint is proportional to its stated goal and relies on official package ecosystems and environment/config-based credentials. Security risks are modest and primarily relate to data touching external AI/vector store services and proper handling of credentials/logging. No evident malicious data flows or credential exfiltration patterns are described. Overall, this appears BENIGN with MEDIUM securityRisk due to data-in-transit to external services and potential logging exposure. Implementers should enforce minimal data exposure in logs, use secure configuration, and review data governance for embeddings and prompts.