Skip to content
ai-supply.store
DiscoverCategoriesLeaderboardsCommunityAgent APIFAQ
Sign inSign up free
catalog / Agentic capability / Semantic Kernel
◆SkillAgentic capabilityFree

Semantic Kernel

Microsoft's open-source SDK for building AI agents and skills in C#, Python, and Java — composable, enterprise-ready, and model-agnostic.

@ai-supply
Installs89k
⟳ upstream dotnet-1.78.0 · updated 19d ago
↗ Source repository
← More Agentic capabilityAgentic capability leaderboard →How we grade security →Source ↗
✓ Grade A · 100/100 · SafeSecurity assessment
✓No compromise signals22capabilities surfaced6of 20 OWASP controls clear
Broad capability surfacePotentially unbounded loopSuspicious network referencesInternal host / private infrastructure reference
scanned 14d ago·osv · gitleaks · opengrep · picklescan + heuristics·full breakdown in the Security tab ↓

Semantic Kernel

Semantic Kernel is Microsoft's open-source SDK that lets developers build AI agents and integrate LLMs into any application. It provides a composable "skill" and "planner" model so you can wire up AI functions alongside native code functions and let the model plan which to call.

Key features

  • Multi-language — C#, Python, and Java SDKs with full feature parity
  • Plugin system — wrap any function (native or prompt-based) as a reusable AI plugin
  • Planner — automatic multi-step planning using function calling
  • Memory — built-in vector-store connectors for semantic search (Azure AI Search, Chroma, Pinecone, and more)
  • Model-agnostic — works with OpenAI, Azure OpenAI, Hugging Face, Ollama, and Anthropic
  • Enterprise integrations — Microsoft 365, Azure, and Teams connectors out of the box

Quick start (Python)

npx ai-supply add semantic-kernel-agent-sdk

# Or install directly
pip install semantic-kernel
import asyncio
from semantic_kernel import Kernel
from semantic_kernel.connectors.ai.open_ai import OpenAIChatCompletion

kernel = Kernel()
kernel.add_service(OpenAIChatCompletion(model_id="gpt-4o", api_key="..."))

summarize = kernel.add_function(
    function_name="summarize",
    plugin_name="text",
    prompt="Summarize the following text in one sentence: {{$input}}"
)

async def main():
    result = await kernel.invoke(summarize, input="Semantic Kernel is great.")
    print(result)

asyncio.run(main())

Curated mirror of the open-source Semantic Kernel project (MIT). Install upstream from the repository.

Rating rank
#1
of 35 in Agentic capability
Install rank
#21
of 35 in Agentic capability
Security score
100/100 · A
safe
Security rank
#1
of 35 in Agentic capability
Installs
89k
cat avg 186k
This listing vs category average
Installs
this
cat avg
Security (of 100)
this
cat avg
Adoption trend
See the Agentic capability leaderboard →
✓ Security: Safe · 100100/100 · grade Ascanned 14d ago
✓ no compromise signals22 risk-surface · 9/20 OWASP controls flagged

Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.

What this capability can do · high confidence (static)
Tools (1)
semantic_kernel.planning.invoke_plan.duration
⚑ networkinstall: script:microsoft-semantic-kernel-c781da1/python/Makefile
egress → www.microsoft.com, opensource.microsoft.com, docs.github.com, aka.ms, api.nuget.org, ollama.com, go.microsoft.com, learn.microsoft.com +32
skill: Bug report17 scripts

Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).

OWASP Top 10 for LLM Applications
⚠LLM01Prompt Injectionhigh
Adversarial instructions embedded in an artifact that hijack a downstream LLM.
•Prompt-injection phrasing — instruction-subversion language detected · microsoft-semantic-kernel-c781da1/docs/decisions/0040-chat-prompt-xml-support.md (CWE-77)expected
⚠LLM05Improper Output Handlinghigh
Code that pipes model/user output into shell, eval, SQL or paths unsafely.
•Suspicious code patterns — pipe-to-shell install · microsoft-semantic-kernel-c781da1/.github/workflows/python-integration-tests.yml (CWE-494)expected
⚠LLM06Excessive Agencyhigh
Over-broad tool/permission surface or unrestricted egress.
•External endpoints declared — 2 distinct host(s) · microsoft-semantic-kernel-c781da1/.editorconfigexpected
•External endpoints declared — 1 distinct host(s) · microsoft-semantic-kernel-c781da1/.github/ISSUE_TEMPLATE/feature_request.mdexpected
•Broad capability surface — 3 high-impact capability categories referenced — verify least-privilege · microsoft-semantic-kernel-c781da1/.github/workflows/devflow-pr-review.yml (CWE-272)risk surface
•External endpoints declared — 4 distinct host(s) · microsoft-semantic-kernel-c781da1/CONTRIBUTING.mdexpected
•External endpoints declared — 18 distinct host(s) · microsoft-semantic-kernel-c781da1/README.mdexpected
•External endpoints declared — 3 distinct host(s) · microsoft-semantic-kernel-c781da1/SECURITY.mdexpected
•External endpoints declared — 5 distinct host(s) · microsoft-semantic-kernel-c781da1/docs/FAQS.mdexpected
•External endpoints declared — 11 distinct host(s) · microsoft-semantic-kernel-c781da1/docs/decisions/0050-updated-vector-store-design.mdexpected
•External endpoints declared — 6 distinct host(s) · microsoft-semantic-kernel-c781da1/docs/decisions/0054-processes.mdexpected
•External endpoints declared — 7 distinct host(s) · microsoft-semantic-kernel-c781da1/docs/decisions/0059-text-search.mdexpected
•External endpoints declared — 16 distinct host(s) · microsoft-semantic-kernel-c781da1/docs/decisions/0067-hybrid-search.mdexpected
•External endpoints declared — 10 distinct host(s) · microsoft-semantic-kernel-c781da1/dotnet/notebooks/README.mdexpected
•Egress to a private/loopback host — 127.0.0.1 · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/A2AClientServer/README.md (CWE-918)expected
•External endpoints declared — 8 distinct host(s) · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/BookingRestaurant/README.mdexpected
•Broad capability surface — 4 high-impact capability categories referenced — verify least-privilege · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/CopilotAgentPlugins/README.md (CWE-272)risk surface
⚠LLM07System Prompt Leakagemedium
Secrets, internal hosts or proprietary logic exposed in shipped prompts.
•Internal host / private infrastructure reference — shipped content references a private IP range or internal-only host · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/A2AClientServer/README.md (CWE-200)risk surface
⚠LLM10Unbounded Consumptionmedium
Unbounded loops/recursion causing DoS or runaway cost.
Enforced at runtime by the gateway (rate limits + spend caps + size caps); static check flags unbounded loops.
•Potentially unbounded loop — an infinite loop (while True / while(1) / for(;;)) may cause runaway consumption · microsoft-semantic-kernel-c781da1/README.md (CWE-835)risk surface
⚠LLM03Supply Chainlow
Vulnerable/compromised dependencies, models or archives in the artifact.
•Dependency manifest — 1 npm dependencies declared · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/ProcessFrameworkWithSignalR/package.jsonrisk surface
•Dependency manifest — 23 npm dependencies declared · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend/package.jsonrisk surface
•Dependency manifest — 21 npm dependencies declared · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/ProcessWithCloudEvents/ProcessWithCloudEvents.Client/package.jsonrisk surface
•Dependency manifest — 8 pip requirements declared · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/QualityCheck/python-server/requirements.txtrisk surface
§LLM09MisinformationGovernance
Artifacts designed to produce false/deceptive output.
Detectable only by runtime behavioral evaluation; addressed via responsible-use attestation.
✓LLM02Sensitive Information DisclosurePassed
✓LLM04Data and Model PoisoningPassed
Backdoors/poisoning in training data or serialized models.
Behavioral poisoning needs model execution; static check covers unsafe serialization + dataset skew only.
✓LLM08Vector and Embedding WeaknessesPassed
PII or plaintext source leakage in embedding/vector exports.
Embedding inversion/poisoning is largely runtime; static check covers PII in vector exports.
OWASP Machine Learning Security Top 10
⚠ML02Data Poisoninghigh
Poisoned training datasets with triggers or anomalous distributions.
Static check covers trigger phrasing, PII and label skew; full poisoning detection is runtime.
•Prompt-injection phrasing — instruction-subversion language detected · microsoft-semantic-kernel-c781da1/docs/decisions/0040-chat-prompt-xml-support.md (CWE-77)expected
⚠ML09Output Integrityhigh
Middleware tampering with model outputs in transit.
Gateway enforces TLS + response integrity; static check flags output-rewriting code.
•Suspicious code patterns — pipe-to-shell install · microsoft-semantic-kernel-c781da1/.github/workflows/python-integration-tests.yml (CWE-494)expected
⚠ML06AI Supply Chainlow
Compromised PyPI/npm packages, typosquats, unsafe serialized models.
•Dependency manifest — 1 npm dependencies declared · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/ProcessFrameworkWithSignalR/package.jsonrisk surface
•Dependency manifest — 23 npm dependencies declared · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend/package.jsonrisk surface
•Dependency manifest — 21 npm dependencies declared · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/ProcessWithCloudEvents/ProcessWithCloudEvents.Client/package.jsonrisk surface
•Dependency manifest — 8 pip requirements declared · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/QualityCheck/python-server/requirements.txtrisk surface
§ML01Input Manipulation (Adversarial)Governance
Models vulnerable to adversarial perturbations.
Requires runtime robustness evaluation; addressed via publisher robustness attestation.
§ML03Model InversionGovernance
Training data reconstructable from a model's outputs.
Runtime/evaluation property; addressed via model-card data-provenance + DP attestation.
§ML04Membership InferenceGovernance
Determining whether a record was in the training set.
Runtime/evaluation property; addressed via overfitting disclosure + DP attestation.
§ML08Model SkewingGovernance
Models trained on skewed data producing biased output.
Requires fairness evaluation; addressed via model-card bias/limitations disclosure.
✓ML05Model TheftPassed
Unlicensed re-distribution / license-incompatible derivatives.
Static check verifies license declaration; extraction throttling is runtime.
✓ML07Transfer Learning AttackPassed
Backdoored base models / LoRA adapters propagating to derivatives.
Backdoor detection needs behavioral probing; static check covers unsafe serialization + provenance.
✓ML10Model Poisoning (Weights)Passed
Tampered model weight files; integrity must be verifiable.
Static check enforces safe formats + records a content hash for downstream verification.
Other findings (29) · hygiene / uncategorized
•Unrecognized file type — '.editorconfig' is not on the allowlist · microsoft-semantic-kernel-c781da1/.editorconfigrisk surface
•Unrecognized file type — '.gitattributes' is not on the allowlist · microsoft-semantic-kernel-c781da1/.gitattributesrisk surface
•Unrecognized file type — '.?' is not on the allowlist · microsoft-semantic-kernel-c781da1/.github/CODEOWNERSrisk surface
•Disallowed file type — '.ps1' executables are not permitted · microsoft-semantic-kernel-c781da1/.github/workflows/check-coverage.ps1 (CWE-434)risk surface
•Unrecognized file type — '.gitignore' is not on the allowlist · microsoft-semantic-kernel-c781da1/.gitignorerisk surface
•Unrecognized file type — '.mmd' is not on the allowlist · microsoft-semantic-kernel-c781da1/docs/decisions/diagrams/agent-abstractions.mmdrisk surface
•Unrecognized file type — '.props' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/Directory.Build.propsrisk surface
•Unrecognized file type — '.targets' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/Directory.Build.targetsrisk surface
•Unrecognized file type — '.slnx' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/MEVD.slnxrisk surface
•Unrecognized file type — '.dotsettings' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/SK-dotnet.slnx.DotSettingsrisk surface
•Unrecognized file type — '.ncrunchsolution' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/SK-dotnet.v3.ncrunchsolutionrisk surface
•Unrecognized file type — '.slnf' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/SK-release.slnfrisk surface
•Disallowed file type — '.cmd' executables are not permitted · microsoft-semantic-kernel-c781da1/dotnet/build.cmd (CWE-434)risk surface
•Unrecognized file type — '.cs' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/notebooks/config/Settings.csrisk surface
•Unrecognized file type — '.azure-example' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/notebooks/config/settings.json.azure-examplerisk surface
•Unrecognized file type — '.openai-example' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/notebooks/config/settings.json.openai-examplerisk surface
•Unrecognized file type — '.config' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/nuget.configrisk surface
•Unrecognized file type — '.csproj' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/samples/AgentFrameworkMigration/AgentOrchestrations/Step01_Concurrent/AgentOrchestrations_Step01_Concurrent.csprojrisk surface
•Unrecognized file type — '.handlebars' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/samples/Concepts/Resources/65-prompt-override.handlebarsrisk surface
•Unrecognized file type — '.bpe' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/samples/Concepts/Resources/EnglishRoberta/vocab.bperisk surface
•Unrecognized file type — '.http' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/A2AClientServer/A2AServer/A2AServer.httprisk surface
•Suspicious network references — raw IP URL (17 URLs) · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/A2AClientServer/README.mdrisk surface
•Unrecognized file type — '.razor' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/AgentFrameworkWithAspire/ChatWithAgent.Web/Components/App.razorrisk surface
•Unrecognized file type — '.sln' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/CopilotAgentPlugins/CopilotAgentPluginsDemoSample/CopilotAgentPluginsDemoSample.slnrisk surface
•Unrecognized file type — '.fsx' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/FSharpScripts/huggingFaceChatCompletion.fsxrisk surface
•Unrecognized file type — '.resx' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/HuggingFaceImageToText/FormMain.resxrisk surface
•Suspicious network references — raw IP URL (14 URLs) · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/ModelContextProtocolClientServer/README.mdrisk surface
•Unrecognized file type — '.proto' is not on the allowlist · microsoft-semantic-kernel-c781da1/dotnet/samples/Demos/ProcessWithCloudEvents/ProcessWithCloudEvents.Client/src/services/grpc/proto/documentGeneration.protorisk surface
•Suspicious network references — raw IP URL (2 URLs) · microsoft-semantic-kernel-c781da1/dotnet/src/Agents/UnitTests/A2A/BaseA2AClientTest.csrisk surface
✔ verified source · pinned microsoft-semantic-kernel-c781da1
Check against a policy

The same gate an agent runs before installing (POST /api/v1/trust/semantic-kernel-agent-sdk/check). Click a policy:

Consume Semantic Kernel programmatically. Authenticate with an API key or session — see Authorize an agent.

# Agents: CHECK BEFORE YOU INSTALL (no auth) — score, grade, level, capability manifest
curl https://ai-supply.store/api/v1/trust/semantic-kernel-agent-sdk

# Gate against your org policy (returns { pass, violations })
curl -X POST https://ai-supply.store/api/v1/trust/semantic-kernel-agent-sdk/check \
  -H "Content-Type: application/json" \
  -d '{"minGrade":"B","denyPermissions":["shell"],"denyUnknownEgress":true}'

# CLI
npx ai-supply add semantic-kernel-agent-sdk

# REST (install → download)
curl -X POST https://ai-supply.store/api/v1/listings/semantic-kernel-agent-sdk/install \
  -H "Authorization: Bearer $AIM_KEY"

# MCP tool
install_listing({ "slug": "semantic-kernel-agent-sdk" })
OpenAPI spec →
vlatest
✓ Security: Safe · 1001mo ago

Curated mirror — latest upstream source. See the repository for tagged releases.

Sign in and install this listing to leave a review.

More from @ai-supply

View profile →
◉Agent
MetaGPT
Multi-agent framework that assigns GPT roles (PM, engineer, QA) to solve complex software tasks end-to-end.
↓ 1.0M
⇄Connector
vLLM
High-throughput, memory-efficient LLM inference engine with PagedAttention and continuous batching.
↓ 892k
⇄Connector
Meilisearch
Lightning-fast open-source search engine with typo-tolerance, semantic hybrid search, and sub-50ms response times.
↓ 811k
△Eval
Weights & Biases (wandb)
ML experiment tracking and visualization — log metrics, hyperparameters, models, and media in real time.
↓ 784k
ai-supply.store

Free, security-vetted AI capabilities — skills, MCPs, plugins, agents, datasets and more, each graded and freshness-tracked, and built for humans and agents alike.

api · v3.1status · all green
Contact
support@ai-supply.storesecurity@ai-supply.store
Catalog
  • Discover
  • Categories
  • Leaderboards
  • Benchmarks
  • Security
  • Scan a repo
Community
  • Community
  • FAQ
For agents
  • Quickstart (60s)
  • Authorize an agent
  • Agent API
  • OpenAPI spec
For builders
  • Publish
  • Dashboard
Account
  • Create account
  • Sign in
  • Settings
Legal
  • Terms
  • Publisher Agreement
  • Acceptable Use
  • Privacy