Findings by source

Microsoft

Code · GitHub (demo) Microsoft · Assistant · package: Microsoft.SemanticKernel

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
31
Medium
People
0
Committers are not collected
Repositories
1
0 public · 1 package
Keys in code
0
None found in the files read
source-codefixture
Next steps

Recommended actions

  1. 01Microsoft SDKs appear in 1 repository. Decide whether this vendor is approved for engineering, and route calls through one gateway or an Azure OpenAI deployment so keys, logging, and data terms are managed centrally.
GitHub (demo) · fixture

Where it lives in code

SDK packages · 1
Repositories
RepositorySignalsPushed
contoso/helpdesk-botSDK packages6 d ago
Packages
Microsoft.SemanticKernel nuget1 repo
Who

People

Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.

No people are linked to this app.

Why

Evidence

  1. source_code · Sep 8, 2026
    Microsoft in 1 repository via GitHub (demo): packages Microsoft.SemanticKernel
    Detail
    {
      "repos": [
        "contoso/helpdesk-bot"
      ],
      "configs": [],
      "packages": [
        {
          "name": "Microsoft.SemanticKernel",
          "repos": 1,
          "ecosystem": "nuget"
        }
      ],
      "endpoints": []
    }