kafka-schema-registry
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to perform local static analysis of project files. It identifies Kafka dependencies, producers, and consumers to provide data governance recommendations and automated schema extraction.
- [EXTERNAL_DOWNLOADS]: All external references, including package names (e.g., 'io.confluent', 'confluent-kafka') and the Terraform provider ('confluentinc/confluent'), target well-known and trusted technology ecosystems. These are standard dependencies for the Kafka/Confluent platform and do not involve untrusted remote code execution.
- [DATA_EXFILTRATION]: No unauthorized network operations or data transmission patterns were found. The skill extracts PII for local tagging and report generation as part of its documented functionality. Access to sensitive data (PII) is handled through static analysis and metadata tagging without external transmission.
- [PROMPT_INJECTION]: The instructions do not contain any patterns used to override agent safety protocols, extract system prompts, or hijack model behavior.
- [COMMAND_EXECUTION]: The workflow relies on standard file system tools (Read, Write, Grep, Glob) for analysis and does not involve the execution of arbitrary shell scripts, subprocesses, or untrusted binary code.
Audit Metadata