kafka-python-client

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill documentation includes a recommendation to install the uv package manager using a piped shell command: curl -LsSf https://astral.sh/uv/install.sh | sh. This refers to the official installation method for a well-known developer tool from Astral (astral.sh).
  • [EXTERNAL_DOWNLOADS]: The skill references the official uv installer and author-provided Docker Compose files from lenses.io for environment setup in the evaluation suite. These resources originate from well-known or vendor-owned domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill workflow ingests topic metadata and JSON schemas from external Kafka MCP servers. While this introduces an untrusted data surface, the risk is mitigated by a mandatory "Hard Gate" confirmation step (Step 2) where the agent must recap discovered values and wait for user approval before writing project files or running tests.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:45 PM
Security Audit — agent-trust-hub — kafka-python-client