kafka-python-client
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documentation includes a recommendation to install the
uvpackage manager using a piped shell command:curl -LsSf https://astral.sh/uv/install.sh | sh. This refers to the official installation method for a well-known developer tool from Astral (astral.sh). - [EXTERNAL_DOWNLOADS]: The skill references the official
uvinstaller and author-provided Docker Compose files fromlenses.iofor environment setup in the evaluation suite. These resources originate from well-known or vendor-owned domains. - [INDIRECT_PROMPT_INJECTION]: The skill workflow ingests topic metadata and JSON schemas from external Kafka MCP servers. While this introduces an untrusted data surface, the risk is mitigated by a mandatory "Hard Gate" confirmation step (Step 2) where the agent must recap discovered values and wait for user approval before writing project files or running tests.
Audit Metadata