NYC

kafka-expert

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE] (SAFE): No malicious patterns or security risks were identified in the skill's instructions or code snippets. The code examples use standard Kafka libraries and connect to local instances.
  • [Indirect Prompt Injection] (LOW): The skill defines tools for reading and processing Kafka stream data. This represents a potential indirect prompt injection surface if the agent consumes data from untrusted external topics.
  • Ingestion points: KafkaConsumer logic in SKILL.md used to read from Kafka topics.
  • Boundary markers: None present in the provided code snippets.
  • Capability inventory: Bash, Write, Edit tools are permitted.
  • Sanitization: No explicit sanitization or validation of the message payload is shown in the examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:54 PM