Skills mirrord-kafka
๐Ÿ“ฆ

mirrord-kafka

v2.5 Content revision r1 High Risk โš™๏ธ External commands๐Ÿ“ Filesystem access

Configure Kafka Queue Splitting with mirrord

Kafka splitting requires matching Kubernetes resources, client authentication, and developer message filters. This skill guides configuration generation, compatibility checks, and troubleshooting for mirrord.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "mirrord-kafka" from https://skillstore.io/skills/metalbear-co-mirrord-kafka.md and its manifest at https://skillstore.io/api/skills/metalbear-co-mirrord-kafka/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "mirrord-kafka". Our Kafka Streams workload needs splitting and a payload filter.

Expected outcome:

  • Kafka Streams requires the Java client, a Streams application identifier, and the Kafka sidecar.
  • Payload filtering with jq_filter is unavailable for the Java client.
  • Use supported header filters and confirm the required operator settings before deployment.

Using "mirrord-kafka". A non-Streams KafkaJS consumer fails with INCONSISTENT_GROUP_PROTOCOL.

Expected outcome:

  • The documented cause is a custom partition-assignment protocol incompatible with the operator consumer.
  • For operator 3.195.0 or later, review the temporary consumer-group option.
  • Confirm rollout completion; operator 3.204.0 or later supports increasing the group-join timeout.

Using "mirrord-kafka". Our managed Kafka platform rejects temporary topics with PolicyViolation.

Expected outcome:

  • Check the platform minimum replication factor against the temporary-topic configuration.
  • Operator 3.191.0 or later supports copying the source replication factor or setting an explicit value.
  • Review the proposed configuration before applying it.

Security Audit

High Risk
v1 โ€ข 9/29/2026 Open versioned report

Most alerts are false positives involving Markdown backticks, TLS property names, or read-only discovery. Four alerts identify credential exposure through command arguments or unencrypted key exports; unfiltered workload inspection adds a separate disclosure risk. No evidence found of malicious exfiltration or prompt injection.

6
Files scanned
1,165
Lines analyzed
1
Review items
0
False positives ignored

Confirmed security concerns (4)

High
Certificate/key files
openssl pkcs12 -in keystore.p12 -nocerts -nodes -out client-key.pem
The -nodes option exports an unencrypted private key to client-key.pem without specifying restrictive permissions. This creates an avoidable credential exposure risk.
High
Certificate/key files
openssl pkcs12 -in keystore.p12 -nocerts -nodes -out client-key.pem
The command uses -nodes to write an unencrypted private key without restrictive permission guidance. This unnecessarily exposes sensitive key material on disk.
High
Java keystore files
--from-literal=keystore.jks.base64="$(base64 < keystore.jks | tr -d '\n')" \
The private keystore is expanded into --from-literal, exposing credential-bearing bytes in process arguments. The same example also puts the store password in arguments.
Medium
Unfiltered Workload Inspection Can Expose Inline Secrets
The workflow requests complete deployment YAML to discover container names and environment variables. Inline passwords or tokens can enter agent context without filtering or redaction.
The command explicitly requests full YAML, including literal environment values. Exposure depends on workload contents, but no output filtering is specified.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Shell command substitution
--from-literal=keystore.jks.base64="$(base64 < keystore.jks | tr -d '\n')" \
The substitution puts the private keystore into kubectl command arguments through --from-literal. Process inspection or execution logging can capture this credential-bearing data.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/metalbear-co-mirrord-kafka/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/metalbear-co-mirrord-kafka/security.svg)](https://skillstore.io/skills/metalbear-co-mirrord-kafka?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/metalbear-co-mirrord-kafka?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/metalbear-co-mirrord-kafka/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/metalbear-co-mirrord-kafka.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

metalbear-co. (2026). mirrord-kafka security audit report (audit version 1) [Author version 2.5]. Skillstore. https://skillstore.io/skills/metalbear-co-mirrord-kafka/audits/1

BibTeX citation

@techreport{metalbear-co-metalbear-co-mirrord-kafka-2026, author = {metalbear-co}, title = {mirrord-kafka security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/metalbear-co-mirrord-kafka/audits/1}, note = {Author version 2.5} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "mirrord-kafka security audit report (audit version 1)" version: "2.5" type: report authors: - name: "metalbear-co" date-released: "2026-09-29" url: "https://skillstore.io/skills/metalbear-co-mirrord-kafka/audits/1" identifiers: - type: other value: "skillstore:metalbear-co-mirrord-kafka:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Prepare a Team Kafka Connection

Generate namespace-specific connection and split resources with Secret references and the required Helm settings.

Debug Selected Consumer Messages

Draft header or payload filters that route relevant Kafka messages to a local application.

Diagnose Failed Splitting Sessions

Compare redacted errors and installed versions against documented protocol, replication, and rollout constraints.

Try These Prompts

Check Setup Requirements
Explain the prerequisites for mirrord Kafka splitting. Ask for versions and nonsecret workload details. Do not inspect my cluster or request credentials.
Draft a Standard Consumer Setup
Draft Kafka splitting resources for [deployment] in [namespace], using [broker], [topic environment variable], and [group environment variable]. Reference [Secret name] without reading its values. Include Helm guidance and matching mirrord configuration; do not apply changes.
Design Payload Filters
Design filters for [queue ID] using this redacted payload example: [sample]. Check [operator version], [CLI version], and [client backend]. Explain JSON or raw protobuf options, filter errors, and mirror versus steal behavior.
Review Migration and Failure Recovery
Review these redacted legacy resources and logs: [inputs]. Plan migration to current resources for [versions]. Check namespace lookup, authentication references, replication policies, and rollout timeouts. Provide validation and recovery steps without reading secrets or changing the cluster.

Best Practices

  • Confirm operator and CLI versions, namespace ownership, and Kafka client compatibility before generating resources.
  • Use Secret references and owner-only credential files; avoid command-line credential values and unprotected private-key exports.
  • Review generated changes and redact workload output before sharing it with an agent.

Avoid

  • Pasting passwords, private keys, or unredacted workload YAML into prompts.
  • Using jq_filter with Kafka Streams or assuming protobuf schema-registry framing is supported.
  • Setting group.id manually or defining both groupId and appId for one queue.

Frequently Asked Questions

Which AI tools can use this skill?
The marketplace lists Claude, Codex, and Claude Code. Cluster inspection also requires an available kubectl installation and appropriate access.
Which mirrord versions support the current resources?
The references require operator 3.170.0 or later and CLI 3.221.0 or later. Individual features require newer versions.
Does Kafka splitting require a paid plan?
The skill identifies Kafka splitting as a Team or Enterprise feature. Confirm licensing before configuring the operator.
Can I filter Kafka messages by their contents?
Yes, jq_filter supports content filtering with librdkafka. It requires operator 3.183.0 or later and CLI 3.232.0 or later.
Should I provide Kafka credentials to the agent?
No. Provide Secret names and property keys only. The audit flags unsafe reference examples that need correction before use.
Can this skill help migrate deprecated resources?
Yes. The references map legacy client and consumer resources to MirrordPropertyList and MirrordSplitConfig, including namespace and authentication changes.

Developer Details

License

MIT

Author version

v2.5

Skillstore revision

r1

Version notice

The author-declared version is not valid SemVer.

Ref

bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2

Maintenance freshness

9/30/2026

Usage

0 downloads ยท 0 views

More from metalbear-co

View all
View all