Distinguishing proven mismatches from unknowns is the design decision that makes a tool like this usable. Most cross-repo analysers collapse "I checked and these disagree" with "I could not resolve this", and the second category is large in any real Spring codebase: runtime-resolved topics, config-driven URLs, DTOs built reflectively. Reporting those as findings trains people to ignore the output within a week.
Kafka is the harder half of what you are modelling. An HTTP contract at least has a caller that names the endpoint, while a topic has producers and consumers that never reference each other in code, so the only evidence is configuration plus a serialised shape. Keeping the evidence attached to the finding is what makes that reviewable instead of a guess.