Neat! Although, I'm curious why the tool doesn't just run addr2line for you?
The leak report is being generated internally by malloc. It is then logged via utrace(2) when a process is traced through ktrace(1).
The kdump utility simply dumps the report, strvis(3) escaping any potentially unsafe characters. As this is untrusted user data, passing it as the input/args to another command is unwise. Also kdump(1) uses pledge(2) and cannot execute commands.
It's not that difficult to run addr2line yourself with the information provided, and that's really for the best.