I’m not aware of any future plans. However both are available on github (KPL, KCL) and are open source(ish) under the Amazon Software License. I say “ish” because of some concerns about section 3.3, limits of use. So you could port the code to .NET. In addition, there is support for running the KCL with other languages (Ruby, .NET, etc) but you still need to run a Java daemon.
Can someone create an IAM group with more permissions than the group they are in?
Yes, if the IAM system is misconfigured. If a user is in group A which has the attach group policy permission, and has no other limits, they can attach an arbitrary policy to group B. As per of the AWS shared responsibility model, you are responsible for your IAM setup.