call-deployed-crew
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes a system where user-provided inputs from the
POST /kickoffendpoint are interpolated into LLM prompts using{placeholder}tokens. - Ingestion points: Data enters via the
inputsdictionary in thePOST /kickoffrequest body (SKILL.md, references/api-contract.md). - Boundary markers: The skill documentation notes that CrewAI uses curly braces for interpolation and warns that literal braces in prompts (e.g., JSON samples) can be misidentified as input placeholders (SKILL.md, Section 2).
- Capability inventory: The skill facilitates the execution of AI agents and tasks which may involve LLM calls and tool execution (SKILL.md, Section 8).
- Sanitization: The skill recommends validating input keys against the
GET /inputsendpoint before kickoff and notes that input values are stringified usingstr()before interpolation (SKILL.md, Section 2). - [EXTERNAL_DOWNLOADS]: The skill reference implementation depends on standard, well-known libraries and tools.
- Evidence: The Python client requires
httpx, and the documentation mentionscrewaiandjqfor the bash implementation (references/python-client.md).
Audit Metadata