call-deployed-crew

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a system where user-provided inputs from the POST /kickoff endpoint are interpolated into LLM prompts using {placeholder} tokens.
  • Ingestion points: Data enters via the inputs dictionary in the POST /kickoff request body (SKILL.md, references/api-contract.md).
  • Boundary markers: The skill documentation notes that CrewAI uses curly braces for interpolation and warns that literal braces in prompts (e.g., JSON samples) can be misidentified as input placeholders (SKILL.md, Section 2).
  • Capability inventory: The skill facilitates the execution of AI agents and tasks which may involve LLM calls and tool execution (SKILL.md, Section 8).
  • Sanitization: The skill recommends validating input keys against the GET /inputs endpoint before kickoff and notes that input values are stringified using str() before interpolation (SKILL.md, Section 2).
  • [EXTERNAL_DOWNLOADS]: The skill reference implementation depends on standard, well-known libraries and tools.
  • Evidence: The Python client requires httpx, and the documentation mentions crewai and jq for the bash implementation (references/python-client.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 08:33 PM