Call out which CrewAI security primitives apply to agent.kickoff()
versus Crew/Flow paths, and fix the execution-boundary wording so it
does not imply INPUT hooks run on standalone kickoffs.
Co-authored-by: Rip&Tear <theCyberTech@users.noreply.github.com>