Bohrium — agentic threat model
Bohrium acts as an AI-powered scientific research navigator, presenting moderate risk primarily centered around intellectual property theft, scientific data poisoning, and unauthorized consumption of high-performance computing infrastructure.
OWASP AIVSS score rationale
| Autonomy of Action | 0.30 | |
| Goal-Driven Planning | 0.40 | |
| Self-Modification | 0.10 | |
| Dynamic Tool Use | 0.50 | |
| Persistent Memory | 0.30 | |
| Contextual Awareness | 0.60 | |
| Dynamic Identity | 0.10 | |
| Multi-Agent Interactions | 0.20 | |
| Non-Determinism | 0.50 | |
| Opacity & Reflexivity | 0.60 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Utilizes proprietary scientific LLMs co-developed with AISI. Primary threats include adversarial prompt injection designed to extract proprietary model weights or generate misaligned/hallucinated scientific outputs.
Integrates massive scientific datasets. Highly vulnerable to data poisoning of scientific knowledge bases, which could corrupt research outcomes, and unauthorized data exfiltration of sensitive or proprietary research data.
Not certain from the listing — the 'Science Navigator' orchestrates research tasks, but specific details regarding its agentic framework, tool-calling safety, or memory-poisoning protections are not provided.
Not certain from the listing — mentions integration with 'intelligent computing infrastructure', but does not detail the security of the hosting environment, container sandboxing, or protection against resource abuse.
Not certain from the listing — no details are provided regarding real-time monitoring, scientific output validation, guardrails, or logging of user and agent interactions.
Not certain from the listing — compliance standards, data privacy policies, and access control mechanisms for global scientific collaboration are not specified.
Not certain from the listing — while designed as a collaborative platform for global researchers, there is no explicit mention of multi-agent orchestration or third-party agent marketplace risks.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).