AgentReadyHomeAgent ListingRuntimePricing

← CallingYouNow

CallingYouNow — agentic threat model

8.2AIVSS 8.2 · High

CallingYouNow acts as a public-facing voice agent handling sensitive customer interactions across regulated industries like healthcare and law. Its primary risks stem from voice-based prompt injection, unauthorized call routing, and the handling of sensitive PII/PHI without explicit security or compliance guarantees.

OWASP AIVSS score rationale

AIVSS = (CVSS_Base + AARS) × Mitigation_Factor, where AARS = (10 − CVSS_Base) × (Factor_Sum / 10) × ThM
CVSS base 7.5AARS uplift 0.66Factor sum 2.5/10Threat ×1.05Mitigation ×1.0
Autonomy of Action
0.40
Goal-Driven Planning
0.20
Self-Modification
0.00
Dynamic Tool Use
0.30
Persistent Memory
0.20
Contextual Awareness
0.30
Dynamic Identity
0.10
Multi-Agent Interactions
0.00
Non-Determinism
0.40
Opacity & Reflexivity
0.60

Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.

MAESTRO 7-layer threat model

Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.

L1 · Foundation Models⚠ not certain from listing

Not certain from the listing — likely relies on commercial speech-to-text, LLM, and text-to-speech pipelines. It is highly vulnerable to voice-based prompt injection (vishing injections) where callers manipulate the underlying LLM to bypass business rules.

L2 · Data Operations⚠ not certain from listing

Not certain from the listing — captures call information and likely syncs with business databases or CRMs. This introduces risks of data exfiltration of caller PII/PHI and database poisoning if malicious inputs are transcribed and saved without sanitization.

L3 · Agent Frameworks⚠ not certain from listing

Not certain from the listing — orchestrates call routing and appointment booking tools. Vulnerable to tool misuse if conversational manipulation allows callers to trigger unauthorized API calls, such as booking fake appointments or routing calls to premium/external numbers.

L4 · Deployment & Infrastructure⚠ not certain from listing

Not certain from the listing — integrates telephony infrastructure (VoIP/SIP) with LLM APIs. Vulnerable to SIP toll fraud, denial of service via call flooding, and insecure webhook integrations connecting the voice platform to business backends.

L5 · Evaluation & Observability⚠ not certain from listing

Not certain from the listing — requires robust call logging, transcription auditing, and real-time guardrails. Without active monitoring, the agent could hallucinate business policies, leak internal prompts, or make unauthorized commitments to callers.

L6 · Security & Compliance (cross-cutting)⚠ not certain from listing

Not certain from the listing — serves highly regulated sectors including healthcare (HIPAA) and law firms. The lack of explicit compliance certifications or data-handling policies poses severe regulatory and privacy risks for businesses deploying it.

L7 · Agent Ecosystem⚠ not certain from listing

Not certain from the listing — interacts with external scheduling platforms and CRM ecosystems. A compromise in these downstream integrations could lead to cascading data exposure or unauthorized access to the agent's telephony capabilities.

MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).

These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.