AgentReadyHomeAgent ListingRuntimePricing

← ChatGPT Free Online

ChatGPT Free Online — agentic threat model

7.9AIVSS 7.9 · High

ChatGPT Free Online presents a moderate-to-high risk profile due to its combination of code execution, web search, and lack of registration barriers, which can be exploited for automated abuse, though its lack of persistent state or deep system integration limits systemic damage.

OWASP AIVSS score rationale

AIVSS = (CVSS_Base + AARS) × Mitigation_Factor, where AARS = (10 − CVSS_Base) × (Factor_Sum / 10) × ThM
CVSS base 7.3AARS uplift 1.05Factor sum 3.7/10Threat ×1.05Mitigation ×0.95
Autonomy of Action
0.30
Goal-Driven Planning
0.40
Self-Modification
0.10
Dynamic Tool Use
0.60
Persistent Memory
0.10
Contextual Awareness
0.50
Dynamic Identity
0.10
Multi-Agent Interactions
0.10
Non-Determinism
0.80
Opacity & Reflexivity
0.70

Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.

MAESTRO 7-layer threat model

Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.

L1 · Foundation Models✓ mapped

Utilizes a GPT-5 class foundation model capable of multimodal generation (text and images) and reasoning. Highly susceptible to prompt injection, jailbreaking, and adversarial manipulation to bypass safety filters.

L2 · Data Operations⚠ not certain from listing

Not certain from the listing — likely relies on real-time web search scraping and internal model knowledge. Lacks explicit details on vector database usage, RAG pipelines, or user data retention policies for this no-registration tier.

L3 · Agent Frameworks✓ mapped

Features tool integration for web search, image generation, and code interpretation. Insecure tool execution or prompt injection could lead to SSRF via web search or malicious code execution within the interpreter environment.

L4 · Deployment & Infrastructure⚠ not certain from listing

Not certain from the listing — requires robust sandboxing for the code interpreter to prevent container escape, privilege escalation, or resource exhaustion, but the hosting infrastructure details are not disclosed.

L5 · Evaluation & Observability⚠ not certain from listing

Not certain from the listing — likely employs standard input/output guardrails and rate limiting, but specific observability, logging, and abuse-detection mechanisms for anonymous users are not detailed.

L6 · Security & Compliance (cross-cutting)✓ mapped

The service is offered with 'no-registration' and 'zero cost', which severely limits identity verification, user auditing, and access control, increasing the risk of automated exploitation and compliance violations.

L7 · Agent Ecosystem✓ mapped

Operates primarily as a single-agent assistant. There is no evidence of multi-agent orchestration, marketplace integrations, or autonomous agent-to-agent communication in this public offering.

MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).

These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.