Consensus — agentic threat model
Consensus is a low-risk, retrieval-focused research assistant whose primary threat vector is the manipulation of scientific search results (data poisoning) rather than autonomous execution or system compromise.
OWASP AIVSS score rationale
| Autonomy of Action | 0.20 | |
| Goal-Driven Planning | 0.30 | |
| Self-Modification | 0.00 | |
| Dynamic Tool Use | 0.20 | |
| Persistent Memory | 0.20 | |
| Contextual Awareness | 0.40 | |
| Dynamic Identity | 0.00 | |
| Multi-Agent Interactions | 0.00 | |
| Non-Determinism | 0.50 | |
| Opacity & Reflexivity | 0.40 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — likely relies on commercial LLMs for synthesis. Vulnerable to prompt injection that could distort scientific summaries or bypass safety guardrails.
Highly critical layer containing over 200 million scientific papers. Vulnerable to data poisoning (e.g., injecting fraudulent or predatory journal articles into the index) and licensing/copyright compliance issues.
Not certain from the listing — utilizes a search-and-synthesize orchestration framework. Vulnerable to insecure tool integration between the LLM and the vector database/search index.
Not certain from the listing — likely hosted on standard cloud infrastructure. Vulnerable to unauthorized access to the proprietary search index or vector database hosting.
Not certain from the listing — requires robust evaluation to prevent hallucinated scientific claims. Vulnerable to drift in summarization quality and lack of automated detection for adversarial search queries.
Not certain from the listing — requires standard web application security and data privacy compliance. Vulnerable to API abuse and unauthorized scraping of the proprietary paper index.
Not certain from the listing — mentions integration with existing systems but lacks a complex multi-agent ecosystem. Vulnerable to downstream data integrity issues if integrated into external workflows.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).