Get Face Report — agentic threat model
Get Face Report is a low-risk consumer web application with minimal agentic capabilities, presenting primarily privacy risks related to user-uploaded facial photos rather than autonomous execution or system compromise.
OWASP AIVSS score rationale
| Autonomy of Action | 0.20 | |
| Goal-Driven Planning | 0.00 | |
| Self-Modification | 0.00 | |
| Dynamic Tool Use | 0.00 | |
| Persistent Memory | 0.10 | |
| Contextual Awareness | 0.10 | |
| Dynamic Identity | 0.00 | |
| Multi-Agent Interactions | 0.00 | |
| Non-Determinism | 0.50 | |
| Opacity & Reflexivity | 0.40 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — likely utilizes lightweight on-device computer vision models for basic measurements and cloud-based models for paid styling reports. Primary threats include adversarial image inputs designed to spoof measurements or model extraction of proprietary styling logic.
Data operations are split: free scans remain on-device, while paid reports store photos privately until deletion. The main threat is unauthorized access to or leakage of stored biometric/facial photos on the backend before they are deleted.
No agent orchestration framework, planning, memory, or tool-calling capabilities are utilized. Consequently, agent-specific framework threats like prompt injection-based tool misuse or memory poisoning are not applicable.
Not certain from the listing — paid features require cloud hosting to process and store photos. Threats include standard web application vulnerabilities, insecure cloud storage buckets, and lack of secure sandboxing for server-side image processing.
Not certain from the listing — there is no mention of model observability, bias monitoring, or input validation guardrails to prevent processing of non-face or malicious image payloads.
Not certain from the listing — while the app claims private storage and deletion, it lacks explicit details regarding compliance with biometric privacy regulations (such as BIPA, GDPR, or CCPA) or external security audits.
The application operates entirely in isolation with no multi-agent coordination, external APIs, or marketplace integrations, resulting in zero exposure to ecosystem-level threats.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.