Humains — agentic threat model
Humains exhibits high agentic risk due to its high autonomy in executing financial transactions (collecting payments) and initiating direct customer outreach without human supervision. While its built-in observability features provide visibility, the lack of explicit security and compliance guardrails for payment handling presents a significant threat surface.
OWASP AIVSS score rationale
| Autonomy of Action | 0.90 | |
| Goal-Driven Planning | 0.80 | |
| Self-Modification | 0.20 | |
| Dynamic Tool Use | 0.80 | |
| Persistent Memory | 0.60 | |
| Contextual Awareness | 0.70 | |
| Dynamic Identity | 0.40 | |
| Multi-Agent Interactions | 0.30 | |
| Non-Determinism | 0.80 | |
| Opacity & Reflexivity | 0.50 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — The 'brain-inspired cognitive architecture' likely sits on top of commercial or proprietary LLMs. Threats include prompt injection leading to unauthorized payment triggers or social engineering of customers.
Not certain from the listing — The agent must access customer data, product catalogs, and payment processing states. Threats include data exfiltration of customer PII or poisoning of the sales context.
The agent uses a proprietary cognitive architecture to autonomously plan and execute goals (sales, payments). Threats include tool misuse (unauthorized payment collection API calls) and goal hijacking.
Not certain from the listing — Likely hosted as a SaaS with API integrations. Threats include API key exposure (payment gateways, CRM) and container compromise.
The listing highlights 'Full visibility into every agent interaction and decision' and 'Real-time performance tracking'. This mitigates some observability blind spots, but risks of evaluation gaming or bypass of guardrails during live voice/chat remain.
Not certain from the listing — No explicit compliance standards (PCI-DSS for payments, SOC2, GDPR) are mentioned despite handling payments and customer interactions.
The agent scales across multiple communication channels and interacts with external APIs (payment, CRM). Threats include cascading failures if payment APIs or communication channels are compromised.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).