AgentReadyHomeAgent ListingRuntimePricing

← Jev AI

Jev AI — agentic threat model

7.1AIVSS 7.1 · High

Jev AI serves as a decision-routing and safety-checking middleware; its primary risk is downstream compromise or safety-bypass if its classification and probability outputs are manipulated by adversarial inputs.

OWASP AIVSS score rationale

AIVSS = (CVSS_Base + AARS) × Mitigation_Factor, where AARS = (10 − CVSS_Base) × (Factor_Sum / 10) × ThM
CVSS base 7.5AARS uplift 0.35Factor sum 1.4/10Threat ×1.0Mitigation ×0.9
Autonomy of Action
0.10
Goal-Driven Planning
0.10
Self-Modification
0.00
Dynamic Tool Use
0.10
Persistent Memory
0.10
Contextual Awareness
0.30
Dynamic Identity
0.00
Multi-Agent Interactions
0.20
Non-Determinism
0.30
Opacity & Reflexivity
0.20

Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.

MAESTRO 7-layer threat model

Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.

L1 · Foundation Models⚠ not certain from listing

Not certain from the listing — Jev AI likely wraps existing foundation models or uses a proprietary lightweight model to generate typed decisions and probabilities, exposing it to prompt injection or adversarial state manipulation.

L2 · Data Operations⚠ not certain from listing

Not certain from the listing — The platform processes 'shared state' to make decisions, but details on how this state is stored, vectorized, or protected against data leakage are not provided.

L3 · Agent Frameworks✓ mapped

The platform provides SDKs and REST APIs to orchestrate agent workflows, routing, and classification, meaning vulnerabilities in the SDK or state-handling logic could lead to insecure workflow execution.

L4 · Deployment & Infrastructure⚠ not certain from listing

Not certain from the listing — Jev AI is deployed via an online playground, SDK, and REST API, but the underlying hosting environment, sandboxing of state evaluations, and API credential management are unspecified.

L5 · Evaluation & Observability✓ mapped

The platform natively supports 'safety checks' and outputs probabilities alongside typed decisions, providing built-in guardrails and a degree of mathematical observability for its classifications.

L6 · Security & Compliance (cross-cutting)⚠ not certain from listing

Not certain from the listing — While it offers 'safety checks' as a feature, there is no explicit mention of enterprise security compliance, RBAC, or audit logging for the developer platform.

L7 · Agent Ecosystem✓ mapped

Designed to support agent workflows and routing, a compromise in Jev AI's decision engine could cause cascading failures across all downstream agents relying on its classification and safety checks.

MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).

These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.