AgentReadyHomeAgent ListingRuntimePricing

← LeadCanvas

LeadCanvas — agentic threat model

7.3AIVSS 7.3 · High

LeadCanvas presents a moderate agentic risk profile, primarily driven by its automated data scraping capabilities, CRM integration, and AI-driven personalized outreach generation, though it operates with a human-in-the-loop for final message delivery.

OWASP AIVSS score rationale

AIVSS = (CVSS_Base + AARS) × Mitigation_Factor, where AARS = (10 − CVSS_Base) × (Factor_Sum / 10) × ThM
CVSS base 6.3AARS uplift 1.41Factor sum 3.8/10Threat ×1.0Mitigation ×0.95
Autonomy of Action
0.40
Goal-Driven Planning
0.30
Self-Modification
0.10
Dynamic Tool Use
0.50
Persistent Memory
0.60
Contextual Awareness
0.70
Dynamic Identity
0.20
Multi-Agent Interactions
0.10
Non-Determinism
0.50
Opacity & Reflexivity
0.40

Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.

MAESTRO 7-layer threat model

Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.

L1 · Foundation Models⚠ not certain from listing

Not certain from the listing — The specific foundation models used for generating personalized outreach messages and scoring leads are not disclosed. Standard LLM risks like prompt injection could lead to the generation of malicious, deceptive, or highly inappropriate outreach messages.

L2 · Data Operations✓ mapped

The agent performs extensive data operations, scraping Google Maps and LinkedIn, and processing business intelligence signals (SEO, PageSpeed, ads). Risks include data poisoning of the lead database or CRM via malicious profiles, and potential privacy violations regarding scraped contact data.

L3 · Agent Frameworks✓ mapped

The orchestration framework manages a pipeline of finding, qualifying, and drafting outreach. Insecure tool integration is a risk if the scraping tools or CRM APIs can be manipulated via injection attacks embedded in target business profiles.

L4 · Deployment & Infrastructure⚠ not certain from listing

Not certain from the listing — The hosting environment, sandboxing of scraping processes, and storage of CRM data are not described. Insecure storage of API keys for Google Maps, LinkedIn, or LLM providers represents a critical infrastructure threat.

L5 · Evaluation & Observability⚠ not certain from listing

Not certain from the listing — There is no mention of observability, guardrails, or logging mechanisms to detect if the AI is generating biased, toxic, or highly inaccurate outreach drafts or opportunity scores.

L6 · Security & Compliance (cross-cutting)⚠ not certain from listing

Not certain from the listing — Compliance controls regarding GDPR/LOPD for scraping personal data (emails, phone numbers) in Spain/LATAM are not specified, nor are user authentication and authorization policies within the CRM.

L7 · Agent Ecosystem✓ mapped

The agent operates primarily as a single-user horizontal SaaS tool. Ecosystem risks are low, though automated outreach could interact negatively with external communication platforms (WhatsApp, email servers) leading to spam flagging or account suspension.

MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).

These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.