AgentReadyHomeAgent Listing

← LunaAI

LunaAI — agentic threat model

9.2AIVSS 9.2 · Critical

LunaAI presents a high agentic risk profile due to its direct integration with enterprise CRMs and its capability to autonomously generate and send emails, which could be leveraged for automated phishing, spamming, or unauthorized data exfiltration if compromised.

OWASP AIVSS score rationale

AIVSS = (CVSS_Base + AARS) × Mitigation_Factor, where AARS = (10 − CVSS_Base) × (Factor_Sum / 10) × ThM
CVSS base 8.2AARS uplift 1.0Factor sum 5.3/10Threat ×1.05Mitigation ×1.0
Autonomy of Action
0.80
Goal-Driven Planning
0.70
Self-Modification
0.10
Dynamic Tool Use
0.70
Persistent Memory
0.60
Contextual Awareness
0.80
Dynamic Identity
0.40
Multi-Agent Interactions
0.10
Non-Determinism
0.60
Opacity & Reflexivity
0.50

Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.

MAESTRO 7-layer threat model

Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.

L1 · Foundation Models⚠ not certain from listing

Not certain from the listing — The specific LLMs used for generating personalized sales emails and analyzing lead data are not disclosed. Risks include prompt injection leading to inappropriate or malicious email generation, and potential model alignment drift.

L2 · Data Operations✓ mapped

LunaAI utilizes a massive 275+ million contact database and gathers real-time internet information to enrich leads. This presents significant risks regarding data privacy, compliance (GDPR/CCPA), data lineage, and potential ingestion of poisoned or malicious web data during internet scraping.

L3 · Agent Frameworks⚠ not certain from listing

Not certain from the listing — The underlying orchestration framework is proprietary. However, the agent executes multi-step workflows (lead search, personalization, automated follow-up sequences). Risks include insecure tool integration with CRMs and potential manipulation of the follow-up logic via prompt injection.

L4 · Deployment & Infrastructure⚠ not certain from listing

Not certain from the listing — As a closed-source, paid SaaS platform, the hosting environment, sandboxing of web-scraping tools, and secrets management for CRM API keys are not detailed. Compromise of this layer could expose sensitive CRM credentials.

L5 · Evaluation & Observability⚠ not certain from listing

Not certain from the listing — There is no mention of guardrails, content filtering for generated emails, or anomaly detection to prevent automated spamming or brand damage if the AI hallucinates or is manipulated.

L6 · Security & Compliance (cross-cutting)⚠ not certain from listing

Not certain from the listing — While the platform integrates with major CRMs (Salesforce, HubSpot, Pipedrive) implying OAuth or API key usage, no specific compliance certifications (e.g., SOC2, ISO 27001) or fine-grained access controls are detailed in the directory listing.

L7 · Agent Ecosystem⚠ not certain from listing

Not certain from the listing — The agent operates primarily as a standalone sales automation tool interacting with external APIs (CRMs, email servers) rather than a multi-agent marketplace, but it acts as an autonomous representative of the user's brand, risking cascading reputation damage.

MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).