RAADS-R Test — agentic threat model
The RAADS-R Test agent presents a very low agentic risk profile due to its lack of external tools, system access, or autonomous decision-making. The primary risks are data privacy regarding sensitive self-assessment responses and the potential for prompt injection to generate misleading medical advice.
OWASP AIVSS score rationale
| Autonomy of Action | 0.20 | |
| Goal-Driven Planning | 0.00 | |
| Self-Modification | 0.00 | |
| Dynamic Tool Use | 0.00 | |
| Persistent Memory | 0.00 | |
| Contextual Awareness | 0.70 | |
| Dynamic Identity | 0.00 | |
| Multi-Agent Interactions | 0.00 | |
| Non-Determinism | 0.70 | |
| Opacity & Reflexivity | 0.00 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — likely relies on a standard commercial foundation model to handle multilingual interaction and explain score ranges. The main threat is prompt injection that could bypass the disclaimer and force the model to provide definitive medical diagnoses or harmful psychological advice.
Not certain from the listing — likely stores the 80 RAADS-R questions statically within the application code or prompt context rather than using a vector database. The primary threat is the potential logging or exposure of sensitive user questionnaire responses.
Not certain from the listing — likely uses a basic web-based chatbot framework rather than a complex agentic orchestration framework. Threats include session state manipulation or calculation bypasses in the questionnaire logic.
Not certain from the listing — likely hosted on standard cloud web infrastructure. Threats include typical web vulnerabilities such as Cross-Site Scripting (XSS) or insecure transport of user responses.
Not certain from the listing — no evaluation, guardrail, or observability mechanisms are mentioned. There is a risk of undetected drift if the model's tone becomes overly clinical or diagnostic over time.
The agent incorporates a clear compliance boundary by explicitly stating it does not diagnose users or make medical decisions. However, because it collects sensitive neurodivergence screening data, it lacks explicit assurances regarding health data privacy standards (e.g., HIPAA or GDPR compliance for health-related data).
The agent operates entirely in isolation as a standalone web utility with no multi-agent coordination or marketplace integrations, making ecosystem-level threats negligible.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.