Recomi — agentic threat model
Recomi presents a moderate risk profile as a customer-facing chatbot platform; while its direct system execution capabilities are low, its integration with proprietary business data and public-facing websites exposes it to prompt injection, data exfiltration, and reputational risks.
OWASP AIVSS score rationale
| Autonomy of Action | 0.40 | |
| Goal-Driven Planning | 0.20 | |
| Self-Modification | 0.00 | |
| Dynamic Tool Use | 0.30 | |
| Persistent Memory | 0.30 | |
| Contextual Awareness | 0.50 | |
| Dynamic Identity | 0.10 | |
| Multi-Agent Interactions | 0.10 | |
| Non-Determinism | 0.60 | |
| Opacity & Reflexivity | 0.50 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — Recomi is closed source and does not specify the underlying foundation models used. Threats include prompt injection leading to misaligned outputs, system instruction leakage, or model reprogramming.
Not certain from the listing — The platform supports tailoring chatbots to specific business data, implying a RAG pipeline or vector database, but details are omitted. Threats include knowledge-base poisoning and unauthorized data exfiltration via indirect prompt injection.
Not certain from the listing — The orchestration framework is unspecified. Threats include insecure tool integration, particularly with upcoming lead generation tools and multi-platform integrations that could be abused to trigger unauthorized API calls.
Not certain from the listing — Hosting, sandboxing, and infrastructure details are not disclosed. Threats include container compromise, lateral movement within the hosting environment, and exposure of API keys used for integrations.
Not certain from the listing — No details are provided regarding built-in guardrails, evaluation metrics, or logging systems. Threats include blind spots to adversarial inputs and a lack of audit trails for security incidents.
Not certain from the listing — While 'Privacy & Security' is listed as a key feature, specific compliance standards (e.g., GDPR, SOC2) or access control mechanisms are not detailed. Threats include unauthorized access to the agent configuration dashboard.
Not certain from the listing — Recomi focuses on single custom chatbots for websites and does not explicitly support multi-agent marketplaces or A2A interactions. Threats are minimal here, though future integrations could introduce cascading risks.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).