Sandy AI — agentic threat model
Sandy AI presents a moderate-to-high risk profile due to its direct integration with sensitive CRM data, real-time call transcriptions, and active capabilities like email drafting and meeting scheduling, which could be exploited via prompt injection.
OWASP AIVSS score rationale
| Autonomy of Action | 0.60 | |
| Goal-Driven Planning | 0.50 | |
| Self-Modification | 0.10 | |
| Dynamic Tool Use | 0.60 | |
| Persistent Memory | 0.50 | |
| Contextual Awareness | 0.70 | |
| Dynamic Identity | 0.30 | |
| Multi-Agent Interactions | 0.20 | |
| Non-Determinism | 0.60 | |
| Opacity & Reflexivity | 0.50 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — Sandy AI likely relies on commercial foundation models (e.g., OpenAI GPT-4) for natural language understanding, transcription analysis, and email drafting, leaving it susceptible to standard adversarial prompt injections and model alignment bypasses.
Not certain from the listing — The agent processes real-time call transcriptions, contact insights, and CRM data. Without explicit details on data isolation, there is a risk of data leakage or unauthorized access to sensitive customer conversation histories.
Not certain from the listing — Orchestration manages tools for email drafting, meeting scheduling, and CRM updates. Insecure tool integration could allow malicious inputs from customer support queries to trigger unauthorized scheduling or email generation.
Not certain from the listing — Hosted as part of the Salesmate SaaS platform. Security relies entirely on the parent platform's infrastructure hardening, API security, and tenant isolation mechanisms.
Not certain from the listing — While the agent features 'Call Tracker & Insights', it is unclear if there are dedicated security guardrails, anomaly detection, or LLM-specific transaction logging to detect prompt injection or data exfiltration attempts.
Not certain from the listing — As a closed-source commercial product, it likely inherits Salesmate's baseline compliance, but the listing does not specify AI-specific governance, compliance with the EU AI Act, or specialized data privacy controls for transcriptions.
Not certain from the listing — Primarily operates as a single-agent copilot within the Salesmate ecosystem, but potential future integrations with external marketplaces or third-party APIs could introduce cascading trust boundaries.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).