11x.ai — agentic threat model
11x.ai represents a high-risk agentic profile due to its autonomous multi-channel communication capabilities and direct integration with sensitive enterprise CRM systems, making it a prime target for indirect prompt injection and data exfiltration.
OWASP AIVSS score rationale
| Autonomy of Action | 0.80 | |
| Goal-Driven Planning | 0.70 | |
| Self-Modification | 0.10 | |
| Dynamic Tool Use | 0.70 | |
| Persistent Memory | 0.70 | |
| Contextual Awareness | 0.70 | |
| Dynamic Identity | 0.40 | |
| Multi-Agent Interactions | 0.30 | |
| Non-Determinism | 0.60 | |
| Opacity & Reflexivity | 0.60 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — Likely relies on third-party frontier LLMs. Highly vulnerable to indirect prompt injection via incoming emails or lead responses, which could hijack the agent's instructions.
Not certain from the listing — Processes proprietary CRM data and lead lists. Risks include data exfiltration of customer PII and database poisoning if malicious lead data is ingested into the vector store or CRM.
Not certain from the listing — Orchestrates multi-step sales workflows (prospecting to closing). Vulnerabilities include tool misuse, such as sending unauthorized emails or corrupting CRM records due to manipulated execution paths.
Not certain from the listing — Hosted cloud infrastructure. Key threats include the exposure of sensitive API keys for CRMs (e.g., Salesforce, HubSpot) and email delivery services.
Not certain from the listing — Features 'advanced analytics' but lacks explicit security guardrails or monitoring for toxic/manipulated outbound communications.
Not certain from the listing — Closed-source commercial platform. Likely implements standard SaaS security, but compliance with data privacy regulations (GDPR/CCPA) regarding automated outreach is critical and unverified here.
Not certain from the listing — Operates as a virtual employee interacting with human teams and external prospects. Threat of trust abuse where external actors trick the agent into performing unauthorized internal actions.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).