ChemCrow — agentic threat model
ChemCrow presents a high-risk profile due to its ability to autonomously plan and execute chemical syntheses using 13 integrated tools. Without explicit safety guardrails or sandboxing mentioned in its open-source listing, its dual-use potential (e.g., synthesizing hazardous materials) poses significant physical and digital security risks.
OWASP AIVSS score rationale
| Autonomy of Action | 0.80 | |
| Goal-Driven Planning | 0.90 | |
| Self-Modification | 0.10 | |
| Dynamic Tool Use | 0.80 | |
| Persistent Memory | 0.20 | |
| Contextual Awareness | 0.50 | |
| Dynamic Identity | 0.10 | |
| Multi-Agent Interactions | 0.10 | |
| Non-Determinism | 0.60 | |
| Opacity & Reflexivity | 0.50 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
ChemCrow relies on LLMs optimized for chemistry. The primary threat is prompt injection or jailbreaking to bypass safety alignments, potentially allowing users to generate instructions for synthesizing restricted, hazardous, or dual-use chemical substances.
Not certain from the listing — however, the agent likely queries chemical databases and literature. Threats include data poisoning of chemical properties or synthesis pathways, which could lead to failed or highly dangerous physical reactions.
The framework orchestrates 13 expert-designed tools for synthesis and drug discovery. A major threat is insecure tool integration or tool misuse, where malicious inputs manipulate tool arguments to execute unintended or unsafe chemical calculations and planning steps.
Not certain from the listing — as an open-source tool, deployment safety depends on the user. If deployed without strict sandboxing, the execution of chemistry tools or APIs could lead to local system compromise or unauthorized network access to laboratory hardware.
Not certain from the listing — there is no mention of built-in safety guardrails, real-time monitoring, or logging of synthesis plans. This creates a blind spot where malicious or unsafe chemical recipes can be generated without detection.
Not certain from the listing — the agent lacks explicit compliance controls regarding chemical export regulations, dual-use technology restrictions, or identity verification for users requesting sensitive synthesis plans.
Not certain from the listing — while designed as a standalone agent with tools, integrating ChemCrow into automated laboratory ecosystems (A2A) without human-in-the-loop validation could lead to physical execution of hazardous chemical syntheses.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).