Katie AI SDR — agentic threat model
Katie AI SDR presents a high-risk profile due to its deep integration with corporate CRMs and autonomous multi-channel communication capabilities, which could be abused for data exfiltration or automated brand damage if compromised.
OWASP AIVSS score rationale
| Autonomy of Action | 0.80 | |
| Goal-Driven Planning | 0.70 | |
| Self-Modification | 0.10 | |
| Dynamic Tool Use | 0.60 | |
| Persistent Memory | 0.60 | |
| Contextual Awareness | 0.80 | |
| Dynamic Identity | 0.40 | |
| Multi-Agent Interactions | 0.10 | |
| Non-Determinism | 0.70 | |
| Opacity & Reflexivity | 0.60 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — likely utilizes commercial LLMs for message personalization and intent analysis. Threats include prompt injection that could bypass safety guardrails, leading to the generation of inappropriate or malicious outreach messages.
Integrates directly with corporate CRMs and ingests data from 50+ external sources. Threats include CRM data exfiltration, unauthorized access to prospect PII, and data poisoning of lead scoring models via manipulated external signals.
Orchestrates multi-step workflows including prospecting, scoring, and multi-channel messaging. Threats include insecure tool integration with CRM APIs and email/communication gateways, potentially allowing unauthorized data modification or message sending.
Not certain from the listing — deployed as a closed-source SaaS. Threats include insecure storage of CRM API keys/tokens and potential container compromise leading to lateral movement into connected enterprise systems.
Not certain from the listing — no mention of logging, guardrails, or human-in-the-loop verification. Lack of observability could lead to undetected drift in lead scoring or unmonitored generation of brand-damaging outreach.
Not certain from the listing — requires robust OAuth/IAM controls for CRM access and strict compliance with data privacy regulations (GDPR/CCPA) given its extensive processing of prospect and customer PII.
Not certain from the listing — operates primarily as a standalone horizontal SDR. Risks include interaction with automated buyer agents or triggering security/spam filters of recipient email ecosystems.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).