Raya by Teammates.ai — agentic threat model
Raya exhibits high agentic risk due to its high autonomy, direct integration with payment/refund systems, and public-facing omnichannel exposure, making it a high-value target for prompt injection and financial fraud.
OWASP AIVSS score rationale
| Autonomy of Action | 0.90 | |
| Goal-Driven Planning | 0.80 | |
| Self-Modification | 0.10 | |
| Dynamic Tool Use | 0.80 | |
| Persistent Memory | 0.70 | |
| Contextual Awareness | 0.80 | |
| Dynamic Identity | 0.30 | |
| Multi-Agent Interactions | 0.20 | |
| Non-Determinism | 0.70 | |
| Opacity & Reflexivity | 0.60 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Not certain from the listing — likely utilizes commercial LLMs optimized for multilingual support (especially Arabic dialects). Primary threats include prompt injection bypassing guardrails to trigger unauthorized actions or leak system prompts.
Not certain from the listing — syncs with CRMs and e-commerce databases. Threats include data exfiltration of customer PII and knowledge-base poisoning if the agent ingests malicious data from compromised tickets or emails.
Raya orchestrates tool execution across 30+ native integrations to process payments, refunds, and track orders. Threats include insecure tool integration and tool misuse, where adversarial inputs manipulate the agent into executing unauthorized financial transactions.
Not certain from the listing — closed-source SaaS deployment. Threats include container compromise, exposure of API keys for CRM/payment gateways, and lack of sandboxing for execution environments.
Raya monitors trends and conversation outcomes for analytics. Threats include blind spots in detecting adversarial prompt injections across 50+ languages (especially Arabic dialects) and insufficient logging of automated financial transactions.
Not certain from the listing — handling payments and CRM data requires PCI-DSS and GDPR compliance, but no specific compliance certifications, RBAC controls, or human-in-the-loop guardrails are detailed.
Not certain from the listing — acts as a standalone teammate, but interacts with external APIs (CRMs, payment gateways). Threats include cascading failures if integrated systems return malicious payloads or fail.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).