seedream 6 — agentic threat model
Seedream 6.0 is a specialized image generation model with minimal agentic capabilities, presenting low operational risk but remaining susceptible to prompt injection, content moderation bypasses, and intellectual property concerns.
OWASP AIVSS score rationale
| Autonomy of Action | 0.10 | |
| Goal-Driven Planning | 0.00 | |
| Self-Modification | 0.00 | |
| Dynamic Tool Use | 0.00 | |
| Persistent Memory | 0.00 | |
| Contextual Awareness | 0.10 | |
| Dynamic Identity | 0.00 | |
| Multi-Agent Interactions | 0.00 | |
| Non-Determinism | 0.70 | |
| Opacity & Reflexivity | 0.80 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
Uses Bytedance's proprietary Seedream 6.0 image generation model. Primary threats include adversarial prompt injection to bypass safety filters, model stealing/reverse engineering, and generating copyright-infringing or harmful visual outputs.
Not certain from the listing — The training dataset and data ingestion pipeline are proprietary. Potential risks include training data poisoning, lack of data lineage transparency, and intellectual property/copyright infringement claims regarding the training corpus.
Not certain from the listing — As a standard image generator, it likely lacks a complex agentic orchestration framework, minimizing threats related to tool misuse, recursive planning loops, or state manipulation.
Not certain from the listing — Hosted on Bytedance's infrastructure. Standard web application threats apply, including server-side request forgery (SSRF) if the tool supports image-to-image URL inputs, and resource exhaustion (denial of service) during GPU-intensive rendering.
Not certain from the listing — No details are provided regarding output verification or safety guardrails. There is a risk of insufficient logging of malicious prompts or failure to detect automated abuse/scraping.
Not certain from the listing — Compliance posture regarding data privacy laws and emerging generative AI regulations (such as watermarking requirements under the EU AI Act) is unverified.
Not certain from the listing — The tool operates as a standalone vertical application with no indicated integration into broader multi-agent marketplaces or collaborative ecosystems.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).