← Yevideo - AI Video and Image
Yevideo - AI Video and Image — agentic threat model
Yevideo is a low-autonomy multimodal generation platform with low agentic risk, primarily exposed to content abuse (such as deepfakes or policy-violating generations) and API-related vulnerabilities rather than autonomous decision-making failures.
OWASP AIVSS score rationale
| Autonomy of Action | 0.20 | |
| Goal-Driven Planning | 0.20 | |
| Self-Modification | 0.00 | |
| Dynamic Tool Use | 0.30 | |
| Persistent Memory | 0.20 | |
| Contextual Awareness | 0.20 | |
| Dynamic Identity | 0.00 | |
| Multi-Agent Interactions | 0.00 | |
| Non-Determinism | 0.80 | |
| Opacity & Reflexivity | 0.70 |
Scored with the canonical OWASP AIVSS formula (AIVSS calculator reference); agentic risk factors estimated from the agent’s described capabilities.
MAESTRO 7-layer threat model
Per-layer threats for this agent. Layers tagged “not certain from listing” are general, caveated commentary where the public description didn’t pin that layer.
The platform relies heavily on multimodal foundation models (text-to-video, image-to-video, etc.). These models are highly susceptible to adversarial prompt injections designed to bypass safety filters, potentially generating copyrighted, harmful, or deepfake content.
Not certain from the listing — The platform manages a 'Large Inspiration Library' and user-uploaded media assets. Gaps in data operations could lead to unauthorized access, data exfiltration of proprietary creative assets, or poisoning of the shared inspiration templates.
Not certain from the listing — Orchestration is focused on a 'One-Click Generate Similar' workflow that carries over generation settings. Vulnerabilities here include insecure parameter handling or prompt injection during the replication of creative directions.
Not certain from the listing — The platform provides an API and a unified web workspace. Infrastructure threats include unauthorized API access, lack of rate limiting leading to GPU resource exhaustion (DoS), and insecure storage of generated media assets.
Not certain from the listing — There is no mention of automated content moderation, output guardrails, or generation logging. A lack of observability could allow users to generate and export policy-violating content undetected.
Not certain from the listing — No compliance certifications (such as SOC2) or enterprise access controls (RBAC) are specified for the workspace or API, posing risks to corporate data governance.
Not certain from the listing — Although tagged as an 'AI Agents Platform', the description focuses on horizontal creative tools. There is no evidence of multi-agent coordination or third-party agent marketplaces, minimizing ecosystem-specific risks.
MAESTRO — the 7-layer agentic threat-modeling framework (Cloud Security Alliance / Ken Huang).