Want a guided walk-through that starts from one of these? Open the four-question wizard →

READY
08 templates
00 · blank canvas Ready
+
DRAG AGENTS ONTO CANVAS

Blank canvas

Start from nothing. Drag in agents, memory, tools, externals, and humans from the palette.

starterempty
AGENTS
0
EDGES
0
FINDINGS
0
TRIFECTA
0
01 · consumer fintech Ready

Consumer Fintech

10-agent consumer fintech: chat and voice frontends, an autonomous orchestrator, a policy/compliance reviewer, and specialists for accounts, transactions, fraud, recommendations, and support. An MCP tool bus and a HITL gate sit between the agent fleet and external KYC / payments / banking APIs.

fintechconsumer MAESTROOWASP
AGENTS
10
EDGES
40
FINDINGS
29
TRIFECTA
1
03 · customer support automation Ready

Customer Support Automation

A user-facing chat agent backed by a RAG knowledge store, a ticket-system API the agent writes to, and a human escalation gate. Untrusted user input flows into a RAG-and-write-capable agent under partial-provenance memory and an unsigned audit log.

supporthelpdesk OWASP
AGENTS
1
EDGES
6
FINDINGS
12
TRIFECTA
0
04 · mcp-based tool server Ready

MCP-based tool server

A single third-party MCP server exposes shell and write-capable tools to multiple client agents through one shared protocol channel. Concentrates descriptor-injection, cross-client interference, and third-party trust-anchor risk on one server.

infra MAESTROOWASP
AGENTS
2
EDGES
13
FINDINGS
20
TRIFECTA
0
05 · rpa: expense reimbursement Ready

RPA: Expense Reimbursement

RPA agent that extracts, validates (via policy RAG), and routes expense claims. Matches the OWASP MAS Guide §3 worked threat model. Open the case study for the full per-layer threat list.

rpafintechcase-study MAESTROOWASP
Real-world case studies
AGENTS
3
EDGES
15
FINDINGS
15
TRIFECTA
1
06 · elizaos (web3 agent os) Ready

ElizaOS (Web3 agent OS)

An ElizaOS-style agent system: multi-LLM, plugin tool bus, Solana blockchain integration, multi-platform clients. Matches the OWASP MAS Guide §4 worked threat model. Runaway-loop, wallet-key compromise, and plugin-vulnerability scenarios all surface on this graph.

web3blockchaincase-study MAESTROOWASP
AGENTS
2
EDGES
12
FINDINGS
32
TRIFECTA
2
07 · anthropic mcp: host + multiple servers Ready

Anthropic MCP: host + multiple servers

An MCP host (Claude Desktop / IDE) with multiple MCP Clients each connecting to a distinct MCP Server, mapping to the OWASP MAS Guide §5 worked threat model. Surfaces protocol-abuse, schema-mismatch, network-exposure, and rogue-server scenarios.

mcpinfracase-study MAESTROOWASP
AGENTS
1
EDGES
12
FINDINGS
21
TRIFECTA
1
COMING NEXT
00 templates
PHASE 2
02 templates