AI Infra Guard
github.com/tencent/ai-infra-guard- Category
- Cybersecurity
- Rank
- No. 2056Tools index
Previous survey · No. 2064 ·
- Type
- APP
- Use case
- Security & Identity · Model & Agent Evaluation
- GitHub
- 6.8k stars
- Latest release
- v4.6.4
- Date
About
Tencent Zhuque Lab's AI red-teaming platform combining AI infrastructure vulnerability scanning, MCP server and agent-skill scanning, agent scanning, and jailbreak evaluation in one self-service security toolkit.
What it does
A self-hosted security workbench for teams running AI systems. A Go web service fingerprints AI services on a network, such as Ollama, vLLM and Dify, and matches the detected versions against a rule library of known vulnerabilities. Alongside it sit Python agents that use a language model to audit MCP server code, agent skill folders and agent workflows, plus a jailbreak evaluation module that fires attack prompts at a model and has a judge score the replies. Everything runs from one browser interface on port 8088, or piecemeal from the command line.
Why it's ranked here
Breadth with a backer. One Apache 2.0 repository from Tencent Zhuque Lab covers infrastructure CVE matching, MCP and skill auditing, agent testing and jailbreak evaluation, four jobs behind one interface. Detection rules are plain YAML kept in the repository rather than compiled into the binary, so rule updates ship without a rebuild and are lint-checked in CI. The skill scanner publishes its own benchmark scores, an F1 of 0.9848 with Claude Opus 4.6 on SkillTrustBench, which is a measurable claim rather than a slogan. The weak spot is deployment: the web platform has no authentication.
What's good
The standalone MCP and skill scanners write SARIF 2.1.0, the standard static-analysis format, so findings drop straight into GitHub Code Scanning, GitLab or the VS Code Problems panel. Each scanner installs on its own with pip, needs only an API key and a model name, and accepts any OpenAI-compatible endpoint, including OpenRouter. The skill scanner sorts findings into nine named risk categories, from instruction hijacking to insecure dependencies. The MCP scanner can probe a live remote server with custom headers, not only read source. Docker setup is one compose command against prebuilt images.
Tradeoffs
The README states plainly that the platform lacks an authentication mechanism and must not sit on a public network, so it belongs on a laptop or an isolated internal host. The Docker stack asks for 4GB of RAM and 10GB of disk. The language-model scanners cost tokens on every run and their accuracy depends on the model you pick: the published false-positive rate ranges from 0.0120 to 0.0723 across five models. Command-line output defaults to Chinese unless you pass the English language flag. The recommended install pipes a remote shell script straight into bash.
How to use it well
Two distinct uses. For a security team auditing what AI services are exposed internally, run the Docker stack on an isolated host and point the infrastructure scan at your network ranges. For a developer shipping agent skills or MCP servers, skip the platform and pip install the matching scanner, set the language to English, and add it to CI with SARIF output so findings appear next to code review. Pick a stronger model if false positives would block merges. It does not replace runtime guardrails: it audits code and endpoints, it does not filter live traffic.
Technical notes+
The Go entry point cmd/cli/main.go delegates to a cobra command tree; go.mod targets Go 1.23.2 and pulls gin, gorm with glebarez/sqlite, mark3labs/mcp-go, openai-go and the projectdiscovery HTTP stack. The Dockerfile is a three-stage build: pnpm frontend, static Go binary with CGO disabled, then a python:3.12-alpine runtime that installs agent-scan with uv and exposes 8088 with a pgrep healthcheck. mcp-scan/mcp_scan/main.py and skill-scan/skill_scan/main.py resolve the key from LLM_API_KEY or OPENAI_API_KEY (mcp also OPENROUTER_API_KEY), default --language to zh, and call to_sarif outside --aig-mode; agent-scan/agent_scan/main.py emits plain JSON and takes an --agent_provider YAML for dynamic tests. AGENTS.md lists go test and a yamlcheck validator for the data rules.
Observed
- License
- Apache 2.0, with an attribution requirement for derivative works
- Languages
- Go core service, Python scanning agents
- Interfaces
- Web UI, REST and WebSocket API, Go CLI, three standalone Python CLIs
- Packaging
- Docker Compose with prebuilt images; aig-skill-scan on pip
- Output format
- SARIF 2.1.0 from the standalone MCP and skill scanners
- Model support
- Any OpenAI-compatible endpoint via API key and base URL
- Authentication
- None on the web platform; README warns against public deployment
- Rule storage
- YAML fingerprint and vulnerability rules in the repository
Read from README.md, go.mod, Dockerfile, cmd/cli/main.go, mcp-scan/mcp_scan/main.py, skill-scan/skill_scan/main.py, agent-scan/agent_scan/main.py, docs/architecture_evolution.md, AIG-PromptSecurity/cli/__init__.py, AGENTS.md.
Tags
Tech Stack
Comments (0)
No comments yet
Editorially curated, with community endorsements as a secondary signal. Corrections welcome.