# AI Agent Platforms Supported by the Agent Scanner: Complete Provider Guide

> Discover which AI agent platforms the Agent Scanner supports. Explore providers like OpenAI, Gemini, Mistral, and Ollama in this comprehensive guide for AI-Infra-Guard users.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: api-reference
- Published: 2026-08-25

---

**The Agent Scanner in Tencent/AI-Infra-Guard supports 16+ AI agent platforms including OpenAI, Anthropic, Google Gemini, Groq, Mistral, Ollama, and custom HTTP/WebSocket endpoints, configured via the [`providers.yaml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/providers.yaml) file.**

The **Agent Scanner** is a core component of the [Tencent/AI-Infra-Guard](https://github.com/Tencent/AI-Infra-Guard) repository designed to audit AI infrastructure for security vulnerabilities. Understanding which **AI agent platforms are supported by the Agent Scanner** is essential for security teams working with diverse large language model (LLM) deployments across cloud and on-premise environments.

## OpenAI-Compatible AI Agent Platforms

The majority of supported providers implement the OpenAI API format, allowing seamless integration through a unified interface. These providers are defined in [`agent-scan/providers.yaml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/providers.yaml) and share standardized configuration parameters including `base_url`, `endpoint`, and `env_keys`.

### Major Cloud Providers

**OpenAI** serves as the default provider, supporting models including `gpt-4o`, `gpt-4o-mini`, `gpt-4-turbo`, `o1`, and `o1-mini`. The scanner reads the `OPENAI_API_KEY` environment variable by default.

**Groq** delivers high-performance inference for open models like `llama-3.1-70b-versatile`, `llama-3.1-8b-instant`, and `mixtral-8x7b-32768`.

**Mistral AI** supports `mistral-large-latest`, `mistral-medium`, and `mistral-small-latest` through their OpenAI-compatible endpoint.

**DeepSeek** provides access to `deepseek-chat` and `deepseek-coder` models for specialized coding tasks.

**Perplexity** offers search-augmented models including `llama-3.1-sonar-large-128k-online` and `llama-3.1-sonar-small-128k-online`.

**OpenRouter** acts as a unified gateway for multiple providers, allowing access to `openai/gpt-4o` and `anthropic/claude-3-opus` through a single API.

### Hosting Platforms and Gateways

**Together AI** enables running models like `meta-llama/Llama-3-8b-chat-hf` on dedicated inference infrastructure.

**Fireworks AI** provides optimized serving for models such as `accounts/fireworks/models/llama-v3-8b-instruct`.

**LiteLLM** functions as a proxy gateway, allowing the scanner to route requests through existing LiteLLM deployments using the `gpt-3.5-turbo` interface.

### Local and Self-Hosted Options

**Ollama** supports local model execution including `llama3.2`, `llama3.1`, `mistral`, and `phi3` without cloud dependencies.

**LocalAI** enables on-premise deployments that mimic the OpenAI API, typically configured with `gpt-3.5-turbo` as the default model identifier.

## Native API Platforms

Beyond OpenAI compatibility, the **Agent Scanner** implements direct integrations with proprietary API formats.

**Anthropic** provides native support for the Claude family of models including `claude-3-haiku-20240307`, `claude-3-sonnet-20240229`, and `claude-3-opus-20240229` through its distinct API structure.

**Google** (Gemini) supports `gemini-2.5-pro`, `gemini-2.0-flash`, `gemini-1.5-pro`, and `gemini-1.5-flash` via the Gemini API, requiring `GOOGLE_API_KEY` authentication.

**Cohere** integrates with the `command` model series through its specialized API endpoints.

**HuggingFace** allows direct model inference for any compatible model (e.g., `gpt2`) using the Inference API or dedicated endpoints.

**Replicate** enables serverless model execution for models like `meta/llama-2-70b-chat` through their prediction API.

## Custom Endpoint Support

For organizations running proprietary or air-gapped models, the scanner supports generic protocol handlers:

**HTTP** provider allows connection to user-defined REST endpoints with custom authentication schemes.

**WebSocket** provider enables real-time streaming connections to conversational agents.

Both custom providers accept configuration through external YAML files without requiring modifications to the core [`providers.yaml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/providers.yaml).

## Provider Configuration and Runtime Discovery

The scanner discovers the appropriate **AI agent platform** at runtime by loading the `--agent_provider` YAML file or falling back to the default configuration. According to the source code in [`agent_scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent_scan/main.py), the CLI parses these arguments and builds the LLM client through [`core/agent_adapter/adapter.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/core/agent_adapter/adapter.py).

Each provider definition requires:

- **`env_keys`** – Environment variable(s) containing API credentials
- **`base_url`** – Root endpoint for the service
- **`endpoint`** – Specific path for chat completions (typically `/v1/chat/completions`)
- **`default_model`** – Fallback model when none specified
- **`models`** – Exhaustive list of supported model identifiers

The `connectivity` check in [`agent_scan/core/agent_adapter/connectivity.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent_scan/core/agent_adapter/connectivity.py) validates that supplied provider configurations are reachable before initiating security scans.

## Running Scans with Different Providers

### Standard OpenAI Scan

```bash
aig-agent-scan --repo /path/to/project \
               --model gpt-4o \
               --api_key $OPENAI_API_KEY

```

### Groq Provider Configuration

```bash
export GROQ_API_KEY=your_groq_key

aig-agent-scan --repo /path/to/project \
               --model llama-3.1-8b-instant \
               --base_url https://api.groq.com/openai/v1 \
               --api_key $GROQ_API_KEY

```

### Custom Provider YAML Definition

Create [`my_provider.yaml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/my_provider.yaml):

```yaml
providers:
  http:
    http:
      env_keys: []
      base_url: "https://my.custom.api"
      endpoint: "/v1/chat/completions"
      default_model: "my-model"

```

Execute with:

```bash
aig-agent-scan --repo /path/to/project \
               --agent_provider my_provider.yaml

```

### Google Gemini Integration

```bash
export GOOGLE_API_KEY=your_gemini_key

aig-agent-scan --repo /path/to/project \
               --model gemini-1.5-flash \
               --base_url https://generativelanguage.googleapis.com/v1beta \
               --api_key $GOOGLE_API_KEY

```

## Key Implementation Files

Understanding the architecture requires familiarity with these specific components:

- **[`agent-scan/providers.yaml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/providers.yaml)** – Central registry of all supported AI agent platforms and their metadata
- **[`agent_scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent_scan/main.py)** – CLI entry point that processes `--agent_provider` arguments and instantiates clients
- **[`agent_scan/core/agent_adapter/adapter.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent_scan/core/agent_adapter/adapter.py)** – Wraps provider configurations into `AIProviderClient` instances used throughout the scanning engine
- **[`agent_scan/core/agent_adapter/connectivity.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent_scan/core/agent_adapter/connectivity.py)** – Validates network reachability and authentication for configured providers
- **[`agent_scan/utils/config.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent_scan/utils/config.py)** – Defines `DEFAULT_MODEL` and `DEFAULT_BASE_URL` constants that provider configurations override

## Summary

- The **Agent Scanner** supports 16 distinct **AI agent platforms** ranging from commercial APIs to self-hosted solutions.
- OpenAI-compatible providers (Groq, Mistral, DeepSeek, Ollama) represent the largest category, configured through standardized YAML parameters.
- Native API integrations exist for Anthropic, Google Gemini, Cohere, HuggingFace, and Replicate.
- Custom HTTP and WebSocket endpoints allow scanning of proprietary or air-gapped models without code modifications.
- Provider configurations in [`providers.yaml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/providers.yaml) specify `env_keys`, `base_url`, `endpoint`, and supported `models` for automatic discovery.
- Runtime validation occurs through [`connectivity.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/connectivity.py) before security scanning begins.

## Frequently Asked Questions

### How do I add a custom AI agent platform not listed in the default providers?

Create a YAML file with your provider's `base_url`, `endpoint`, and `env_keys`, then pass it via `--agent_provider your_file.yaml`. The scanner validates the configuration through [`agent_scan/core/agent_adapter/connectivity.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent_scan/core/agent_adapter/connectivity.py) before executing. This approach requires no modifications to the core codebase.

### Which environment variables does the Agent Scanner check for API keys?

Each provider defines its own environment variable list in the `env_keys` array within [`providers.yaml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/providers.yaml). For example, OpenAI uses `OPENAI_API_KEY`, Groq uses `GROQ_API_KEY`, and Google uses `GOOGLE_API_KEY`. The scanner reads these at runtime to authenticate requests.

### Can I use the Agent Scanner with locally hosted models?

Yes. The **Agent Scanner** supports **Ollama** and **LocalAI** for completely local deployments, plus generic **HTTP** and **WebSocket** providers for custom local servers. These options enable security scanning of air-gapped environments without transmitting code to external APIs.

### What happens if the configured provider is unreachable?

The [`connectivity.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/connectivity.py) module performs pre-flight validation before the scan begins. If the provider's endpoint is unreachable or authentication fails, the scanner exits with an error indicating the connectivity failure, preventing wasted computation on invalid configurations.