AI Agent Platforms Supported by the Agent Scanner: Complete Provider Guide

The Agent Scanner in Tencent/AI-Infra-Guard supports 16+ AI agent platforms including OpenAI, Anthropic, Google Gemini, Groq, Mistral, Ollama, and custom HTTP/WebSocket endpoints, configured via the providers.yaml file.

The Agent Scanner is a core component of the Tencent/AI-Infra-Guard repository designed to audit AI infrastructure for security vulnerabilities. Understanding which AI agent platforms are supported by the Agent Scanner is essential for security teams working with diverse large language model (LLM) deployments across cloud and on-premise environments.

OpenAI-Compatible AI Agent Platforms

The majority of supported providers implement the OpenAI API format, allowing seamless integration through a unified interface. These providers are defined in agent-scan/providers.yaml and share standardized configuration parameters including base_url, endpoint, and env_keys.

Major Cloud Providers

OpenAI serves as the default provider, supporting models including gpt-4o, gpt-4o-mini, gpt-4-turbo, o1, and o1-mini. The scanner reads the OPENAI_API_KEY environment variable by default.

Groq delivers high-performance inference for open models like llama-3.1-70b-versatile, llama-3.1-8b-instant, and mixtral-8x7b-32768.

Mistral AI supports mistral-large-latest, mistral-medium, and mistral-small-latest through their OpenAI-compatible endpoint.

DeepSeek provides access to deepseek-chat and deepseek-coder models for specialized coding tasks.

Perplexity offers search-augmented models including llama-3.1-sonar-large-128k-online and llama-3.1-sonar-small-128k-online.

OpenRouter acts as a unified gateway for multiple providers, allowing access to openai/gpt-4o and anthropic/claude-3-opus through a single API.

Hosting Platforms and Gateways

Together AI enables running models like meta-llama/Llama-3-8b-chat-hf on dedicated inference infrastructure.

Fireworks AI provides optimized serving for models such as accounts/fireworks/models/llama-v3-8b-instruct.

LiteLLM functions as a proxy gateway, allowing the scanner to route requests through existing LiteLLM deployments using the gpt-3.5-turbo interface.

Local and Self-Hosted Options

Ollama supports local model execution including llama3.2, llama3.1, mistral, and phi3 without cloud dependencies.

LocalAI enables on-premise deployments that mimic the OpenAI API, typically configured with gpt-3.5-turbo as the default model identifier.

Native API Platforms

Beyond OpenAI compatibility, the Agent Scanner implements direct integrations with proprietary API formats.

Anthropic provides native support for the Claude family of models including claude-3-haiku-20240307, claude-3-sonnet-20240229, and claude-3-opus-20240229 through its distinct API structure.

Google (Gemini) supports gemini-2.5-pro, gemini-2.0-flash, gemini-1.5-pro, and gemini-1.5-flash via the Gemini API, requiring GOOGLE_API_KEY authentication.

Cohere integrates with the command model series through its specialized API endpoints.

HuggingFace allows direct model inference for any compatible model (e.g., gpt2) using the Inference API or dedicated endpoints.

Replicate enables serverless model execution for models like meta/llama-2-70b-chat through their prediction API.

Custom Endpoint Support

For organizations running proprietary or air-gapped models, the scanner supports generic protocol handlers:

HTTP provider allows connection to user-defined REST endpoints with custom authentication schemes.

WebSocket provider enables real-time streaming connections to conversational agents.

Both custom providers accept configuration through external YAML files without requiring modifications to the core providers.yaml.

Provider Configuration and Runtime Discovery

The scanner discovers the appropriate AI agent platform at runtime by loading the --agent_provider YAML file or falling back to the default configuration. According to the source code in agent_scan/main.py, the CLI parses these arguments and builds the LLM client through core/agent_adapter/adapter.py.

Each provider definition requires:

  • env_keys – Environment variable(s) containing API credentials
  • base_url – Root endpoint for the service
  • endpoint – Specific path for chat completions (typically /v1/chat/completions)
  • default_model – Fallback model when none specified
  • models – Exhaustive list of supported model identifiers

The connectivity check in agent_scan/core/agent_adapter/connectivity.py validates that supplied provider configurations are reachable before initiating security scans.

Running Scans with Different Providers

Standard OpenAI Scan

aig-agent-scan --repo /path/to/project \
               --model gpt-4o \
               --api_key $OPENAI_API_KEY

Groq Provider Configuration

export GROQ_API_KEY=your_groq_key

aig-agent-scan --repo /path/to/project \
               --model llama-3.1-8b-instant \
               --base_url https://api.groq.com/openai/v1 \
               --api_key $GROQ_API_KEY

Custom Provider YAML Definition

Create my_provider.yaml:

providers:
  http:
    http:
      env_keys: []
      base_url: "https://my.custom.api"
      endpoint: "/v1/chat/completions"
      default_model: "my-model"

Execute with:

aig-agent-scan --repo /path/to/project \
               --agent_provider my_provider.yaml

Google Gemini Integration

export GOOGLE_API_KEY=your_gemini_key

aig-agent-scan --repo /path/to/project \
               --model gemini-1.5-flash \
               --base_url https://generativelanguage.googleapis.com/v1beta \
               --api_key $GOOGLE_API_KEY

Key Implementation Files

Understanding the architecture requires familiarity with these specific components:

Summary

  • The Agent Scanner supports 16 distinct AI agent platforms ranging from commercial APIs to self-hosted solutions.
  • OpenAI-compatible providers (Groq, Mistral, DeepSeek, Ollama) represent the largest category, configured through standardized YAML parameters.
  • Native API integrations exist for Anthropic, Google Gemini, Cohere, HuggingFace, and Replicate.
  • Custom HTTP and WebSocket endpoints allow scanning of proprietary or air-gapped models without code modifications.
  • Provider configurations in providers.yaml specify env_keys, base_url, endpoint, and supported models for automatic discovery.
  • Runtime validation occurs through connectivity.py before security scanning begins.

Frequently Asked Questions

How do I add a custom AI agent platform not listed in the default providers?

Create a YAML file with your provider's base_url, endpoint, and env_keys, then pass it via --agent_provider your_file.yaml. The scanner validates the configuration through agent_scan/core/agent_adapter/connectivity.py before executing. This approach requires no modifications to the core codebase.

Which environment variables does the Agent Scanner check for API keys?

Each provider defines its own environment variable list in the env_keys array within providers.yaml. For example, OpenAI uses OPENAI_API_KEY, Groq uses GROQ_API_KEY, and Google uses GOOGLE_API_KEY. The scanner reads these at runtime to authenticate requests.

Can I use the Agent Scanner with locally hosted models?

Yes. The Agent Scanner supports Ollama and LocalAI for completely local deployments, plus generic HTTP and WebSocket providers for custom local servers. These options enable security scanning of air-gapped environments without transmitting code to external APIs.

What happens if the configured provider is unreachable?

The connectivity.py module performs pre-flight validation before the scan begins. If the provider's endpoint is unreachable or authentication fails, the scanner exits with an error indicating the connectivity failure, preventing wasted computation on invalid configurations.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →