How to Integrate AI-Infra-Guard Skill Scan into CI/CD Pipelines
AI-Infra-Guard integrates with CI/CD pipelines through its standalone aig-skill-scan CLI tool, which emits standardized SARIF 2.1.0 reports, reads configuration from environment variables, and can gate deployments by failing builds when security findings are detected.
The Tencent/AI-Infra-Guard repository provides a dedicated sub-project called aig-skill-scan specifically designed for static, LLM-driven security auditing of AI Agent Skills such as OpenClaw Skills. This Python package operates as a zero-dependency command-line utility that fits naturally into automated workflows, allowing teams to enforce security policies before skills reach production environments.
Standalone CLI Architecture for CI/CD Automation
The aig-skill-scan tool is distributed via PyPI and installable via pip install aig-skill-scan. Unlike monolithic security scanners requiring complex setup, this tool operates as a standalone binary that writes SARIF 2.1.0 JSON directly to stdout by default, as documented in skill-scan/README.md.
Key architectural decisions that facilitate CI integration include:
- Zero-configuration execution: The scanner requires no local configuration files to run basic scans against repositories.
- Standardized output format: SARIF 2.1.0 ensures native compatibility with GitHub Advanced Security, GitLab SAST, and Azure DevOps security dashboards.
- Externalized rule management: Detection logic resides as YAML files in the version-controlled
data/directory, decoupled from the scanner binary.
Environment-Driven Configuration
As implemented in Tencent/AI-Infra-Guard, the scanner reads configuration parameters from environment variables or an optional .env file. This design aligns with CI/CD best practices where API keys, scan targets, and threshold settings are injected as pipeline variables rather than hardcoded in source control.
Teams can configure scan behavior dynamically across development, staging, and production environments without rebuilding container images or modifying repository files.
GitHub Actions Integration Example
The following workflow demonstrates complete integration into GitHub Actions. The configuration installs the scanner, executes a SARIF-formatted scan, uploads results to GitHub Advanced Security, and enforces security gates.
name: Skill-Scan CI
on:
push:
branches: [ main ]
pull_request:
jobs:
skill-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Install aig-skill-scan
run: pip install aig-skill-scan
- name: Run Skill Scan
id: scan
run: |
aig-skill-scan --repo ./path/to/skill \
--output-format sarif > scan-results.sarif
- name: Upload SARIF report
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: scan-results.sarif
category: aig-skill-scan
- name: Enforce no findings
if: steps.scan.outcome == 'failure'
run: exit 1
GitLab CI Integration Example
For GitLab environments, the scanner integrates with the built-in SAST dashboard by specifying the SARIF artifact report. The following .gitlab-ci.yml configuration installs the package and surfaces findings directly in merge request security scans.
stages:
- scan
skill_scan:
image: python:3.11
stage: scan
script:
- pip install aig-skill-scan
- aig-skill-scan --repo $CI_PROJECT_DIR/skill \
--output-format sarif > sarif.json
artifacts:
reports:
sast: sarif.json
only:
- merge_requests
- main
Rule Validation and Continuous Updates
The detection rules powering aig-skill-scan live as YAML files in the repository's data/ directory. Because these rules are external to the compiled binaries, security teams can update detection logic without releasing new scanner versions.
The repository maintains quality through a validation workflow defined in .github/workflows/yaml-lint.yml. This pipeline executes the built-in yamlcheck tool against all rule files before merges, ensuring that malformed rules cannot break production scans.
Implementing Security Gates with Batch Scanning
The CLI accepts lists of hostnames or IP ranges for multi-host batch scanning, enabling single-pipeline security audits across microservice fleets as documented in readme/README_ZH.md. To implement "shift-left" security as promoted in the repository's root README.md, configure your pipeline to parse the SARIF output and fail the job when findings are detected.
The following bash pattern gates deployments based on scan results:
pip install aig-skill-scan
aig-skill-scan --repo ./skills \
--output-format sarif | tee scan.sarif
if grep -q '"level":"error"' scan.sarif; then
echo "Security issues detected!"
exit 1
fi
This approach ensures that skill packages failing the security audit cannot progress to build, deployment, or release stages.
Summary
- AI-Infra-Guard Skill Scan integrates via the
pip-installableaig-skill-scanCLI tool designed for ephemeral CI environments. - The scanner emits SARIF 2.1.0 JSON compatible with GitHub Actions, GitLab SAST, and Azure Pipelines security dashboards.
- Configuration uses environment variables or
.envfiles, supporting standard CI secret management practices. - Detection rules reside in the version-controlled
data/directory and are validated by theyamlchecktool in.github/workflows/yaml-lint.yml. - Security gates prevent deployment by failing pipelines when the SARIF report contains error-level findings, enabling shift-left security.
Frequently Asked Questions
What output format does AI-Infra-Guard Skill Scan produce for CI integration?
The tool generates SARIF 2.1.0 JSON output written to stdout by default. According to the source code in skill-scan/README.md, this standardized format allows seamless ingestion by GitHub Advanced Security, GitLab SAST, and other security dashboards without requiring format conversion or custom parsers.
How do I install the AI-Infra-Guard Skill Scan tool in a CI pipeline?
Install the package using pip install aig-skill-scan within your CI container or job step. The tool requires no additional compilation, system dependencies, or configuration files, making it suitable for ephemeral build environments and disposable containers.
Can AI-Infra-Guard Skill Scan fail a CI build when security issues are found?
Yes. By configuring your pipeline to inspect the SARIF output for error-level findings and exit with a non-zero status code, the scanner can gate deployments. The repository's root README.md explicitly promotes this "shift-left" approach to prevent vulnerable AI Agent Skills from reaching production environments.
How are detection rules updated without redeploying the scanner?
Detection rules are stored as YAML files in the data/ directory and are external to the compiled binary. CI pipelines can validate rule changes using the yamlcheck tool referenced in .github/workflows/yaml-lint.yml, allowing security logic updates without modifying the scanner package version or rebuilding deployment artifacts.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →