How AI-Infra-Guard Handles MCP Security Scanning: Architecture and Implementation

AI-Infra-Guard implements MCP (Model-Code-Package) security scanning through a modular Go-based architecture centered in internal/mcp, utilizing a plugin-driven scanner engine that aggregates vulnerabilities into standardized reports.

Tencent's AI-Infra-Guard provides comprehensive security scanning for AI infrastructure, with MCP security scanning serving as a core capability for analyzing model code packages. This subsystem operates as a dedicated module within the larger platform, offering both Go-native and Python-wrapped interfaces to accommodate diverse deployment scenarios. The implementation emphasizes extensibility, allowing security teams to integrate custom detection logic without modifying core scanner code.

MCP Security Scanning Architecture

The MCP scanner follows a layered architecture that separates orchestration logic from detection mechanisms. This design enables independent updates to security rules while maintaining stable scanning pipelines.

Scanner Engine (internal/mcp/scanner.go)

The scanner engine in internal/mcp/scanner.go serves as the central orchestration point for all MCP security operations. This component accepts a target repository path, initializes the configured plugin registry, and executes scanning operations sequentially. The engine aggregates individual plugin findings into a unified VulReport structure defined in pkg/vulstruct/scanner.go, which standardizes CVE identifiers, severity classifications, and remediation metadata for downstream consumption by the rule engine and web interface.

Plugin System (internal/mcp/plugins.go)

Detection capabilities are implemented through the plugin framework defined in internal/mcp/plugins.go. Each plugin implements a strict interface requiring Init(), Scan(), and Result() methods, enabling consistent lifecycle management across different detection strategies. Built-in plugins cover critical threat vectors including vulnerable dependency detection, unsafe prompt pattern analysis, and configuration misconfiguration identification. This architecture supports both static analysis and dynamic testing approaches within the same scanning pipeline.

Utility Functions (internal/mcp/utils/utils.go)

Shared functionality resides in internal/mcp/utils/utils.go, providing helper methods for file system traversal, YAML/JSON configuration parsing, and result formatting. These utilities ensure consistent error handling and data processing across the scanner engine and individual plugins, maintaining code reuse throughout the MCP security scanning module.

MCP Security Scanning Workflow

When triggering an MCP scan through any interface, the system executes a standardized five-stage pipeline:

  1. CLI Invocation – The user initiates scanning via ./ai-infra-guard scan -t <target> --repo <path> or through the Python wrapper python mcp-scan/main.py --repo <path>, which calls the entry point in cmd/cli/main.go.

  2. Repository Loading – The scanner engine walks the target repository structure, building an internal representation of files, dependencies, and metadata required for analysis.

  3. Plugin Execution – Each registered plugin receives the repository context through a ScanContext object, performing specialized checks such as known vulnerable package identification or insecure prompt template detection. Plugins return ScanResult structures containing Finding objects.

  4. Result Aggregation – Individual plugin outputs merge into a centralized VulReport structure, correlating findings across different detection methods to eliminate duplicates and severity conflicts.

  5. Output Generation – The final report emits as JSON, SARIF, or renders through the web dashboard, feeding automated alerting and remediation workflows.

Running MCP Security Scans

AI-Infra-Guard exposes MCP security scanning functionality through multiple interfaces to support diverse operational environments.

Command Line Interface

The Go-based CLI provides direct access to the scanner engine with full configuration control:


# Build the binary from source

go build -o ai-infra-guard ./cmd/cli/main.go

# Execute MCP security scan against local repository

./ai-infra-guard scan -t http://127.0.0.1:8088 --repo /path/to/project

Python Wrapper

For Python-centric workflows, the mcp-scan submodule offers equivalent functionality:


# Install dependencies

pip install -r mcp-scan/requirements.txt

# Run MCP security scanning via Python interface

python mcp-scan/main.py --repo /path/to/project

Extending MCP Security Scanning with Custom Plugins

The decoupled architecture enables security teams to implement custom detection logic without modifying core scanner code. New plugins must implement the interface defined in internal/mcp/plugins.go and register themselves during initialization.

The following example demonstrates implementing a custom security check:

// myplugin.go
package myplugin

import (
    "github.com/Tencent/AI-Infra-Guard/internal/mcp"
)

type MyPlugin struct{}

func (p *MyPlugin) Init() error { 
    return nil 
}

func (p *MyPlugin) Scan(ctx *mcp.ScanContext) (*mcp.ScanResult, error) {
    // Custom analysis logic targeting specific MCP vulnerabilities
    findings := []mcp.Finding{
        // Populate with detected security issues
    }
    return &mcp.ScanResult{Findings: findings}, nil
}

func (p *MyPlugin) Result() *mcp.PluginResult { 
    return nil 
}

func init() { 
    mcp.RegisterPlugin(&MyPlugin{}) 
}

Register the plugin by importing the package in your main application:

import _ "path/to/myplugin" // Automatic registration via init()

Summary

  • AI-Infra-Guard implements MCP security scanning through a dedicated internal/mcp module written in Go, providing both native and Python-wrapped interfaces.

  • The scanner engine (internal/mcp/scanner.go) orchestrates repository analysis and aggregates results into standardized VulReport structures.

  • A plugin architecture (internal/mcp/plugins.go) enables extensible detection capabilities through a standardized interface supporting static and dynamic analysis methods.

  • Built-in plugins address critical AI infrastructure risks including vulnerable dependencies, unsafe prompt patterns, and configuration errors.

  • The system supports multiple output formats including JSON and SARIF, integrating with broader security orchestration workflows.

Frequently Asked Questions

What is MCP security scanning in AI-Infra-Guard?

MCP (Model-Code-Package) security scanning refers to the specialized analysis of AI model artifacts, codebases, and package dependencies to identify security vulnerabilities specific to AI infrastructure. According to the Tencent/AI-Infra-Guard source code, this capability focuses on detecting vulnerable dependencies, unsafe prompt templates, and configuration misconfigurations that could compromise AI systems.

How does the plugin architecture support extensibility?

The plugin system defined in internal/mcp/plugins.go requires each detection module to implement standardized Init(), Scan(), and Result() methods. This interface abstraction allows security engineers to add new detection capabilities—such as novel vulnerability signatures or compliance checks—without modifying the core scanner logic in internal/mcp/scanner.go, ensuring stable scanning pipelines while enabling rapid response to emerging threats.

What output formats does the MCP scanner support?

The MCP scanner aggregates findings into a VulReport structure that supports multiple serialization formats. Based on the implementation in pkg/vulstruct/scanner.go, the system generates JSON for programmatic consumption, SARIF for integration with standard security analysis tools, and structured data for the web dashboard interface, facilitating integration with CI/CD pipelines and security information management systems.

Can I integrate custom security checks into the MCP scanner?

Yes, the architecture explicitly supports custom plugin development. By implementing the plugin interface and utilizing the ScanContext and ScanResult types, developers can create detection modules for organization-specific security policies or proprietary vulnerability signatures. Registering these plugins through the mcp.RegisterPlugin() function makes them available to both the Go CLI and Python wrapper interfaces.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →