How to Install AI-Infra-Guard: Three Methods for Deploying the Hybrid Go/Python Platform
AI-Infra-Guard can be installed via Docker Compose with pre-built images, a one-click shell script that automates the setup, or built from source by compiling the Go binary and Python agents.
AI-Infra-Guard (A.I.G) is an open-source AI red-team platform developed by Tencent that combines Go-based infrastructure scanning with Python-powered security agents. Whether you need a production-ready deployment or a development environment for customizing detection rules, installing AI-Infra-Guard requires only Docker and Git. This guide covers every installation method supported by the Tencent/AI-Infra-Guard repository, from one-line commands to full source compilation.
Prerequisites
Before installing AI-Infra-Guard, ensure your system meets these requirements:
- Docker (≥ 20.10) with Compose V2 support
- Git for cloning the repository
- (Optional) Python 3.9+ and pip if running Python agents manually outside Docker
The platform exposes the web interface on port 8088 by default, so ensure this port is available or modify the docker-compose.images.yml configuration accordingly.
Method 1: Docker Compose with Pre-Built Images (Recommended)
The fastest way to install AI-Infra-Guard uses pre-built images from Docker Hub. This method deploys the complete stack—including the web UI, REST API, and all three scan engines—without compiling any code.
First, clone the repository:
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
Then start the services using the pre-built image configuration:
docker-compose -f docker-compose.images.yml up -d
For Docker Compose V2+, use docker compose instead of docker-compose.
Once containers start, access the web UI at http://localhost:8088. The API documentation is available at /docs/index.html, and all scan modules are immediately operational.
Method 2: One-Click Install Script
For fresh machines or CI environments, the docker.sh script automates the entire installation process. It checks for Docker (installing it if missing), clones the repository, and executes the Docker Compose command.
Run the installer with:
curl https://raw.githubusercontent.com/Tencent/AI-Infra-Guard/refs/heads/main/docker.sh | bash
This script performs the same operations as Method 1, making it ideal for unattended deployments or quick evaluations on new virtual machines.
Method 3: Build from Source
Developers contributing to Tencent/AI-Infra-Guard or requiring custom modifications should build from source. This approach compiles the Go binary located in cmd/cli/main.go and prepares the Python agents manually.
Clone the repository and build the Go service:
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
go build -o ai-infra-guard ./cmd/cli/main.go
Install dependencies for the Python scanning agents:
pip install -r mcp-scan/requirements.txt
pip install -r agent-scan/requirements.txt
pip install -r AIG-PromptSecurity/requirements.txt
Launch the web server directly:
./ai-infra-guard webserver --server 127.0.0.1:8088
Alternatively, use the local Docker Compose file to containerize your custom build:
docker-compose up -d
Building from source gives you full control over the detection rules stored in data/fingerprints/ and data/vuln/, allowing updates without rebuilding binaries.
Verifying Your Installation
Confirm your AI-Infra-Guard installation is functioning correctly:
- Open
http://localhost:8088and verify the dashboard loads without errors. - Visit
http://localhost:8088/api-checker/docsto confirm the Swagger API documentation is accessible. - Execute a test scan against a local target using the CLI:
./ai-infra-guard scan -t http://127.0.0.1:8000
For manual Python agent testing, run the MCP scanner directly:
python mcp-scan/main.py --repo /path/to/mcp/server
Architecture Overview
Understanding the platform architecture helps troubleshoot installation issues. AI-Infra-Guard v3.6.0+ consists of three independent scan engines orchestrated by a Go-based entry point in cmd/cli/main.go:
- AI Infra Scan (Go): Fingerprinting engine for AI services and CVE matching
- MCP Scan (Python): Static analysis and LLM verification for Model-Context-Protocol servers
- Agent Scan (Go): Multi-agent workflow security testing
Detection rules reside externally in the data/ directory, enabling rule updates without service restarts or rebuilds.
Summary
- Docker Compose with pre-built images is the recommended installation method for most users, requiring only
docker-compose -f docker-compose.images.yml up -dto run the complete platform. - The one-click script at
docker.shautomates Docker installation and deployment for fresh environments. - Building from source requires compiling
cmd/cli/main.goand installing Python dependencies for developers needing custom builds. - All methods expose the web UI on port 8088 and include the complete rule sets located in
data/fingerprints/anddata/vuln/.
Frequently Asked Questions
What are the minimum system requirements for AI-Infra-Guard?
AI-Infra-Guard requires Docker 20.10 or later with Compose V2 support. The platform runs on any Linux, macOS, or Windows host capable of running Docker containers. For source builds, Go 1.20+ and Python 3.9+ are necessary to compile cmd/cli/main.go and run the Python agents in mcp-scan/ and AIG-PromptSecurity/.
Can I run AI-Infra-Guard without Docker?
Yes, though it requires manual setup. Build the Go binary with go build -o ai-infra-guard ./cmd/cli/main.go, install Python dependencies from the various requirements.txt files, then execute ./ai-infra-guard webserver --server 127.0.0.1:8088. However, Docker is recommended for production deployments to ensure consistent dependency management across the hybrid Go/Python architecture.
How do I update AI-Infra-Guard to the latest version?
For Docker Compose installations, run docker-compose -f docker-compose.images.yml pull followed by up -d to fetch the latest images. Because detection rules are stored externally in the data/ directory and mounted as volumes, rule updates only require pulling the latest Git repository changes without rebuilding containers. Source installations require git pull and recompiling cmd/cli/main.go.
Which installation method should I choose for production environments?
Use the Docker Compose with pre-built images method for production. This approach uses the official docker-compose.images.yml configuration, which pulls tested images from Docker Hub and ensures all three scan engines (AI Infra, MCP, and Agent) start with correct inter-service networking. The one-click script is suitable for testing but review docker.sh before executing in production environments.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →