How to Install AI-Infra-Guard: Three Methods for Deploying the Hybrid Go/Python Platform

AI-Infra-Guard can be installed via Docker Compose with pre-built images, a one-click shell script that automates the setup, or built from source by compiling the Go binary and Python agents.

AI-Infra-Guard (A.I.G) is an open-source AI red-team platform developed by Tencent that combines Go-based infrastructure scanning with Python-powered security agents. Whether you need a production-ready deployment or a development environment for customizing detection rules, installing AI-Infra-Guard requires only Docker and Git. This guide covers every installation method supported by the Tencent/AI-Infra-Guard repository, from one-line commands to full source compilation.

Prerequisites

Before installing AI-Infra-Guard, ensure your system meets these requirements:

  • Docker (≥ 20.10) with Compose V2 support
  • Git for cloning the repository
  • (Optional) Python 3.9+ and pip if running Python agents manually outside Docker

The platform exposes the web interface on port 8088 by default, so ensure this port is available or modify the docker-compose.images.yml configuration accordingly.

The fastest way to install AI-Infra-Guard uses pre-built images from Docker Hub. This method deploys the complete stack—including the web UI, REST API, and all three scan engines—without compiling any code.

First, clone the repository:

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard

Then start the services using the pre-built image configuration:

docker-compose -f docker-compose.images.yml up -d

For Docker Compose V2+, use docker compose instead of docker-compose.

Once containers start, access the web UI at http://localhost:8088. The API documentation is available at /docs/index.html, and all scan modules are immediately operational.

Method 2: One-Click Install Script

For fresh machines or CI environments, the docker.sh script automates the entire installation process. It checks for Docker (installing it if missing), clones the repository, and executes the Docker Compose command.

Run the installer with:

curl https://raw.githubusercontent.com/Tencent/AI-Infra-Guard/refs/heads/main/docker.sh | bash

This script performs the same operations as Method 1, making it ideal for unattended deployments or quick evaluations on new virtual machines.

Method 3: Build from Source

Developers contributing to Tencent/AI-Infra-Guard or requiring custom modifications should build from source. This approach compiles the Go binary located in cmd/cli/main.go and prepares the Python agents manually.

Clone the repository and build the Go service:

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
go build -o ai-infra-guard ./cmd/cli/main.go

Install dependencies for the Python scanning agents:

pip install -r mcp-scan/requirements.txt
pip install -r agent-scan/requirements.txt
pip install -r AIG-PromptSecurity/requirements.txt

Launch the web server directly:

./ai-infra-guard webserver --server 127.0.0.1:8088

Alternatively, use the local Docker Compose file to containerize your custom build:

docker-compose up -d

Building from source gives you full control over the detection rules stored in data/fingerprints/ and data/vuln/, allowing updates without rebuilding binaries.

Verifying Your Installation

Confirm your AI-Infra-Guard installation is functioning correctly:

  1. Open http://localhost:8088 and verify the dashboard loads without errors.
  2. Visit http://localhost:8088/api-checker/docs to confirm the Swagger API documentation is accessible.
  3. Execute a test scan against a local target using the CLI:
./ai-infra-guard scan -t http://127.0.0.1:8000

For manual Python agent testing, run the MCP scanner directly:

python mcp-scan/main.py --repo /path/to/mcp/server

Architecture Overview

Understanding the platform architecture helps troubleshoot installation issues. AI-Infra-Guard v3.6.0+ consists of three independent scan engines orchestrated by a Go-based entry point in cmd/cli/main.go:

  • AI Infra Scan (Go): Fingerprinting engine for AI services and CVE matching
  • MCP Scan (Python): Static analysis and LLM verification for Model-Context-Protocol servers
  • Agent Scan (Go): Multi-agent workflow security testing

Detection rules reside externally in the data/ directory, enabling rule updates without service restarts or rebuilds.

Summary

  • Docker Compose with pre-built images is the recommended installation method for most users, requiring only docker-compose -f docker-compose.images.yml up -d to run the complete platform.
  • The one-click script at docker.sh automates Docker installation and deployment for fresh environments.
  • Building from source requires compiling cmd/cli/main.go and installing Python dependencies for developers needing custom builds.
  • All methods expose the web UI on port 8088 and include the complete rule sets located in data/fingerprints/ and data/vuln/.

Frequently Asked Questions

What are the minimum system requirements for AI-Infra-Guard?

AI-Infra-Guard requires Docker 20.10 or later with Compose V2 support. The platform runs on any Linux, macOS, or Windows host capable of running Docker containers. For source builds, Go 1.20+ and Python 3.9+ are necessary to compile cmd/cli/main.go and run the Python agents in mcp-scan/ and AIG-PromptSecurity/.

Can I run AI-Infra-Guard without Docker?

Yes, though it requires manual setup. Build the Go binary with go build -o ai-infra-guard ./cmd/cli/main.go, install Python dependencies from the various requirements.txt files, then execute ./ai-infra-guard webserver --server 127.0.0.1:8088. However, Docker is recommended for production deployments to ensure consistent dependency management across the hybrid Go/Python architecture.

How do I update AI-Infra-Guard to the latest version?

For Docker Compose installations, run docker-compose -f docker-compose.images.yml pull followed by up -d to fetch the latest images. Because detection rules are stored externally in the data/ directory and mounted as volumes, rule updates only require pulling the latest Git repository changes without rebuilding containers. Source installations require git pull and recompiling cmd/cli/main.go.

Which installation method should I choose for production environments?

Use the Docker Compose with pre-built images method for production. This approach uses the official docker-compose.images.yml configuration, which pulls tested images from Docker Hub and ensures all three scan engines (AI Infra, MCP, and Agent) start with correct inter-service networking. The one-click script is suitable for testing but review docker.sh before executing in production environments.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →