# How to Perform an AI Infrastructure Scan with AI-Infra-Guard: Complete Setup and Execution Guide

> Learn how to perform an AI infrastructure scan with AI-Infra-Guard. Our guide details setup and execution using its Go-Python architecture for robust vulnerability checks.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: how-to-guide
- Published: 2026-08-25

---

**AI-Infra-Guard performs AI infrastructure scans through a hybrid Go-Python architecture where the Go-based CLI orchestrates web services and agents while Python plugins execute vulnerability checks against model servers and pipelines.**

AI-Infra-Guard is an open-source security scanning platform developed by Tencent that identifies vulnerabilities in AI model deployments and associated infrastructure. The tool combines a **Go-based core service** with **Python scanning plugins** to deliver comprehensive coverage of both static code analysis and runtime environment assessment. This guide explains how to configure and execute a complete AI infrastructure scan using the official Tencent/AI-Infra-Guard repository.

## Architecture Overview

The system operates across three logical layers defined in the source structure:

- **Orchestration & API Layer**: Implemented in Go under `cmd/cli/`, providing the web interface, CLI commands, and WebSocket task scheduler. The entry point resides in [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go), while [`cmd/cli/cmd/webserver.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/webserver.go) handles HTTP server initialization.

- **Agent Runtime Layer**: Comprises the Go agent binary built from [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go) and supporting Python agents in the `agent-scan/` directory. This layer establishes persistent WebSocket connections back to the orchestrator for distributed scanning.

- **Scanning Plugins Layer**: Python modules located in `mcp-scan/`, `agent-scan/`, and `AIG-PromptSecurity/` that execute concrete vulnerability checks. The unified task model defined in `pkg/task/` coordinates data structures between layers.

## Building the Core Components

### Compiling the CLI and Server

Build the primary orchestration binary from the root directory:

```bash
go build -o ai-infra-guard ./cmd/cli/main.go

```

This produces the main executable that handles both the webserver and CLI scanning commands.

### Building the Remote Agent

For infrastructure requiring remote assessment, compile the agent binary:

```bash
go build -o agent ./cmd/agent

```

The resulting binary connects to the central server via WebSocket as implemented in [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go).

## Starting the Scanning Service

Launch the HTTP and WebSocket server to enable scanning operations:

```bash
./ai-infra-guard webserver --server 127.0.0.1:8088

```

This command invokes the server logic in [`cmd/cli/cmd/webserver.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/webserver.go), which listens for CLI connections and agent registrations. The service exposes a JSON API documented in [`docs/swagger.yaml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docs/swagger.yaml).

## Execution Methods for AI Infrastructure Scanning

### Direct CLI Scanning

Run immediate scans without deploying remote agents:

```bash
./ai-infra-guard scan -t http://127.0.0.1:8088

```

The CLI contacts the running server, creates a scan task using the structures in `pkg/task/`, and aggregates results directly.

### Agent-Assisted Remote Scanning

For isolated or external targets, deploy the compiled agent with environment configuration:

```bash
AIG_SERVER=127.0.0.1:8088 ./agent

```

The agent opens a WebSocket channel to receive plugin instructions, executes them on the target host, and streams results back to the server.

## Running Specialized Python Plugins

The Python plugins perform deep inspection of AI-specific attack surfaces.

### MCP Model Code Analysis

Execute static and dynamic analysis of model code repositories:

```bash
pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project

```

This module targets model-related vulnerabilities and pipeline configurations.

### Container and Host Fingerprinting

Assess container-level security and perform remote host fingerprinting:

```bash
pip install -r agent-scan/requirements.txt
python agent-scan/main.py --repo /path/to/project --agent_provider /path/to/provider.yaml

```

The `--agent_provider` parameter specifies YAML configuration for the scanning provider.

### Prompt Injection Security Testing

Detect prompt injection and jailbreak risks:

```bash
pip install -r AIG-PromptSecurity/requirements.txt

# Execute specific test scripts from AIG-PromptSecurity/tests/

```

This component evaluates the security posture of AI model input handling.

## Understanding Scan Results and Rule Configuration

After execution, the server returns a JSON report aggregating findings from all active plugins. The scanner references YAML rule bases located in `data/vuln/` and `data/fingerprints/` to identify known vulnerabilities and system fingerprints. These rule files define the detection signatures consulted by both the Go orchestration layer and the Python scanning modules.

## Summary

- Build the Go CLI from [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) to establish the orchestration service
- Launch the webserver using [`cmd/cli/cmd/webserver.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/webserver.go) to enable HTTP/WebSocket communication
- Execute direct scans via CLI or deploy agents compiled from [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go) for remote infrastructure assessment
- Run Python plugins from `mcp-scan/` and `agent-scan/` directories to analyze model code and container environments
- Reference YAML rule bases in `data/vuln/` and `data/fingerprints/` for vulnerability definitions and detection logic

## Frequently Asked Questions

### What is the difference between direct CLI scanning and agent-assisted scanning?

Direct CLI scanning runs locally and connects to the server API for immediate target assessment, while agent-assisted scanning deploys a lightweight binary compiled from [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go) to remote hosts that maintains a persistent WebSocket connection for distributed infrastructure evaluation.

### Which Python plugin should I use for analyzing AI model code?

Use the **MCP scan** module located at [`mcp-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/main.py) for static and dynamic analysis of model code repositories, as it specifically targets model-related vulnerabilities, pipeline configurations, and associated dependencies.

### Where does AI-Infra-Guard store its vulnerability detection rules?

The scanner references YAML rule files located in `data/vuln/` and `data/fingerprints/`, which contain the detection signatures and vulnerability definitions used by both the Go orchestration layer and Python plugins during the AI infrastructure scan process.

### Can AI-Infra-Guard scan infrastructure without running the Go server?

No, the Python plugins require the Go-based server to be actively running because the architecture uses a unified task model defined in `pkg/task/` that coordinates execution, data collection, and result aggregation between the orchestration service and scanning agents.