How to Perform an AI Infrastructure Scan with AI-Infra-Guard: Complete Setup and Execution Guide
AI-Infra-Guard performs AI infrastructure scans through a hybrid Go-Python architecture where the Go-based CLI orchestrates web services and agents while Python plugins execute vulnerability checks against model servers and pipelines.
AI-Infra-Guard is an open-source security scanning platform developed by Tencent that identifies vulnerabilities in AI model deployments and associated infrastructure. The tool combines a Go-based core service with Python scanning plugins to deliver comprehensive coverage of both static code analysis and runtime environment assessment. This guide explains how to configure and execute a complete AI infrastructure scan using the official Tencent/AI-Infra-Guard repository.
Architecture Overview
The system operates across three logical layers defined in the source structure:
-
Orchestration & API Layer: Implemented in Go under
cmd/cli/, providing the web interface, CLI commands, and WebSocket task scheduler. The entry point resides incmd/cli/main.go, whilecmd/cli/cmd/webserver.gohandles HTTP server initialization. -
Agent Runtime Layer: Comprises the Go agent binary built from
cmd/agent/main.goand supporting Python agents in theagent-scan/directory. This layer establishes persistent WebSocket connections back to the orchestrator for distributed scanning. -
Scanning Plugins Layer: Python modules located in
mcp-scan/,agent-scan/, andAIG-PromptSecurity/that execute concrete vulnerability checks. The unified task model defined inpkg/task/coordinates data structures between layers.
Building the Core Components
Compiling the CLI and Server
Build the primary orchestration binary from the root directory:
go build -o ai-infra-guard ./cmd/cli/main.go
This produces the main executable that handles both the webserver and CLI scanning commands.
Building the Remote Agent
For infrastructure requiring remote assessment, compile the agent binary:
go build -o agent ./cmd/agent
The resulting binary connects to the central server via WebSocket as implemented in cmd/agent/main.go.
Starting the Scanning Service
Launch the HTTP and WebSocket server to enable scanning operations:
./ai-infra-guard webserver --server 127.0.0.1:8088
This command invokes the server logic in cmd/cli/cmd/webserver.go, which listens for CLI connections and agent registrations. The service exposes a JSON API documented in docs/swagger.yaml.
Execution Methods for AI Infrastructure Scanning
Direct CLI Scanning
Run immediate scans without deploying remote agents:
./ai-infra-guard scan -t http://127.0.0.1:8088
The CLI contacts the running server, creates a scan task using the structures in pkg/task/, and aggregates results directly.
Agent-Assisted Remote Scanning
For isolated or external targets, deploy the compiled agent with environment configuration:
AIG_SERVER=127.0.0.1:8088 ./agent
The agent opens a WebSocket channel to receive plugin instructions, executes them on the target host, and streams results back to the server.
Running Specialized Python Plugins
The Python plugins perform deep inspection of AI-specific attack surfaces.
MCP Model Code Analysis
Execute static and dynamic analysis of model code repositories:
pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project
This module targets model-related vulnerabilities and pipeline configurations.
Container and Host Fingerprinting
Assess container-level security and perform remote host fingerprinting:
pip install -r agent-scan/requirements.txt
python agent-scan/main.py --repo /path/to/project --agent_provider /path/to/provider.yaml
The --agent_provider parameter specifies YAML configuration for the scanning provider.
Prompt Injection Security Testing
Detect prompt injection and jailbreak risks:
pip install -r AIG-PromptSecurity/requirements.txt
# Execute specific test scripts from AIG-PromptSecurity/tests/
This component evaluates the security posture of AI model input handling.
Understanding Scan Results and Rule Configuration
After execution, the server returns a JSON report aggregating findings from all active plugins. The scanner references YAML rule bases located in data/vuln/ and data/fingerprints/ to identify known vulnerabilities and system fingerprints. These rule files define the detection signatures consulted by both the Go orchestration layer and the Python scanning modules.
Summary
- Build the Go CLI from
cmd/cli/main.goto establish the orchestration service - Launch the webserver using
cmd/cli/cmd/webserver.goto enable HTTP/WebSocket communication - Execute direct scans via CLI or deploy agents compiled from
cmd/agent/main.gofor remote infrastructure assessment - Run Python plugins from
mcp-scan/andagent-scan/directories to analyze model code and container environments - Reference YAML rule bases in
data/vuln/anddata/fingerprints/for vulnerability definitions and detection logic
Frequently Asked Questions
What is the difference between direct CLI scanning and agent-assisted scanning?
Direct CLI scanning runs locally and connects to the server API for immediate target assessment, while agent-assisted scanning deploys a lightweight binary compiled from cmd/agent/main.go to remote hosts that maintains a persistent WebSocket connection for distributed infrastructure evaluation.
Which Python plugin should I use for analyzing AI model code?
Use the MCP scan module located at mcp-scan/main.py for static and dynamic analysis of model code repositories, as it specifically targets model-related vulnerabilities, pipeline configurations, and associated dependencies.
Where does AI-Infra-Guard store its vulnerability detection rules?
The scanner references YAML rule files located in data/vuln/ and data/fingerprints/, which contain the detection signatures and vulnerability definitions used by both the Go orchestration layer and Python plugins during the AI infrastructure scan process.
Can AI-Infra-Guard scan infrastructure without running the Go server?
No, the Python plugins require the Go-based server to be actively running because the architecture uses a unified task model defined in pkg/task/ that coordinates execution, data collection, and result aggregation between the orchestration service and scanning agents.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →