How to Perform an AI Infrastructure Scan with AI-Infra-Guard: Complete Setup and Execution Guide

AI-Infra-Guard performs AI infrastructure scans through a hybrid Go-Python architecture where the Go-based CLI orchestrates web services and agents while Python plugins execute vulnerability checks against model servers and pipelines.

AI-Infra-Guard is an open-source security scanning platform developed by Tencent that identifies vulnerabilities in AI model deployments and associated infrastructure. The tool combines a Go-based core service with Python scanning plugins to deliver comprehensive coverage of both static code analysis and runtime environment assessment. This guide explains how to configure and execute a complete AI infrastructure scan using the official Tencent/AI-Infra-Guard repository.

Architecture Overview

The system operates across three logical layers defined in the source structure:

  • Orchestration & API Layer: Implemented in Go under cmd/cli/, providing the web interface, CLI commands, and WebSocket task scheduler. The entry point resides in cmd/cli/main.go, while cmd/cli/cmd/webserver.go handles HTTP server initialization.

  • Agent Runtime Layer: Comprises the Go agent binary built from cmd/agent/main.go and supporting Python agents in the agent-scan/ directory. This layer establishes persistent WebSocket connections back to the orchestrator for distributed scanning.

  • Scanning Plugins Layer: Python modules located in mcp-scan/, agent-scan/, and AIG-PromptSecurity/ that execute concrete vulnerability checks. The unified task model defined in pkg/task/ coordinates data structures between layers.

Building the Core Components

Compiling the CLI and Server

Build the primary orchestration binary from the root directory:

go build -o ai-infra-guard ./cmd/cli/main.go

This produces the main executable that handles both the webserver and CLI scanning commands.

Building the Remote Agent

For infrastructure requiring remote assessment, compile the agent binary:

go build -o agent ./cmd/agent

The resulting binary connects to the central server via WebSocket as implemented in cmd/agent/main.go.

Starting the Scanning Service

Launch the HTTP and WebSocket server to enable scanning operations:

./ai-infra-guard webserver --server 127.0.0.1:8088

This command invokes the server logic in cmd/cli/cmd/webserver.go, which listens for CLI connections and agent registrations. The service exposes a JSON API documented in docs/swagger.yaml.

Execution Methods for AI Infrastructure Scanning

Direct CLI Scanning

Run immediate scans without deploying remote agents:

./ai-infra-guard scan -t http://127.0.0.1:8088

The CLI contacts the running server, creates a scan task using the structures in pkg/task/, and aggregates results directly.

Agent-Assisted Remote Scanning

For isolated or external targets, deploy the compiled agent with environment configuration:

AIG_SERVER=127.0.0.1:8088 ./agent

The agent opens a WebSocket channel to receive plugin instructions, executes them on the target host, and streams results back to the server.

Running Specialized Python Plugins

The Python plugins perform deep inspection of AI-specific attack surfaces.

MCP Model Code Analysis

Execute static and dynamic analysis of model code repositories:

pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project

This module targets model-related vulnerabilities and pipeline configurations.

Container and Host Fingerprinting

Assess container-level security and perform remote host fingerprinting:

pip install -r agent-scan/requirements.txt
python agent-scan/main.py --repo /path/to/project --agent_provider /path/to/provider.yaml

The --agent_provider parameter specifies YAML configuration for the scanning provider.

Prompt Injection Security Testing

Detect prompt injection and jailbreak risks:

pip install -r AIG-PromptSecurity/requirements.txt

# Execute specific test scripts from AIG-PromptSecurity/tests/

This component evaluates the security posture of AI model input handling.

Understanding Scan Results and Rule Configuration

After execution, the server returns a JSON report aggregating findings from all active plugins. The scanner references YAML rule bases located in data/vuln/ and data/fingerprints/ to identify known vulnerabilities and system fingerprints. These rule files define the detection signatures consulted by both the Go orchestration layer and the Python scanning modules.

Summary

  • Build the Go CLI from cmd/cli/main.go to establish the orchestration service
  • Launch the webserver using cmd/cli/cmd/webserver.go to enable HTTP/WebSocket communication
  • Execute direct scans via CLI or deploy agents compiled from cmd/agent/main.go for remote infrastructure assessment
  • Run Python plugins from mcp-scan/ and agent-scan/ directories to analyze model code and container environments
  • Reference YAML rule bases in data/vuln/ and data/fingerprints/ for vulnerability definitions and detection logic

Frequently Asked Questions

What is the difference between direct CLI scanning and agent-assisted scanning?

Direct CLI scanning runs locally and connects to the server API for immediate target assessment, while agent-assisted scanning deploys a lightweight binary compiled from cmd/agent/main.go to remote hosts that maintains a persistent WebSocket connection for distributed infrastructure evaluation.

Which Python plugin should I use for analyzing AI model code?

Use the MCP scan module located at mcp-scan/main.py for static and dynamic analysis of model code repositories, as it specifically targets model-related vulnerabilities, pipeline configurations, and associated dependencies.

Where does AI-Infra-Guard store its vulnerability detection rules?

The scanner references YAML rule files located in data/vuln/ and data/fingerprints/, which contain the detection signatures and vulnerability definitions used by both the Go orchestration layer and Python plugins during the AI infrastructure scan process.

Can AI-Infra-Guard scan infrastructure without running the Go server?

No, the Python plugins require the Go-based server to be actively running because the architecture uses a unified task model defined in pkg/task/ that coordinates execution, data collection, and result aggregation between the orchestration service and scanning agents.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →