How to Use the AI-Infra-Guard WebUI: Complete Setup and Scanning Guide

AI-Infra-Guard provides a browser-based interface at http://localhost:8088 for running three security assessments—AI infrastructure scans, MCP server analysis, and jailbreak evaluations—with real-time progress streaming via WebSocket.

The Tencent/AI-Infra-Guard project delivers a comprehensive security scanning platform for AI infrastructure and LLM deployments. This guide explains how to use the AI-Infra-Guard WebUI to perform vulnerability assessments through an intuitive browser interface without writing complex CLI commands.

Architecture Overview

The WebUI follows a Go-backend, Vue.js-frontend architecture with real-time communication channels. Understanding this structure helps troubleshoot connectivity issues and extend functionality.

Backend Components

The Go binary built from cmd/cli/main.go serves as the entry point. When invoked with the webserver sub-command, it initializes an HTTP server on 127.0.0.1:8088 by default. This server handles three critical responsibilities:

  • Serves static assets (HTML, CSS, JavaScript) from the repository’s web/ directory
  • Exposes REST endpoints under /api/scan/* implemented in internal/api/scan.go
  • Manages a WebSocket hub defined in common/websocket/hub.go for real-time task updates

Frontend Implementation

The browser interface is a Vue.js application bundled under the web/ directory. The main component in web/src/App.vue renders three assessment panels, manages form state, and subscribes to the WebSocket at ws://localhost:8088/ws/tasks for progress notifications.

Building and Starting the WebUI Server

Before accessing the interface, compile the Go binary and launch the server.

Step 1: Build the Binary

Run the following command from the repository root to generate the aig executable:

go build -o aig ./cmd/cli/main.go

This creates a platform-specific binary that embeds the web assets and Python scanning modules.

Step 2: Launch the Server

Start the WebUI server by specifying the bind address and port:

./aig webserver --server 127.0.0.1:8088

The server logs indicate when the HTTP listener is active. Navigate to http://localhost:8088 in your browser to load the interface.

Running AI Infrastructure Scans

The AI Infra Scan fingerprints running AI services (vLLM, Ollama, ComfyUI) against a database of over 2,000 known CVEs.

Configuration Steps

  1. Select "AI基础设施安全扫描 / AI Infra Scan" from the landing page
  2. Enter the target service address (e.g., http://127.0.0.1:8000)
  3. Click Start Scan

Technical Flow

The UI sends a REST POST request to /api/scan/infra with the target payload. The handler in internal/api/scan.go creates a task via the pkg/task manager, which orchestrates the scan. Progress updates stream through the WebSocket bridge, and the final report renders as a table showing component versions, matched CVEs, severity ratings, and remediation links.

Scanning MCP Servers and Agent Skills

The MCP Scan analyzes Model Context Protocol server code for vulnerabilities and evaluates registered agent skills.

Input Methods

The WebUI accepts two input types:

  • Source Archive: Upload a .zip or .tar.gz file containing the MCP server code
  • Git URL: Provide a remote repository address (e.g., https://github.com/user/mcp-server)

Execution Process

After clicking Start Scan, the backend spawns a Python subprocess running mcp-scan/main.py. The task controller monitors execution and pipes results through the WebSocket connection established in common/websocket/hub.go. The report highlights discovered plugins, risky agent skills, and any CVEs present in the codebase.

Performing Jailbreak Evaluations

The Jailbreak Evaluation assesses LLM resistance to adversarial prompts using standardized datasets.

Prerequisites

Navigate to Settings → Model Config and configure:

  • Base URL: The LLM API endpoint
  • API Key: Authentication token (stored only in the browser session, never persisted server-side)

Running the Assessment

  1. Select a dataset from the dropdown (datasets reside in data/eval/)
  2. Click Run Evaluation

The backend initiates the jailbreak evaluator as a subprocess, streaming per-prompt success rates and final safety scores to the Vue.js frontend via WebSocket messages.

Real-Time Updates via WebSocket

All three assessment types utilize a unified real-time communication layer. The frontend establishes a connection to ws://localhost:8088/ws/tasks as implemented in web/src/App.vue.

Message Handling

The browser processes three message types:

  • progress: Updates the visual progress bar component (web/src/components/ProgressBar.vue)
  • log: Displays streaming terminal output
  • result: Renders the final JSON report in the results table

Accessing API Documentation

For programmatic integration or debugging, the server exposes auto-generated Swagger documentation at:


http://localhost:8088/docs/index.html

This interface documents all REST endpoints including /api/scan/infra, /api/scan/mcp, and /api/eval/jailbreak with request schemas and example payloads.

Example API Call

You can trigger scans directly via curl without the UI:

curl -X POST http://127.0.0.1:8088/api/scan/infra \
     -H "Content-Type: application/json" \
     -d '{"targets":["http://127.0.0.1:8000"]}'

Summary

  • The AI-Infra-Guard WebUI runs on http://localhost:8088 after building with go build -o aig ./cmd/cli/main.go and executing ./aig webserver
  • Three assessment modules are available: AI Infra Scan, MCP Server & Agent Skills Scan, and Jailbreak Evaluation
  • Real-time progress relies on WebSocket connections managed by common/websocket/hub.go and rendered in web/src/App.vue
  • REST endpoints in internal/api/scan.go handle task creation while Python subprocesses perform the actual security analysis
  • API documentation is accessible via Swagger UI at /docs/index.html

Frequently Asked Questions

How do I change the default port for the AI-Infra-Guard WebUI?

Modify the --server flag when launching the webserver. For example, use ./aig webserver --server 0.0.0.0:9000 to bind to port 9000 on all interfaces. The address must be reachable by your browser for the WebSocket connection to function.

Is the API key for jailbreak evaluations stored on the server?

No. According to the implementation in web/src/App.vue, API keys entered in Settings → Model Config are kept in the browser's session state only. The key is sent with each evaluation request but never persisted to disk or server configuration files.

Can I run the AI-Infra-Guard WebUI without building from source?

The current implementation requires building the Go binary from cmd/cli/main.go to bundle the static assets and establish the HTTP/WebSocket server. Pre-built releases may be available in the Tencent/AI-Infra-Guard repository releases page, but compilation from source ensures compatibility with your specific platform and Go version.

What Python modules does the WebUI execute during scans?

The task manager spawns three distinct Python subprocesses depending on the scan type: mcp-scan/main.py for MCP analysis, agent-scan/main.py for agent skill evaluation, and the jailbreak evaluator for LLM safety testing. These modules are located within the repository's Python package directories and execute asynchronously while streaming output through the Go WebSocket hub.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →