# Is AI-Infra-Guard Open Source? License, Repository Structure, and Usage Guide

> AI-Infra-Guard is an open-source AI security red-team platform under Apache License 2.0. Explore its repository structure and usage guide to secure your AI systems.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: getting-started
- Published: 2026-08-26

---

**AI-Infra-Guard is an open-source AI security red-team platform released under the Apache License 2.0, with complete source code publicly available in the Tencent/AI-Infra-Guard repository.**

AI-Infra-Guard is developed by Tencent Zhuque Lab as an open-source project for AI infrastructure security testing. The entire codebase—including the Go-based core server, Python scanning modules, and Docker deployment configurations—is hosted on GitHub and freely available for modification and commercial deployment. This article examines the AI-Infra-Guard license terms, repository architecture, and source code access methods.

## AI-Infra-Guard License Terms

The project is officially **open-source** and distributed under the **Apache License 2.0**, a permissive license that permits commercial use, modification, and distribution. The full license text resides in the repository root at [`LICENSE`](https://github.com/Tencent/AI-Infra-Guard/blob/main/LICENSE).

Key Apache 2.0 provisions for AI-Infra-Guard users include:

- **Commercial use**: You may use the software in proprietary applications without licensing fees
- **Modification**: You can fork and modify the Go and Python source code to suit specific requirements
- **Distribution**: You can redistribute the software alongside your own applications
- **Attribution**: You must retain the original copyright notice and license text in all copies

## Repository Architecture and Source Code Structure

AI-Infra-Guard follows a **hybrid-stack architecture** documented in [[`docs/architecture_evolution.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docs/architecture_evolution.md)](https://github.com/Tencent/AI-Infra-Guard/blob/main/docs/architecture_evolution.md), combining Go backend services with Python security scanners. The open-source repository contains all components necessary for deployment and extension.

### Go Core Components

The primary application logic resides in Go source files under the `cmd/` directory:

- **[`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go)**: Entry point for the web server and command-line interface. This file compiles into the `ai-infra-guard` binary that provides the `webserver` command and REST API endpoints defined in [`api.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/api.md).
- **[`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go)**: Standalone agent process that connects to the core server via WebSocket for distributed scanning operations.

### Python Scanning Modules

The repository includes specialized Python sub-modules for dynamic security analysis:

- **[`mcp-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/main.py)**: Performs dynamic code and model scanning using the MCP (Model Context Protocol) framework.
- **[`agent-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/main.py)**: Audits AI agents and their skill packages for vulnerabilities.
- **`AIG-PromptSecurity/cli/`**: Contains command-line tools for evaluating prompts against jailbreak and malicious intent detection.

### Configuration and Deployment Files

- **[`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml)** and **[`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml)**: Orchestrate the Go server, Python services, and optional UI components.
- **`data/`**: Stores vulnerability signatures, fingerprint rules, and evaluation datasets in YAML format.

## How to Access and Use the Open Source Code

You can deploy AI-Infra-Guard using pre-built Docker images or compile directly from the open-source Go and Python code.

### Quick Start with Docker

Run the complete stack using the official Docker Compose configuration:

```bash
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker-compose -f docker-compose.images.yml up -d

# Verify the deployment

curl http://localhost:8088/api/v1/status

```

### Building from Source

Compile the Go binaries and run Python scanners manually:

```bash

# Build the Go CLI binary

go build -o ai-infra-guard ./cmd/cli/main.go

# Start the web server

./ai-infra-guard webserver --server 127.0.0.1:8088

# Install and run the Python MCP scanner

pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project

```

### Installing Individual Python Packages

The repository packages can be installed independently via pip for specific scanning tasks:

```bash
pip install aig-skill-scan
export LLM_API_KEY="your-key"
aig-skill-scan --repo ./my-skill \
                -m deepseek-v4-flash \
                --language en \
                -o result.json

```

### Running Agent Security Scans

Audit AI agents using the standalone agent scanner:

```bash
pip install -r agent-scan/requirements.txt
python agent-scan/main.py --repo ./my-agent \
                          --agent_provider ./provider.yaml

```

## Summary

- AI-Infra-Guard is fully **open-source** under the **Apache License 2.0**, permitting commercial and private use without restriction.
- The repository contains **hybrid Go/Python source code** with entry points at [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) and [`mcp-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/main.py).
- You can deploy via **Docker Compose** using [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml) or build from source using standard Go and Python tooling.
- The **LICENSE file** in the repository root contains the full Apache 2.0 legal text and attribution requirements.

## Frequently Asked Questions

### Is AI-Infra-Guard free for commercial use?

Yes. The Apache License 2.0 allows unrestricted commercial use, modification, and distribution of the AI-Infra-Guard codebase. You can integrate the scanning modules into proprietary security products or offer hosted services based on the software, provided you retain the original license and copyright notices in the `LICENSE` file.

### Where can I find the AI-Infra-Guard source code?

The complete source code is available in the **Tencent/AI-Infra-Guard** repository on GitHub. The repository includes the Go core ([`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go)), Python scanners ([`mcp-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/main.py), [`agent-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/main.py)), Docker configurations, and the `LICENSE` file containing the Apache 2.0 terms.

### What programming languages does AI-Infra-Guard use?

AI-Infra-Guard uses a **hybrid stack**. The core server and CLI are written in **Go** (located in [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) and [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go)), while the specialized security scanners are implemented in **Python** (located in [`mcp-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/main.py) and [`agent-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/main.py)). The web frontend uses Vue/TypeScript.

### Do I need to contribute modifications back to the project?

No. The Apache License 2.0 does not require you to contribute modifications back to the upstream repository. However, if you distribute the software or derivative works, you must include the original license text and attribute the original authors. Contributing improvements via pull requests is encouraged but not legally required.