Is AI-Infra-Guard Open Source? License, Repository Structure, and Usage Guide
AI-Infra-Guard is an open-source AI security red-team platform released under the Apache License 2.0, with complete source code publicly available in the Tencent/AI-Infra-Guard repository.
AI-Infra-Guard is developed by Tencent Zhuque Lab as an open-source project for AI infrastructure security testing. The entire codebase—including the Go-based core server, Python scanning modules, and Docker deployment configurations—is hosted on GitHub and freely available for modification and commercial deployment. This article examines the AI-Infra-Guard license terms, repository architecture, and source code access methods.
AI-Infra-Guard License Terms
The project is officially open-source and distributed under the Apache License 2.0, a permissive license that permits commercial use, modification, and distribution. The full license text resides in the repository root at LICENSE.
Key Apache 2.0 provisions for AI-Infra-Guard users include:
- Commercial use: You may use the software in proprietary applications without licensing fees
- Modification: You can fork and modify the Go and Python source code to suit specific requirements
- Distribution: You can redistribute the software alongside your own applications
- Attribution: You must retain the original copyright notice and license text in all copies
Repository Architecture and Source Code Structure
AI-Infra-Guard follows a hybrid-stack architecture documented in [docs/architecture_evolution.md](https://github.com/Tencent/AI-Infra-Guard/blob/main/docs/architecture_evolution.md), combining Go backend services with Python security scanners. The open-source repository contains all components necessary for deployment and extension.
Go Core Components
The primary application logic resides in Go source files under the cmd/ directory:
cmd/cli/main.go: Entry point for the web server and command-line interface. This file compiles into theai-infra-guardbinary that provides thewebservercommand and REST API endpoints defined inapi.md.cmd/agent/main.go: Standalone agent process that connects to the core server via WebSocket for distributed scanning operations.
Python Scanning Modules
The repository includes specialized Python sub-modules for dynamic security analysis:
mcp-scan/main.py: Performs dynamic code and model scanning using the MCP (Model Context Protocol) framework.agent-scan/main.py: Audits AI agents and their skill packages for vulnerabilities.AIG-PromptSecurity/cli/: Contains command-line tools for evaluating prompts against jailbreak and malicious intent detection.
Configuration and Deployment Files
docker-compose.ymlanddocker-compose.images.yml: Orchestrate the Go server, Python services, and optional UI components.data/: Stores vulnerability signatures, fingerprint rules, and evaluation datasets in YAML format.
How to Access and Use the Open Source Code
You can deploy AI-Infra-Guard using pre-built Docker images or compile directly from the open-source Go and Python code.
Quick Start with Docker
Run the complete stack using the official Docker Compose configuration:
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker-compose -f docker-compose.images.yml up -d
# Verify the deployment
curl http://localhost:8088/api/v1/status
Building from Source
Compile the Go binaries and run Python scanners manually:
# Build the Go CLI binary
go build -o ai-infra-guard ./cmd/cli/main.go
# Start the web server
./ai-infra-guard webserver --server 127.0.0.1:8088
# Install and run the Python MCP scanner
pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project
Installing Individual Python Packages
The repository packages can be installed independently via pip for specific scanning tasks:
pip install aig-skill-scan
export LLM_API_KEY="your-key"
aig-skill-scan --repo ./my-skill \
-m deepseek-v4-flash \
--language en \
-o result.json
Running Agent Security Scans
Audit AI agents using the standalone agent scanner:
pip install -r agent-scan/requirements.txt
python agent-scan/main.py --repo ./my-agent \
--agent_provider ./provider.yaml
Summary
- AI-Infra-Guard is fully open-source under the Apache License 2.0, permitting commercial and private use without restriction.
- The repository contains hybrid Go/Python source code with entry points at
cmd/cli/main.goandmcp-scan/main.py. - You can deploy via Docker Compose using
docker-compose.images.ymlor build from source using standard Go and Python tooling. - The LICENSE file in the repository root contains the full Apache 2.0 legal text and attribution requirements.
Frequently Asked Questions
Is AI-Infra-Guard free for commercial use?
Yes. The Apache License 2.0 allows unrestricted commercial use, modification, and distribution of the AI-Infra-Guard codebase. You can integrate the scanning modules into proprietary security products or offer hosted services based on the software, provided you retain the original license and copyright notices in the LICENSE file.
Where can I find the AI-Infra-Guard source code?
The complete source code is available in the Tencent/AI-Infra-Guard repository on GitHub. The repository includes the Go core (cmd/cli/main.go), Python scanners (mcp-scan/main.py, agent-scan/main.py), Docker configurations, and the LICENSE file containing the Apache 2.0 terms.
What programming languages does AI-Infra-Guard use?
AI-Infra-Guard uses a hybrid stack. The core server and CLI are written in Go (located in cmd/cli/main.go and cmd/agent/main.go), while the specialized security scanners are implemented in Python (located in mcp-scan/main.py and agent-scan/main.py). The web frontend uses Vue/TypeScript.
Do I need to contribute modifications back to the project?
No. The Apache License 2.0 does not require you to contribute modifications back to the upstream repository. However, if you distribute the software or derivative works, you must include the original license text and attribute the original authors. Contributing improvements via pull requests is encouraged but not legally required.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →