What Are the Core Components of AI-Infra-Guard? A Complete Architecture Guide
AI-Infra-Guard consists of four core components: a Go-based backend application for orchestration and web services, three specialized Python scanning submodules for MCP, agent, and prompt security analysis, YAML-based rules and knowledge base data for detection logic, and Docker deployment configurations for containerized operation.
The Tencent/AI-Infra-Guard repository implements a hybrid-technology AI security scanning platform designed to identify vulnerabilities across infrastructure layers. Understanding the core components of AI-Infra-Guard reveals how the system balances high-performance task orchestration with specialized security analysis capabilities. This architecture enables flexible deployment via CLI, web interface, or containerized environments.
The Go Core Application (Backend Engine)
The Go 主应用 (Go main application) serves as the central nervous system of the platform. Written in Go, this component provides the web service, CLI interface, task orchestration, and rule engine that coordinate all scanning activities.
The primary entry point resides in cmd/cli/main.go, which initializes the application and routes commands to specialized handlers. For web-based operations, cmd/cli/cmd/webserver.go launches the HTTP server, while cmd/cli/cmd/scan.go handles CLI-triggered scanning tasks. According to the AI-Infra-Guard source code, the system utilizes common/websocket/server.go to manage real-time communication channels required for agent-based operations.
This Go backend efficiently manages concurrent scanning jobs while maintaining low resource overhead, making it suitable for both lightweight CLI usage and sustained web service deployment.
Python Scanner Submodules
AI-Infra-Guard offloads specialized security analysis to three distinct Python sub-projects, each targeting specific attack vectors in AI infrastructure:
MCP Scanner (mcp-scan)
The mcp-scan/ directory contains a code-level and dynamic scanning engine that analyzes Model Context Protocol (MCP) implementations. The entry point at mcp-scan/main.py accepts repository paths and performs static analysis alongside dynamic behavior monitoring. This module detects vulnerable code patterns and runtime security issues in MCP integrations.
Agent Workflow Scanner (agent-scan)
Located in agent-scan/, this submodule performs agent-based workflow scanning to evaluate how AI agents interact with external systems. Executed via agent-scan/main.py, it requires a provider configuration file (--agent_provider) and simulates agent execution paths to identify privilege escalation or unauthorized data access vulnerabilities.
Prompt Security Analyzer (AIG-PromptSecurity)
The AIG-PromptSecurity/ directory houses a dedicated prompt-injection security assessment tool. The AIG-PromptSecurity/main.py script evaluates input validation mechanisms and prompt sanitization routines, testing for jailbreak vulnerabilities and injection attacks that could compromise model behavior.
Rules and Knowledge Base Data
The detection capabilities of AI-Infra-Guard rely on a comprehensive collection of YAML-based rule files stored across multiple data directories:
data/fingerprints/contains fingerprint rule definitions that identify specific AI frameworks, libraries, and configuration patternsdata/vuln/anddata/vuln_en/store the vulnerability database in Chinese and English respectively, containing detailed descriptions of known AI infrastructure weaknessesdata/mcp/holds MCP-specific detection signaturesdata/eval/contains evaluation datasets for testing scanner accuracy
These files drive the detection logic used by both the Go rule engine and Python analyzers, allowing the system to recognize vulnerable dependencies, misconfigurations, and known CVE signatures without hardcoding detection patterns into the application binaries.
Docker Deployment Orchestration
AI-Infra-Guard provides two containerization strategies through Docker Compose configurations:
docker-compose.ymlbuilds the entire platform from source code, compiling the Go backend and installing Python dependencies during the image creation processdocker-compose.images.ymlpulls pre-built images from container registries for rapid deployment without compilation overhead
These orchestration files enable consistent deployment across development, staging, and production environments while managing service dependencies and network configurations automatically.
Practical Implementation Examples
To interact with the core components of AI-Infra-Guard directly, use the following commands:
Build and run the Go web service (the core backend):
go build -o ai-infra-guard ./cmd/cli/main.go
./ai-infra-guard webserver --server 127.0.0.1:8088
Execute an MCP scan with the Python module:
pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/target/project
Run an Agent-based scan (Python):
pip install -r agent-scan/requirements.txt
python agent-scan/main.py --repo /path/to/target/project \
--agent_provider /path/to/provider.yaml
Launch the whole platform via Docker (uses pre-built images):
docker-compose -f docker-compose.images.yml up -d
Summary
- Go Backend: The
cmd/cli/main.goentry point provides CLI, web server, and orchestration capabilities with WebSocket support incommon/websocket/server.go - Python Scanners: Three specialized modules (
mcp-scan/,agent-scan/,AIG-PromptSecurity/) handle MCP analysis, agent workflows, and prompt injection testing - Rule Data: YAML files in
data/fingerprints/,data/vuln/, and related directories supply the detection logic and vulnerability knowledge base - Containerization:
docker-compose.ymlanddocker-compose.images.ymlenable flexible deployment options from source or pre-built images
Frequently Asked Questions
What programming languages does AI-Infra-Guard use?
AI-Infra-Guard utilizes a hybrid architecture written in Go and Python. The Go component (cmd/cli/main.go) handles the web service, CLI interface, and task orchestration for performance-critical operations. Python modules handle specialized security scanning tasks including MCP analysis, agent-based workflows, and prompt injection testing, leveraging Python's extensive security and AI libraries.
How do I run a specific scanner module independently?
Each Python scanner operates as a standalone executable. For MCP scanning, run python mcp-scan/main.py --repo /target/path. For agent-based scanning, execute python agent-scan/main.py with the required --agent_provider parameter pointing to a provider configuration YAML file. These modules do not require the Go backend to function for single-scan operations.
Where are the vulnerability detection rules stored?
Detection rules reside in the data/ directory hierarchy. Fingerprinting rules live in data/fingerprints/, while vulnerability definitions are split between data/vuln/ (Chinese) and data/vuln_en/ (English) for international accessibility. MCP-specific signatures are stored in data/mcp/, and evaluation datasets occupy data/eval/. All rules use YAML format for human-readable configuration and version control.
Can AI-Infra-Guard be deployed entirely via Docker?
Yes. The platform supports two Docker deployment modes according to the Tencent/AI-Infra-Guard source code. Use docker-compose.images.yml to pull pre-built images for immediate deployment, or docker-compose.yml to build the Go backend and Python environments from source. Both configurations orchestrate the complete stack including the web interface, backend API, and scanner modules.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →