# AI-Infra-Guard Dependencies: Complete Guide to Go Modules and Python Requirements

> Discover AI-Infra-Guard dependencies. This guide explains Go modules and Python requirements for core orchestration and scanning tasks. Understand the hybrid stack for seamless operation.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: getting-started
- Published: 2026-08-23

---

**AI-Infra-Guard relies on a hybrid dependency stack comprising Go modules for core orchestration and Python packages for specialized scanning tasks across four distinct sub-modules.**

Tencent/AI-Infra-Guard is an open-source security scanning platform that combines a high-performance Go backend with Python-based analysis engines. Understanding the dependencies for AI-Infra-Guard is essential for deployment, development, and troubleshooting across its modular architecture. The project organizes requirements into separate files for the core service and each Python scanning module.

## Core Go Dependencies

The foundation of AI-Infra-Guard is built in Go, with all module declarations centralized in `go.mod` and cryptographic checksums stored in `go.sum`. These files define the runtime and build requirements for the web service, CLI tools, and task orchestration layers.

### Web Framework and Networking

The Go core implements HTTP routing and real-time communication through industry-standard libraries:

- **Gin Web Framework**: `github.com/gin-gonic/gin` powers the REST API endpoints
- **WebSocket Support**: `github.com/gorilla/websocket` enables bidirectional communication with scanning agents
- **CLI Framework**: `github.com/spf13/cobra` provides the command-line interface structure

### Database and Utilities

Data persistence and operational logging rely on specific Go modules:

- **GORM**: `gorm.io/gorm` serves as the ORM for database access and model management
- **Structured Logging**: `github.com/sirupsen/logrus` handles log formatting and output
- **Internal Libraries**: Various Tencent-specific packages manage distributed tracing, configuration management, and Protocol Buffer handling

## Python Sub-Module Dependencies

AI-Infra-Guard distributes specialized scanning capabilities across three Python sub-modules, each maintaining isolated requirements files to prevent dependency conflicts.

### MCP Scan Requirements

The [`mcp-scan/requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/requirements.txt) file defines dependencies for dynamic code-level analysis of machine learning pipelines:

- **PyTorch**: `torch` for neural network inspection
- **TensorFlow**: `tensorflow` for model format parsing
- **Scikit-learn**: `scikit-learn` for classical ML algorithm analysis
- **HTTP Client**: `requests` for fetching remote model assets
- **YAML Processing**: `pyyaml` for rule file parsing

### Agent Scan Requirements

Located at [`agent-scan/requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/requirements.txt), these dependencies support the agent-side execution environment:

- **WebSocket Client**: `websocket-client` for real-time communication with the Go server
- **Data Validation**: `pydantic` for type checking and payload validation
- **Cryptography**: `cryptography` for secure handshake and token authentication protocols

### Prompt Security Requirements

The [`AIG-PromptSecurity/requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/AIG-PromptSecurity/requirements.txt) file contains packages for LLM prompt safety assessment:

- **OpenAI SDK**: `openai` for API interactions with language models
- **Transformers**: `transformers` from HuggingFace for local model evaluation
- **Templating**: `jinja2` for dynamic prompt generation and rendering
- **Testing**: `pytest` for security rule verification and test execution

## Container and Orchestration Files

For containerized deployments, the repository includes Docker composition files that reference the above dependency stacks. The [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) orchestrates the Go core service, while [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml) manages containerized Python scanning environments.

## Installing AI-Infra-Guard Dependencies

To set up the complete development environment, install dependencies for each layer sequentially. Begin with the Go modules, then proceed to the Python virtual environments for each scanning module.

### Go Module Installation

```bash

# Clone the repository

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard

# Download and verify Go modules

go mod download

# Build the CLI binary

go build -o ai-infra-guard ./cmd/cli/main.go

```

### Python Environment Setup

Install requirements for each scanning module in separate virtual environments to avoid conflicts:

**MCP Scanner:**

```bash
cd mcp-scan
pip install -r requirements.txt

```

**Agent Scanner:**

```bash
cd agent-scan
pip install -r requirements.txt

```

**Prompt Security:**

```bash
cd AIG-PromptSecurity
pip install -r requirements.txt

```

## Summary

- **AI-Infra-Guard dependencies** are split between Go modules for core services and Python packages for scanning functionality
- The `go.mod` and `go.sum` files manage Gin, Gorilla WebSocket, Cobra, GORM, and internal Tencent libraries
- Three distinct [`requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/requirements.txt) files isolate Python dependencies for MCP scanning, agent communication, and prompt security analysis
- Docker composition files provide containerized deployment options for the entire stack
- Installation requires sequential setup of the Go compiler and Python pip environments for each sub-module

## Frequently Asked Questions

### What Go version is required to build AI-Infra-Guard?

The `go.mod` file specifies the minimum Go version compatible with the core service. As implemented in Tencent/AI-Infra-Guard, you should use Go 1.21 or later to ensure compatibility with the Gin web framework and GORM database operations.

### Can I install only specific Python scanning modules without the Go core?

Yes, each Python sub-module operates independently. Navigate to `mcp-scan/`, `agent-scan/`, or `AIG-PromptSecurity/` and run `pip install -r requirements.txt` within that specific directory. However, the modules require the Go core running for full orchestration and WebSocket communication.

### Are dependency versions pinned in AI-Infra-Guard?

Yes, the `go.sum` file locks Go module versions with cryptographic hashes, while each [`requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/requirements.txt) pins Python packages to specific versions. This guarantees reproducible builds across development, staging, and production environments according to the source code repository.

### Does AI-Infra-Guard support GPU acceleration for scanning?

The Python MCP scanning module includes `torch` and `tensorflow` in its [`requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/requirements.txt), which can utilize CUDA-enabled GPUs when available. Ensure your environment has the appropriate NVIDIA drivers and CUDA toolkit installed alongside the standard Python dependencies.