AI-Infra-Guard Dependencies: Complete Guide to Go Modules and Python Requirements
AI-Infra-Guard relies on a hybrid dependency stack comprising Go modules for core orchestration and Python packages for specialized scanning tasks across four distinct sub-modules.
Tencent/AI-Infra-Guard is an open-source security scanning platform that combines a high-performance Go backend with Python-based analysis engines. Understanding the dependencies for AI-Infra-Guard is essential for deployment, development, and troubleshooting across its modular architecture. The project organizes requirements into separate files for the core service and each Python scanning module.
Core Go Dependencies
The foundation of AI-Infra-Guard is built in Go, with all module declarations centralized in go.mod and cryptographic checksums stored in go.sum. These files define the runtime and build requirements for the web service, CLI tools, and task orchestration layers.
Web Framework and Networking
The Go core implements HTTP routing and real-time communication through industry-standard libraries:
- Gin Web Framework:
github.com/gin-gonic/ginpowers the REST API endpoints - WebSocket Support:
github.com/gorilla/websocketenables bidirectional communication with scanning agents - CLI Framework:
github.com/spf13/cobraprovides the command-line interface structure
Database and Utilities
Data persistence and operational logging rely on specific Go modules:
- GORM:
gorm.io/gormserves as the ORM for database access and model management - Structured Logging:
github.com/sirupsen/logrushandles log formatting and output - Internal Libraries: Various Tencent-specific packages manage distributed tracing, configuration management, and Protocol Buffer handling
Python Sub-Module Dependencies
AI-Infra-Guard distributes specialized scanning capabilities across three Python sub-modules, each maintaining isolated requirements files to prevent dependency conflicts.
MCP Scan Requirements
The mcp-scan/requirements.txt file defines dependencies for dynamic code-level analysis of machine learning pipelines:
- PyTorch:
torchfor neural network inspection - TensorFlow:
tensorflowfor model format parsing - Scikit-learn:
scikit-learnfor classical ML algorithm analysis - HTTP Client:
requestsfor fetching remote model assets - YAML Processing:
pyyamlfor rule file parsing
Agent Scan Requirements
Located at agent-scan/requirements.txt, these dependencies support the agent-side execution environment:
- WebSocket Client:
websocket-clientfor real-time communication with the Go server - Data Validation:
pydanticfor type checking and payload validation - Cryptography:
cryptographyfor secure handshake and token authentication protocols
Prompt Security Requirements
The AIG-PromptSecurity/requirements.txt file contains packages for LLM prompt safety assessment:
- OpenAI SDK:
openaifor API interactions with language models - Transformers:
transformersfrom HuggingFace for local model evaluation - Templating:
jinja2for dynamic prompt generation and rendering - Testing:
pytestfor security rule verification and test execution
Container and Orchestration Files
For containerized deployments, the repository includes Docker composition files that reference the above dependency stacks. The docker-compose.yml orchestrates the Go core service, while docker-compose.images.yml manages containerized Python scanning environments.
Installing AI-Infra-Guard Dependencies
To set up the complete development environment, install dependencies for each layer sequentially. Begin with the Go modules, then proceed to the Python virtual environments for each scanning module.
Go Module Installation
# Clone the repository
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
# Download and verify Go modules
go mod download
# Build the CLI binary
go build -o ai-infra-guard ./cmd/cli/main.go
Python Environment Setup
Install requirements for each scanning module in separate virtual environments to avoid conflicts:
MCP Scanner:
cd mcp-scan
pip install -r requirements.txt
Agent Scanner:
cd agent-scan
pip install -r requirements.txt
Prompt Security:
cd AIG-PromptSecurity
pip install -r requirements.txt
Summary
- AI-Infra-Guard dependencies are split between Go modules for core services and Python packages for scanning functionality
- The
go.modandgo.sumfiles manage Gin, Gorilla WebSocket, Cobra, GORM, and internal Tencent libraries - Three distinct
requirements.txtfiles isolate Python dependencies for MCP scanning, agent communication, and prompt security analysis - Docker composition files provide containerized deployment options for the entire stack
- Installation requires sequential setup of the Go compiler and Python pip environments for each sub-module
Frequently Asked Questions
What Go version is required to build AI-Infra-Guard?
The go.mod file specifies the minimum Go version compatible with the core service. As implemented in Tencent/AI-Infra-Guard, you should use Go 1.21 or later to ensure compatibility with the Gin web framework and GORM database operations.
Can I install only specific Python scanning modules without the Go core?
Yes, each Python sub-module operates independently. Navigate to mcp-scan/, agent-scan/, or AIG-PromptSecurity/ and run pip install -r requirements.txt within that specific directory. However, the modules require the Go core running for full orchestration and WebSocket communication.
Are dependency versions pinned in AI-Infra-Guard?
Yes, the go.sum file locks Go module versions with cryptographic hashes, while each requirements.txt pins Python packages to specific versions. This guarantees reproducible builds across development, staging, and production environments according to the source code repository.
Does AI-Infra-Guard support GPU acceleration for scanning?
The Python MCP scanning module includes torch and tensorflow in its requirements.txt, which can utilize CUDA-enabled GPUs when available. Ensure your environment has the appropriate NVIDIA drivers and CUDA toolkit installed alongside the standard Python dependencies.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →