# Key Features of AI-Infra-Guard: A Deep Dive into Tencent's Security Red-Team Platform

> Explore AI-Infra-Guard's key features, Tencent's advanced security red-team platform. Discover vulnerability scanning, MCP analysis, agent simulation, and jailbreak evaluation.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: deep-dive
- Published: 2026-08-26

---

**AI-Infra-Guard is a modular, multi-language security red-team platform that provides AI infrastructure vulnerability scanning, MCP server analysis, agent workflow simulation, and jailbreak evaluation through a unified web interface and CLI toolset.**

Developed by Tencent, AI-Infra-Guard (AIG) targets the emerging attack surface of modern AI systems. The platform integrates over 2,000 CVE detection rules and 14+ security categories to audit everything from underlying inference engines to high-level agent orchestration. Its architecture combines a Go-based backend service with a Vue-based frontend, offering both real-time web scanning capabilities and CI/CD-friendly command-line interfaces.

## AI Infrastructure Vulnerability Scanning

The **AI Infrastructure Vulnerability Scan** capability fingerprints running AI services and matches them against known vulnerabilities. In [`pkg/vulstruct/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/vulstruct/scanner.go), the scanner connects to targets like vLLM, Ollama, or ComfyUI instances, parses their version responses, and correlates findings against a database of 2,000+ CVE rules.

This feature detects outdated components and misconfigurations in self-hosted inference infrastructure. Security teams can audit internal model serving endpoints without disrupting production traffic, receiving detailed reports through the web UI or JSON exports.

## MCP Server and Agent-Skill Security Analysis

AI-Infra-Guard extends security testing to the **Model Context Protocol (MCP)** ecosystem through the module implemented in [`internal/mcp/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/scanner.go). The parser loads remote or local MCP server definitions and agent-skill source trees, evaluating them against 14+ security categories including tool hijacking, insecure dependencies, and privilege escalation vectors.

The MCP plugin system in [`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go) dynamically loads rule sets from the `data/mcp/` directory. This extensible design allows security researchers to add new detection logic for emerging MCP-specific threats without modifying the core scanner engine.

## Agent Workflow Red-Teaming

The **Agent Scan** capability simulates multi-agent execution paths to identify runtime risks like tool poisoning, memory manipulation, and jailbreak vulnerabilities. Implemented in [`common/agent/agent.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/agent/agent.go), the `AgentManager` coordinates task execution across complex workflows such as Dify or Coze configurations.

Unlike static code analysis, this feature executes dynamic simulations where malicious prompts propagate through agent chains. The analyzer tracks how data flows between tools and memory stores, flagging potential sandbox escapes or unauthorized function calls before deployment.

## Jailbreak Evaluation and API Security Testing

For LLM robustness validation, AI-Infra-Guard includes a **Jailbreak Evaluation** engine triggered via [`common/websocket/knowledge_api.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/knowledge_api.go). The system runs curated datasets against configured endpoints using multi-turn attack strategies including Many-Shot, PAIR, GOAT, and ActorAttack methodologies.

The platform also provides **Model & API Relay Checking** through [`common/websocket/api.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/api.go). When configured with `APICheckerURL`, this proxy performs Claude-signature verification, model fingerprinting, and black-box auditing via PAMELA and Ventor-QTest integrations.

## Modular Architecture and Extensibility

The backend architecture centers on [`common/websocket/server.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/server.go), which bootstraps a Gin router and injects three core managers:

- **TaskManager** ([`common/websocket/task_manager.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/task_manager.go)): Orchestrates scan jobs, handles chunked file uploads, and streams progress via Server-Sent Events (SSE)
- **AgentManager** ([`common/agent/agent.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/agent/agent.go)): Drives multi-agent red-team workflows and external process coordination
- **ModelManager**: Handles LLM endpoint configuration and model metadata persistence

Data persistence uses a lightweight SQLite abstraction layer defined in [`pkg/database/model.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/model.go) and [`pkg/database/task.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/task.go). Rule loading occurs at startup via [`pkg/database/yaml_model.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/yaml_model.go), which converts YAML definitions into Go structs for the fingerprint database (`data/fingerprints/`), vulnerability rules (`data/vuln/`), and evaluation datasets (`data/eval/`).

## Deployment and CLI Integration

AI-Infra-Guard supports multiple deployment modes via [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go), which parses sub-commands to launch either the full web server or individual scanners.

Start the complete platform using Docker Compose:

```bash
docker compose -f docker-compose.images.yml up -d

# Access the Vue-based UI at http://localhost:8088

```

For CI/CD integration, use the standalone CLI tools:

```bash

# Scan AI infrastructure (vLLM, etc.)

aig-infra-scan http://127.0.0.1:8000

# Analyze MCP skills with specific models

pip install aig-skill-scan
export LLM_API_KEY="your-api-key"
aig-skill-scan --repo ./my-skill -m deepseek-v4-flash -o result.json

```

Submit tasks programmatically via the REST API:

```bash
curl -X POST http://localhost:8088/api/v1/app/tasks \
     -H "Content-Type: application/json" \
     -d '{"type":"infra","target":"http://127.0.0.1:8000"}'

```

The Vue-based frontend provides real-time scan progress, automatic Swagger documentation generation, and one-click initiation of all scan types.

## Summary

- **Comprehensive Coverage**: Scans AI infrastructure (2,000+ CVEs), MCP servers (14+ categories), and agent workflows through specialized modules in `pkg/vulstruct/`, `internal/mcp/`, and `common/agent/`
- **Dynamic Simulation**: Executes multi-agent red-team exercises and jailbreak attacks (Many-Shot, PAIR, GOAT) rather than relying solely on static analysis
- **Extensible Rule Engine**: Supports custom fingerprints, vulnerability definitions, and MCP plugins via YAML files in the `data/` directory loaded by [`pkg/database/yaml_model.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/yaml_model.go)
- **Flexible Deployment**: Offers a full-stack web UI served by [`common/websocket/server.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/server.go) alongside CLI tools (`aig-skill-scan`, `mcp-scan`) for pipeline integration
- **Modern Architecture**: Uses Gin framework with SQLite persistence, SSE progress streaming, and WebSocket support for real-time scanning feedback

## Frequently Asked Questions

### How does AI-Infra-Guard detect vulnerabilities in AI infrastructure?

The scanner in [`pkg/vulstruct/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/vulstruct/scanner.go) performs service fingerprinting by connecting to running AI endpoints (vLLM, Ollama, etc.), extracting version information from responses, and matching these against a curated database of 2,000+ CVE rules stored in `data/vuln/`. This passive scanning approach identifies outdated components without requiring access to source code or internal APIs.

### What security categories does the MCP scanner evaluate?

The MCP scanner implemented in [`internal/mcp/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/scanner.go) evaluates servers and agent skills against 14+ security categories including tool hijacking, insecure dependencies, privilege escalation, and unauthorized data access. Users can extend coverage by adding new rule files to the `data/mcp/` directory, which the plugin system loads automatically at startup via [`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go).

### Can AI-Infra-Guard integrate into existing CI/CD pipelines?

Yes. The platform provides standalone CLI entry points through [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go), including `aig-skill-scan`, `mcp-scan`, and `agent-scan` utilities. These tools support JSON output flags and non-interactive execution, allowing automated security scanning of AI skills and MCP servers during build processes before production deployment.

### What types of jailbreak attacks does the evaluation module support?

The jailbreak evaluation engine accessed via [`common/websocket/knowledge_api.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/knowledge_api.go) implements multi-turn attack strategies including Many-Shot prompting, PAIR (Prompt Automatic Iterative Refinement), GOAT (Generative Offensive Agent Tester), and ActorAttack. These methodologies test LLM robustness against sophisticated adversarial prompting techniques beyond simple single-turn injection attempts.