Key Features of AI-Infra-Guard: A Deep Dive into Tencent's Security Red-Team Platform
AI-Infra-Guard is a modular, multi-language security red-team platform that provides AI infrastructure vulnerability scanning, MCP server analysis, agent workflow simulation, and jailbreak evaluation through a unified web interface and CLI toolset.
Developed by Tencent, AI-Infra-Guard (AIG) targets the emerging attack surface of modern AI systems. The platform integrates over 2,000 CVE detection rules and 14+ security categories to audit everything from underlying inference engines to high-level agent orchestration. Its architecture combines a Go-based backend service with a Vue-based frontend, offering both real-time web scanning capabilities and CI/CD-friendly command-line interfaces.
AI Infrastructure Vulnerability Scanning
The AI Infrastructure Vulnerability Scan capability fingerprints running AI services and matches them against known vulnerabilities. In pkg/vulstruct/scanner.go, the scanner connects to targets like vLLM, Ollama, or ComfyUI instances, parses their version responses, and correlates findings against a database of 2,000+ CVE rules.
This feature detects outdated components and misconfigurations in self-hosted inference infrastructure. Security teams can audit internal model serving endpoints without disrupting production traffic, receiving detailed reports through the web UI or JSON exports.
MCP Server and Agent-Skill Security Analysis
AI-Infra-Guard extends security testing to the Model Context Protocol (MCP) ecosystem through the module implemented in internal/mcp/scanner.go. The parser loads remote or local MCP server definitions and agent-skill source trees, evaluating them against 14+ security categories including tool hijacking, insecure dependencies, and privilege escalation vectors.
The MCP plugin system in internal/mcp/plugins.go dynamically loads rule sets from the data/mcp/ directory. This extensible design allows security researchers to add new detection logic for emerging MCP-specific threats without modifying the core scanner engine.
Agent Workflow Red-Teaming
The Agent Scan capability simulates multi-agent execution paths to identify runtime risks like tool poisoning, memory manipulation, and jailbreak vulnerabilities. Implemented in common/agent/agent.go, the AgentManager coordinates task execution across complex workflows such as Dify or Coze configurations.
Unlike static code analysis, this feature executes dynamic simulations where malicious prompts propagate through agent chains. The analyzer tracks how data flows between tools and memory stores, flagging potential sandbox escapes or unauthorized function calls before deployment.
Jailbreak Evaluation and API Security Testing
For LLM robustness validation, AI-Infra-Guard includes a Jailbreak Evaluation engine triggered via common/websocket/knowledge_api.go. The system runs curated datasets against configured endpoints using multi-turn attack strategies including Many-Shot, PAIR, GOAT, and ActorAttack methodologies.
The platform also provides Model & API Relay Checking through common/websocket/api.go. When configured with APICheckerURL, this proxy performs Claude-signature verification, model fingerprinting, and black-box auditing via PAMELA and Ventor-QTest integrations.
Modular Architecture and Extensibility
The backend architecture centers on common/websocket/server.go, which bootstraps a Gin router and injects three core managers:
- TaskManager (
common/websocket/task_manager.go): Orchestrates scan jobs, handles chunked file uploads, and streams progress via Server-Sent Events (SSE) - AgentManager (
common/agent/agent.go): Drives multi-agent red-team workflows and external process coordination - ModelManager: Handles LLM endpoint configuration and model metadata persistence
Data persistence uses a lightweight SQLite abstraction layer defined in pkg/database/model.go and pkg/database/task.go. Rule loading occurs at startup via pkg/database/yaml_model.go, which converts YAML definitions into Go structs for the fingerprint database (data/fingerprints/), vulnerability rules (data/vuln/), and evaluation datasets (data/eval/).
Deployment and CLI Integration
AI-Infra-Guard supports multiple deployment modes via cmd/cli/main.go, which parses sub-commands to launch either the full web server or individual scanners.
Start the complete platform using Docker Compose:
docker compose -f docker-compose.images.yml up -d
# Access the Vue-based UI at http://localhost:8088
For CI/CD integration, use the standalone CLI tools:
# Scan AI infrastructure (vLLM, etc.)
aig-infra-scan http://127.0.0.1:8000
# Analyze MCP skills with specific models
pip install aig-skill-scan
export LLM_API_KEY="your-api-key"
aig-skill-scan --repo ./my-skill -m deepseek-v4-flash -o result.json
Submit tasks programmatically via the REST API:
curl -X POST http://localhost:8088/api/v1/app/tasks \
-H "Content-Type: application/json" \
-d '{"type":"infra","target":"http://127.0.0.1:8000"}'
The Vue-based frontend provides real-time scan progress, automatic Swagger documentation generation, and one-click initiation of all scan types.
Summary
- Comprehensive Coverage: Scans AI infrastructure (2,000+ CVEs), MCP servers (14+ categories), and agent workflows through specialized modules in
pkg/vulstruct/,internal/mcp/, andcommon/agent/ - Dynamic Simulation: Executes multi-agent red-team exercises and jailbreak attacks (Many-Shot, PAIR, GOAT) rather than relying solely on static analysis
- Extensible Rule Engine: Supports custom fingerprints, vulnerability definitions, and MCP plugins via YAML files in the
data/directory loaded bypkg/database/yaml_model.go - Flexible Deployment: Offers a full-stack web UI served by
common/websocket/server.goalongside CLI tools (aig-skill-scan,mcp-scan) for pipeline integration - Modern Architecture: Uses Gin framework with SQLite persistence, SSE progress streaming, and WebSocket support for real-time scanning feedback
Frequently Asked Questions
How does AI-Infra-Guard detect vulnerabilities in AI infrastructure?
The scanner in pkg/vulstruct/scanner.go performs service fingerprinting by connecting to running AI endpoints (vLLM, Ollama, etc.), extracting version information from responses, and matching these against a curated database of 2,000+ CVE rules stored in data/vuln/. This passive scanning approach identifies outdated components without requiring access to source code or internal APIs.
What security categories does the MCP scanner evaluate?
The MCP scanner implemented in internal/mcp/scanner.go evaluates servers and agent skills against 14+ security categories including tool hijacking, insecure dependencies, privilege escalation, and unauthorized data access. Users can extend coverage by adding new rule files to the data/mcp/ directory, which the plugin system loads automatically at startup via internal/mcp/plugins.go.
Can AI-Infra-Guard integrate into existing CI/CD pipelines?
Yes. The platform provides standalone CLI entry points through cmd/cli/main.go, including aig-skill-scan, mcp-scan, and agent-scan utilities. These tools support JSON output flags and non-interactive execution, allowing automated security scanning of AI skills and MCP servers during build processes before production deployment.
What types of jailbreak attacks does the evaluation module support?
The jailbreak evaluation engine accessed via common/websocket/knowledge_api.go implements multi-turn attack strategies including Many-Shot prompting, PAIR (Prompt Automatic Iterative Refinement), GOAT (Generative Offensive Agent Tester), and ActorAttack. These methodologies test LLM robustness against sophisticated adversarial prompting techniques beyond simple single-turn injection attempts.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →