# AI-Infra-Guard Prerequisites: Complete Setup Guide for Tencent's Hybrid Security Scanner

> Discover AI-Infra-Guard prerequisites. Learn how to set up Tencent's hybrid security scanner with Go, Python, and Docker for optimal performance. Get started now.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: getting-started
- Published: 2026-08-26

---

**To run AI-Infra-Guard, you need Go ≥ 1.20, Python ≥ 3.9, and optional Docker ≥ 20.10, with at least 2 CPU cores and 2 GB RAM for optimal performance.**

AI-Infra-Guard is a hybrid-stack security scanning platform developed by Tencent that combines a Go-based core with Python sub-modules for specialized scanning tasks. Before deploying this infrastructure security tool locally or integrating it into CI/CD pipelines, you must configure specific runtime environments and dependencies as defined in the `Tencent/AI-Infra-Guard` repository.

## Programming Language Runtimes

### Go ≥ 1.20 (Core Platform)

The main binary (`ai-infra-guard`) and the Agent executable are compiled from Go source code. The `go.mod` file at the repository root declares the minimum Go version required to build the core server and CLI components.

To compile the core binary from [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go), execute:

```bash
go build -o ai-infra-guard ./cmd/cli/main.go

```

### Python ≥ 3.9 (Scanning Modules)

Three distinct Python modules handle specialized scanning workflows: `mcp-scan`, `agent-scan`, and `AIG-PromptSecurity`. Each module maintains its own [`requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/requirements.txt) file with specific package dependencies.

Install all Python dependencies using **pip**:

```bash
pip install -r mcp-scan/requirements.txt
pip install -r agent-scan/requirements.txt
pip install -r AIG-PromptSecurity/requirements.txt

```

## Build and Package Management Tools

You need both **Go toolchain** (standard go commands) and **pip** (or a virtual environment tool) to fetch dependencies and build the application. The Go compiler handles the core infrastructure, while pip manages the Python sub-modules' libraries.

## Docker and Containerization (Optional)

While not strictly required, **Docker Engine ≥ 20.10** is recommended for simplified deployment. The repository provides a [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) file that orchestrates the full stack including the service, database, and agents.

To deploy using Docker Compose:

```bash
docker-compose up -d

```

## Network and Environment Configuration

### AIG_SERVER Connectivity

The CLI and Agent communicate with the backend via WebSocket connections. Before launching the Agent, you must set the `AIG_SERVER` environment variable to point to the running backend instance, as implemented in [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go).

For local development:

```bash
export AIG_SERVER=127.0.0.1:8088

```

## Hardware Resource Requirements

Allocate at least **2 CPU cores** and **2 GB RAM** for basic operation. Scanning operations—particularly MCP and Agent scans—are CPU- and memory-intensive, so increase resources if running multiple concurrent scans.

## Optional Dependencies

### A.I.G Service for LLM Integration

For AI-driven scanning capabilities described in [`skills/aig-scanner/README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/skills/aig-scanner/README.md), you need access to a running **A.I.G service** (a local or remote language model server). This LLM endpoint generates prompts and evaluates results for advanced security analysis.

### Chromium for Screenshot Utilities

The [`common/utils/chromium/screenshot.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/utils/chromium/screenshot.go) file indicates an optional dependency on **Chromium** (or a Chromium-compatible headless browser). This enables screenshot-based utilities during security assessments.

## Quick Start Checklist

1. Install **Go 1.20+** and build the core binary:

   ```bash
   go build -o ai-infra-guard ./cmd/cli/main.go
   ```

2. Install **Python 3.9+** and required packages:

   ```bash
   pip install -r mcp-scan/requirements.txt
   pip install -r agent-scan/requirements.txt
   pip install -r AIG-PromptSecurity/requirements.txt
   ```

3. (Optional) Start the Docker Compose stack:

   ```bash
   docker-compose up -d
   ```

4. Configure the backend address and launch components:

   ```bash
   export AIG_SERVER=127.0.0.1:8088
   ./ai-infra-guard webserver
   ```

## Summary

- **Go ≥ 1.20** is mandatory for building the core CLI and Agent from [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) and [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go).
- **Python ≥ 3.9** with pip-installed dependencies from three separate [`requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/requirements.txt) files powers the MCP, Agent, and PromptSecurity scanners.
- **Docker ≥ 20.10** provides optional containerized deployment via [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml).
- Network access to the `AIG_SERVER` backend and **2 CPU cores/2 GB RAM** are minimum operational requirements.
- Optional capabilities require **A.I.G service** for LLM features and **Chromium** for screenshot utilities.

## Frequently Asked Questions

### Do I need Python to run AI-Infra-Guard?

Yes, Python ≥ 3.9 is required because the `mcp-scan`, `agent-scan`, and `AIG-PromptSecurity` modules are implemented in Python with their own [`requirements.txt`](https://github.com/Tencent/AI-Infra-Guard/blob/main/requirements.txt) dependency files. These modules handle specific security scanning tasks that complement the Go core.

### Is Docker required for AI-Infra-Guard deployment?

No, Docker is optional but recommended. You can build and run the Go binaries directly using `go build`, but the [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) file provides a convenient way to orchestrate the entire stack including databases and multiple agent instances.

### What hardware resources are required for AI-Infra-Guard?

You need at least **2 CPU cores** and **2 GB RAM** for basic operation. The scanning processes, particularly MCP and Agent scans described in the Python modules, consume significant CPU and memory resources when running concurrently.

### How do I configure the backend server address for the Agent?

Set the `AIG_SERVER` environment variable before launching the Agent binary. According to [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go), the Agent expects this variable to define the WebSocket endpoint for backend communication, typically formatted as `127.0.0.1:8088` for local deployments.