AI-Infra-Guard Prerequisites: Complete Setup Guide for Tencent's Hybrid Security Scanner
To run AI-Infra-Guard, you need Go ≥ 1.20, Python ≥ 3.9, and optional Docker ≥ 20.10, with at least 2 CPU cores and 2 GB RAM for optimal performance.
AI-Infra-Guard is a hybrid-stack security scanning platform developed by Tencent that combines a Go-based core with Python sub-modules for specialized scanning tasks. Before deploying this infrastructure security tool locally or integrating it into CI/CD pipelines, you must configure specific runtime environments and dependencies as defined in the Tencent/AI-Infra-Guard repository.
Programming Language Runtimes
Go ≥ 1.20 (Core Platform)
The main binary (ai-infra-guard) and the Agent executable are compiled from Go source code. The go.mod file at the repository root declares the minimum Go version required to build the core server and CLI components.
To compile the core binary from cmd/cli/main.go, execute:
go build -o ai-infra-guard ./cmd/cli/main.go
Python ≥ 3.9 (Scanning Modules)
Three distinct Python modules handle specialized scanning workflows: mcp-scan, agent-scan, and AIG-PromptSecurity. Each module maintains its own requirements.txt file with specific package dependencies.
Install all Python dependencies using pip:
pip install -r mcp-scan/requirements.txt
pip install -r agent-scan/requirements.txt
pip install -r AIG-PromptSecurity/requirements.txt
Build and Package Management Tools
You need both Go toolchain (standard go commands) and pip (or a virtual environment tool) to fetch dependencies and build the application. The Go compiler handles the core infrastructure, while pip manages the Python sub-modules' libraries.
Docker and Containerization (Optional)
While not strictly required, Docker Engine ≥ 20.10 is recommended for simplified deployment. The repository provides a docker-compose.yml file that orchestrates the full stack including the service, database, and agents.
To deploy using Docker Compose:
docker-compose up -d
Network and Environment Configuration
AIG_SERVER Connectivity
The CLI and Agent communicate with the backend via WebSocket connections. Before launching the Agent, you must set the AIG_SERVER environment variable to point to the running backend instance, as implemented in cmd/agent/main.go.
For local development:
export AIG_SERVER=127.0.0.1:8088
Hardware Resource Requirements
Allocate at least 2 CPU cores and 2 GB RAM for basic operation. Scanning operations—particularly MCP and Agent scans—are CPU- and memory-intensive, so increase resources if running multiple concurrent scans.
Optional Dependencies
A.I.G Service for LLM Integration
For AI-driven scanning capabilities described in skills/aig-scanner/README.md, you need access to a running A.I.G service (a local or remote language model server). This LLM endpoint generates prompts and evaluates results for advanced security analysis.
Chromium for Screenshot Utilities
The common/utils/chromium/screenshot.go file indicates an optional dependency on Chromium (or a Chromium-compatible headless browser). This enables screenshot-based utilities during security assessments.
Quick Start Checklist
-
Install Go 1.20+ and build the core binary:
go build -o ai-infra-guard ./cmd/cli/main.go -
Install Python 3.9+ and required packages:
pip install -r mcp-scan/requirements.txt pip install -r agent-scan/requirements.txt pip install -r AIG-PromptSecurity/requirements.txt -
(Optional) Start the Docker Compose stack:
docker-compose up -d -
Configure the backend address and launch components:
export AIG_SERVER=127.0.0.1:8088 ./ai-infra-guard webserver
Summary
- Go ≥ 1.20 is mandatory for building the core CLI and Agent from
cmd/cli/main.goandcmd/agent/main.go. - Python ≥ 3.9 with pip-installed dependencies from three separate
requirements.txtfiles powers the MCP, Agent, and PromptSecurity scanners. - Docker ≥ 20.10 provides optional containerized deployment via
docker-compose.yml. - Network access to the
AIG_SERVERbackend and 2 CPU cores/2 GB RAM are minimum operational requirements. - Optional capabilities require A.I.G service for LLM features and Chromium for screenshot utilities.
Frequently Asked Questions
Do I need Python to run AI-Infra-Guard?
Yes, Python ≥ 3.9 is required because the mcp-scan, agent-scan, and AIG-PromptSecurity modules are implemented in Python with their own requirements.txt dependency files. These modules handle specific security scanning tasks that complement the Go core.
Is Docker required for AI-Infra-Guard deployment?
No, Docker is optional but recommended. You can build and run the Go binaries directly using go build, but the docker-compose.yml file provides a convenient way to orchestrate the entire stack including databases and multiple agent instances.
What hardware resources are required for AI-Infra-Guard?
You need at least 2 CPU cores and 2 GB RAM for basic operation. The scanning processes, particularly MCP and Agent scans described in the Python modules, consume significant CPU and memory resources when running concurrently.
How do I configure the backend server address for the Agent?
Set the AIG_SERVER environment variable before launching the Agent binary. According to cmd/agent/main.go, the Agent expects this variable to define the WebSocket endpoint for backend communication, typically formatted as 127.0.0.1:8088 for local deployments.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →