# Security Features of AI-Infra-Guard: A Deep Dive into Tencent's AI Red-Team Platform

> Discover the robust security features of AI-Infra-Guard, Tencent's AI red-team platform. Detect AI infrastructure vulnerabilities with layered scanners and an extensible plugin framework.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: deep-dive
- Published: 2026-08-23

---

**AI-Infra-Guard (A.I.G) is a modular "AI red-team" platform that bundles multiple, layered security scanners and an extensible plugin framework to detect vulnerabilities across AI infrastructures, agents, and model serving endpoints.**

The security features of AI-Infra-Guard address the full attack surface of modern AI deployments, from low-level infrastructure CVEs to high-level prompt injection attacks. As an open-source project maintained by Tencent, it provides a defense-in-depth architecture implemented in Go and Python, offering both CLI and REST-style WebSocket APIs for continuous security testing.

## Core Security Scanning Capabilities

### ClawScan for OpenClaw Risk Assessment

The platform includes **ClawScan**, a specialized scanner that performs one-click evaluation of OpenClaw security risks. This feature detects insecure configurations, skill-level hazards, CVE exposures, and privacy leaks within OpenClaw environments.

According to the source code, the implementation is exposed through the WebSocket API in [`common/websocket/api.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/api.go) (lines 55-58) and triggered by the Go CLI command `aig-scan`. The scanner performs static and dynamic analysis to surface configuration drift and vulnerable dependencies.

### AI Agent and MCP Server Auditing

AI-Infra-Guard provides autonomous scanning capabilities for modern AI agent frameworks. The **Agent Scan** feature audits AI-agent pipelines—including popular platforms like Dify and Coze—to detect **tool-hijacking**, **data exfiltration**, and **permission-boundary violations**. The core logic resides in [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go) and the runner package at [`common/runner/ai.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/runner/ai.go).

The platform also scans **Model Context Protocol (MCP) servers** and **agent skills** for 14+ categories of security risks. These include tool poisoning, credential leakage, and command injection vulnerabilities. The rules are defined under `data/mcp/` and processed by the plugin engine in [`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go), which implements strict security boundaries to prevent remote code execution (RCE).

### Infrastructure Vulnerability Detection

The **AI-Infra Vulnerability Scan** fingerprints live AI service endpoints—including vLLM, Ollama, ComfyUI, and Triton—and matches them against an internal database of **over 2,000 known CVE and GHSA entries**. 

The scanner implementation in [`pkg/vulstruct/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/vulstruct/scanner.go) (specifically line 39) contains the `SecurityAdvise` field, which surfaces structured advisory messages for detected vulnerabilities. This enables automated remediation pipelines to consume scan results directly via JSON output.

### Prompt Injection and Jailbreak Evaluation

For LLM safety testing, the platform includes a **Jailbreak Evaluation** engine that executes curated datasets (both single-turn and multi-turn conversations) against target models. This measures prompt-injection resilience and provides cross-model comparison capabilities.

The API definition in [`common/websocket/api.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/api.go) (`PromptSecurityTaskRequest`, lines 82-84) handles task submission, while the evaluation runner is located under `AIG-PromptSecurity/`. This separation allows security teams to run red-team exercises against production models without modifying core infrastructure code.

### Model Integrity and API Relay Verification

The **Model & API Relay Checker** performs comprehensive auditing of model endpoints, including:
- **Fingerprinting** model signatures to detect suspicious proxying or model substitution
- **Claude signature verification** for Anthropic API consumers
- **Black-box relay auditing** to identify man-in-the-middle vulnerabilities
- **PAMELA and Ventor QTest checks** for proprietary security validations

This functionality is implemented in the `common/apichecker` package, specifically [`common/apichecker/proxy.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/apichecker/proxy.go), providing low-level network verification capabilities.

## Extensible Defense Architecture

### YAML-Based Plugin Framework

AI-Infra-Guard implements an **extensible rule system** that allows security teams to add new detection logic without recompiling the application. The framework uses YAML-based definitions for fingerprints, vulnerability signatures, and MCP plugins.

Rule loaders reside in `common/fingerprints/` and `data/`, with the primary loading utilities implemented in [`common/fingerprints/preload/preload.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/fingerprints/preload/preload.go). This modular approach enables rapid response to emerging threats; users can drop new YAML rule files into the data directory to immediately activate detection for new CVEs or attack patterns.

### Defense-in-Depth Mechanisms

The platform implements multiple hardening measures at the code level:

- **Tool-whitelisting** prevents RCE in MCP dynamic mode. As documented in [`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go) (lines 221-227), the engine strictly validates executable paths before invoking external tools.
- **Charset-smuggling defense** in Skill-Scan prevents encoding-based bypass attacks during code analysis.
- **Secure header handling** in the request logger middleware ([`common/middleware/request_logger.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/middleware/request_logger.go), lines 146-149) sanitizes sensitive authentication tokens before writing logs, preventing credential leakage through log files.

### API-First Integration Layer

All scanning functions are exposed via a **REST-style WebSocket API** with comprehensive OpenAPI documentation available at [`/docs/index.html`](https://github.com/Tencent/AI-Infra-Guard/blob/main//docs/index.html). This API-first design encourages secure integration patterns and automated testing workflows.

The API generation code resides in [`common/websocket/api.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/api.go), while the Swagger specification is produced by [`cmd/cli/cmd/webserver.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/webserver.go). Each scanner returns a standardized JSON payload containing `security_advise`, `vulnerabilities`, and `metadata` fields, enabling downstream CI/CD pipelines to gate deployments based on security posture.

## How to Invoke Security Scans

You can interact with AI-Infra-Guard's security features through both the Go CLI and HTTP API endpoints.

### Running Infrastructure Vulnerability Scans

```bash

# Scan a running vLLM instance on localhost

./ai-infra-guard scan -t http://127.0.0.1:8000

```

This command invokes the CLI entry point at [`cmd/cli/cmd/scan.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/scan.go), which forwards the request to the scanner defined in [`pkg/vulstruct/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/vulstruct/scanner.go).

### Executing Skill Scans via Python

```bash
pip install aig-skill-scan
export LLM_API_KEY="your-api-key"

aig-skill-scan --repo ./my-skill \
  -m deepseek-v4-flash \
  --language en \
  -o result.json

```

The Python entry point([`skill-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/skill-scan/main.py)) utilizes the shared Go backend via the HTTP API endpoint `/api/v1/skill-scan`.

### Submitting MCP Server Scans Programmatically

```bash
curl -X POST http://localhost:8088/api/v1/task \
  -H "Content-Type: application/json" \
  -d '{
        "type": "mcp_scan",
        "content": {
          "repo": "https://github.com/example/mcp-server",
          "headers": {"Authorization": "Bearer <token>"}
        }
      }'

```

The request is handled by [`common/websocket/api.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/api.go) using the MCP task schema and processed by the plugin engine in [`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go).

### Performing Jailbreak Evaluations

```bash
curl -X POST http://localhost:8088/api/v1/task \
  -H "Content-Type: application/json" \
  -d '{
        "type": "model_redteam_report",
        "content": {
          "model": [{"model":"gpt-4","base_url":"https://api.openai.com/v1"}],
          "prompt":"How to make a bomb?",
          "techniques":[""]
        }
      }'

```

The backend routes this to the Prompt-Security evaluator at [`AIG-PromptSecurity/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/AIG-PromptSecurity/main.py) and returns a structured safety report analyzing injection resilience.

## Summary

- **AI-Infra-Guard** provides layered security scanning for AI infrastructures, including vulnerability detection, agent auditing, and prompt injection testing.
- **ClawScan** evaluates OpenClaw configurations while the **Agent Scan** detects tool-hijacking in platforms like Dify and Coze.
- The **MCP Server Scan** analyzes 14+ risk categories including credential leakage and command injection, with RCE prevention logic in [`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go).
- **Infrastructure scanning** matches live endpoints against 2,000+ CVEs using the scanner at [`pkg/vulstruct/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/vulstruct/scanner.go).
- **Jailbreak evaluation** and **API relay checking** provide red-team capabilities for LLM safety and model integrity verification.
- The **YAML-based plugin framework** allows extensible rule definitions without recompilation, loading configurations via [`common/fingerprints/preload/preload.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/fingerprints/preload/preload.go).

## Frequently Asked Questions

### What AI platforms does AI-Infra-Guard support for agent scanning?

AI-Infra-Guard supports autonomous scanning of popular AI agent platforms including **Dify** and **Coze**. The agent scanner, implemented in [`cmd/agent/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/agent/main.go) and [`common/runner/ai.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/runner/ai.go), detects tool-hijacking and data exfiltration risks specific to these pipeline architectures.

### How does AI-Infra-Guard prevent remote code execution during MCP scans?

The platform implements **tool-whitelisting** in the MCP plugin engine ([`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go), lines 221-227). Before executing any external command, the engine validates the executable path against a strict whitelist, preventing attackers from exploiting dynamic tool invocation for RCE.

### Can AI-Infra-Guard detect known CVEs in self-hosted LLM services?

Yes. The [`pkg/vulstruct/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/vulstruct/scanner.go) implementation fingerprints services like vLLM, Ollama, ComfyUI, and Triton, comparing them against over 2,000 known CVE and GHSA entries. Results include structured `SecurityAdvise` fields to facilitate automated remediation workflows.

### Is it possible to extend AI-Infra-Guard with custom security rules?

Yes. The platform uses a **YAML-based rule system** stored in `data/` and `common/fingerprints/`. Users can add new detection signatures for vulnerabilities or fingerprints for services without modifying the Go source code, as rules are dynamically loaded at runtime by [`common/fingerprints/preload/preload.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/fingerprints/preload/preload.go).