Security Features of AI-Infra-Guard: A Deep Dive into Tencent's AI Red-Team Platform
AI-Infra-Guard (A.I.G) is a modular "AI red-team" platform that bundles multiple, layered security scanners and an extensible plugin framework to detect vulnerabilities across AI infrastructures, agents, and model serving endpoints.
The security features of AI-Infra-Guard address the full attack surface of modern AI deployments, from low-level infrastructure CVEs to high-level prompt injection attacks. As an open-source project maintained by Tencent, it provides a defense-in-depth architecture implemented in Go and Python, offering both CLI and REST-style WebSocket APIs for continuous security testing.
Core Security Scanning Capabilities
ClawScan for OpenClaw Risk Assessment
The platform includes ClawScan, a specialized scanner that performs one-click evaluation of OpenClaw security risks. This feature detects insecure configurations, skill-level hazards, CVE exposures, and privacy leaks within OpenClaw environments.
According to the source code, the implementation is exposed through the WebSocket API in common/websocket/api.go (lines 55-58) and triggered by the Go CLI command aig-scan. The scanner performs static and dynamic analysis to surface configuration drift and vulnerable dependencies.
AI Agent and MCP Server Auditing
AI-Infra-Guard provides autonomous scanning capabilities for modern AI agent frameworks. The Agent Scan feature audits AI-agent pipelines—including popular platforms like Dify and Coze—to detect tool-hijacking, data exfiltration, and permission-boundary violations. The core logic resides in cmd/agent/main.go and the runner package at common/runner/ai.go.
The platform also scans Model Context Protocol (MCP) servers and agent skills for 14+ categories of security risks. These include tool poisoning, credential leakage, and command injection vulnerabilities. The rules are defined under data/mcp/ and processed by the plugin engine in internal/mcp/plugins.go, which implements strict security boundaries to prevent remote code execution (RCE).
Infrastructure Vulnerability Detection
The AI-Infra Vulnerability Scan fingerprints live AI service endpoints—including vLLM, Ollama, ComfyUI, and Triton—and matches them against an internal database of over 2,000 known CVE and GHSA entries.
The scanner implementation in pkg/vulstruct/scanner.go (specifically line 39) contains the SecurityAdvise field, which surfaces structured advisory messages for detected vulnerabilities. This enables automated remediation pipelines to consume scan results directly via JSON output.
Prompt Injection and Jailbreak Evaluation
For LLM safety testing, the platform includes a Jailbreak Evaluation engine that executes curated datasets (both single-turn and multi-turn conversations) against target models. This measures prompt-injection resilience and provides cross-model comparison capabilities.
The API definition in common/websocket/api.go (PromptSecurityTaskRequest, lines 82-84) handles task submission, while the evaluation runner is located under AIG-PromptSecurity/. This separation allows security teams to run red-team exercises against production models without modifying core infrastructure code.
Model Integrity and API Relay Verification
The Model & API Relay Checker performs comprehensive auditing of model endpoints, including:
- Fingerprinting model signatures to detect suspicious proxying or model substitution
- Claude signature verification for Anthropic API consumers
- Black-box relay auditing to identify man-in-the-middle vulnerabilities
- PAMELA and Ventor QTest checks for proprietary security validations
This functionality is implemented in the common/apichecker package, specifically common/apichecker/proxy.go, providing low-level network verification capabilities.
Extensible Defense Architecture
YAML-Based Plugin Framework
AI-Infra-Guard implements an extensible rule system that allows security teams to add new detection logic without recompiling the application. The framework uses YAML-based definitions for fingerprints, vulnerability signatures, and MCP plugins.
Rule loaders reside in common/fingerprints/ and data/, with the primary loading utilities implemented in common/fingerprints/preload/preload.go. This modular approach enables rapid response to emerging threats; users can drop new YAML rule files into the data directory to immediately activate detection for new CVEs or attack patterns.
Defense-in-Depth Mechanisms
The platform implements multiple hardening measures at the code level:
- Tool-whitelisting prevents RCE in MCP dynamic mode. As documented in
internal/mcp/plugins.go(lines 221-227), the engine strictly validates executable paths before invoking external tools. - Charset-smuggling defense in Skill-Scan prevents encoding-based bypass attacks during code analysis.
- Secure header handling in the request logger middleware (
common/middleware/request_logger.go, lines 146-149) sanitizes sensitive authentication tokens before writing logs, preventing credential leakage through log files.
API-First Integration Layer
All scanning functions are exposed via a REST-style WebSocket API with comprehensive OpenAPI documentation available at /docs/index.html. This API-first design encourages secure integration patterns and automated testing workflows.
The API generation code resides in common/websocket/api.go, while the Swagger specification is produced by cmd/cli/cmd/webserver.go. Each scanner returns a standardized JSON payload containing security_advise, vulnerabilities, and metadata fields, enabling downstream CI/CD pipelines to gate deployments based on security posture.
How to Invoke Security Scans
You can interact with AI-Infra-Guard's security features through both the Go CLI and HTTP API endpoints.
Running Infrastructure Vulnerability Scans
# Scan a running vLLM instance on localhost
./ai-infra-guard scan -t http://127.0.0.1:8000
This command invokes the CLI entry point at cmd/cli/cmd/scan.go, which forwards the request to the scanner defined in pkg/vulstruct/scanner.go.
Executing Skill Scans via Python
pip install aig-skill-scan
export LLM_API_KEY="your-api-key"
aig-skill-scan --repo ./my-skill \
-m deepseek-v4-flash \
--language en \
-o result.json
The Python entry point(skill-scan/main.py) utilizes the shared Go backend via the HTTP API endpoint /api/v1/skill-scan.
Submitting MCP Server Scans Programmatically
curl -X POST http://localhost:8088/api/v1/task \
-H "Content-Type: application/json" \
-d '{
"type": "mcp_scan",
"content": {
"repo": "https://github.com/example/mcp-server",
"headers": {"Authorization": "Bearer <token>"}
}
}'
The request is handled by common/websocket/api.go using the MCP task schema and processed by the plugin engine in internal/mcp/plugins.go.
Performing Jailbreak Evaluations
curl -X POST http://localhost:8088/api/v1/task \
-H "Content-Type: application/json" \
-d '{
"type": "model_redteam_report",
"content": {
"model": [{"model":"gpt-4","base_url":"https://api.openai.com/v1"}],
"prompt":"How to make a bomb?",
"techniques":[""]
}
}'
The backend routes this to the Prompt-Security evaluator at AIG-PromptSecurity/main.py and returns a structured safety report analyzing injection resilience.
Summary
- AI-Infra-Guard provides layered security scanning for AI infrastructures, including vulnerability detection, agent auditing, and prompt injection testing.
- ClawScan evaluates OpenClaw configurations while the Agent Scan detects tool-hijacking in platforms like Dify and Coze.
- The MCP Server Scan analyzes 14+ risk categories including credential leakage and command injection, with RCE prevention logic in
internal/mcp/plugins.go. - Infrastructure scanning matches live endpoints against 2,000+ CVEs using the scanner at
pkg/vulstruct/scanner.go. - Jailbreak evaluation and API relay checking provide red-team capabilities for LLM safety and model integrity verification.
- The YAML-based plugin framework allows extensible rule definitions without recompilation, loading configurations via
common/fingerprints/preload/preload.go.
Frequently Asked Questions
What AI platforms does AI-Infra-Guard support for agent scanning?
AI-Infra-Guard supports autonomous scanning of popular AI agent platforms including Dify and Coze. The agent scanner, implemented in cmd/agent/main.go and common/runner/ai.go, detects tool-hijacking and data exfiltration risks specific to these pipeline architectures.
How does AI-Infra-Guard prevent remote code execution during MCP scans?
The platform implements tool-whitelisting in the MCP plugin engine (internal/mcp/plugins.go, lines 221-227). Before executing any external command, the engine validates the executable path against a strict whitelist, preventing attackers from exploiting dynamic tool invocation for RCE.
Can AI-Infra-Guard detect known CVEs in self-hosted LLM services?
Yes. The pkg/vulstruct/scanner.go implementation fingerprints services like vLLM, Ollama, ComfyUI, and Triton, comparing them against over 2,000 known CVE and GHSA entries. Results include structured SecurityAdvise fields to facilitate automated remediation workflows.
Is it possible to extend AI-Infra-Guard with custom security rules?
Yes. The platform uses a YAML-based rule system stored in data/ and common/fingerprints/. Users can add new detection signatures for vulnerabilities or fingerprints for services without modifying the Go source code, as rules are dynamically loaded at runtime by common/fingerprints/preload/preload.go.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →