What Is Tencent AI Infra Guard? A Complete Guide to the Open-Source AI Red-Team Platform

Tencent AI Infra Guard (A.I.G) is an open-source, hybrid-stack AI red-team platform that combines a high-performance Go core with Python agents to scan, evaluate, and harden AI infrastructure, MCP servers, AI agents, and prompt-generation pipelines.

Developed by Tencent and hosted on GitHub, this platform delivers deterministic security scanning augmented by LLM reasoning. It targets the full AI stack—from network-exposed inference endpoints to code-level vulnerabilities in Model Context Protocol (MCP) servers—through a modular, data-driven architecture.

Architecture Evolution and Design Principles

Tencent AI Infra Guard has matured through three distinct architectural phases, each expanding its scanning capabilities and deployment flexibility.

The Three-Phase Evolution

The platform’s development trajectory is documented in the architecture evolution spec, showing a clear progression from a simple CLI tool to a multi-module enterprise platform:

Phase Core Capabilities Tech Stack Deployment Model
v0.1 – Single-binary Infra scanner Network fingerprinting of AI services (Ollama, vLLM, Dify, etc.) with rule-driven CVE/GHSA matching Go (cmd/cli binary) Stand-alone CLI / lightweight Web UI
v2.6 – Dual-engine (Infra + MCP) Static and LLM-assisted code analysis for MCP servers; unified task API over WebSocket/REST Go + OpenAI-compatible LLM client (common/utils/models/openai.go) Single binary with internal/mcp module
v3.6+ – Multi-module platform Prompt-Security Evaluation (AIG-PromptSecurity/), Agent Scan (common/agent/), MCP Scan (mcp-scan/), Skill Scan (skill-scan/) as pluggable engines; Docker-compose orchestration Go (core services & task scheduler) + Python (agents, evaluation) Docker images, Compose, or single-binary fallback

Core Design Principles

According to the Tencent/AI-Infra-Guard source code, the platform adheres to three foundational principles:

  • Rule-first, LLM-augmented – Deterministic YAML fingerprints and vulnerability rules provide the baseline detection, while LLM reasoning is reserved for complex cases like MCP code audits and agent behavior simulation.
  • Language split by concern – Go handles high-concurrency network probing and the web/API layer in common/websocket/server.go, while Python manages LLM-heavy workflows such as jailbreak testing in AIG-PromptSecurity/main.py.
  • Data-driven detection – All signatures reside under the data/ directory (fingerprints/, vuln/, mcp/, eval/), enabling out-of-band rule updates without recompiling binaries.

Key Components and Source Code Structure

Understanding the repository layout is essential for customizing scans or contributing rules. The codebase splits functionality between Go-based infrastructure services and Python-based evaluation agents.

Go Core and CLI Entry Points

The Go implementation provides the primary execution environment and networking layer:

  • cmd/cli/main.go – The main entry point that initializes both the CLI interface and the embedded WebServer.
  • cmd/cli/cmd/scan.go – Implements the scan sub-command, parsing flags and creating a runner instance to execute tasks.
  • common/websocket/server.go – Hosts the WebSocket/REST task scheduler that orchestrates multi-module scans and streams results to the Web UI.

MCP and Agent Scanning Modules

For specialized AI security testing, the platform includes dedicated scanners:

  • internal/mcp/scanner.go – Contains the core logic for MCP server auditing, combining static rule matching with LLM-assisted code analysis to detect insecure tool implementations.
  • common/agent/agent_task.go – Defines the agent-scan workflow engine, handling multi-agent injection attacks, SSRF testing, and prompt leakage validation against target AI systems.

Python Evaluation Engines

The Python components handle complex semantic analysis and adversarial testing:

  • AIG-PromptSecurity/main.py – The prompt-security evaluation engine that executes jailbreak attacks and safety classifiers against target models.
  • skill-scan/ – A standalone Python package (aig-skill-scan) for repository-level code analysis of AI skills and tools.

How to Deploy and Use Tencent AI Infra Guard

The platform supports multiple deployment modes, from one-click Docker installations to custom Go binary builds.

For immediate access to the Web UI and API, use the pre-built Docker images:

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker-compose -f docker-compose.images.yml up -d

Once running, the Web interface is available at http://localhost:8088 and the Swagger-compatible API is accessible under /api/v1/....

CLI Scanning Examples

To perform raw infrastructure scans without Docker, build the Go binary and execute targeted probes:


# Build the Go binary

go build -o aig ./cmd/cli/main.go

# Scan a local vLLM instance

./aig scan -t http://127.0.0.1:8000 \
            --fps data/fingerprints \
            --vul data/vuln \
            --output result.json

This invokes the scanner defined in cmd/cli/cmd/scan.go, using the YAML definitions stored in data/fingerprints/ for service identification and data/vuln/ for CVE matching.

Python SDK Usage

For prompt-security evaluation or skill scanning, install the Python packages directly:

Skill scanning via CLI:

pip install aig-skill-scan
export LLM_API_KEY="your-api-key"
aig-skill-scan --repo /path/to/skill \
               -m deepseek-v4-flash \
               --language en \
               -o skill_result.json

Programmatic prompt evaluation:

from aig_promptsecurity import Evaluator

e = Evaluator(model="gpt-4o-mini", attack="jailbreak")
score = e.evaluate(prompt="You are a helpful assistant...")
print("Safety score:", score)

Summary

Tencent AI Infra Guard delivers a comprehensive AI red-team solution through its hybrid architecture:

  • Multi-layer scanning covers infrastructure (Ollama, vLLM), MCP servers, AI agents, and prompt vulnerabilities.
  • Hybrid Go/Python stack optimizes performance: Go manages high-concurrency networking in common/websocket/server.go, while Python handles LLM reasoning in AIG-PromptSecurity/.
  • Data-driven rules stored in data/fingerprints/, data/vuln/, and data/mcp/ allow hot-updates without recompilation.
  • Flexible deployment supports Docker Compose, standalone binaries from cmd/cli/main.go, or Python package installation.

Frequently Asked Questions

What types of AI infrastructure can Tencent AI Infra Guard scan?

The platform can fingerprint and assess network-exposed AI services including Ollama, vLLM, Dify, and various OpenAI-compatible endpoints through its data/fingerprints/ definitions. It also performs deep code analysis on MCP servers and custom AI agents to detect implementation flaws and security misconfigurations.

How does the hybrid Go and Python architecture benefit security scanning?

Go provides the high-performance core for concurrent network probing and API serving in cmd/cli/main.go and common/websocket/server.go, while Python handles computationally intensive LLM interactions for tasks like jailbreak testing and semantic code analysis. This separation ensures scalable infrastructure scanning without sacrificing the reasoning capabilities needed for complex AI security evaluations.

Can I use Tencent AI Infra Guard without Docker?

Yes. You can build the single-binary CLI from source using go build -o aig ./cmd/cli/main.go and run scans directly against targets. The platform also provides pure Python packages (aig-skill-scan, aig-promptsecurity) for users who only need specific evaluation modules without the full containerized stack.

Where are the vulnerability signatures stored and how are they updated?

All detection signatures reside in the data/ directory, specifically data/fingerprints/ for service identification, data/vuln/ for CVE/GHSA rules, and data/mcp/ for MCP-specific security checks. Because these are YAML files separate from the compiled binaries, security teams can update rules by modifying the filesystem or mounting new volumes without rebuilding the application or restarting containers.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →