# AI-Infra-Guard Architecture: Hybrid Go-Python Platform for AI Infrastructure Security

> Discover the AI-Infra-Guard architecture a hybrid Go-Python platform for AI infrastructure security. Learn how it combines Go orchestration with Python scanning for robust protection.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: architecture
- Published: 2026-08-26

---

**AI-Infra-Guard employs a hybrid architecture combining a Go-based core service for orchestration and web APIs with Python scanning modules for specialized security analysis, communicating via WebSocket streams and REST endpoints.**

The Tencent/AI-Infra-Guard project implements a modular, extensible security scanning platform designed to audit AI infrastructure components. Its architecture separates high-performance orchestration from domain-specific analysis logic, enabling independent evolution of the scanning engine while maintaining a unified management interface.

## Core Components of the AI-Infra-Guard Architecture

### Go Core Application

The foundation of AI-Infra-Guard is a **Go-based core service** that handles all orchestration, API exposure, and task management. Located in [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go), this component provides both CLI entry points and a web server implementation found in [`cmd/cli/cmd/webserver.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/webserver.go).

The Go layer manages:
- **WebSocket server** ([`common/websocket/server.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/server.go)) for real-time progress updates
- **Task scheduling** using goroutine pools ([`common/websocket/task_manager.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/task_manager.go))
- **Database persistence** via SQLite or configurable backends ([`pkg/database/task.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/task.go))
- **REST API** endpoints for task creation and result retrieval

### Python Scanning Sub-Modules

Specialized security logic resides in **Python sub-modules** that the Go core invokes as subprocesses. This separation allows domain experts to write complex analysis logic while the Go layer handles concurrency and I/O.

The three primary scanners include:
- **MCP-Scan** ([`mcp-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/main.py)): Performs static and dynamic code analysis on Model Context Protocol implementations
- **Agent-Scan** ([`agent-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/main.py)): Evaluates AI agent workflow security
- **AIG-PromptSecurity** ([`AIG-PromptSecurity/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/AIG-PromptSecurity/main.py)): Conducts LLM jailbreak and prompt injection testing

Each scanner operates as a command-line tool that reads target specifications from arguments and outputs structured JSON for the Go server to consume.

### Rule and Knowledge Base

Detection capabilities rely on a comprehensive **data layer** stored in `data/` directories containing YAML and JSON configurations:
- `data/fingerprints/`: Technology and version detection signatures
- `data/vuln/`: Vulnerability signatures and CVE mappings
- `data/mcp/`: MCP-specific security rules

Both Go and Python components load these rules at runtime, ensuring consistent detection logic across the stack.

## Data Flow and Interaction Model

The AI-Infra-Guard architecture follows a specific execution pattern when processing scan requests:

1. **User Interface Request**: The Vue/Vite frontend (`frontend/src/pages/`) sends a POST request to `/api/v1/tasks` via the OpenAPI-defined REST interface
2. **Task Persistence**: The Go server records the job in the database layer ([`pkg/database/task.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/task.go)) and spawns a managed goroutine
3. **Scanner Invocation**: The task manager executes the appropriate Python scanner (e.g., `python mcp-scan/main.py --repo <target>`) as a subprocess
4. **Rule Processing**: The Python module loads relevant rules from `data/` directories and performs analysis
5. **Real-time Updates**: Progress events stream through the WebSocket implementation ([`common/websocket/server.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/server.go)) to the frontend
6. **Result Aggregation**: Final JSON output is parsed by the Go core, stored in the database, and made available via the REST API at `/api/v1/tasks/<task-id>/result`

## Deployment Architecture

### Docker Compose Setup

Production deployments use Docker Compose to containerize the entire stack. The [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml) file defines services for the Go server, Python environments, and the frontend UI:

```bash
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker compose -f docker-compose.images.yml up -d

```

This configuration exposes the web interface on port 8088 and ensures all scanner dependencies are pre-installed.

### Manual Development Mode

For development or debugging individual components, you can run the Go server directly:

```bash
go build -o aig ./cmd/cli/main.go
./aig webserver --server 127.0.0.1:8088

```

## Key Implementation Files

Understanding the AI-Infra-Guard architecture requires familiarity with these critical source files:

- [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) - Application entry point and CLI framework
- [`cmd/cli/cmd/webserver.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/cmd/webserver.go) - HTTP server initialization and routing
- [`common/websocket/server.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/server.go) - WebSocket connection management for live updates
- [`common/websocket/task_manager.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/task_manager.go) - Goroutine pool and task lifecycle management
- [`pkg/database/task.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/task.go) - Database models and persistence logic
- [`mcp-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/mcp-scan/main.py) - MCP security scanner implementation
- [`agent-scan/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/agent-scan/main.py) - AI agent workflow analyzer
- [`AIG-PromptSecurity/main.py`](https://github.com/Tencent/AI-Infra-Guard/blob/main/AIG-PromptSecurity/main.py) - LLM prompt security evaluator
- [`api.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/api.md) - OpenAPI/Swagger documentation served at [`/docs/index.html`](https://github.com/Tencent/AI-Infra-Guard/blob/main//docs/index.html)

## Practical Usage Examples

### Starting the Complete Platform

```bash
docker compose -f docker-compose.images.yml up -d

```

### Creating a Scan Task via API

```bash
curl -X POST http://localhost:8088/api/v1/tasks \
     -H "Content-Type: application/json" \
     -d '{
           "type":"mcp_scan",
           "target":"https://github.com/example/mcp-server",
           "options":{}
         }'

```

### Checking Task Status

```bash
curl http://localhost:8088/api/v1/tasks/<task-id>

```

### Running Python Scanners Directly

For CI/CD integration without the full stack:

```bash
pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project

```

## Summary

- **Hybrid Language Stack**: Go handles high-performance orchestration and APIs while Python manages complex security analysis logic
- **Modular Scanner Design**: Independent Python modules for MCP, Agent, and Prompt security allow targeted analysis without core modifications
- **Real-time Communication**: WebSocket streams in [`common/websocket/server.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/server.go) provide live progress updates to the Vue frontend
- **Containerized Deployment**: Docker Compose configurations enable single-command deployment across Linux, macOS, and Windows
- **Data-driven Detection**: Centralized rule storage in `data/` directories ensures consistent vulnerability detection across components

## Frequently Asked Questions

### What programming languages does AI-Infra-Guard use?

AI-Infra-Guard uses **Go** for the core application server, task management, and API layer, and **Python** for the specialized security scanning modules. The frontend is built with **TypeScript** using Vue and Vite.

### How does the Go core communicate with Python scanners?

The Go core spawns Python processes as subprocesses and communicates via stdout and temporary JSON files. The [`common/websocket/task_manager.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/task_manager.go) handles the lifecycle of these external processes while streaming progress updates to connected clients.

### Can AI-Infra-Guard be deployed without Docker?

Yes. You can build the Go binary manually using `go build -o aig ./cmd/cli/main.go` and run `./aig webserver`, though you must ensure Python dependencies are installed for the scanner modules located in `mcp-scan/`, `agent-scan/`, and `AIG-PromptSecurity/`.

### Where are the security rules and fingerprints stored?

All detection rules, vulnerability signatures, and MCP-specific configurations reside in the `data/` directory, specifically in `data/fingerprints/`, `data/vuln/`, and `data/mcp/`. These YAML and JSON files are loaded by both the Go orchestrator and Python scanners at runtime.