AI-Infra-Guard Architecture: Hybrid Go-Python Platform for AI Infrastructure Security

AI-Infra-Guard employs a hybrid architecture combining a Go-based core service for orchestration and web APIs with Python scanning modules for specialized security analysis, communicating via WebSocket streams and REST endpoints.

The Tencent/AI-Infra-Guard project implements a modular, extensible security scanning platform designed to audit AI infrastructure components. Its architecture separates high-performance orchestration from domain-specific analysis logic, enabling independent evolution of the scanning engine while maintaining a unified management interface.

Core Components of the AI-Infra-Guard Architecture

Go Core Application

The foundation of AI-Infra-Guard is a Go-based core service that handles all orchestration, API exposure, and task management. Located in cmd/cli/main.go, this component provides both CLI entry points and a web server implementation found in cmd/cli/cmd/webserver.go.

The Go layer manages:

Python Scanning Sub-Modules

Specialized security logic resides in Python sub-modules that the Go core invokes as subprocesses. This separation allows domain experts to write complex analysis logic while the Go layer handles concurrency and I/O.

The three primary scanners include:

Each scanner operates as a command-line tool that reads target specifications from arguments and outputs structured JSON for the Go server to consume.

Rule and Knowledge Base

Detection capabilities rely on a comprehensive data layer stored in data/ directories containing YAML and JSON configurations:

  • data/fingerprints/: Technology and version detection signatures
  • data/vuln/: Vulnerability signatures and CVE mappings
  • data/mcp/: MCP-specific security rules

Both Go and Python components load these rules at runtime, ensuring consistent detection logic across the stack.

Data Flow and Interaction Model

The AI-Infra-Guard architecture follows a specific execution pattern when processing scan requests:

  1. User Interface Request: The Vue/Vite frontend (frontend/src/pages/) sends a POST request to /api/v1/tasks via the OpenAPI-defined REST interface
  2. Task Persistence: The Go server records the job in the database layer (pkg/database/task.go) and spawns a managed goroutine
  3. Scanner Invocation: The task manager executes the appropriate Python scanner (e.g., python mcp-scan/main.py --repo <target>) as a subprocess
  4. Rule Processing: The Python module loads relevant rules from data/ directories and performs analysis
  5. Real-time Updates: Progress events stream through the WebSocket implementation (common/websocket/server.go) to the frontend
  6. Result Aggregation: Final JSON output is parsed by the Go core, stored in the database, and made available via the REST API at /api/v1/tasks/<task-id>/result

Deployment Architecture

Docker Compose Setup

Production deployments use Docker Compose to containerize the entire stack. The docker-compose.images.yml file defines services for the Go server, Python environments, and the frontend UI:

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker compose -f docker-compose.images.yml up -d

This configuration exposes the web interface on port 8088 and ensures all scanner dependencies are pre-installed.

Manual Development Mode

For development or debugging individual components, you can run the Go server directly:

go build -o aig ./cmd/cli/main.go
./aig webserver --server 127.0.0.1:8088

Key Implementation Files

Understanding the AI-Infra-Guard architecture requires familiarity with these critical source files:

Practical Usage Examples

Starting the Complete Platform

docker compose -f docker-compose.images.yml up -d

Creating a Scan Task via API

curl -X POST http://localhost:8088/api/v1/tasks \
     -H "Content-Type: application/json" \
     -d '{
           "type":"mcp_scan",
           "target":"https://github.com/example/mcp-server",
           "options":{}
         }'

Checking Task Status

curl http://localhost:8088/api/v1/tasks/<task-id>

Running Python Scanners Directly

For CI/CD integration without the full stack:

pip install -r mcp-scan/requirements.txt
python mcp-scan/main.py --repo /path/to/project

Summary

  • Hybrid Language Stack: Go handles high-performance orchestration and APIs while Python manages complex security analysis logic
  • Modular Scanner Design: Independent Python modules for MCP, Agent, and Prompt security allow targeted analysis without core modifications
  • Real-time Communication: WebSocket streams in common/websocket/server.go provide live progress updates to the Vue frontend
  • Containerized Deployment: Docker Compose configurations enable single-command deployment across Linux, macOS, and Windows
  • Data-driven Detection: Centralized rule storage in data/ directories ensures consistent vulnerability detection across components

Frequently Asked Questions

What programming languages does AI-Infra-Guard use?

AI-Infra-Guard uses Go for the core application server, task management, and API layer, and Python for the specialized security scanning modules. The frontend is built with TypeScript using Vue and Vite.

How does the Go core communicate with Python scanners?

The Go core spawns Python processes as subprocesses and communicates via stdout and temporary JSON files. The common/websocket/task_manager.go handles the lifecycle of these external processes while streaming progress updates to connected clients.

Can AI-Infra-Guard be deployed without Docker?

Yes. You can build the Go binary manually using go build -o aig ./cmd/cli/main.go and run ./aig webserver, though you must ensure Python dependencies are installed for the scanner modules located in mcp-scan/, agent-scan/, and AIG-PromptSecurity/.

Where are the security rules and fingerprints stored?

All detection rules, vulnerability signatures, and MCP-specific configurations reside in the data/ directory, specifically in data/fingerprints/, data/vuln/, and data/mcp/. These YAML and JSON files are loaded by both the Go orchestrator and Python scanners at runtime.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →