What Kind of Threat Intelligence Does AI-Infra-Guard Leverage?
AI-Infra-Guard leverages a hybrid model combining local static analysis with two cloud-based threat intelligence services: supply-chain risk scanning for malicious Skills and real-time CVE/GHSA advisory lookups for OpenClaw versions.
The Tencent AI-Infra-Guard project augments its local security scanning capabilities with lightweight, privacy-preserving cloud lookups to detect supply-chain compromises and emerging vulnerabilities. This threat intelligence architecture ensures that scans remain current without requiring frequent skill updates or transmitting sensitive workspace data.
Hybrid Threat Intelligence Architecture
AI-Infra-Guard operates on a local-first, cloud-augmented principle similar to traditional antivirus solutions. The scanner performs fast static checks locally while querying remote databases for the latest threat signatures and vulnerability data that cannot be maintained efficiently within the skill itself.
This design delivers two distinct intelligence streams:
- Supply-chain risk intelligence – Detects malicious or compromised Skills that may have been altered after installation
- Advisory intelligence – Retrieves current CVE and GHSA vulnerability data for detected OpenClaw versions
Supply-Chain Risk Intelligence
The first intelligence stream targets supply-chain attacks against Skills installed from external registries. When AI-Infra-Guard encounters a Skill, it can query the cloud API to verify the component's security status.
According to skills/edgeone-clawscan/SKILL.md, the scanner sends a minimal data package to the GET /clawscan/skill_security endpoint:
skill_name– The identifier of the Skill being scannedsource– The registry label (e.g.,clawhubfor ClawHub registry)
The API returns a JSON verdict indicating whether the Skill has been flagged as malicious, compromised, or altered post-installation. This allows the scanner to detect supply-chain risks without maintaining a local blocklist that would quickly become stale.
CVE and GHSA Advisory Lookup
The second stream provides vulnerability advisory intelligence specific to the OpenClaw runtime itself. This ensures that scans account for known vulnerabilities in the underlying infrastructure.
The scanner queries GET /clawscan/advisories with the following parameters:
product_name– Fixed stringOpenClawversion– The detected OpenClaw version number running in the environment
This lookup retrieves up-to-date CVE and GHSA advisories relevant to the specific OpenClaw version in use. When the API returns vulnerability data, AI-Infra-Guard incorporates these findings into the final security report, ensuring comprehensive coverage of both Skill-level and infrastructure-level risks.
Privacy Controls and Data Transmission
AI-Infra-Guard implements strict privacy boundaries for its threat intelligence lookups. Only minimal metadata is transmitted; the Skill’s source code, conversation logs, workspace files, and any secrets remain entirely local and are never uploaded to Tencent’s infrastructure.
Operators maintain full control over these lookups through the AIG_CLOUD_LOOKUP environment variable. Setting this variable to off (or any falsey value) disables all outbound requests, forcing the scanner to rely exclusively on local checks. This configuration supports air-gapped environments and strict compliance requirements.
Implementation in the Source Code
The threat intelligence integration spans multiple components within the Tencent/AI-Infra-Guard repository:
skills/edgeone-clawscan/SKILL.md– Documents the external request specifications and threat intelligence flow, including the exact endpoints and parameters sentcommon/websocket/knowledge_api.go– Implements the HTTP client used by the Go backend to query the cloud APIs for the first-generation scanning enginecommon/websocket/knowledge2_api.go– Provides the second-generation API wrapper utilized by newer skills for improved performance and error handlingcmd/cli/cmd/scan.go– Serves as the CLI entry point that respects theAIG_CLOUD_LOOKUPenvironment variable and forwards relevant metadata to the backend intelligence services
Configuring Cloud Lookups
Enable or disable threat intelligence lookups using environment variables:
# Default behavior – cloud lookup enabled
export AIG_CLOUD_LOOKUP=true
# Air-gapped mode – disable all outbound requests
export AIG_CLOUD_LOOKUP=off
You can also query the threat intelligence endpoints manually for integration with external security tooling:
Supply-chain security lookup:
curl "${AIG_BASE_URL:-https://matrix.tencent.com/clawscan}/skill_security" \
-G --data-urlencode "skill_name=my-dangerous-skill" \
--data-urlencode "source=clawhub"
Vulnerability advisory lookup:
curl "${AIG_BASE_URL:-https://matrix.tencent.com/clawscan}/advisories" \
-G --data-urlencode "product_name=OpenClaw" \
--data-urlencode "version=1.0.15"
Both endpoints return JSON responses that the scanner parses and incorporates into its final report. If either request fails due to network errors, disabled lookup, or API unavailability, the scan continues using local checks and notes the omission in the output.
Summary
- AI-Infra-Guard combines local static analysis with cloud-based threat intelligence to detect supply-chain risks and infrastructure vulnerabilities.
- The supply-chain service (
/clawscan/skill_security) checks Skills against current threat data using only the skill name and registry source. - The advisory service (
/clawscan/advisories) retrieves CVE/GHSA data for specific OpenClaw versions. - Privacy is preserved by transmitting only minimal metadata—never source code, logs, or secrets.
- The
AIG_CLOUD_LOOKUPenvironment variable controls cloud connectivity, supporting offline or air-gapped deployments. - Core implementation resides in
skills/edgeone-clawscan/SKILL.md,knowledge_api.go,knowledge2_api.go, andcmd/cli/cmd/scan.go.
Frequently Asked Questions
What specific data does AI-Infra-Guard transmit for threat intelligence lookups?
AI-Infra-Guard transmits only minimal metadata required for the lookup. For supply-chain checks, it sends the skill_name and source registry label. For vulnerability lookups, it sends the fixed product string OpenClaw and the detected version number. According to the source code in skills/edgeone-clawscan/SKILL.md, no source code, conversation logs, workspace files, or secrets are ever uploaded to the cloud.
How do I disable cloud-based threat intelligence in AI-Infra-Guard?
Set the environment variable AIG_CLOUD_LOOKUP=off before running a scan. As implemented in cmd/cli/cmd/scan.go, any falsey value for this variable disables both the supply-chain risk lookup and the CVE advisory lookup, forcing the scanner to operate in pure local mode. This configuration is essential for air-gapped environments or strict data sovereignty requirements.
What happens if the threat intelligence API is unavailable during a scan?
When cloud lookups fail due to network errors, API downtime, or disabled connectivity, AI-Infra-Guard gracefully degrades to local-only scanning. The scan continues with existing static checks, and the final report notes which intelligence services were unavailable. This ensures that transient API failures do not block critical security assessments.
Which source files handle the threat intelligence API integration?
The integration is distributed across four key files: skills/edgeone-clawscan/SKILL.md defines the API contracts and external request specifications; common/websocket/knowledge_api.go implements the HTTP client for legacy skills; common/websocket/knowledge2_api.go provides the modern API wrapper; and cmd/cli/cmd/scan.go manages the CLI-level configuration and data routing to these services.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →