How to Find Example Use Cases for AI-Infra-Guard: A Complete Guide

Example use cases for AI-Infra-Guard are documented in the repository's top-level README.md, specialized submodule guides (mcp-scan, agent-scan, skill-scan), and the docs/ directory, covering Docker deployment, AI infrastructure vulnerability scanning, MCP server analysis, agent workflow testing, and jailbreak evaluation.

AI-Infra-Guard (A.I.G) is a modular AI red-team platform developed by Tencent that bundles four main security engines into a unified testing framework. Whether you are scanning local vLLM instances for CVE vulnerabilities, analyzing MCP servers for unsafe tool hijacking, or evaluating LLM jailbreak resistance, concrete implementation examples are embedded directly in the source repository. This guide maps each primary use case to its exact file location and provides copy-paste commands to reproduce real-world security testing scenarios.

Core Engine Capabilities and Example Applications

AI Infrastructure Vulnerability Scanning

The AI-infra vulnerability scan engine fingerprints running AI services such as vLLM, Ollama, and ComfyUI, matching them against more than 2,000 CVE entries. A typical use case involves scanning a locally running vLLM endpoint to discover outdated model libraries or dangerous misconfigurations before production deployment.

MCP and Skill Scanner Analysis

The MCP & Skill scanner analyzes MCP servers and agent-skill bundles using YAML fingerprints and CVE rules to detect unsafe tool hijacking or privilege escalation vulnerabilities. Users can upload a GitHub URL of a custom MCP server or analyze a zipped skill project without manually cloning repositories.

Multi-Agent Workflow Testing

The Agent-scan engine executes multi-agent workflows (Dify, Coze, or custom implementations) to check for loss-of-control, privilege-escalation, and data-leakage vulnerabilities. This engine is essential for validating that production AI agent pipelines cannot be manipulated into unauthorized actions.

Jailbreak Resistance Evaluation

The Jailbreak evaluation engine runs curated datasets against configured LLM endpoints, reporting success rates per attack type such as "Many-Shot" prompting. Security teams use this to assess the robustness of fine-tuned models against adversarial inputs before public release.

Step-by-Step Implementation Examples

Quick Docker Deployment for Web UI

To launch the complete AI-Infra-Guard platform with a pre-built web interface, execute the following commands from the repository root as documented in README.md:

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker-compose -f docker-compose.images.yml up -d

After deployment, the UI is reachable at http://localhost:8088 where you can access all scanning engines through a graphical interface.

Scanning a Running vLLM Service

To perform an AI infrastructure scan against a local vLLM endpoint, navigate to the web UI and select "AI基础设施安全扫描" (AI Infra Security Scan). Enter the target URL:

http://127.0.0.1:8000

Click "Start Scan" to fingerprint the service and check against the CVE database. This example is detailed in the README.md Quick Usage Guide section.

Using the aig-skill-scan CLI

For standalone skill analysis, install the dedicated CLI tool and scan local skill directories as shown in skills/aig-scanner/README.md:

pip install aig-skill-scan
export LLM_API_KEY="your-api-key"
aig-skill-scan --repo /path/to/skill \
               -m deepseek-v4-flash \
               --language en \
               -o result.json

Remote MCP Server Analysis

To analyze an MCP server directly from a remote GitHub repository without manually cloning, use the mcp-scan CLI as documented in mcp-scan/README.md:

./ai-infra-guard mcp-scan https://github.com/yourorg/your-mcp-server

The CLI automatically pulls the repository and executes the security scanner against the MCP configuration.

Jailbreak Evaluation Configuration

To evaluate a custom LLM endpoint against jailbreak datasets, first configure the model in the UI under Settings → Model Config:

Base URL: http://127.0.0.1:8000/v1
API Key: sk-your-key

Then select a dataset (e.g., "Many-Shot") and click "Start Evaluation" to generate quantitative resistance metrics. Sample test cases are available in the data/eval/example-datasets directory.

OpenClaw Skill Integration

Integrate AI-Infra-Guard as an OpenClaw skill to enable security scanning from chat interfaces, as documented in skills/aig-scanner/README.md:

clawhub install aig-scanner
export AIG_BASE_URL=https://aig.example.com/

Once installed, you can invoke scanning capabilities directly from any OpenClaw chat session.

Key Documentation Files and Source Locations

Understanding the repository structure helps locate specific examples quickly. According to the Tencent/AI-Infra-Guard source code, the following files contain authoritative use-case documentation:

  • README.md (top-level): Central hub for Docker deployment commands, CLI snippets, and UI quick-start guides.
  • docs/architecture_evolution.md: Illustrates how the four engines interconnect, helping you map specific use cases to the correct component.
  • mcp-scan/README.md: Details remote URL scanning syntax, YAML configuration files, and example prompts for MCP security analysis.
  • agent-scan/README.md: Contains CLI instructions for feeding Dify or Coze workflow definitions to the agent-scanner and interpreting multi-agent test results.
  • skills/aig-scanner/README.md: Provides exact CLI syntax for the skill-scan tool and OpenClaw integration steps.
  • api.md: Full Swagger-compatible specification for programmatic API access to all scanning engines.
  • CHANGELOG.md: Lists new features (such as SkillJack additions or new jailbreak datasets) that inspire fresh test scenarios.
  • data/eval/example-datasets/: Directory containing ready-made jailbreak test cases demonstrating real-world evaluation usage.

Summary

  • Example use cases for AI-Infra-Guard are primarily documented in the top-level README.md and specialized submodule guides under mcp-scan/, agent-scan/, and skills/.
  • The platform provides four core engines: AI infrastructure scanning, MCP/skill analysis, multi-agent workflow testing, and jailbreak evaluation.
  • Docker deployment via docker-compose.images.yml provides immediate access to the web UI at localhost:8088.
  • CLI tools like aig-skill-scan and mcp-scan enable headless automation and CI/CD integration for security pipelines.
  • Sample datasets in data/eval/example-datasets/ provide concrete jailbreak test scenarios for immediate LLM evaluation.
  • Integration examples for OpenClaw (aig-scanner skill) demonstrate how to embed security scanning into existing agent workflows.

Frequently Asked Questions

Where are the primary example commands documented in AI-Infra-Guard?

The primary example commands are documented in the top-level README.md file, which includes Docker startup instructions, CLI usage snippets, and UI configuration steps. Additional engine-specific examples are located in the respective submodule README files such as mcp-scan/README.md and agent-scan/README.md.

Can I run AI-Infra-Guard without Docker for testing individual components?

Yes. You can install individual components like aig-skill-scan via pip and run CLI commands directly against local repositories or remote URLs. The mcp-scan and agent-scan modules also provide standalone binaries that execute without requiring the full Docker stack.

How do I test my custom LLM model against jailbreak attacks using AI-Infra-Guard?

Configure your model endpoint in the web UI under Settings → Model Config by providing the base URL and API key. Then navigate to the Jailbreak Evaluation section, select a dataset from data/eval/example-datasets (such as "Many-Shot"), and execute the evaluation to receive quantitative resistance metrics per attack type.

What file contains the API specification for integrating AI-Infra-Guard into my own platform?

The api.md file at the repository root contains the complete Swagger-compatible API specification. This document details all programmatic endpoints for triggering scans, retrieving results, and managing configurations, enabling seamless integration with external security platforms and automated testing pipelines.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →